Docker MCP
Supports an optional remote connection path through Cloudflare Access and Tunnel, where the included gateway verifies the Cloudflare Access JWT, configured audience, and allowed identity before forwarding MCP traffic to the Docker MCP server.
Provides tools for inspecting and maintaining a local Docker Desktop environment via a restricted Docker API proxy, including container, image, and Compose inspection; logs; stats; audits; narrow maintenance operations such as image pull, container restart, safe pruning/cleanup, and Compose redeploy; and Docker Scout quickview, CVE, recommendation, SBOM, and compare capabilities.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Docker MCPlist my running Docker containers and show their status"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Docker MCP
A restricted Model Context Protocol server for inspecting and maintaining a local Docker Desktop environment without exposing the raw Docker socket to the MCP client.
Independent project. This repository is not a fork of
docker/hub-mcpordocker/mcp-gateway. It serves a different purpose: local Docker Engine inspection and narrowly scoped maintenance. It can integrate with Docker MCP Gateway as a client/runtime layer, but it does not derive from that gateway's source code.
Why this exists
Giving an AI client the raw Docker socket is effectively equivalent to giving it Docker administrator access. Docker MCP puts a narrow policy boundary in front of the Engine instead:
MCP client
-> Docker MCP server
-> restricted Docker API proxy
-> Docker EngineFor a remote MCP client, an authenticated edge can be added:
Remote MCP client
-> Cloudflare Access
-> authenticated MCP gateway
-> Docker MCP server
-> restricted Docker API proxy
-> Docker EngineOnly the socket proxy receives /var/run/docker.sock.
Related MCP server: Docker MCP Server
Scope
Read-only inspection:
containers_listcontainer_inspectcontainer_logscontainer_statscompose_statusimages_listimage_inspectmcp_deployment_auditimage_usage_auditmaintenance_job_statusmaintenance_runner_status
Narrow maintenance:
image_pullcontainer_restartimage_prune_danglingcleanup_stale_mcp_containerscleanup_superseded_imagescompose_redeploy
Docker Scout:
scout_quickviewscout_cvesscout_recommendationsscout_sbomscout_compare
The project intentionally does not expose arbitrary docker exec, docker run, shell access, generic container deletion, arbitrary Compose paths, arbitrary builds, or the raw Docker socket.
Requirements
Windows with Docker Desktop
Docker MCP Toolkit
PowerShell
Docker Engine running
Local installation
Clone or download the repository, open PowerShell in the repository root, and run:
Set-ExecutionPolicy -Scope Process Bypass
.\install.ps1The default Docker MCP profile is dockerlocal. To use another profile:
.\install.ps1 -Profile my-profileThe installer:
builds the restricted Docker API proxy;
verifies the proxy on loopback;
builds the Docker MCP server image;
installs the local Docker MCP catalog entry;
adds the server to the selected Docker MCP profile;
enables the server tools and performs tool discovery.
Verify the installation:
.\test.ps1To run the Docker MCP Gateway locally with this profile:
docker mcp gateway run --profile dockerlocalFor supported local MCP clients, Docker MCP Toolkit can also connect a client to the profile:
docker mcp client connect <client-name> --profile dockerlocalThe exact client names supported by Docker MCP Toolkit depend on the installed Docker Desktop version.
Remote connection through Cloudflare Access
The remote path is optional. It is intended for an MCP client that cannot directly reach the local Docker MCP profile.
Use placeholders such as:
Public hostname: docker-mcp.example.com
MCP endpoint: https://docker-mcp.example.com/mcp
Access team: team-name.cloudflareaccess.com
Origin target: http://dockerlocal-gateway:8080No real hostname, tunnel identifier, account identifier, email address, audience tag, token, or credential belongs in this repository.
1. Start the remote stack
Run:
Set-ExecutionPolicy -Scope Process Bypass
.\install-public.ps1The installer prompts at runtime for:
Cloudflare Access team domain;
Access application audience tag;
allowed identity email.
Those values are written only to the ignored local file:
public/gateway.env2. Create the Cloudflare side
In Cloudflare:
create a Tunnel or use an existing Tunnel;
create a public hostname such as
docker-mcp.example.com;point the origin to
http://dockerlocal-gateway:8080;protect the hostname with a Cloudflare Access self-hosted application;
configure the Access policy for the identity that is allowed to use the MCP endpoint.
If cloudflared runs as a Docker container, attach it to the Docker MCP edge network:
docker network connect dockerlocal-public_edge <cloudflared-container>The public MCP client should then connect to:
https://docker-mcp.example.com/mcpThe included gateway verifies the Cloudflare Access JWT, the configured audience, and the configured identity before forwarding MCP traffic.
See docs/CONNECTING.md for the full local and remote connection flow.
Host-side Compose maintenance runner
The Docker MCP container deliberately does not receive arbitrary host filesystem access. Narrow Compose redeploy operations are therefore delegated to a small Windows runner.
Install it with:
.\install-maintenance-runner.ps1The runner accepts only:
an allowlisted project;
an allowlisted service;
redeploy_current;rebuild_and_redeploy.
By default only this project's own Compose services are allowlisted.
Additional host projects can be configured locally in:
%LOCALAPPDATA%\DockerLocalMCP\maintenance-projects.local.jsonStart from maintenance-projects.example.json. The local file is ignored by Git and should not contain secrets.
Secret handling
Do not commit:
public/gateway.env;.envfiles;API keys, tokens, passwords, Access audience values, or identity allowlists;
maintenance-projects.local.json;runtime logs, heartbeats, or maintenance job files.
Dependency and security automation
This repository includes:
Dependabot version updates for Python, Dockerfiles, Docker Compose and GitHub Actions;
CodeQL analysis for Python, JavaScript/TypeScript and GitHub Actions;
GitHub Dependabot vulnerability alerts through the repository's security settings.
License
MIT. See LICENSE.
This server cannot be deployed
Maintenance
Related MCP Connectors
Read-only MCP access to a documented IT fleet: state, changes, posture. 15 tools.
Securely control computers you explicitly pair through files, terminals, processes, screenshots, desktop UI/input, clipboard, browser automation, diagnostics, and document tools.
Read-only finance and operations controls for AI agents with evidence and safe next actions.
Read-only local AI advice, shared reports and website audits. No PC scan or local actions.
Related MCP Servers
- AlicenseNot gradedqualityNot gradedmaintenanceEnables AI assistants to interact with Docker containers through safe, permission-controlled access to inspect, manage, and diagnose containers, images, and compose services with built-in timeouts and AI-powered analysis.-
- AlicenseNot gradedqualityCmaintenanceProvides a local API to manage Docker containers and volumes, enabling operations like listing, inspecting, starting, stopping, and removing containers, as well as managing volumes, all through HTTP endpoints without shell commands.104 npmMIT
- AlicenseNot gradedqualityAmaintenanceA secure, local-first MCP server for read-only inspection and troubleshooting of development environments, exposing narrow, typed, auditable capabilities for repository inspection, log summarization, Docker review, and security scanning without granting unrestricted machine access.MIT
- AlicenseNot gradedqualityCmaintenanceEnables safe, local DevOps inspection through a JSON-lines server with schema validation, path isolation, and redaction, supporting read-only Git operations, Kubernetes YAML validation, Terraform plan summaries, and sanitized log analysis.MIT