docker-mcp
docker-mcp
A read-only MCP server for Docker. Exposes your Docker daemon over the Model Context Protocol so AI assistants can inspect containers and logs without any write access.
Built with FastAPI and FastMCP.
Tools
Tool | Description |
| List running containers (pass |
| Full details for a container — ports, networks, env vars, mounts, resource limits |
| Fetch container logs with filtering by tail/head, time range, and regex pattern |
get_logs parameters
Parameter | Default | Description |
| — | Container ID or name |
|
| Last N lines. Mutually exclusive with |
| — | First N lines. Mutually exclusive with |
| — | UTC datetime — only return logs after this time |
| — | UTC datetime — only return logs before this time |
| — | Convenience shorthand: logs from the last N minutes |
| — | Regex (or substring) filter applied to log lines |
|
| Prefix each line with an RFC3339 timestamp |
Quick start
Docker run
docker run -d \
--name docker-mcp \
-p 8000:8000 \
-v /var/run/docker.sock:/var/run/docker.sock:ro \
-e MCP_API_KEY=mysecret \
codeberg.org/jhot/docker-mcp:latestDocker Compose
services:
docker-mcp:
image: codeberg.org/jhot/docker-mcp:latest
ports:
- "8000:8000"
volumes:
- /var/run/docker.sock:/var/run/docker.sock:ro
environment:
MCP_API_KEY: ${MCP_API_KEY:-}
restart: unless-stoppedMCP_API_KEY=mysecret docker compose up -dConfiguration
Variable | Default | Description |
| unset | Bearer token for |
| unset | Docker daemon socket. Unset = |
|
| Uvicorn bind address |
|
| Host port (container always listens on 8000) |
|
| Uvicorn log level |
MCP endpoint
The MCP Streamable HTTP endpoint is at http://localhost:8000/mcp.
Configure your client (e.g. Claude Desktop, Cursor) to connect to it:
{
"mcpServers": {
"docker": {
"url": "http://localhost:8000/mcp",
"headers": {
"Authorization": "Bearer mysecret"
}
}
}
}Omit headers if MCP_API_KEY is not set.
Security
The Docker socket grants full control of the Docker daemon. Treat access to this server the same as access to the socket itself:
Set
MCP_API_KEYfor any network-accessible deployment.Use a firewall or reverse proxy to restrict which clients can reach port 8000.
The
:rosocket mount prevents replacing the socket file but does not restrict Docker API calls —MCP_API_KEYis the primary access control.
Remote Docker
To connect to a remote Docker daemon instead of the local socket, remove the volumes block and set DOCKER_HOST:
docker run -d \
--name docker-mcp \
-p 8000:8000 \
-e DOCKER_HOST=tcp://192.168.1.10:2376 \
-e MCP_API_KEY=mysecret \
codeberg.org/jhot/docker-mcp:latestRoutes
Path | Auth | Description |
| public | Landing page |
| public |
|
| public | Tool metadata list |
| gated | FastMCP Streamable HTTP endpoint |
Development
Requirements: mise, Python 3.12, Docker
mise exec -- task install # uv sync
mise exec -- task fmt # ruff format
mise exec -- task lint # ruff check
mise exec -- task test # unit tests (no Docker required)
mise exec -- task test-integration # integration tests (requires live Docker)
mise exec -- task run # dev server at http://localhost:8000
mise exec -- task build # docker build
mise exec -- task up # docker compose up --buildLatest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/jhot21/docker-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server