Docker MCP Guardian
Connects to the local Docker daemon to provide guarded container inspection and optional restart capabilities, with read-only defaults, credential redaction, canonical ID resolution, and bounded API timeouts.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Docker MCP Guardianwhat Docker containers are running right now?"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Docker MCP Guardian
A security-hardened Model Context Protocol (MCP) server written in Python with FastMCP that connects local LLM agents (Claude Desktop, Claude Code) to the Docker daemon with strict zero-trust boundaries.
Core Capabilities & Safeguards
Read-Only by Default: Mutation tools (
safe_restart_container) reject calls before touching the Docker socket unlessGUARDIAN_ALLOW_WRITE=trueis explicitly set.Canonical ID Resolution: Resolves container IDs to Docker's internal canonical name before evaluating regex denylists, preventing evasion via hex IDs.
Credential & Secret Redaction:
inspect_containerstrips all environment variable values, returning only variable keys to prevent LLM prompt leakage.Isolated Stdio JSON-RPC: Strict logging separation ensures zero unstructured stdout writes, preventing JSON-RPC stream corruption in MCP clients.
Bounded Daemon Timeouts: Every Docker API call is capped by
GUARDIAN_DOCKER_TIMEOUT(default 5s), so a wedged or missing daemon returns a structureddaemon_unavailableerror instead of hanging the session.
Related MCP server: Docker MCP Server
Quickstart
Prerequisites
Python 3.10+
Docker Engine / Docker Desktop
mcp>=1.0.0,<2(pinned to FastMCP API)
Local Installation
git clone https://github.com/SivaSaiKrishnaSuryadevara/docker-mcp-guardian.git
cd docker-mcp-guardian
python3 -m venv .venv
source .venv/bin/activate
pip install -r requirements.txt
pytest tests/ -vConnect to Claude Code
claude mcp add docker-guardian -- "$PWD/.venv/bin/python" "$PWD/server.py"For Claude Desktop, add the same interpreter and script paths (absolute) under mcpServers in claude_desktop_config.json.
Configuration
Variable | Default | Purpose |
|
| Must be |
|
| Containers that can never be restarted (always wins) |
| (unset) | If set, only matching containers can be restarted |
| error/exception/fatal/... | Pattern the log scanner flags |
|
| Seconds per Docker API call |
|
| Log level (logs go to stderr only) |
Write-up
The design decisions behind this server are covered in ARTICLE.md.
This server cannot be deployed
Maintenance
Related MCP Connectors
Zero-secret MCP gateway for AI agents: risk-scored, audited calls with human-in-the-loop approval.
- gatewayOAuthai.sealgate
MCP gateway with runtime security policy, tool-call-level control, and audit of agent actions.
Security & DLP proxy for MCP: tool-poisoning scans, PII redaction on tool args/results. Beta.
Hosting for AI agents: your AI client deploys Docker apps to live HTTPS URLs over MCP.
Related MCP Servers
- AlicenseNot gradedqualityDmaintenanceEnables secure Docker command execution from isolated environments like containers through MCP protocol. Provides tools for managing Docker containers, images, and Docker Compose services with security validation and async operation support.MIT
- AlicenseNot gradedqualityNot gradedmaintenanceEnables AI assistants to interact with Docker containers through safe, permission-controlled access to inspect, manage, and diagnose containers, images, and compose services with built-in timeouts and AI-powered analysis.-
- AlicenseNot gradedqualityAmaintenanceEnables AI agents to manage Docker containers through a secure MCP interface, supporting container lifecycle operations, log inspection, resource monitoring, and system diagnostics with role-based access control.3MIT
- AlicenseAqualityBmaintenanceEnables agentic Docker container operations including file read/write, command execution, and interactive TTY sessions via the local Docker binary.1915 npmMIT