21 KiB
| title | description | keywords | |
|---|---|---|---|
| Remote API | API Documentation for Docker |
|
Docker Remote API
Docker's Remote API uses an open schema model. In this model, unknown properties in incoming messages are ignored. Client applications need to take this behavior into account to ensure they do not break when talking to newer Docker daemons.
The API tends to be REST, but for some complex commands, like attach or pull, the HTTP connection is hijacked to transport STDOUT, STDIN, and STDERR.
By default the Docker daemon listens on unix:///var/run/docker.sock and the
client must have root access to interact with the daemon. If a group named
docker exists on your system, docker applies ownership of the socket to the
group.
To connect to the Docker daemon with cURL you need to use cURL 7.40 or
later, as these versions have the --unix-socket flag available. To
run curl against the daemon on the default socket, use the
following:
When using cUrl 7.50 or later:
$ curl --unix-socket /var/run/docker.sock http://localhost/containers/json
When using cURL 7.40, localhost must be omitted:
$ curl --unix-socket /var/run/docker.sock http://containers/json
If you have bound the Docker daemon to a different socket path or TCP port, you would reference that in your cURL rather than the default.
The current version of the API is v1.25 which means calling /info is the same
as calling /v1.25/info. To call an older version of the API use
/v1.24/info. If a newer daemon is installed, new properties may be returned
even when calling older versions of the API.
Use the table below to find the API version for a Docker version:
| Docker version | API version | Changes |
|---|---|---|
| 1.13.x | 1.25 | API changes |
| 1.12.x | 1.24 | API changes |
| 1.11.x | 1.23 | API changes |
| 1.10.x | 1.22 | API changes |
| 1.9.x | 1.21 | API changes |
| 1.8.x | 1.20 | API changes |
| 1.7.x | 1.19 | API changes |
| 1.6.x | 1.18 | API changes |
Refer to the GitHub repository for older releases.
Authentication
Authentication configuration is handled client side, so the
client has to send the authConfig as a POST in /images/(name)/push. The
authConfig, set as the X-Registry-Auth header, is currently a Base64 encoded
(JSON) string with the following structure:
{"username": "string", "password": "string", "email": "string",
"serveraddress" : "string", "auth": ""}
Callers should leave the auth empty. The serveraddress is a domain/ip
without protocol. Throughout this structure, double quotes are required.
Using Docker Machine with the API
If you are using docker-machine, the Docker daemon is on a host that
uses an encrypted TCP socket using TLS. This means, for Docker Machine users,
you need to add extra parameters to curl or wget when making test
API requests, for example:
curl --insecure \
--cert $DOCKER_CERT_PATH/cert.pem \
--key $DOCKER_CERT_PATH/key.pem \
https://YOUR_VM_IP:2376/images/json
wget --no-check-certificate --certificate=$DOCKER_CERT_PATH/cert.pem \
--private-key=$DOCKER_CERT_PATH/key.pem \
https://YOUR_VM_IP:2376/images/json -O - -q
Docker Events
The following diagram depicts the container states accessible through the API.
Some container-related events are not affected by container state, so they are not included in this diagram. These events are:
- export emitted by
docker export - exec_create emitted by
docker exec - exec_start emitted by
docker execafter exec_create - detach emitted when client is detached from container process
- exec_detach emitted when client is detached from exec process
Running docker rmi emits an untag event when removing an image name. The rmi command may also emit delete events when images are deleted by ID directly or by deleting the last tag referring to the image.
Acknowledgment: This diagram and the accompanying text were used with the permission of Matt Good and Gilder Labs. See Matt's original blog post Docker Events Explained.
Version history
This section lists each version from latest to oldest. Each listing includes a link to the full documentation set and the changes relevant in that release.
v1.25 API changes
Docker Remote API v1.25 documentation
POST /buildacceptsnetworkmodeparameter to specify network used during build.GET /images/(name)/jsonnow returnsOsVersionif populatedGET /infonow returnsIsolation.POST /containers/createnow takesAutoRemovein HostConfig, to enable auto-removal of the container on daemon side when the container's process exits.GET /containers/jsonandGET /containers/(id or name)/jsonnow return"removing"as a value for theState.Statusfield if the container is being removed. Previously, "exited" was returned as status.GET /containers/jsonnow acceptsremovingas a valid value for thestatusfilter.GET /containers/jsonnow supports filtering containers byhealthstatus.DELETE /volumes/(name)now accepts aforcequery parameter to force removal of volumes that were already removed out of band by the volume driver plugin.POST /containers/create/andPOST /containers/(name)/updatenow validates restart policies.POST /containers/createnow validates IPAMConfig in NetworkingConfig, and returns error for invalid IPv4 and IPv6 addresses (--ipand--ip6indocker create/run).POST /containers/createnow takes aMountsfield inHostConfigwhich replacesBinds,Volumes, andTmpfs. note:Binds,Volumes, andTmpfsare still available and can be combined withMounts.POST /buildnow performs a preliminary validation of theDockerfilebefore starting the build, and returns an error if the syntax is incorrect. Note that this change is unversioned and applied to all API versions.POST /buildacceptscachefromparameter to specify images used for build cache.GET /networks/endpoint now correctly returns a list of all networks, instead of the default network if a trailing slash is provided, but nonameorid.DELETE /containers/(name)endpoint now returns an error ofremoval of container name is already in progresswith status code of 400, when container name is in a state of removal in progress.GET /containers/jsonnow supports ais-taskfilter to filter containers that are tasks (part of a service in swarm mode).POST /containers/createnow takesStopTimeoutfield.POST /services/createandPOST /services/(id or name)/updatenow acceptMonitorandMaxFailureRatioparameters, which control the response to failures during service updates.POST /services/(id or name)/updatenow accepts aForceUpdateparameter inside theTaskTemplate, which causes the service to be updated even if there are no changes which would ordinarily trigger an update.GET /networks/(name)now returns fieldCreatedin response to show network created time.POST /containers/(id or name)/execnow accepts anEnvfield, which holds a list of environment variables to be set in the context of the command execution.GET /volumes,GET /volumes/(name), andPOST /volumes/createnow return theOptionsfield which holds the driver specific options to use for when creating the volume.GET /exec/(id)/jsonnow returnsPid, which is the system pid for the exec'd process.POST /containers/pruneprunes stopped containers.POST /images/pruneprunes unused images.POST /volumes/pruneprunes unused volumes.POST /networks/pruneprunes unused networks.- Every API response now includes a
Docker-Experimentalheader specifying if experimental features are enabled (value can betrueorfalse). - The
hostConfigoption now accepts the fieldsCpuRealtimePeriodandCpuRtRuntimeto allocate cpu runtime to rt tasks whenCONFIG_RT_GROUP_SCHEDis enabled in the kernel. - The
SecurityOptionsfield within theGET /inforesponse now includesusernsif user namespaces are enabled in the daemon.
v1.24 API changes
Docker Remote API v1.24 documentation
POST /containers/createnow takesStorageOptfield.GET /infonow returnsSecurityOptionsfield, showing ifapparmor,seccomp, orselinuxis supported.GET /infono longer returns theExecutionDriverproperty. This property was no longer used after integration with ContainerD in Docker 1.11.GET /networksnow supports filtering bylabelanddriver.GET /containers/jsonnow supports filtering containers bynetworkname or id.POST /containers/createnow takesIOMaximumBandwidthandIOMaximumIOpsfields. Windows daemon only.POST /containers/createnow returns an HTTP 400 "bad parameter" message if no command is specified (instead of an HTTP 500 "server error")GET /images/searchnow takes afiltersquery parameter.GET /eventsnow supports areloadevent that is emitted when the daemon configuration is reloaded.GET /eventsnow supports filtering by daemon name or ID.GET /eventsnow supports adetachevent that is emitted on detaching from container process.GET /eventsnow supports anexec_detachevent that is emitted on detaching from exec process.GET /images/jsonnow supports filterssinceandbefore.POST /containers/(id or name)/startno longer accepts aHostConfig.POST /images/(name)/tagno longer has aforcequery parameter.GET /images/searchnow supports maximum returned search resultslimit.POST /containers/{name:.*}/copyis now removed and errors out starting from this API version.- API errors are now returned as JSON instead of plain text.
POST /containers/createandPOST /containers/(id)/startallow you to configure kernel parameters (sysctls) for use in the container.POST /containers/<container ID>/execandPOST /exec/<exec ID>/startno longer expects a "Container" field to be present. This property was not used and is no longer sent by the docker client.POST /containers/create/now validates the hostname (should be a valid RFC 1123 hostname).POST /containers/create/HostConfig.PidModefield now acceptscontainer:<name|id>, to have the container join the PID namespace of an existing container.
v1.23 API changes
Docker Remote API v1.23 documentation
GET /containers/jsonreturns the state of the container, one ofcreated,restarting,running,paused,exitedordead.GET /containers/jsonreturns the mount points for the container.GET /networks/(name)now returns anInternalfield showing whether the network is internal or not.GET /networks/(name)now returns anEnableIPv6field showing whether the network has ipv6 enabled or not.POST /containers/(name)/updatenow supports updating container's restart policy.POST /networks/createnow supports enabling ipv6 on the network by setting theEnableIPv6field (doing this with a label will no longer work).GET /infonow returnsCgroupDriverfield showing what cgroup driver the daemon is using;cgroupfsorsystemd.GET /infonow returnsKernelMemoryfield, showing if "kernel memory limit" is supported.POST /containers/createnow takesPidsLimitfield, if the kernel is >= 4.3 and the pids cgroup is supported.GET /containers/(id or name)/statsnow returnspids_stats, if the kernel is >= 4.3 and the pids cgroup is supported.POST /containers/createnow allows you to override usernamespaces remapping and use privileged options for the container.POST /containers/createnow allows specifyingnocopyfor named volumes, which disables automatic copying from the container path to the volume.POST /authnow returns anIdentityTokenwhen supported by a registry.POST /containers/createwith bothHostnameandDomainnamefields specified will result in the container's hostname being set toHostname, rather thanHostname.Domainname.GET /volumesnow supports more filters, new added filters arenameanddriver.GET /containers/(id or name)/logsnow accepts adetailsquery parameter to stream the extra attributes that were provided to the containersLogOpts, such as environment variables and labels, with the logs.POST /images/loadnow returns progress information as a JSON stream, and has aquietquery parameter to suppress progress details.
v1.22 API changes
Docker Remote API v1.22 documentation
POST /container/(name)/updateupdates the resources of a container.GET /containers/jsonsupports filterisolationon Windows.GET /containers/jsonnow returns the list of networks of containers.GET /infoNow returnsArchitectureandOSTypefields, providing information about the host architecture and operating system type that the daemon runs on.GET /networks/(name)now returns aNamefield for each container attached to the network.GET /versionnow returns theBuildTimefield in RFC3339Nano format to make it consistent with other date/time values returned by the API.AuthConfignow supports aregistrytokenfor token based authenticationPOST /containers/createnow has a 4M minimum value limit forHostConfig.KernelMemory- Pushes initiated with
POST /images/(name)/pushand pulls initiated withPOST /images/createwill be cancelled if the HTTP connection making the API request is closed before the push or pull completes. POST /containers/createnow allows you to set a read/write rate limit for a device (in bytes per second or IO per second).GET /networksnow supports filtering byname,idandtype.POST /containers/createnow allows you to set the static IPv4 and/or IPv6 address for the container.POST /networks/(id)/connectnow allows you to set the static IPv4 and/or IPv6 address for the container.GET /infonow includes the number of containers running, stopped, and paused.POST /networks/createnow supports restricting external access to the network by setting theInternalfield.POST /networks/(id)/disconnectnow includes aForceoption to forcefully disconnect a container from networkGET /containers/(id)/jsonnow returns theNetworkIDof containers.POST /networks/createNow supports an options field in the IPAM config that provides options for custom IPAM plugins.GET /networks/{network-id}Now returns IPAM config options for custom IPAM plugins if any are available.GET /networks/<network-id>now returns subnets info for user-defined networks.GET /infocan now return aSystemStatusfield useful for returning additional information about applications that are built on top of engine.
v1.21 API changes
Docker Remote API v1.21 documentation
GET /volumeslists volumes from all volume drivers.POST /volumes/createto create a volume.GET /volumes/(name)get low-level information about a volume.DELETE /volumes/(name)remove a volume with the specified name.VolumeDriverwas moved fromconfigtoHostConfigto make the configuration portable.GET /images/(name)/jsonnow returns information about an image'sRepoTagsandRepoDigests.- The
configoption now accepts the fieldStopSignal, which specifies the signal to use to kill a container. GET /containers/(id)/statswill return networking information respectively for each interface.- The
HostConfigoption now includes theDnsOptionsfield to configure the container's DNS options. POST /buildnow optionally takes a serialized map of build-time variables.GET /eventsnow includes atimenanofield, in addition to the existingtimefield.GET /eventsnow supports filtering by image and container labels.GET /infonow lists engine version information and return the information ofCPUSharesandCpuset.GET /containers/jsonwill returnImageIDof the image used by container.POST /exec/(name)/startwill now return an HTTP 409 when the container is either stopped or paused.POST /containers/createnow takesKernelMemoryin HostConfig to specify kernel memory limit.GET /containers/(name)/jsonnow accepts asizeparameter. Setting this parameter to '1' returns container size information in theSizeRwandSizeRootFsfields.GET /containers/(name)/jsonnow returns aNetworkSettings.Networksfield, detailing network settings per network. This field deprecates theNetworkSettings.Gateway,NetworkSettings.IPAddress,NetworkSettings.IPPrefixLen, andNetworkSettings.MacAddressfields, which are still returned for backward-compatibility, but will be removed in a future version.GET /exec/(id)/jsonnow returns aNetworkSettings.Networksfield, detailing networksettings per network. This field deprecates theNetworkSettings.Gateway,NetworkSettings.IPAddress,NetworkSettings.IPPrefixLen, andNetworkSettings.MacAddressfields, which are still returned for backward-compatibility, but will be removed in a future version.- The
HostConfigoption now includes theOomScoreAdjfield for adjusting the badness heuristic. This heuristic selects which processes the OOM killer kills under out-of-memory conditions.
v1.20 API changes
Docker Remote API v1.20 documentation
GET /containers/(id)/archiveget an archive of filesystem content from a container.PUT /containers/(id)/archiveupload an archive of content to be extracted to an existing directory inside a container's filesystem.POST /containers/(id)/copyis deprecated in favor of the abovearchiveendpoint which can be used to download files and directories from a container.- The
hostConfigoption now accepts the fieldGroupAdd, which specifies a list of additional groups that the container process will run as.
v1.19 API changes
Docker Remote API v1.19 documentation
- When the daemon detects a version mismatch with the client, usually when the client is newer than the daemon, an HTTP 400 is now returned instead of a 404.
GET /containers/(id)/statsnow acceptsstreambool to get only one set of stats and disconnect.GET /containers/(id)/logsnow accepts asincetimestamp parameter.GET /infoThe fieldsDebug,IPv4Forwarding,MemoryLimit, andSwapLimitare now returned as boolean instead of as an int. In addition, the end point now returns the new boolean fieldsCpuCfsPeriod,CpuCfsQuota, andOomKillDisable.- The
hostConfigoption now accepts the fieldsCpuPeriodandCpuQuota POST /buildacceptscpuperiodandcpuquotaoptions
v1.18 API changes
Docker Remote API v1.18 documentation
GET /versionnow returnsOs,ArchandKernelVersion.POST /containers/createandPOST /containers/(id)/startallow you to set ulimit settings for use in the container.GET /infonow returnsSystemTime,HttpProxy,HttpsProxyandNoProxy.GET /images/jsonadded aRepoDigestsfield to include image digest information.POST /buildcan now set resource constraints for all containers created for the build.CgroupParentcan be passed in the host config to setup container cgroups under a specific cgroup.POST /buildclosing the HTTP request cancels the buildPOST /containers/(id)/execincludesWarningsfield to response.
