From 1c3206fad9fe7b97120d9d62df47f8c817778192 Mon Sep 17 00:00:00 2001 From: Alexa Date: Mon, 31 Aug 2026 10:11:54 -0500 Subject: [PATCH 01/19] docs: squash-merge security IA into platform-enterprise-IA Co-authored-by: Cursor --- content/guides/admin-set-up.md | 28 ++-- content/guides/admin-user-management.md | 12 +- content/guides/genai-claude-code-mcp.md | 2 +- content/guides/gha.md | 2 +- content/guides/zscaler.md | 2 +- content/manuals/_index.md | 6 +- content/manuals/accounts/_index.md | 6 +- content/manuals/accounts/create-account.md | 2 +- content/manuals/accounts/manage-account.md | 6 +- content/manuals/admin/_index.md | 2 +- content/manuals/admin/company/_index.md | 4 +- content/manuals/admin/company/company-faqs.md | 2 +- content/manuals/admin/insights.md | 14 +- content/manuals/admin/organization/_index.md | 4 +- .../admin/organization/deactivate-account.md | 2 +- .../admin/organization/manage/_index.md | 4 +- .../organization/manage/manage-a-team.md | 4 +- .../organization/manage/manage-licenses.md | 6 +- .../organization/manage/manage-products.md | 14 +- .../admin/organization/manage/members.md | 8 +- .../admin/organization/organization-faqs.md | 4 +- .../admin/organization/setup/_index.md | 4 +- .../organization/setup/convert-account.md | 2 +- .../organization/setup/general-settings.md | 6 +- .../admin/organization/setup/onboard.md | 30 ++-- content/manuals/ai/gordon/_index.md | 2 +- .../ai/gordon/concepts/data-privacy.md | 4 +- .../ai/gordon/how-to/configure-tools.md | 2 +- .../manuals/ai/gordon/how-to/permissions.md | 2 +- .../access-controls/organization.md | 6 +- .../ai/sandboxes/governance/audit/_index.md | 4 +- .../sandboxes/governance/audit/configure.md | 4 +- .../sign-in-enforcement.md | 2 +- content/manuals/build-cloud/_index.md | 2 +- content/manuals/build-cloud/ci.md | 8 +- .../features/networking/networking-how-tos.md | 2 +- .../manuals/desktop/features/wsl/_index.md | 2 +- content/manuals/desktop/release-notes.md | 68 ++++----- .../settings-and-maintenance/settings.md | 12 +- .../desktop/setup/install/mac-install.md | 4 +- .../install/mac-permission-requirements.md | 2 +- .../desktop/setup/install/windows-install.md | 4 +- .../windows-permission-requirements.md | 2 +- content/manuals/desktop/setup/sign-in.md | 4 +- .../manuals/desktop/use-desktop/kubernetes.md | 8 +- content/manuals/dhi/how-to/customize.md | 4 +- content/manuals/dhi/how-to/helm.md | 4 +- content/manuals/dhi/how-to/mirror.md | 16 +- content/manuals/dhi/how-to/policies.md | 2 +- content/manuals/dhi/how-to/use.md | 12 +- content/manuals/dhi/how-to/verify.md | 4 +- content/manuals/dhi/tools/api.md | 2 +- content/manuals/dhi/tools/mcp.md | 2 +- content/manuals/docker-hub/release-notes.md | 8 +- content/manuals/docker-hub/repos/create.md | 2 +- .../manuals/docker-hub/repos/manage/access.md | 6 +- .../docker-hub/repos/manage/builds/migrate.md | 4 +- .../manuals/docker-hub/repos/manage/export.md | 2 +- content/manuals/docker-hub/usage/pulls.md | 2 +- .../enterprise-deployment/_index.md | 2 +- .../msi-install-and-configure.md | 4 +- .../pkg-install-and-configure.md | 2 +- .../enterprise-deployment/use-intune.md | 2 +- .../enterprise-deployment/use-jamf-pro.md | 2 +- .../{security => }/hardened-desktop/_index.md | 21 ++- .../hardened-desktop/air-gapped-containers.md | 15 +- .../enhanced-container-isolation/_index.md | 5 +- .../enhanced-container-isolation/config.md | 9 +- .../enable-eci.md | 14 +- .../enhanced-container-isolation/faq.md | 9 +- .../limitations.md | 1 + .../image-access-management.md | 7 +- .../hardened-desktop/namespace-access.md | 2 + .../registry-access-management.md | 9 +- .../settings-management/_index.md | 15 +- .../compliance-reporting.md | 5 +- .../configure-admin-console.md | 5 +- .../configure-json-file.md | 3 +- .../settings-management/settings-reference.md | 5 +- content/manuals/enterprise/security/_index.md | 78 ---------- .../security/single-sign-on/FAQs/_index.md | 6 - .../security/single-sign-on/FAQs/general.md | 35 ----- .../security/single-sign-on/FAQs/idp-faqs.md | 53 ------- .../single-sign-on/FAQs/users-faqs.md | 62 -------- .../manuals/extensions/private-marketplace.md | 14 +- .../manuals/extensions/settings-feedback.md | 2 +- content/manuals/faqs/_index.md | 15 ++ .../manuals/{security => }/faqs/containers.md | 3 + .../FAQs => faqs}/domain-faqs.md | 5 +- .../FAQs => faqs}/enforcement-faqs.md | 11 +- .../manuals/{security => }/faqs/general.md | 9 +- .../{security => }/faqs/networking-and-vms.md | 5 +- content/manuals/faqs/sso-faqs.md | 140 ++++++++++++++++++ content/manuals/platform-release-notes.md | 16 +- .../manuals/{ => platform}/security/_index.md | 11 +- .../platform/security/access-tokens/_index.md | 9 ++ .../organization-access-tokens.md} | 3 +- .../access-tokens/personal-access-tokens.md} | 6 +- .../security/authentication}/2fa/_index.md | 1 + .../2fa/recover-hub-account.md | 0 .../security/authentication/_index.md | 9 ++ .../authentication}/enforce-sign-in/_index.md | 7 +- .../enforce-sign-in/methods.md | 1 + .../oidc-connections/_index.md | 8 +- .../oidc-connections/create-manage.md | 4 +- .../oidc-connections/rulesets-claims.md | 4 +- .../authentication}/single-sign-on/_index.md | 7 +- .../authentication}/single-sign-on/connect.md | 18 +-- .../single-sign-on/images/SSO.png | Bin .../authentication}/single-sign-on/manage.md | 3 +- .../single-sign-on/troubleshoot-sso.md | 4 +- .../security/images/jit-disabled-flow.svg | 0 .../security/images/jit-enabled-flow.svg | 0 .../security/provisioning/_index.md | 7 +- .../provisioning/auto-provisioning.md | 4 +- .../provisioning}/domain-management.md | 12 +- .../security/provisioning/just-in-time.md | 6 +- .../security/provisioning/scim/_index.md | 6 +- .../provisioning/scim/group-mapping.md | 6 +- .../provisioning/scim/migrate-scim.md | 8 +- .../provisioning/scim/provision-scim.md | 18 +-- .../provisioning/troubleshoot-provisioning.md | 0 .../security/roles-and-permissions/_index.md | 9 +- .../roles-and-permissions/core-roles.md | 6 +- .../custom-roles/_index.md | 6 +- .../custom-roles/manage.md | 2 +- .../custom-roles/permissions-reference.md | 2 +- .../security/security-announcements.md | 30 ++-- content/manuals/retired.md | 2 +- .../manuals/scout/explore/metrics-exporter.md | 8 +- .../scout/integrations/registry/acr.md | 2 +- .../integrations/registry/artifactory.md | 2 +- .../scout/integrations/registry/ecr.md | 2 +- content/manuals/security/faqs/_index.md | 6 - .../manuals/unassociated-machines/_index.md | 8 +- content/reference/api/hub/latest.yaml | 2 +- data/redirects.yml | 4 +- 137 files changed, 615 insertions(+), 619 deletions(-) rename content/manuals/enterprise/{security => }/hardened-desktop/_index.md (86%) rename content/manuals/enterprise/{security => }/hardened-desktop/air-gapped-containers.md (88%) rename content/manuals/enterprise/{security => }/hardened-desktop/enhanced-container-isolation/_index.md (97%) rename content/manuals/enterprise/{security => }/hardened-desktop/enhanced-container-isolation/config.md (94%) rename content/manuals/enterprise/{security => }/hardened-desktop/enhanced-container-isolation/enable-eci.md (85%) rename content/manuals/enterprise/{security => }/hardened-desktop/enhanced-container-isolation/faq.md (89%) rename content/manuals/enterprise/{security => }/hardened-desktop/enhanced-container-isolation/limitations.md (98%) rename content/manuals/enterprise/{security => }/hardened-desktop/image-access-management.md (92%) rename content/manuals/enterprise/{security => }/hardened-desktop/namespace-access.md (97%) rename content/manuals/enterprise/{security => }/hardened-desktop/registry-access-management.md (92%) rename content/manuals/enterprise/{security => }/hardened-desktop/settings-management/_index.md (81%) rename content/manuals/enterprise/{security => }/hardened-desktop/settings-management/compliance-reporting.md (94%) rename content/manuals/enterprise/{security => }/hardened-desktop/settings-management/configure-admin-console.md (93%) rename content/manuals/enterprise/{security => }/hardened-desktop/settings-management/configure-json-file.md (99%) rename content/manuals/enterprise/{security => }/hardened-desktop/settings-management/settings-reference.md (98%) delete mode 100644 content/manuals/enterprise/security/_index.md delete mode 100644 content/manuals/enterprise/security/single-sign-on/FAQs/_index.md delete mode 100644 content/manuals/enterprise/security/single-sign-on/FAQs/general.md delete mode 100644 content/manuals/enterprise/security/single-sign-on/FAQs/idp-faqs.md delete mode 100644 content/manuals/enterprise/security/single-sign-on/FAQs/users-faqs.md create mode 100644 content/manuals/faqs/_index.md rename content/manuals/{security => }/faqs/containers.md (94%) rename content/manuals/{enterprise/security/single-sign-on/FAQs => faqs}/domain-faqs.md (89%) rename content/manuals/{enterprise/security/single-sign-on/FAQs => faqs}/enforcement-faqs.md (70%) rename content/manuals/{security => }/faqs/general.md (85%) rename content/manuals/{security => }/faqs/networking-and-vms.md (87%) create mode 100644 content/manuals/faqs/sso-faqs.md rename content/manuals/{ => platform}/security/_index.md (92%) create mode 100644 content/manuals/platform/security/access-tokens/_index.md rename content/manuals/{enterprise/security/access-tokens.md => platform/security/access-tokens/organization-access-tokens.md} (98%) rename content/manuals/{security/access-tokens.md => platform/security/access-tokens/personal-access-tokens.md} (93%) rename content/manuals/{security => platform/security/authentication}/2fa/_index.md (99%) rename content/manuals/{security => platform/security/authentication}/2fa/recover-hub-account.md (100%) create mode 100644 content/manuals/platform/security/authentication/_index.md rename content/manuals/{enterprise/security => platform/security/authentication}/enforce-sign-in/_index.md (91%) rename content/manuals/{enterprise/security => platform/security/authentication}/enforce-sign-in/methods.md (99%) rename content/manuals/{enterprise/security => platform/security/authentication}/oidc-connections/_index.md (83%) rename content/manuals/{enterprise/security => platform/security/authentication}/oidc-connections/create-manage.md (92%) rename content/manuals/{enterprise/security => platform/security/authentication}/oidc-connections/rulesets-claims.md (94%) rename content/manuals/{enterprise/security => platform/security/authentication}/single-sign-on/_index.md (86%) rename content/manuals/{enterprise/security => platform/security/authentication}/single-sign-on/connect.md (92%) rename content/manuals/{enterprise/security => platform/security/authentication}/single-sign-on/images/SSO.png (100%) rename content/manuals/{enterprise/security => platform/security/authentication}/single-sign-on/manage.md (98%) rename content/manuals/{enterprise/security => platform/security/authentication}/single-sign-on/troubleshoot-sso.md (97%) rename content/manuals/{enterprise => platform}/security/images/jit-disabled-flow.svg (100%) rename content/manuals/{enterprise => platform}/security/images/jit-enabled-flow.svg (100%) rename content/manuals/{enterprise => platform}/security/provisioning/_index.md (95%) rename content/manuals/{enterprise => platform}/security/provisioning/auto-provisioning.md (91%) rename content/manuals/{enterprise/security => platform/security/provisioning}/domain-management.md (90%) rename content/manuals/{enterprise => platform}/security/provisioning/just-in-time.md (93%) rename content/manuals/{enterprise => platform}/security/provisioning/scim/_index.md (82%) rename content/manuals/{enterprise => platform}/security/provisioning/scim/group-mapping.md (97%) rename content/manuals/{enterprise => platform}/security/provisioning/scim/migrate-scim.md (94%) rename content/manuals/{enterprise => platform}/security/provisioning/scim/provision-scim.md (94%) rename content/manuals/{enterprise => platform}/security/provisioning/troubleshoot-provisioning.md (100%) rename content/manuals/{enterprise => platform}/security/roles-and-permissions/_index.md (89%) rename content/manuals/{enterprise => platform}/security/roles-and-permissions/core-roles.md (96%) rename content/manuals/{enterprise => platform}/security/roles-and-permissions/custom-roles/_index.md (87%) rename content/manuals/{enterprise => platform}/security/roles-and-permissions/custom-roles/manage.md (98%) rename content/manuals/{enterprise => platform}/security/roles-and-permissions/custom-roles/permissions-reference.md (98%) rename content/manuals/{ => platform}/security/security-announcements.md (91%) delete mode 100644 content/manuals/security/faqs/_index.md diff --git a/content/guides/admin-set-up.md b/content/guides/admin-set-up.md index 4978217bb01c..8947dec46184 100644 --- a/content/guides/admin-set-up.md +++ b/content/guides/admin-set-up.md @@ -56,11 +56,11 @@ This guide covers the following Docker features: repositories. Your organization was created with your subscription and is managed by one or more owners. Users signed into the organization are assigned seats based on the purchased subscription. -- [Enforce sign-in](/manuals/enterprise/security/enforce-sign-in/_index.md): +- [Enforce sign-in](/manuals/platform/security/authentication/enforce-sign-in/_index.md): By default, Docker Desktop doesn't require sign-in. You can configure settings to enforce this and ensure your developers sign in to your Docker organization. -- [SSO](/manuals/enterprise/security/single-sign-on/_index.md): Without SSO, +- [SSO](/manuals/platform/security/authentication/single-sign-on/_index.md): Without SSO, user management in a Docker organization is manual. Setting up an SSO connection between your identity provider and Docker ensures compliance with your security policy and automates user provisioning. Adding @@ -142,7 +142,7 @@ If you suspect your company has multiple Docker organizations: ### Gather requirements -[Settings Management](/manuals/enterprise/security/hardened-desktop/settings-management/_index.md) lets you preset numerous configuration parameters for Docker Desktop. +[Settings Management](/manuals/enterprise/hardened-desktop/settings-management/_index.md) lets you preset numerous configuration parameters for Docker Desktop. Work with the following stakeholders to establish your company's baseline configuration: @@ -154,11 +154,11 @@ configuration: Review these areas together: - Security features and - [enforcing sign-in](/manuals/enterprise/security/enforce-sign-in/_index.md) + [enforcing sign-in](/manuals/platform/security/authentication/enforce-sign-in/_index.md) for Docker Desktop users - Additional Docker products included in your subscriptions -To view the parameters that can be preset, see [Configure Settings Management](/manuals/enterprise/security/hardened-desktop/settings-management/configure-json-file.md#step-two-configure-the-settings-you-want-to-lock-in). +To view the parameters that can be preset, see [Configure Settings Management](/manuals/enterprise/hardened-desktop/settings-management/configure-json-file.md#step-two-configure-the-settings-you-want-to-lock-in). ### Optional: Meet with the Docker Implementation team @@ -172,11 +172,11 @@ To schedule a meeting, email successteam@docker.com. ### Send finalized settings files to the MDM team After reaching an agreement with the relevant teams about your baseline and -security configurations as outlined in the previous section, configure Settings Management either via [Docker Home](/manuals/enterprise/security/hardened-desktop/settings-management/configure-admin-console.md) or with an -[`admin-settings.json` file](/manuals/enterprise/security/hardened-desktop/settings-management/configure-json-file.md). +security configurations as outlined in the previous section, configure Settings Management either via [Docker Home](/manuals/enterprise/hardened-desktop/settings-management/configure-admin-console.md) or with an +[`admin-settings.json` file](/manuals/enterprise/hardened-desktop/settings-management/configure-json-file.md). Once the file is ready, collaborate with your MDM team to deploy your chosen -settings, along with your chosen method for [enforcing sign-in](/manuals/enterprise/security/enforce-sign-in/_index.md). +settings, along with your chosen method for [enforcing sign-in](/manuals/platform/security/authentication/enforce-sign-in/_index.md). > [!IMPORTANT] > @@ -196,9 +196,9 @@ organizations. Single sign-on (SSO) lets developers authenticate using their identity providers (IdPs) to access Docker. SSO is available for a whole company and all associated organizations, or an individual organization that has a Docker Business subscription. For more information, see the -[documentation](/manuals/enterprise/security/single-sign-on/_index.md). +[documentation](/manuals/platform/security/authentication/single-sign-on/_index.md). -You can also enable [SCIM](/manuals/enterprise/security/provisioning/scim/_index.md) +You can also enable [SCIM](/manuals/platform/security/provisioning/scim/_index.md) for further automation of provisioning and deprovisioning of users. #### Set up Docker product entitlements included in the subscription @@ -252,7 +252,7 @@ SSO and SCIM setup. > [!IMPORTANT] > > Some users may need CLI based logins to Docker Hub, and for this they will -> need a [personal access token (PAT)](/manuals/security/access-tokens.md). +> need a [personal access token (PAT)](/manuals/platform/security/access-tokens/personal-access-tokens.md). ### Test Registry Access Management and Image Access Management @@ -261,7 +261,7 @@ SSO and SCIM setup. > Communicate with your users before proceeding, as this step will impact all > existing users signing into your Docker organization. -If you plan to use [Registry Access Management (RAM)](/manuals/enterprise/security/hardened-desktop/registry-access-management.md) and/or [Image Access Management (IAM)](/manuals/enterprise/security/hardened-desktop/image-access-management.md): +If you plan to use [Registry Access Management (RAM)](/manuals/enterprise/hardened-desktop/registry-access-management.md) and/or [Image Access Management (IAM)](/manuals/enterprise/hardened-desktop/image-access-management.md): 1. Ensure your test developer signs in to Docker Desktop using their organization credentials @@ -312,7 +312,7 @@ that matches your verified domain must sign in using your SSO connection. Make sure the Identity provider groups associated with your SSO connection cover all the developer groups that you want to have access to the Docker subscription. -For instructions on how to enforce SSO, see [Enforce SSO](/manuals/enterprise/security/single-sign-on/connect.md). +For instructions on how to enforce SSO, see [Enforce SSO](/manuals/platform/security/authentication/single-sign-on/connect.md). ### Deploy configuration settings and enforce sign-in to users @@ -327,4 +327,4 @@ To continue optimizing your Docker environment: - Review your [organization's usage data](/manuals/admin/insights.md) to track adoption - Monitor [Docker Scout findings](/manuals/scout/explore/analysis.md) for security insights -- Explore [additional security features](/manuals/enterprise/security/_index.md) to enhance your configuration +- Explore [additional security features](/manuals/enterprise/hardened-desktop/_index.md) to enhance your configuration diff --git a/content/guides/admin-user-management.md b/content/guides/admin-user-management.md index 84ff0adb7545..f054ad47717c 100644 --- a/content/guides/admin-user-management.md +++ b/content/guides/admin-user-management.md @@ -58,7 +58,7 @@ Docker's predefined roles offer flexibility for various organizational needs. As - Editor: Partial administrative access to the organization. Editors can create, edit, and delete repositories. They can also edit an existing team's access permissions. - Owner: Full organization administrative access. Owners can manage organization repositories, teams, members, settings, and billing. -For more information, see [Roles and permissions](/manuals/enterprise/security/roles-and-permissions.md). +For more information, see [Roles and permissions](/manuals/platform/security/roles-and-permissions.md). #### Enhance with teams @@ -89,7 +89,7 @@ This page guides you through onboarding owners and members, and using tools like When you create a Docker organization, you automatically become its sole owner. While optional, adding additional owners can significantly ease the process of onboarding and managing your organization by distributing administrative responsibilities. It also ensures continuity and prevents blockers if the primary owner is unavailable. -For detailed information on owners, see [Roles and permissions](/manuals/enterprise/security/roles-and-permissions.md). +For detailed information on owners, see [Roles and permissions](/manuals/platform/security/roles-and-permissions.md). ### Invite members and assign roles @@ -119,11 +119,11 @@ SSO: - Reduces password-related vulnerabilities. - Simplifies onboarding as it works seamlessly with SCIM and group mapping for automated provisioning. -For more information, see the [SSO documentation](/manuals/enterprise/security/single-sign-on/_index.md). +For more information, see the [SSO documentation](/manuals/platform/security/authentication/single-sign-on/_index.md). #### Automate onboarding with SCIM and JIT provisioning -Streamline user provisioning and role management with [SCIM](/manuals/enterprise/security/provisioning/scim/_index.md) and [Just-in-Time (JIT) provisioning](/manuals/enterprise/security/provisioning/just-in-time.md). +Streamline user provisioning and role management with [SCIM](/manuals/platform/security/provisioning/scim/_index.md) and [Just-in-Time (JIT) provisioning](/manuals/platform/security/provisioning/just-in-time.md). With SCIM you can: @@ -145,7 +145,7 @@ It also: - Ensures consistent access control policies. - Help you scale permissions as teams grow or change. -For more information on how it works, see [Group mapping](/manuals/enterprise/security/provisioning/scim/group-mapping.md). +For more information on how it works, see [Group mapping](/manuals/platform/security/provisioning/scim/group-mapping.md). ## Monitoring and insights @@ -194,5 +194,5 @@ Now that you've mastered user and access management in Docker, you can: - Review your [activity logs](/manuals/admin/activity-logs.md) regularly to maintain security awareness - Check your [Insights dashboard](/manuals/admin/insights.md) to identify opportunities for optimization -- Explore [advanced security features](/manuals/enterprise/security/_index.md) to further enhance your Docker environment +- Explore [advanced security features](/manuals/enterprise/hardened-desktop/_index.md) to further enhance your Docker environment - Share best practices with your team to ensure consistent adoption of security policies diff --git a/content/guides/genai-claude-code-mcp.md b/content/guides/genai-claude-code-mcp.md index c71ee9f89203..7eecad93e79f 100644 --- a/content/guides/genai-claude-code-mcp.md +++ b/content/guides/genai-claude-code-mcp.md @@ -71,7 +71,7 @@ Make sure you have: 1. Select the **Docker Hub**MCP server 1. Add the MCP server, then open the **Configuration** tab 1. Enter your Docker Hub username -1. [Create a read-only personal access token](/security/access-tokens/#create-a-personal-access-token) and enter your access token under **Secrets** +1. [Create a read-only personal access token](/platform/security/access-tokens/personal-access-tokens/#create-a-personal-access-token) and enter your access token under **Secrets** 1. Save the configuration ![Docker Hub](images/genai-claude-code-mcp-catalog-docker-hub.avif "Docker Hub") diff --git a/content/guides/gha.md b/content/guides/gha.md index 4da6330e797f..197730cbe556 100644 --- a/content/guides/gha.md +++ b/content/guides/gha.md @@ -52,7 +52,7 @@ that, you must authenticate with your Docker credentials (username and access token) as part of the GitHub Actions workflow. For instructions on how to create a Docker access token, see -[Create and manage access tokens](/manuals/security/access-tokens.md). +[Create and manage access tokens](/manuals/platform/security/access-tokens/personal-access-tokens.md). Once you have your Docker credentials ready, add the credentials to your GitHub repository so you can use them in GitHub Actions: diff --git a/content/guides/zscaler.md b/content/guides/zscaler.md index c705e34e526a..80a8a0640b4a 100644 --- a/content/guides/zscaler.md +++ b/content/guides/zscaler.md @@ -47,7 +47,7 @@ necessary. If you are not using Zscaler as a system-level proxy, manually configure proxy settings in Docker Desktop. Set up proxy settings for all clients in the -organization using [Settings Management](/manuals/enterprise/security/hardened-desktop/settings-management/_index.md), +organization using [Settings Management](/manuals/enterprise/hardened-desktop/settings-management/_index.md), or edit proxy configuration in the Docker Desktop GUI under [**Settings > Resources > Proxies**](/manuals/desktop/settings-and-maintenance/settings.md#proxies). ## Install root certificates in Docker images diff --git a/content/manuals/_index.md b/content/manuals/_index.md index 20c7a49c57b4..befcaf0dd5f2 100644 --- a/content/manuals/_index.md +++ b/content/manuals/_index.md @@ -94,7 +94,7 @@ params: - title: Security description: Security guardrails for both administrators and developers. icon: lock-closed - link: /security/ + link: /platform/security/ - title: Subscription description: Commercial use licenses for Docker products. icon: credit-card @@ -104,6 +104,10 @@ params: description: Deploy Docker Desktop at scale within your company icon: arrow-down-tray link: /enterprise/enterprise-deployment/ + - title: Hardened Docker Desktop + description: Security features that strengthen developer environments. + icon: shield-check + link: /enterprise/hardened-desktop/ --- This section contains user guides on how to install, set up, configure, and use diff --git a/content/manuals/accounts/_index.md b/content/manuals/accounts/_index.md index 67ffb1841983..0cb3765e2f38 100644 --- a/content/manuals/accounts/_index.md +++ b/content/manuals/accounts/_index.md @@ -22,10 +22,10 @@ grid: - title: Personal access tokens description: Learn how to create and manage access tokens for your account. icon: lock-closed - link: /security/access-tokens/ + link: /platform/security/access-tokens/personal-access-tokens/ - title: Set up two-factor authentication description: Add an extra layer of authentication to your Docker account. - link: /security/2fa/ + link: /platform/security/authentication/2fa/ icon: device-phone-mobile - title: Organization overview description: Learn how to create and manage Docker organizations. @@ -56,7 +56,7 @@ Docker also ties a verified email to the account. - Email: How Docker contacts you for notifications and security-related communications. - Sign-in method: Email and password, - [single sign-on (SSO)](/manuals/enterprise/security/single-sign-on/_index.md), + [single sign-on (SSO)](/manuals/platform/security/authentication/single-sign-on/_index.md), Google, or GitHub. ## Next steps diff --git a/content/manuals/accounts/create-account.md b/content/manuals/accounts/create-account.md index 5bdff24960c3..c4986499e0cc 100644 --- a/content/manuals/accounts/create-account.md +++ b/content/manuals/accounts/create-account.md @@ -86,4 +86,4 @@ basis: ## Next steps - [Manage a Docker account](/manuals/accounts/manage-account.md) -- [Enable two-factor authentication](/manuals/security/2fa/_index.md) +- [Enable two-factor authentication](/manuals/platform/security/authentication/2fa/_index.md) diff --git a/content/manuals/accounts/manage-account.md b/content/manuals/accounts/manage-account.md index d75ab1ab4f35..856cfae99c20 100644 --- a/content/manuals/accounts/manage-account.md +++ b/content/manuals/accounts/manage-account.md @@ -77,7 +77,7 @@ To update your two-factor authentication (2FA) settings: 1. Select **2FA**. For more information, see -[Enable two-factor authentication](/manuals/security/2fa/_index.md). +[Enable two-factor authentication](/manuals/platform/security/authentication/2fa/_index.md). ## Manage personal access tokens @@ -88,7 +88,7 @@ To manage personal access tokens: 1. Select **Personal access tokens**. For more information, see -[Create and manage access tokens](/manuals/security/access-tokens.md). +[Create and manage access tokens](/manuals/platform/security/access-tokens/personal-access-tokens.md). ## Manage connected accounts @@ -127,4 +127,4 @@ For information on deactivating your account, see - [Docker accounts overview](/manuals/accounts/_index.md) - [Create a Docker account](/manuals/accounts/create-account.md) -- [Enable two-factor authentication](/manuals/security/2fa/_index.md) +- [Enable two-factor authentication](/manuals/platform/security/authentication/2fa/_index.md) diff --git a/content/manuals/admin/_index.md b/content/manuals/admin/_index.md index 780462e3d624..224820580228 100644 --- a/content/manuals/admin/_index.md +++ b/content/manuals/admin/_index.md @@ -22,7 +22,7 @@ grid: - title: Security description: Explore security features for administrators. icon: shield-check - link: /enterprise/security/ + link: /platform/security/ aliases: - /docker-hub/admin-overview --- diff --git a/content/manuals/admin/company/_index.md b/content/manuals/admin/company/_index.md index 55398a5b3474..5697d54e8be7 100644 --- a/content/manuals/admin/company/_index.md +++ b/content/manuals/admin/company/_index.md @@ -16,11 +16,11 @@ grid: - title: Configure SSO and SCIM description: Set up single sign-on and SCIM provisioning for your company. icon: key - link: /enterprise/security/single-sign-on/ + link: /platform/security/authentication/single-sign-on/ - title: Domain management description: Add and verify your company's domains. icon: check-badge - link: /enterprise/security/domain-management/ + link: /platform/security/provisioning/domain-management/ - title: FAQs description: Explore frequently asked questions about companies. link: /faq/admin/company-faqs/ diff --git a/content/manuals/admin/company/company-faqs.md b/content/manuals/admin/company/company-faqs.md index 8ab054c97ce7..c6f4f78d1652 100644 --- a/content/manuals/admin/company/company-faqs.md +++ b/content/manuals/admin/company/company-faqs.md @@ -46,4 +46,4 @@ organization members and change single sign-on (SSO) and System for Cross-domain Identity Management (SCIM) settings. Changes to company settings impact all users in each organization under the company. -For more information, see [Roles and permissions](/manuals/enterprise/security/roles-and-permissions.md). +For more information, see [Roles and permissions](/manuals/platform/security/roles-and-permissions.md). diff --git a/content/manuals/admin/insights.md b/content/manuals/admin/insights.md index 1b498cc8bbbc..8a6ff5d6567a 100644 --- a/content/manuals/admin/insights.md +++ b/content/manuals/admin/insights.md @@ -28,7 +28,7 @@ Key benefits include: To use Insights, you must meet the following requirements: - [Docker Business subscription](https://www.docker.com/pricing?ref=Docs&refAction=DocsAdminInsights) -- Administrators must [enforce sign-in](/manuals/enterprise/security/enforce-sign-in/_index.md) +- Administrators must [enforce sign-in](/manuals/platform/security/authentication/enforce-sign-in/_index.md) for users - Your Account Executive must turn on Insights for your organization @@ -59,9 +59,9 @@ The chart contains the following data: | Data | Description | | :--------------------------- | :---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| Active user | The number of users who have actively used Docker Desktop and either signed in with a Docker account that has a license in your organization or signed in to a Docker account with an email address from a domain associated with your organization.

Users who don’t sign in to an account associated with your organization are not represented in the data. To ensure users sign in with an account associated with your organization, you can [enforce sign-in](/manuals/enterprise/security/enforce-sign-in/_index.md). | +| Active user | The number of users who have actively used Docker Desktop and either signed in with a Docker account that has a license in your organization or signed in to a Docker account with an email address from a domain associated with your organization.

Users who don’t sign in to an account associated with your organization are not represented in the data. To ensure users sign in with an account associated with your organization, you can [enforce sign-in](/manuals/platform/security/authentication/enforce-sign-in/_index.md). | | Total organization members | The number of users who have used Docker Desktop, regardless of their Insights activity. | -| Users opted out of analytics | The number of users who are members of your organization that have opted out of sending analytics.

When users opt out of sending analytics, you won't see any of their data in Insights. To ensure that the data includes all users, you can use [Settings Management](/manuals/enterprise/security/hardened-desktop/settings-management/_index.md) to set `analyticsEnabled` for all your users. | +| Users opted out of analytics | The number of users who are members of your organization that have opted out of sending analytics.

When users opt out of sending analytics, you won't see any of their data in Insights. To ensure that the data includes all users, you can use [Settings Management](/manuals/enterprise/hardened-desktop/settings-management/_index.md) to set `analyticsEnabled` for all your users. | | Active users (graph) | The view over time for total active users. | ### Builds @@ -163,7 +163,7 @@ A Docker Desktop user export file contains the following data points: - Username: User's Docker ID - Email: User's email address associated with their Docker ID - Type: User type -- Role: User [role](/manuals/enterprise/security/roles-and-permissions.md) +- Role: User [role](/manuals/platform/security/roles-and-permissions.md) - Teams: Team(s) within your organization the user is a member of - Date Joined: The date the user joined your organization @@ -173,7 +173,7 @@ A Docker Desktop user export file contains the following data points: installed - Last Seen Date: The last date the user used the Docker Desktop application - Opted Out Analytics: Whether the user has opted out of the - [Send usage statistics](/manuals/enterprise/security/hardened-desktop/settings-management/settings-reference.md#send-usage-statistics) setting in Docker Desktop + [Send usage statistics](/manuals/enterprise/hardened-desktop/settings-management/settings-reference.md#send-usage-statistics) setting in Docker Desktop ## Troubleshoot Insights @@ -191,7 +191,7 @@ solutions to resolve common problems: If users have opted out of sending usage statistics for Docker Desktop, then their usage data will not be a part of Insights. To manage the setting at scale for all your users, you can use [Settings - Management](/manuals/enterprise/security/hardened-desktop/settings-management/_index.md) and turn on the + Management](/manuals/enterprise/hardened-desktop/settings-management/_index.md) and turn on the `analyticsEnabled` setting. - Ensure users use Docker Desktop and aren't using the standalone @@ -207,4 +207,4 @@ solutions to resolve common problems: Users who don’t sign in to an account associated with your organization are not represented in the data. To ensure users sign in with an account associated with your organization, you can [enforce - sign-in](/manuals/enterprise/security/enforce-sign-in/_index.md). + sign-in](/manuals/platform/security/authentication/enforce-sign-in/_index.md). diff --git a/content/manuals/admin/organization/_index.md b/content/manuals/admin/organization/_index.md index 438bf56e5a69..aec33fa838bc 100644 --- a/content/manuals/admin/organization/_index.md +++ b/content/manuals/admin/organization/_index.md @@ -26,7 +26,7 @@ grid: Start here to manage security and access for your organization, including single sign-on, provisioning, and image and registry access management. icon: shield-check - link: /enterprise/security/ + link: /platform/security/ --- A Docker organization is a collection of teams and repositories under @@ -67,7 +67,7 @@ permissions. For details about each role and its permissions, see [Roles and -permissions](/manuals/enterprise/security/roles-and-permissions/_index.md). +permissions](/manuals/platform/security/roles-and-permissions/_index.md). ## Next steps diff --git a/content/manuals/admin/organization/deactivate-account.md b/content/manuals/admin/organization/deactivate-account.md index cd4b8cfaa8f5..a1bd7972d207 100644 --- a/content/manuals/admin/organization/deactivate-account.md +++ b/content/manuals/admin/organization/deactivate-account.md @@ -37,7 +37,7 @@ organization: - Unlink your [GitHub and Bitbucket accounts](/manuals/docker-hub/repos/manage/builds/link-source.md#unlink-a-github-user-account). - For Business organizations, [remove your SSO - connection](/manuals/enterprise/security/single-sign-on/manage.md#delete-a-connection). + connection](/manuals/platform/security/authentication/single-sign-on/manage.md#delete-a-connection). ## Deactivate diff --git a/content/manuals/admin/organization/manage/_index.md b/content/manuals/admin/organization/manage/_index.md index 5ccfc50fa17c..f6854f955395 100644 --- a/content/manuals/admin/organization/manage/_index.md +++ b/content/manuals/admin/organization/manage/_index.md @@ -16,7 +16,7 @@ grid: - title: Security description: Configure single sign-on, provisioning, and access management. icon: shield-check - link: /enterprise/security/ + link: /platform/security/ - title: Billing description: Manage payment methods and view billing history. icon: credit-card @@ -31,7 +31,7 @@ revoke licenses and seats, and change access to Docker products. You manage your organization from [Docker Home](https://app.docker.com) and must be assigned the -[organization owner role](/manuals/enterprise/security/roles-and-permissions/_index.md). +[organization owner role](/manuals/platform/security/roles-and-permissions/_index.md). ## Seats and licenses diff --git a/content/manuals/admin/organization/manage/manage-a-team.md b/content/manuals/admin/organization/manage/manage-a-team.md index 31fd9b53bfc7..58b7acf48b20 100644 --- a/content/manuals/admin/organization/manage/manage-a-team.md +++ b/content/manuals/admin/organization/manage/manage-a-team.md @@ -34,7 +34,7 @@ An organization owner is an administrator who has the following permissions: organization settings - Specify [permissions](#permissions-reference) for each team in the organization -- Enable [SSO](/manuals/enterprise/security/single-sign-on/_index.md) for the +- Enable [SSO](/manuals/platform/security/authentication/single-sign-on/_index.md) for the organization When SSO is enabled for your organization, the organization owner can @@ -46,7 +46,7 @@ Organization owners can add others with the owner role to help them manage users, teams, and repositories in the organization. For more information on roles, see -[Roles and permissions](/manuals/enterprise/security/roles-and-permissions.md). +[Roles and permissions](/manuals/platform/security/roles-and-permissions.md). ## Create a team diff --git a/content/manuals/admin/organization/manage/manage-licenses.md b/content/manuals/admin/organization/manage/manage-licenses.md index 4a1d142dc728..56ccc7bd0638 100644 --- a/content/manuals/admin/organization/manage/manage-licenses.md +++ b/content/manuals/admin/organization/manage/manage-licenses.md @@ -50,7 +50,7 @@ a member: 1. Select **Emails or usernames**. 1. Enter the email addresses or Docker IDs of the people you want to invite, then assign their - [role](/manuals/enterprise/security/roles-and-permissions/_index.md). + [role](/manuals/platform/security/roles-and-permissions/_index.md). 1. Under **Licenses (optional)**, select one or more licenses that are available to your organization. 1. Select **Invite** to send the invite. @@ -88,8 +88,8 @@ set up auto-assignment for Docker Core as well. AI Governance licenses include single sign-on (SSO) and provisioning features regardless of your Docker Core subscription. Automatic license assignment requires -[setting up SSO](/manuals/enterprise/security/single-sign-on/connect.md), then -[provisioning](/manuals/enterprise/security/provisioning/_index.md) with System +[setting up SSO](/manuals/platform/security/authentication/single-sign-on/connect.md), then +[provisioning](/manuals/platform/security/provisioning/_index.md) with System for Cross-domain Identity Management (SCIM) or Just-in-Time (JIT). ## Manage licenses diff --git a/content/manuals/admin/organization/manage/manage-products.md b/content/manuals/admin/organization/manage/manage-products.md index dd6afd68cb5f..4ed394b5a99e 100644 --- a/content/manuals/admin/organization/manage/manage-products.md +++ b/content/manuals/admin/organization/manage/manage-products.md @@ -25,9 +25,9 @@ use the following procedures to control access for all members. To manage Docker Desktop access: -1. [Enforce sign-in](../../../enterprise/security/enforce-sign-in/_index.md). +1. [Enforce sign-in](../../../platform/security/authentication/enforce-sign-in/_index.md). 1. Manage members [manually](./members.md) or use - [provisioning](../../../enterprise/security/provisioning/_index.md). + [provisioning](../../../platform/security/provisioning/_index.md). With sign-in enforced, only users who are a member of your organization can use Docker Desktop after signing in. @@ -39,9 +39,9 @@ To manage Docker Hub access: 1. Sign in to [Docker Home](https://app.docker.com/) and select your organization, then select **Docker Desktop**. 1. Select **Registry Access** to configure - [Registry Access Management](../../../enterprise/security/hardened-desktop/registry-access-management.md). + [Registry Access Management](../../../enterprise/hardened-desktop/registry-access-management.md). 1. Select **Image Access** to control - [Image Access Management](../../../enterprise/security/hardened-desktop/image-access-management.md). + [Image Access Management](../../../enterprise/hardened-desktop/image-access-management.md). ### Docker Build Cloud access @@ -72,7 +72,7 @@ To manage Docker Scout access: [repository settings](../../../scout/explore/dashboard.md#repository-settings). 1. To manage access to Docker Scout for use on local images with Docker Desktop, use - [Settings Management](../../../enterprise/security/hardened-desktop/settings-management/_index.md) + [Settings Management](../../../enterprise/hardened-desktop/settings-management/_index.md) and set `sbomIndexing` to `false` to disable, or to `true` to enable. ### Testcontainers Cloud access @@ -98,7 +98,7 @@ To manage access to Testcontainers Cloud: > subscribe. To manage Docker Offload access for your organization, use [Settings -Management](../../../enterprise/security/hardened-desktop/settings-management/_index.md): +Management](../../../enterprise/hardened-desktop/settings-management/_index.md): 1. Sign in to [Docker Home](https://app.docker.com/), then select **Docker Desktop**. @@ -123,7 +123,7 @@ Management](../../../enterprise/security/hardened-desktop/settings-management/_i 1. Select **Save**. For more details on Settings Management, see the [Settings -reference](../../../enterprise/security/hardened-desktop/settings-management/settings-reference.md#enable-docker-offload). +reference](../../../enterprise/hardened-desktop/settings-management/settings-reference.md#enable-docker-offload). ## Monitor product usage for your organization diff --git a/content/manuals/admin/organization/manage/members.md b/content/manuals/admin/organization/manage/members.md index f8fe6cf014e2..75656ddc5913 100644 --- a/content/manuals/admin/organization/manage/members.md +++ b/content/manuals/admin/organization/manage/members.md @@ -40,7 +40,7 @@ or email address. 1000 members and separate multiple entries by comma, semicolon, or space. When you invite members, you assign them a role. See -[Roles and permissions](/manuals/enterprise/security/roles-and-permissions/_index.md) +[Roles and permissions](/manuals/platform/security/roles-and-permissions/_index.md) for details about the access permissions for each role. Pending invitations appear in the table. Invitees can accept or decline the @@ -196,7 +196,7 @@ being added to the team. ### Remove members from teams If your organization uses single sign-on (SSO) with -[SCIM](/manuals/enterprise/security/provisioning/scim/_index.md) enabled, you +[SCIM](/manuals/platform/security/provisioning/scim/_index.md) enabled, you should remove members from your identity provider (IdP). This automatically removes members from Docker. If SCIM is disabled, follow procedures in this doc to remove members manually in Docker. @@ -215,10 +215,10 @@ from a specific team: ### Update a member role Organization owners can manage -[roles](/manuals/enterprise/security/roles-and-permissions/_index.md) within +[roles](/manuals/platform/security/roles-and-permissions/_index.md) within an organization. If an organization is part of a company, the company owner can also manage that organization's roles. If you have SSO enabled, you can -use [SCIM for role mapping](/manuals/enterprise/security/provisioning/scim/_index.md). +use [SCIM for role mapping](/manuals/platform/security/provisioning/scim/_index.md). To update a member role: diff --git a/content/manuals/admin/organization/organization-faqs.md b/content/manuals/admin/organization/organization-faqs.md index e013e5539d7e..7ea67a06184f 100644 --- a/content/manuals/admin/organization/organization-faqs.md +++ b/content/manuals/admin/organization/organization-faqs.md @@ -28,12 +28,12 @@ assign them to a team during the invite process. ### Can I force my organization's members to authenticate before using Docker Desktop and are there any benefits? Yes. You can -[enforce sign-in](/manuals/enterprise/security/enforce-sign-in/_index.md). +[enforce sign-in](/manuals/platform/security/authentication/enforce-sign-in/_index.md). Some benefits of enforcing sign-in are: - Ensures users receive the benefits of your subscription. -- Ensures security features like [Image Access Management](/manuals/enterprise/security/hardened-desktop/image-access-management.md) and [Registry Access Management](/manuals/enterprise/security/hardened-desktop/registry-access-management.md) are applied. +- Ensures security features like [Image Access Management](/manuals/enterprise/hardened-desktop/image-access-management.md) and [Registry Access Management](/manuals/enterprise/hardened-desktop/registry-access-management.md) are applied. - Ensures you gain insights into users' activity. ### Can I convert my personal Docker ID to an organization account? diff --git a/content/manuals/admin/organization/setup/_index.md b/content/manuals/admin/organization/setup/_index.md index eb36ef60da67..1a30cc663c26 100644 --- a/content/manuals/admin/organization/setup/_index.md +++ b/content/manuals/admin/organization/setup/_index.md @@ -28,7 +28,7 @@ grid: - title: Security description: Configure single sign-on, provisioning, and access management. icon: shield-check - link: /enterprise/security/ + link: /platform/security/ --- Before you manage members and access, set up your Docker organization. You can @@ -39,7 +39,7 @@ an existing user account into an organization. You set up your organization from [Docker Home](https://app.docker.com) and must be assigned the -[organization owner role](/manuals/enterprise/security/roles-and-permissions/_index.md). +[organization owner role](/manuals/platform/security/roles-and-permissions/_index.md). Setting up an organization happens in broad phases: 1. You can create a new organization, or convert an existing user account diff --git a/content/manuals/admin/organization/setup/convert-account.md b/content/manuals/admin/organization/setup/convert-account.md index 7c5b856d5bfc..db3ebf6765e7 100644 --- a/content/manuals/admin/organization/setup/convert-account.md +++ b/content/manuals/admin/organization/setup/convert-account.md @@ -16,7 +16,7 @@ useful if you need multiple users to access your account and the repositories it’s connected to. Converting it to an organization gives you better control over permissions for these users through [teams](/manuals/admin/organization/manage/manage-a-team.md) and -[roles](/manuals/enterprise/security/roles-and-permissions.md). +[roles](/manuals/platform/security/roles-and-permissions.md). When you convert a user account to an organization, the account is migrated to a Docker Team subscription by default. diff --git a/content/manuals/admin/organization/setup/general-settings.md b/content/manuals/admin/organization/setup/general-settings.md index 3c7d4c9b2e04..95b95b139e72 100644 --- a/content/manuals/admin/organization/setup/general-settings.md +++ b/content/manuals/admin/organization/setup/general-settings.md @@ -33,7 +33,7 @@ To edit this information: After configuring your organization information, you can: -- [Configure single sign-on (SSO)](/manuals/enterprise/security/single-sign-on/connect.md) -- [Set up SCIM provisioning](/manuals/enterprise/security/provisioning/scim/_index.md) -- [Manage domains](/manuals/enterprise/security/domain-management.md) +- [Configure single sign-on (SSO)](/manuals/platform/security/authentication/single-sign-on/connect.md) +- [Set up SCIM provisioning](/manuals/platform/security/provisioning/scim/_index.md) +- [Manage domains](/manuals/platform/security/provisioning/domain-management.md) - [Create a company](/manuals/admin/company/new-company.md) diff --git a/content/manuals/admin/organization/setup/onboard.md b/content/manuals/admin/organization/setup/onboard.md index e71216f1bff7..e77ed85ef52f 100644 --- a/content/manuals/admin/organization/setup/onboard.md +++ b/content/manuals/admin/organization/setup/onboard.md @@ -105,7 +105,7 @@ add additional owners. To add an owner, invite a user and assign them the owner role. For more details, see [Invite members](/manuals/admin/organization/manage/members.md) and -[Roles and permissions](/manuals/enterprise/security/roles-and-permissions.md). +[Roles and permissions](/manuals/platform/security/roles-and-permissions.md). ### Step three: Invite members @@ -116,7 +116,7 @@ they are signed in. To add a member, invite a user and assign them the member role. For more details, see [Invite members](/manuals/admin/organization/manage/members.md) and -[Roles and permissions](/manuals/enterprise/security/roles-and-permissions.md). +[Roles and permissions](/manuals/platform/security/roles-and-permissions.md). ### Step four: Manage user access with SSO and SCIM @@ -127,20 +127,20 @@ subscription, see [Upgrade a plan](/manuals/subscription/manage.md#upgrade-plans Use your identity provider (IdP) to manage members and provision them to Docker automatically via SSO and SCIM. See the following for more details: -- [Configure SSO](/manuals/enterprise/security/single-sign-on/connect.md) +- [Configure SSO](/manuals/platform/security/authentication/single-sign-on/connect.md) to authenticate and add members when they sign in to Docker through your identity provider. - Optional. - [Enforce SSO](/manuals/enterprise/security/single-sign-on/connect.md) to + [Enforce SSO](/manuals/platform/security/authentication/single-sign-on/connect.md) to ensure that when users sign in to Docker, they must use SSO. > [!NOTE] > > Enforcing single sign-on (SSO) and enforcing Docker Desktop sign in > are different features. For more details, see - > [Enforcing sign-in versus enforcing single sign-on (SSO)](/manuals/enterprise/security/enforce-sign-in/_index.md#enforcing-sign-in-versus-enforcing-single-sign-on-sso). + > [Enforcing sign-in versus enforcing single sign-on (SSO)](/manuals/platform/security/authentication/enforce-sign-in/_index.md#enforcing-sign-in-versus-enforcing-single-sign-on-sso). -- [Configure SCIM](/manuals/enterprise/security/provisioning/scim/_index.md) to +- [Configure SCIM](/manuals/platform/security/provisioning/scim/_index.md) to automatically provision, add, and de-provision members to Docker through your identity provider. @@ -150,29 +150,29 @@ By default, members of your organization can use Docker Desktop without signing in. When users don’t sign in as a member of your organization, they don’t receive the [benefits of your organization’s subscription](https://www.docker.com/pricing?ref=Docs&refAction=DocsAdminOnboard) -and they can circumvent [Docker’s security features](/manuals/enterprise/security/hardened-desktop/_index.md). +and they can circumvent [Docker’s security features](/manuals/enterprise/hardened-desktop/_index.md). There are multiple ways you can enforce sign-in, depending on your organization's Docker configuration: -- [Registry key method (Windows only)](/manuals/enterprise/security/enforce-sign-in/methods.md#registry-key-method-windows-only) -- [`.plist` method (Mac only)](/manuals/enterprise/security/enforce-sign-in/methods.md#plist-method-mac-only) -- [`registry.json` method (All)](/manuals/enterprise/security/enforce-sign-in/methods.md#registryjson-method-all) +- [Registry key method (Windows only)](/manuals/platform/security/authentication/enforce-sign-in/methods.md#registry-key-method-windows-only) +- [`.plist` method (Mac only)](/manuals/platform/security/authentication/enforce-sign-in/methods.md#plist-method-mac-only) +- [`registry.json` method (All)](/manuals/platform/security/authentication/enforce-sign-in/methods.md#registryjson-method-all) ### Step six: Manage Docker Desktop security Docker offers the following security features to manage your organization's security posture: -- [Image Access Management](/manuals/enterprise/security/hardened-desktop/image-access-management.md): Control which types of images your developers can pull from Docker Hub. -- [Registry Access Management](/manuals/enterprise/security/hardened-desktop/registry-access-management.md): Define which registries your developers can access. -- [Settings management](/manuals/enterprise/security/hardened-desktop/settings-management.md): Set and control Docker Desktop settings for your users. +- [Image Access Management](/manuals/enterprise/hardened-desktop/image-access-management.md): Control which types of images your developers can pull from Docker Hub. +- [Registry Access Management](/manuals/enterprise/hardened-desktop/registry-access-management.md): Define which registries your developers can access. +- [Settings management](/manuals/enterprise/hardened-desktop/settings-management.md): Set and control Docker Desktop settings for your users. ## Next steps - [Manage Docker products](../manage/manage-products.md) to configure access and view usage. -- Configure [Hardened Docker Desktop](/manuals/enterprise/security/hardened-desktop/_index.md) to improve your organization’s security posture for containerized development. -- [Manage your domains](/manuals/enterprise/security/domain-management.md) to ensure that all Docker users in your domain are part of your organization. +- Configure [Hardened Docker Desktop](/manuals/enterprise/hardened-desktop/_index.md) to improve your organization’s security posture for containerized development. +- [Manage your domains](/manuals/platform/security/provisioning/domain-management.md) to ensure that all Docker users in your domain are part of your organization. Your Docker subscription provides many more additional features. To learn more, see [Docker subscriptions and features](https://www.docker.com/pricing?ref=Docs&refAction=DocsAdminOnboard). diff --git a/content/manuals/ai/gordon/_index.md b/content/manuals/ai/gordon/_index.md index 6b586e91c999..c4809547468a 100644 --- a/content/manuals/ai/gordon/_index.md +++ b/content/manuals/ai/gordon/_index.md @@ -67,7 +67,7 @@ Before you begin: > 1. Contact Docker Support to activate Gordon for your organization. Docker > will confirm when activation is complete. > 2. Once confirmed, an organization administrator must turn on Gordon via -> [Settings Management](/manuals/enterprise/security/hardened-desktop/settings-management/_index.md). +> [Settings Management](/manuals/enterprise/hardened-desktop/settings-management/_index.md). > Set **Enable Gordon** to **Enabled** or **Always enabled**. Ensure all > Settings Management prerequisites are met for the setting to take effect > on Docker Desktop clients. diff --git a/content/manuals/ai/gordon/concepts/data-privacy.md b/content/manuals/ai/gordon/concepts/data-privacy.md index 38f5a5b49acb..c85dbcffc827 100644 --- a/content/manuals/ai/gordon/concepts/data-privacy.md +++ b/content/manuals/ai/gordon/concepts/data-privacy.md @@ -95,7 +95,7 @@ For Business subscriptions, administrators can enable or disable Gordon for their organization using Settings Management. Review your organization's data handling requirements before enabling Gordon. -See [Settings Management](/enterprise/security/hardened-desktop/settings-management/) +See [Settings Management](/enterprise/hardened-desktop/settings-management/) for configuration details. ## Disabling Gordon @@ -112,7 +112,7 @@ Individual users: Business organizations: Administrators can disable Gordon for the entire organization using Settings -Management. See [Settings Management](/enterprise/security/hardened-desktop/settings-management/) +Management. See [Settings Management](/enterprise/hardened-desktop/settings-management/) for details. ## Questions about privacy diff --git a/content/manuals/ai/gordon/how-to/configure-tools.md b/content/manuals/ai/gordon/how-to/configure-tools.md index 90c3b6ae11f7..e016b41e6538 100644 --- a/content/manuals/ai/gordon/how-to/configure-tools.md +++ b/content/manuals/ai/gordon/how-to/configure-tools.md @@ -77,5 +77,5 @@ Administrators can: - Lock tool configuration to prevent users from changing it - Set organization-wide tool policies -See [Settings Management](/enterprise/security/hardened-desktop/settings-management/) +See [Settings Management](/enterprise/hardened-desktop/settings-management/) for details. diff --git a/content/manuals/ai/gordon/how-to/permissions.md b/content/manuals/ai/gordon/how-to/permissions.md index 3e08cfb3c58a..0fda05508464 100644 --- a/content/manuals/ai/gordon/how-to/permissions.md +++ b/content/manuals/ai/gordon/how-to/permissions.md @@ -121,5 +121,5 @@ Available controls: For Business subscriptions, Gordon must be enabled by an administrator before users can access it. -See [Settings Management](/enterprise/security/hardened-desktop/settings-management/) +See [Settings Management](/enterprise/hardened-desktop/settings-management/) for details. diff --git a/content/manuals/ai/sandboxes/governance/access-controls/organization.md b/content/manuals/ai/sandboxes/governance/access-controls/organization.md index 18d8eeb14cef..1b439823a29e 100644 --- a/content/manuals/ai/sandboxes/governance/access-controls/organization.md +++ b/content/manuals/ai/sandboxes/governance/access-controls/organization.md @@ -23,10 +23,10 @@ programmatic management of network and filesystem policies, use the [Governance API](/reference/api/ai-governance/). By default, only organization -[owners](/manuals/enterprise/security/roles-and-permissions/core-roles.md) can +[owners](/manuals/platform/security/roles-and-permissions/core-roles.md) can view and manage AI Governance policies. To let someone other than an owner manage policies, create a -[custom role](/manuals/enterprise/security/roles-and-permissions/custom-roles/_index.md) +[custom role](/manuals/platform/security/roles-and-permissions/custom-roles/_index.md) with the **Governance** permissions and assign it to a user or team. > [!NOTE] @@ -114,7 +114,7 @@ in one of two ways: - Manually, in Docker Home. - Automatically, by using - [group mapping](/manuals/enterprise/security/provisioning/scim/group-mapping.md) + [group mapping](/manuals/platform/security/provisioning/scim/group-mapping.md) to synchronize your identity provider's groups with the teams in your organization. Group mapping creates teams that don't already exist and keeps their membership in step with your IdP groups. diff --git a/content/manuals/ai/sandboxes/governance/audit/_index.md b/content/manuals/ai/sandboxes/governance/audit/_index.md index 35ac8c59b7da..3dfca85862c2 100644 --- a/content/manuals/ai/sandboxes/governance/audit/_index.md +++ b/content/manuals/ai/sandboxes/governance/audit/_index.md @@ -32,7 +32,7 @@ To use AI Governance Audit Logs, your organization needs: - A Docker [AI Governance plan](/manuals/subscription/plans/ai-governance.md) - An enforced organization governance policy - A Docker organization account -- An organization owner, or a user with a [custom role](/manuals/enterprise/security/roles-and-permissions/custom-roles/_index.md) that includes AI Governance audit permissions, to configure delivery and view hosted events +- An organization owner, or a user with a [custom role](/manuals/platform/security/roles-and-permissions/custom-roles/_index.md) that includes AI Governance audit permissions, to configure delivery and view hosted events > [!NOTE] > Other Docker subscriptions are not sufficient on their own to use AI Governance @@ -58,7 +58,7 @@ Docker supports two delivery modes for audit records: app.docker.com. Cloud delivery is on by default when AI Governance is enabled. Organization owners can disable it in [audit delivery settings](configure.md). -Organization owners and users with a [custom role](/manuals/enterprise/security/roles-and-permissions/custom-roles/_index.md) that includes AI Governance audit permissions can configure local disk, Docker Cloud, or both. +Organization owners and users with a [custom role](/manuals/platform/security/roles-and-permissions/custom-roles/_index.md) that includes AI Governance audit permissions can configure local disk, Docker Cloud, or both. The hosted audit log view, CSV export, and SIEM forwarding all require Docker Cloud delivery to be enabled. Local delivery alone does not power these features. diff --git a/content/manuals/ai/sandboxes/governance/audit/configure.md b/content/manuals/ai/sandboxes/governance/audit/configure.md index 38342b898f44..314c449479f0 100644 --- a/content/manuals/ai/sandboxes/governance/audit/configure.md +++ b/content/manuals/ai/sandboxes/governance/audit/configure.md @@ -6,7 +6,7 @@ description: Configure local and cloud delivery, retention, and history for Dock keywords: docker sandboxes, audit delivery, AI Governance, audit logs, retention, cloud delivery, AI Platform --- -Organization owners and users with a [custom role](/manuals/enterprise/security/roles-and-permissions/custom-roles/_index.md) that includes AI Governance audit permissions can configure where Docker writes audit events. +Organization owners and users with a [custom role](/manuals/platform/security/roles-and-permissions/custom-roles/_index.md) that includes AI Governance audit permissions can configure where Docker writes audit events. Two delivery destinations are available and can be used independently or together: @@ -21,7 +21,7 @@ Your organization needs: - A Docker [AI Governance plan](/manuals/subscription/plans/ai-governance.md) - An enforced organization governance policy -- Organization owner access, or a [custom role](/manuals/enterprise/security/roles-and-permissions/custom-roles/_index.md) with AI Governance audit permissions +- Organization owner access, or a [custom role](/manuals/platform/security/roles-and-permissions/custom-roles/_index.md) with AI Governance audit permissions Only users who have an AI Governance license and are governed by the enforced organization policy send Docker Sandboxes audit data. diff --git a/content/manuals/ai/sandboxes/governance/monitor-and-enforce/sign-in-enforcement.md b/content/manuals/ai/sandboxes/governance/monitor-and-enforce/sign-in-enforcement.md index ba30413d3453..6794c045a14f 100644 --- a/content/manuals/ai/sandboxes/governance/monitor-and-enforce/sign-in-enforcement.md +++ b/content/manuals/ai/sandboxes/governance/monitor-and-enforce/sign-in-enforcement.md @@ -269,5 +269,5 @@ For access, contact ACME IT Security: Console - [Governance overview](../_index.md): how local and organization governance fit together -- [Enforce sign-in for Docker Desktop](/manuals/enterprise/security/enforce-sign-in/_index.md): +- [Enforce sign-in for Docker Desktop](/manuals/platform/security/authentication/enforce-sign-in/_index.md): the equivalent control for Docker Desktop diff --git a/content/manuals/build-cloud/_index.md b/content/manuals/build-cloud/_index.md index 80458665e99d..4b04be3a920e 100644 --- a/content/manuals/build-cloud/_index.md +++ b/content/manuals/build-cloud/_index.md @@ -64,4 +64,4 @@ Once you've signed up and created a builder, continue by [setting up the builder in your local environment](./setup.md). For information about roles and permissions related to Docker Build Cloud, see -[Roles and Permissions](/manuals/enterprise/security/roles-and-permissions/core-roles.md#docker-build-cloud). +[Roles and Permissions](/manuals/platform/security/roles-and-permissions/core-roles.md#docker-build-cloud). diff --git a/content/manuals/build-cloud/ci.md b/content/manuals/build-cloud/ci.md index 110853ecd513..d01d115d6af9 100644 --- a/content/manuals/build-cloud/ci.md +++ b/content/manuals/build-cloud/ci.md @@ -37,8 +37,8 @@ See [Loading build results](./usage/#loading-build-results) for details. To enable your CI/CD system to build and push images using Docker Build Cloud, provide both an access token and a username. The type of token and the username you use depend on your account type and permissions. -- If you are an organization administrator or have permission to create [organization access tokens (OAT)](/manuals/enterprise/security/access-tokens.md), use an OAT and set `DOCKER_ACCOUNT` to your Docker Hub organization name. -- If you do not have permission to create OATs or are using a personal account, use a [personal access token (PAT)](/security/access-tokens/) and set `DOCKER_ACCOUNT` to your Docker Hub username. +- If you are an organization administrator or have permission to create [organization access tokens (OAT)](/manuals/platform/security/access-tokens/organization-access-tokens.md), use an OAT and set `DOCKER_ACCOUNT` to your Docker Hub organization name. +- If you do not have permission to create OATs or are using a personal account, use a [personal access token (PAT)](/platform/security/access-tokens/personal-access-tokens/) and set `DOCKER_ACCOUNT` to your Docker Hub username. ### Creating access tokens @@ -46,7 +46,7 @@ To enable your CI/CD system to build and push images using Docker Build Cloud, p If you are an organization administrator: -- Create an [organization access token (OAT)](/manuals/enterprise/security/access-tokens.md). The token must have these permissions: +- Create an [organization access token (OAT)](/manuals/platform/security/access-tokens/organization-access-tokens.md). The token must have these permissions: 1. **cloud-connect** scope 2. **Read public repositories** permission 3. **Repository access** with **Image push** permission for the target repository: @@ -60,7 +60,7 @@ If you are not an organization administrator: #### For personal accounts -- Create a [personal access token (PAT)](/security/access-tokens/) with the following permissions: +- Create a [personal access token (PAT)](/platform/security/access-tokens/personal-access-tokens/) with the following permissions: 1. **Read & write** access. - Note: Building with Docker Build Cloud only requires read access, but you need write access to push images to a Docker Hub repository. diff --git a/content/manuals/desktop/features/networking/networking-how-tos.md b/content/manuals/desktop/features/networking/networking-how-tos.md index 6591a3abb671..cc8db7d6b76a 100644 --- a/content/manuals/desktop/features/networking/networking-how-tos.md +++ b/content/manuals/desktop/features/networking/networking-how-tos.md @@ -97,7 +97,7 @@ For more details on proxies and proxy configurations, see the [Proxy settings do You can control how Docker handles container networking and DNS resolution to better support a range of environments — from IPv4-only to dual-stack and IPv6-only systems. These settings help prevent timeouts and connectivity issues caused by incompatible or misconfigured host networks. -You can set the following settings on the **Network** tab in the Docker Desktop Dashboard settings, or if you're an admin, with Settings Management via the [`admin-settings.json` file](/manuals/enterprise/security/hardened-desktop/settings-management/configure-json-file.md#networking), or [Docker Home](/manuals/enterprise/security/hardened-desktop/settings-management/configure-admin-console.md) +You can set the following settings on the **Network** tab in the Docker Desktop Dashboard settings, or if you're an admin, with Settings Management via the [`admin-settings.json` file](/manuals/enterprise/hardened-desktop/settings-management/configure-json-file.md#networking), or [Docker Home](/manuals/enterprise/hardened-desktop/settings-management/configure-admin-console.md) > [!NOTE] > diff --git a/content/manuals/desktop/features/wsl/_index.md b/content/manuals/desktop/features/wsl/_index.md index 080e9d1bac09..2d6692fc6cd1 100644 --- a/content/manuals/desktop/features/wsl/_index.md +++ b/content/manuals/desktop/features/wsl/_index.md @@ -97,7 +97,7 @@ WSL is designed to aid interoperability between Windows and Linux environments. For environments that require stricter isolation: - Run Docker Desktop in Hyper-V mode instead of WSL 2 to avoid the shared-kernel model entirely. -- Enable [Enhanced Container Isolation](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/_index.md) to add an additional layer of protection around container workloads regardless of backend. +- Enable [Enhanced Container Isolation](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/_index.md) to add an additional layer of protection around container workloads regardless of backend. ## Additional resources diff --git a/content/manuals/desktop/release-notes.md b/content/manuals/desktop/release-notes.md index 7260ad82eb1b..c6b7954e1292 100644 --- a/content/manuals/desktop/release-notes.md +++ b/content/manuals/desktop/release-notes.md @@ -1446,7 +1446,7 @@ For more frequently asked questions, see the [FAQs](/manuals/desktop/troubleshoo ### Security -- Added security patches to address CVEs [2025-52565](https://github.com/opencontainers/runc/security/advisories/GHSA-9493-h29p-rfm2), [2025-52881](https://github.com/opencontainers/runc/security/advisories/GHSA-cgrx-mc8f-2prm), and [2025-31133](https://github.com/opencontainers/runc/security/advisories/GHSA-qw9x-cqr3-wc7r) when using [Enhanced Container Isolation](https://docs.docker.com/enterprise/security/hardened-desktop/enhanced-container-isolation). +- Added security patches to address CVEs [2025-52565](https://github.com/opencontainers/runc/security/advisories/GHSA-9493-h29p-rfm2), [2025-52881](https://github.com/opencontainers/runc/security/advisories/GHSA-cgrx-mc8f-2prm), and [2025-31133](https://github.com/opencontainers/runc/security/advisories/GHSA-qw9x-cqr3-wc7r) when using [Enhanced Container Isolation](https://docs.docker.com/enterprise/hardened-desktop/enhanced-container-isolation). ## 4.52.0 @@ -1572,7 +1572,7 @@ For more frequently asked questions, see the [FAQs](/manuals/desktop/troubleshoo ### New - You can now specify PAC files and Embedded PAC scripts with installer flags for [macOS](/manuals/desktop/setup/install/mac-install.md#proxy-configuration) and [Windows](/manuals/desktop/setup/install/windows-install.md#proxy-configuration). -- Administrators can set proxy settings via [macOS configuration profiles](/manuals/enterprise/security/enforce-sign-in/methods.md#macos-configuration-profiles-method-recommended). +- Administrators can set proxy settings via [macOS configuration profiles](/manuals/platform/security/authentication/enforce-sign-in/methods.md#macos-configuration-profiles-method-recommended). ### Upgrades @@ -1604,7 +1604,7 @@ For more frequently asked questions, see the [FAQs](/manuals/desktop/troubleshoo ### Security -- Fixed [CVE-2025-10657](https://www.cve.org/CVERecord?id=CVE-2025-10657) where the Enhanced Container Isolation [Docker Socket command restrictions](../enterprise/security/hardened-desktop/enhanced-container-isolation/config.md#command-restrictions) feature was not working properly in Docker Desktop 4.46.0 only (the configuration for it was being ignored). +- Fixed [CVE-2025-10657](https://www.cve.org/CVERecord?id=CVE-2025-10657) where the Enhanced Container Isolation [Docker Socket command restrictions](../enterprise/hardened-desktop/enhanced-container-isolation/config.md#command-restrictions) feature was not working properly in Docker Desktop 4.46.0 only (the configuration for it was being ignored). ### New @@ -1649,7 +1649,7 @@ For more frequently asked questions, see the [FAQs](/manuals/desktop/troubleshoo ### New - Added a new Learning center walkthrough for Docker MCP Toolkit and other onboarding improvements. -- Administrators can now control [PAC configurations with Settings Management](/manuals/enterprise/security/hardened-desktop/settings-management/configure-json-file.md#proxy-settings). +- Administrators can now control [PAC configurations with Settings Management](/manuals/enterprise/hardened-desktop/settings-management/configure-json-file.md#proxy-settings). - The update experience has been redesigned to make it easier to understand and manage updates for Docker Desktop and its components. ### Upgrades @@ -1785,9 +1785,9 @@ We are aware of [CVE-2025-23266](https://nvd.nist.gov/vuln/detail/CVE-2025-23266 - Fixed an issue pulling images with zstd differential layers when the containerd image store is enabled. - Fixed a bug causing containers launching with the `--restart` flag to not restart properly when using Enhanced Container Isolation. -- Improved interaction between [Kubernetes custom registry images](/manuals/desktop/use-desktop/kubernetes.md#configuring-a-custom-image-registry-for-kubernetes-control-plane-images) and Enhanced Container Isolation (ECI), so the [ECI Docker Socket image list](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/config.md) no longer needs to be manually updated when using a custom registry for Kubernetes control plane images. +- Improved interaction between [Kubernetes custom registry images](/manuals/desktop/use-desktop/kubernetes.md#configuring-a-custom-image-registry-for-kubernetes-control-plane-images) and Enhanced Container Isolation (ECI), so the [ECI Docker Socket image list](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/config.md) no longer needs to be manually updated when using a custom registry for Kubernetes control plane images. - Fixed a bug where a Docker Desktop Kubernetes cluster in kind mode fails to start after restarting Docker Desktop if the user is required to be signed in but is currently signed out. -- Fixed a bug that prevented the mounting of MCP secrets into containers when [Enhanced Container Isolation](/enterprise/security/hardened-desktop/enhanced-container-isolation/) is enabled. +- Fixed a bug that prevented the mounting of MCP secrets into containers when [Enhanced Container Isolation](/enterprise/hardened-desktop/enhanced-container-isolation/) is enabled. - Fixed a bug preventing the use of `--publish-all` when `--publish` was already specified. - Fixed a bug causing the **Images** view to scroll infinitely. Fixes [docker/for-mac#7725](https://github.com/docker/for-mac/issues/7725). - Fixed a bug which caused the **Volumes** tab to be blank while in Resource Saver mode. @@ -1951,7 +1951,7 @@ We are aware of [CVE-2025-23266](https://nvd.nist.gov/vuln/detail/CVE-2025-23266 - Improved the sign-in enforcement message when more than 10 organizations are enforced. - Changed the way ports are mapped by Docker Desktop to fully support IPv6 ports. - Fixed a bug in the Dashboard container logs screen causing the scrollbar to disappear as the mouse approaches. -- [Enforced sign-in](/manuals/enterprise/security/enforce-sign-in/_index.md) fixed for Teams subscription users. +- [Enforced sign-in](/manuals/platform/security/authentication/enforce-sign-in/_index.md) fixed for Teams subscription users. - `llama.cpp` server now supports streaming and tool calling in Model Runner. - Sign-in Enforcement capability is now available to all subscriptions. @@ -2046,7 +2046,7 @@ We are aware of [CVE-2025-23266](https://nvd.nist.gov/vuln/detail/CVE-2025-23266 - Improved error messages when downloading Registry Access Management configuration. - If Docker can't bind an ICMPv4 socket, it now logs an error and continues rather than quits. - Enabled the memory protection keys mechanism in the Docker Desktop Linux VM, allowing containers like Oracle database images to run correctly. -- Fixed a problem with containers accessing `/proc/sys/kernel/shm*` sysctls when [Enhanced Container Isolation](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/_index.md) is enabled on Mac, Windows Hyper-V, or Linux. +- Fixed a problem with containers accessing `/proc/sys/kernel/shm*` sysctls when [Enhanced Container Isolation](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/_index.md) is enabled on Mac, Windows Hyper-V, or Linux. - Added kernel module `nft_fib_inet`, required for running firewalld in a Linux container. - MacOS QEMU Virtualization option is being deprecated on July 14, 2025. @@ -2203,7 +2203,7 @@ We are aware of [CVE-2025-23266](https://nvd.nist.gov/vuln/detail/CVE-2025-23266 #### For all platforms - Fixed a bug where access tokens generated by the `docker login` web flow could not be refreshed by Docker Desktop. -- Fixed a bug where container creation via the Docker API using `curl` failed when [Enhanced Container Isolation](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/_index.md) was enabled. +- Fixed a bug where container creation via the Docker API using `curl` failed when [Enhanced Container Isolation](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/_index.md) was enabled. - Fixed a bug where the RAM policy was not refreshed after the refresh period had elapsed. - Fixed a bug in Enhanced Container Isolation when mounting the Docker socket into a container, and then creating Docker containers with bind-mounts from within that container. - Fixed an issue that caused a discrepancy between the GUI and the CLI, the former forcing the `0.0.0.0` HostIP in port-mappings. This caused default binding IPs configured through Engine's `ip` flag, or through the bridge option `com.docker.network.bridge.host_binding_ipv4`, to not be used. @@ -2262,7 +2262,7 @@ We are aware of [CVE-2025-23266](https://nvd.nist.gov/vuln/detail/CVE-2025-23266 #### For all platforms - Fixed an issue that caused the AI Catalog in Docker Hub to be unavailable in Docker Desktop. -- Fixed an issue that caused Docker Desktop to panic with `index out of range [0] with length 0` when using [Enhanced Container Isolation](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/_index.md). +- Fixed an issue that caused Docker Desktop to panic with `index out of range [0] with length 0` when using [Enhanced Container Isolation](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/_index.md). ### Known issues @@ -2352,13 +2352,13 @@ We are aware of [CVE-2025-23266](https://nvd.nist.gov/vuln/detail/CVE-2025-23266 - Existing Docker Desktop installations using the WSL2 engine on Windows are now automatically migrated to a unified single-distribution architecture for enhanced consistency and performance. - Administrators can now: - - Enforce sign-in with macOS [configuration profiles](/manuals/enterprise/security/enforce-sign-in/methods.md#configuration-profiles-method-mac-only) (Early Access). + - Enforce sign-in with macOS [configuration profiles](/manuals/platform/security/authentication/enforce-sign-in/methods.md#configuration-profiles-method-mac-only) (Early Access). - Enforce sign-in for more than one organization at a time (Early Access). - Deploy Docker Desktop for Mac in bulk with the [PKG installer](/manuals/enterprise/enterprise-deployment/pkg-install-and-configure.md) (Early Access). - Use Desktop Settings Management to manage and enforce defaults via admin.docker.com (Early Access). - Enhance Container Isolation (ECI) has been improved to: - - Allow admins to [turn off Docker socket mount restrictions](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/config.md#allowing-all-containers-to-mount-the-docker-socket). - - Support wildcard tags when using the [`allowedDerivedImages` setting](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/config.md#docker-socket-mount-permissions-for-derived-images). + - Allow admins to [turn off Docker socket mount restrictions](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/config.md#allowing-all-containers-to-mount-the-docker-socket). + - Support wildcard tags when using the [`allowedDerivedImages` setting](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/config.md#docker-socket-mount-permissions-for-derived-images). ### Upgrades @@ -2462,7 +2462,7 @@ We are aware of [CVE-2025-23266](https://nvd.nist.gov/vuln/detail/CVE-2025-23266 - Fixed a bug where the **Push to Docker Hub** action in the **Images** view would result in an `invalid tag format` error. Fixes [docker/for-win#14258](https://github.com/docker/for-win/issues/14258). - Fixed an issue where Docker Desktop startup failed when ICMPv6 setup was not successful. - Added drivers that allow USB/IP to work. -- Fixed a bug in Enhanced Container Isolation (ECI) [Docker socket mount permissions for derived images](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/config.md) where it was incorrectly denying Docker socket mounts for some images when Docker Desktop uses the containerd image store. +- Fixed a bug in Enhanced Container Isolation (ECI) [Docker socket mount permissions for derived images](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/config.md) where it was incorrectly denying Docker socket mounts for some images when Docker Desktop uses the containerd image store. - Enable `NFT_NUMGEN`, `NFT_FIB_IPV4` and `NFT_FIB_IPV6` kernel modules. - Build UI: - Highlight build check warnings in the **Completed builds** list. @@ -2470,7 +2470,7 @@ We are aware of [CVE-2025-23266](https://nvd.nist.gov/vuln/detail/CVE-2025-23266 - Image tags added to **Build results** section under the **Info** tab. - Improved efficiency of host-side disk utilization for fresh installations on Mac and Linux. - Fixed a bug that prevented the Sign in enforcement popup to be triggered when token expires. -- Fixed a bug where containers would not be displayed in the GUI immediately after signing in when using [enforced sign-in](/manuals/enterprise/security/enforce-sign-in/_index.md). +- Fixed a bug where containers would not be displayed in the GUI immediately after signing in when using [enforced sign-in](/manuals/platform/security/authentication/enforce-sign-in/_index.md). - `settings.json` has been renamed to `settings-store.json` - The host networking feature no longer requires users to be signed-in in order to use it. @@ -2572,7 +2572,7 @@ We are aware of [CVE-2025-23266](https://nvd.nist.gov/vuln/detail/CVE-2025-23266 - If you authenticate via the CLI, you can now authenticate through a browser-based flow, removing the need for manual PAT generation. - Windows now supports automatic reclamation of disk space in Docker Desktop for WSL2 installations [using a managed virtual hard disk](/manuals/desktop/features/wsl/best-practices.md). - Deploying Docker Desktop via the [MSI installer](/manuals/enterprise/enterprise-deployment/msi-install-and-configure.md) is now generally available. -- Two new methods to [enforce sign-in](/manuals/enterprise/security/enforce-sign-in/_index.md) (windows registry key and `.plist` file) are now generally available. +- Two new methods to [enforce sign-in](/manuals/platform/security/authentication/enforce-sign-in/_index.md) (windows registry key and `.plist` file) are now generally available. - Fresh installations of Docker Desktop now use the containerd image store by default. - [Compose Bridge](/manuals/compose/bridge/_index.md) (Experimental) is now available from the Compose file viewer. Easily convert and deploy your Compose project to a Kubernetes cluster. @@ -2619,8 +2619,8 @@ We are aware of [CVE-2025-23266](https://nvd.nist.gov/vuln/detail/CVE-2025-23266 > [!NOTE] > Using `docker login` with an address that includes URL path segments is not a documented use case and is considered unsupported. The recommended usage is to specify only a registry hostname, and optionally a port, as the address for `docker login`. - When running `docker compose up` and Docker Desktop is in the Resource Saver mode, the command is unresponsive. As a workaround, manually exit the Resource Saving mode and Docker Compose becomes responsive again. -- When [Enhanced Container Isolation (ECI)](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/_index.md) is enabled, Docker Desktop may not enter Resource Saver mode. This will be fixed in a future Docker Desktop release. -- The new [ECI Docker socket mount permissions for derived images](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/config.md#docker-socket-mount-permissions-for-derived-images) feature does not yet work when Docker Desktop is configured with the **Use containerd for pulling and storing images**. This will be fixed in the next Docker Desktop release. +- When [Enhanced Container Isolation (ECI)](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/_index.md) is enabled, Docker Desktop may not enter Resource Saver mode. This will be fixed in a future Docker Desktop release. +- The new [ECI Docker socket mount permissions for derived images](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/config.md#docker-socket-mount-permissions-for-derived-images) feature does not yet work when Docker Desktop is configured with the **Use containerd for pulling and storing images**. This will be fixed in the next Docker Desktop release. ## 4.33.2 @@ -2766,7 +2766,7 @@ For more information, see [microsoft/WSL#11794](https://github.com/microsoft/WSL - Improved instructions for `watch` in the Compose File Viewer - Added support for Golang projects that don't have dependencies in Docker Init. Addresses [docker/roadmap#611](https://github.com/docker/roadmap/issues/611) -- [Settings Management](/manuals/enterprise/security/hardened-desktop/settings-management/_index.md) now lets admins set the default value to `ProxyEnableKerberosNTLM`. +- [Settings Management](/manuals/enterprise/hardened-desktop/settings-management/_index.md) now lets admins set the default value to `ProxyEnableKerberosNTLM`. - Removed a temporary compatibility fix for older versions of Visual Studio Code. - Builds view: - Changed icon for imported build record to a "files" icon. @@ -2821,7 +2821,7 @@ For more information, see [microsoft/WSL#11794](https://github.com/microsoft/WSL ### New -- [Air-Gapped Containers](/manuals/enterprise/security/hardened-desktop/air-gapped-containers.md) is now generally available. +- [Air-Gapped Containers](/manuals/enterprise/hardened-desktop/air-gapped-containers.md) is now generally available. - Docker Compose File Viewer shows your Compose YAML with syntax highlighting and contextual links to relevant docs (Beta, progressive rollout). - New Sidebar user experience. @@ -2845,7 +2845,7 @@ For more information, see [microsoft/WSL#11794](https://github.com/microsoft/WSL - Added `proxyEnableKerberosNTLM` config to `settings.json` to enable fallback to basic proxy authentication if Kerberos/NTLM environment is not properly set up. - Fixed a bug where Docker Debug was not working properly with Enhanced Container Isolation enabled. - Fixed a bug where UDP responses were not truncated properly. -- Fixed a bug where the **Update** screen was hidden when using [Settings Management](/manuals/enterprise/security/hardened-desktop/settings-management/_index.md). +- Fixed a bug where the **Update** screen was hidden when using [Settings Management](/manuals/enterprise/hardened-desktop/settings-management/_index.md). - Fixed a bug where proxy settings defined in `admin-settings.json` were not applied correctly on startup. - Fixed a bug where the **Manage Synchronized file shares with Compose** toggle did not correctly reflect the value with the feature. - Fixed a bug where a bind mounted file modified on host is not updated after the container restarts, when gRPC FUSE file sharing is used on macOS and on Windows with Hyper-V. Fixes [docker/for-mac#7274](https://github.com/docker/for-mac/issues/7274), [docker/for-win#14060](https://github.com/docker/for-win/issues/14060). @@ -2908,7 +2908,7 @@ For more information, see [microsoft/WSL#11794](https://github.com/microsoft/WSL #### For all platforms - Docker Desktop now supports [SOCKS5 proxies](/manuals/desktop/features/networking.md#socks5-proxy-support). Requires a Business subscription. -- Added a new setting to manage the onboarding survey in [Settings Management](/manuals/enterprise/security/hardened-desktop/settings-management/_index.md). +- Added a new setting to manage the onboarding survey in [Settings Management](/manuals/enterprise/hardened-desktop/settings-management/_index.md). #### For Windows @@ -2985,14 +2985,14 @@ This can be resolved by adding the user to the **docker-users** group. Before st ### New -- You can now enforce Rosetta usage via [Settings Management](/manuals/enterprise/security/hardened-desktop/settings-management/_index.md). -- [Docker socket mount restrictions](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/config.md) with ECI is now generally available. +- You can now enforce Rosetta usage via [Settings Management](/manuals/enterprise/hardened-desktop/settings-management/_index.md). +- [Docker socket mount restrictions](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/config.md) with ECI is now generally available. - Docker Engine and CLI updated to [Moby 26.0](https://github.com/moby/moby/releases/tag/v26.0.0). This includes Buildkit 0.13, sub volumes mounts, networking updates, and improvements to the containerd multi-platform image store UX. - New and improved Docker Desktop error screens: swift troubleshooting, easy diagnostics uploads, and actionable remediation. - Compose supports [Synchronized file shares (experimental)](/manuals/desktop/features/synchronized-file-sharing.md). - New [interactive Compose CLI (experimental)](/manuals/compose/how-tos/environment-variables/envvars.md#compose_menu). - Beta release of: - - Air-Gapped Containers with [Settings Management](/manuals/enterprise/security/hardened-desktop/air-gapped-containers.md). + - Air-Gapped Containers with [Settings Management](/manuals/enterprise/hardened-desktop/air-gapped-containers.md). - [Host networking](/manuals/engine/network/drivers/host.md#docker-desktop) in Docker Desktop. - [Docker Debug](use-desktop/container.md#integrated-terminal) for running containers. - [Volumes Backup & Share extension](use-desktop/volumes.md) functionality available in the **Volumes** tab. @@ -3063,7 +3063,7 @@ This can be resolved by adding the user to the **docker-users** group. Before st ### New -- [Settings Management](/manuals/enterprise/security/hardened-desktop/settings-management/_index.md) now allows admins to set the default file-sharing implementation and specify which paths developer can add file shares to. +- [Settings Management](/manuals/enterprise/hardened-desktop/settings-management/_index.md) now allows admins to set the default file-sharing implementation and specify which paths developer can add file shares to. - Added support for `socks5://` HTTP and HTTPS proxy URLs when the [`SOCKS` proxy support beta feature](/manuals/desktop/features/networking.md) is enabled. - Users can now filter volumes to see which ones are in use in the **Volumes** tab. @@ -3182,7 +3182,7 @@ This can be resolved by adding the user to the **docker-users** group. Before st - Docker init now supports Java and is generally available to all users. - [Synchronized File Shares](/manuals/desktop/features/synchronized-file-sharing.md) provides fast and flexible host-to-VM file sharing within Docker Desktop. Utilizing the technology behind [Docker’s acquisition of Mutagen](https://www.docker.com/blog/mutagen-acquisition/), this feature provides an alternative to virtual bind mounts that uses synchronized filesystem caches, improving performance for developers working with large codebases. -- Organization admins can now [configure Docker socket mount permissions](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/config.md) when ECI is enabled. +- Organization admins can now [configure Docker socket mount permissions](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/config.md) when ECI is enabled. - [Containerd Image Store](/manuals/desktop/features/containerd.md) support is now generally available to all users. - Get a debug shell into any container or image with the new [`docker debug` command](/reference/cli/docker/debug/) (Beta). - Organization admins, with a Docker Business subscription, can now configure a custom list of extensions with [Private Extensions Marketplace](/manuals/extensions/private-marketplace.md) enabled (Beta) @@ -3283,7 +3283,7 @@ This can be resolved by adding the user to the **docker-users** group. Before st ### New -- Administrators can now control access to beta and experimental features in the **Features in development** tab with [Settings Management](/manuals/enterprise/security/hardened-desktop/settings-management/_index.md). +- Administrators can now control access to beta and experimental features in the **Features in development** tab with [Settings Management](/manuals/enterprise/hardened-desktop/settings-management/_index.md). - Introduced four new version update states in the footer. - `docker init` (Beta) now supports PHP with Apache + Composer. - The [**Builds** view](use-desktop/builds.md) is now GA. You can now inspect builds, troubleshoot errors, and optimize build speed. @@ -3393,7 +3393,7 @@ This can be resolved by adding the user to the **docker-users** group. Before st - Rosetta is now Generally Available for all users on macOS 13 or later. It provides faster emulation of Intel-based images on Apple Silicon. To use Rosetta, see [Settings](/manuals/desktop/settings-and-maintenance/settings.md). Rosetta is enabled by default on macOS 14.1 and later. - Docker Desktop now detects if a WSL version is out of date. If an out dated version of WSL is detected, you can allow Docker Desktop to automatically update the installation or you can manually update WSL outside of Docker Desktop. - New installations of Docker Desktop for Windows now require a Windows version of 19044 or later. -- Administrators now have the ability to control Docker Scout image analysis in [Settings Management](/manuals/enterprise/security/hardened-desktop/settings-management/_index.md). +- Administrators now have the ability to control Docker Scout image analysis in [Settings Management](/manuals/enterprise/hardened-desktop/settings-management/_index.md). ### Upgrades @@ -3654,7 +3654,7 @@ This can be resolved by adding the user to the **docker-users** group. Before st #### For all platforms -- [Settings Management](/manuals/enterprise/security/hardened-desktop/settings-management/_index.md) now lets you turn off Docker Extensions for your organisation. +- [Settings Management](/manuals/enterprise/hardened-desktop/settings-management/_index.md) now lets you turn off Docker Extensions for your organisation. - Fixed a bug where turning on Kubernetes from the UI failed when the system was paused. - Fixed a bug where turning on Wasm from the UI failed when the system was paused. - Bind mounts are now shown when you [inspect a container](use-desktop/container.md). @@ -4286,7 +4286,7 @@ This can be resolved by adding the user to the **docker-users** group. Before st ### New -- Two new security features have been introduced for Docker Business users, Settings Management and Enhanced Container Isolation. Read more about Docker Desktop’s new [Hardened Docker Desktop security model](/manuals/enterprise/security/hardened-desktop/_index.md). +- Two new security features have been introduced for Docker Business users, Settings Management and Enhanced Container Isolation. Read more about Docker Desktop’s new [Hardened Docker Desktop security model](/manuals/enterprise/hardened-desktop/_index.md). - Added the new Dev Environments CLI `docker dev`, so you can create, list, and run Dev Envs via command line. Now it's easier to integrate Dev Envs into custom scripts. - Docker Desktop can now be installed to any drive and folder using the `--installation-dir`. Partially addresses [docker/roadmap#94](https://github.com/docker/roadmap/issues/94). @@ -4983,7 +4983,7 @@ Installing Docker Desktop 4.5.0 from scratch has a bug which defaults Docker Des ### New - Easy, Secure sign in with Auth0 and Single Sign-on - - Single Sign-on: Users with a Docker Business subscription can now configure SSO to authenticate using their identity providers (IdPs) to access Docker. For more information, see [Single Sign-on](/manuals/enterprise/security/single-sign-on/_index.md). + - Single Sign-on: Users with a Docker Business subscription can now configure SSO to authenticate using their identity providers (IdPs) to access Docker. For more information, see [Single Sign-on](/manuals/platform/security/authentication/single-sign-on/_index.md). - Signing in to Docker Desktop now takes you through the browser so that you get all the benefits of auto-filling from password managers. ### Upgrades @@ -4995,7 +4995,7 @@ Installing Docker Desktop 4.5.0 from scratch has a bug which defaults Docker Des ### Security -- Fixed [CVE-2021-45449](../security/_index.md#cve-2021-45449) that affects users currently on Docker Desktop version 4.3.0 or 4.3.1. +- Fixed [CVE-2021-45449](../platform/security/security-announcements.md#cve-2021-45449) that affects users currently on Docker Desktop version 4.3.0 or 4.3.1. Docker Desktop version 4.3.0 and 4.3.1 has a bug that may log sensitive information (access token or password) on the user's machine during login. This only affects users if they are on Docker Desktop 4.3.0, 4.3.1 and the user has logged in while on 4.3.0, 4.3.1. Gaining access to this data would require having access to the user’s local files. @@ -5035,7 +5035,7 @@ This only affects users if they are on Docker Desktop 4.3.0, 4.3.1 and the user ### Security -- Fixed [CVE-2021-45449](../security/_index.md#cve-2021-45449) that affects users currently on Docker Desktop version 4.3.0 or 4.3.1. +- Fixed [CVE-2021-45449](../platform/security/security-announcements.md#cve-2021-45449) that affects users currently on Docker Desktop version 4.3.0 or 4.3.1. Docker Desktop version 4.3.0 and 4.3.1 has a bug that may log sensitive information (access token or password) on the user's machine during login. This only affects users if they are on Docker Desktop 4.3.0, 4.3.1 and the user has logged in while on 4.3.0, 4.3.1. Gaining access to this data would require having access to the user’s local files. diff --git a/content/manuals/desktop/settings-and-maintenance/settings.md b/content/manuals/desktop/settings-and-maintenance/settings.md index 32f91f922ed2..8882f02dff7b 100644 --- a/content/manuals/desktop/settings-and-maintenance/settings.md +++ b/content/manuals/desktop/settings-and-maintenance/settings.md @@ -24,7 +24,7 @@ You can also locate the `settings-store.json` file at: - Windows: `C:\Users\[USERNAME]\AppData\Roaming\Docker\settings-store.json` - Linux: `~/.docker/desktop/settings-store.json` -For information on enforcing settings at an organization level, see [Settings Management](/manuals/enterprise/security/hardened-desktop/settings-management/settings-reference.md). +For information on enforcing settings at an organization level, see [Settings Management](/manuals/enterprise/hardened-desktop/settings-management/settings-reference.md). ## General @@ -48,7 +48,7 @@ Configure startup behavior, UI appearance, terminal preferences, and feature def | **Choose file sharing implementation for your containers** | Choose whether you want to share files using **VirtioFS**, or **gRPC FUSE** | **VirtioFS** | Mac | Use VirtioFS for speedy file sharing. VirtioFS has reduced the time taken to complete filesystem operations by [up to 98%](https://github.com/docker/roadmap/issues/7#issuecomment-1044452206). It is the only file sharing implementation supported by Docker VMM. | |**Use Rosetta for x86_64/amd64 emulation on Apple Silicon** | Accelerate x86/AMD64 binary emulation on Apple Silicon. This option is only available if you have selected **Apple Virtualization framework** as the Virtual Machine Manager. | Disabled | Mac | | | **Send usage statistics** | Send diagnostics, crash reports, and usage data to Docker to improve and troubleshoot the application. Docker may periodically prompt you for more information. | Enabled | All | | -| **Use Enhanced Container Isolation** | Prevent containers from breaching the Linux VM. For more information, see [Enhanced Container Isolation](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/_index.md). | Disabled | All | Must be signed in and have a Docker Business subscription. | +| **Use Enhanced Container Isolation** | Prevent containers from breaching the Linux VM. For more information, see [Enhanced Container Isolation](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/_index.md). | Disabled | All | Must be signed in and have a Docker Business subscription. | | **Show CLI hints** | Display helpful CLI suggestions in terminal. | Enabled | All | Improves discoverability | | **Enable Docker Scout image analysis** | Show a **Start analysis** button when inspecting an image, which analyzes the image with Docker Scout. | Enabled | All | | | **Enable background SBOM indexing** | Automatically analyze images that you build or pull. | Disabled | All | | @@ -119,7 +119,7 @@ For more information, see [Volume mounting requires file sharing for any project Docker Desktop supports HTTP/HTTPS and SOCKS5 proxies. SOCKS5 requires a Business subscription. To prevent developers from accidentally changing the proxy settings, see -[Settings Management](/manuals/enterprise/security/hardened-desktop/settings-management/_index.md#what-features-can-i-configure-with-settings-management). +[Settings Management](/manuals/enterprise/hardened-desktop/settings-management/_index.md#what-features-can-i-configure-with-settings-management). #### Docker Desktop proxy @@ -133,7 +133,7 @@ Used for Docker Desktop host-level traffic: signing in to Docker, the Desktop ap > [!NOTE] > -> If you use a PAC file hosted on a web server, add the MIME type `application/x-ns-proxy-autoconfig` for the `.pac` extension. Without this, the PAC file may not parse correctly. See [Hardened Docker Desktop](/manuals/enterprise/security/hardened-desktop/air-gapped-containers.md#proxy-auto-configuration-files). +> If you use a PAC file hosted on a web server, add the MIME type `application/x-ns-proxy-autoconfig` for the `.pac` extension. Without this, the PAC file may not parse correctly. See [Hardened Docker Desktop](/manuals/enterprise/hardened-desktop/air-gapped-containers.md#proxy-auto-configuration-files). #### Containers proxy @@ -155,10 +155,10 @@ Used for `docker image pull` (always enforced - all `docker pull` and Compose pu When you run Windows containers, enable **Use proxy for Windows Docker daemon** to let the Windows Docker daemon connect to Docker Desktop's internal proxy. This allows Windows containers to use the configured Docker Desktop proxy, and -it is required if you want [Registry Access Management](/manuals/enterprise/security/hardened-desktop/registry-access-management.md) +it is required if you want [Registry Access Management](/manuals/enterprise/hardened-desktop/registry-access-management.md) restrictions to apply to Windows image operations. Administrators can manage the same behavior with -[**Override Windows "dockerd" port**](/manuals/enterprise/security/hardened-desktop/settings-management/settings-reference.md#override-windows-dockerd-port). +[**Override Windows "dockerd" port**](/manuals/enterprise/hardened-desktop/settings-management/settings-reference.md#override-windows-dockerd-port). #### Proxy authentication diff --git a/content/manuals/desktop/setup/install/mac-install.md b/content/manuals/desktop/setup/install/mac-install.md index 3c065841aa15..848ab969da20 100644 --- a/content/manuals/desktop/setup/install/mac-install.md +++ b/content/manuals/desktop/setup/install/mac-install.md @@ -127,7 +127,7 @@ The `install` command accepts the following flags: - `--allowed-org=`: Requires the user to sign in and be part of the specified Docker Hub organization when running the application - `--user=`: Performs the privileged configurations once during installation. This removes the need for the user to grant root privileges on first run. For more information, see [Privileged helper permission requirements](/manuals/desktop/setup/install/mac-permission-requirements.md#permission-requirements). To find the username, enter `ls /Users` in the CLI. -- `--admin-settings`: Automatically creates an `admin-settings.json` file which is used by administrators to control certain Docker Desktop settings on client machines within their organization. For more information, see [Settings Management](/manuals/enterprise/security/hardened-desktop/settings-management/_index.md). +- `--admin-settings`: Automatically creates an `admin-settings.json` file which is used by administrators to control certain Docker Desktop settings on client machines within their organization. For more information, see [Settings Management](/manuals/enterprise/hardened-desktop/settings-management/_index.md). - It must be used together with the `--allowed-org=` flag. - For example: `--allowed-org= --admin-settings="{'configurationFileVersion': 2, 'enhancedContainerIsolation': {'value': true, 'locked': false}}"` @@ -154,7 +154,7 @@ $ sudo /Applications/Docker.app/Contents/MacOS/install --user testuser --proxy-h > [!TIP] > -> As an IT administrator, you can use endpoint management (MDM) software to identify the number of Docker Desktop instances and their versions within your environment. This can provide accurate license reporting, help ensure your machines use the latest version of Docker Desktop, and enable you to [enforce sign-in](/manuals/enterprise/security/enforce-sign-in/_index.md). +> As an IT administrator, you can use endpoint management (MDM) software to identify the number of Docker Desktop instances and their versions within your environment. This can provide accurate license reporting, help ensure your machines use the latest version of Docker Desktop, and enable you to [enforce sign-in](/manuals/platform/security/authentication/enforce-sign-in/_index.md). > - [Intune](https://learn.microsoft.com/en-us/mem/intune/apps/app-discovered-apps) > - [Jamf](https://docs.jamf.com/10.25.0/jamf-pro/administrator-guide/Application_Usage.html) > - [Kandji](https://support.kandji.io/support/solutions/articles/72000559793-view-a-device-application-list) diff --git a/content/manuals/desktop/setup/install/mac-permission-requirements.md b/content/manuals/desktop/setup/install/mac-permission-requirements.md index 34bc7d7e2ff8..a8fff2bc84b3 100644 --- a/content/manuals/desktop/setup/install/mac-permission-requirements.md +++ b/content/manuals/desktop/setup/install/mac-permission-requirements.md @@ -113,7 +113,7 @@ retain their original permissions. ## Enhanced Container Isolation In addition, Docker Desktop supports [Enhanced Container Isolation -mode](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/_index.md) (ECI), +mode](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/_index.md) (ECI), available to Business customers only, which further secures containers without impacting developer workflows. diff --git a/content/manuals/desktop/setup/install/windows-install.md b/content/manuals/desktop/setup/install/windows-install.md index af06573c64ba..f237bdb87fc7 100644 --- a/content/manuals/desktop/setup/install/windows-install.md +++ b/content/manuals/desktop/setup/install/windows-install.md @@ -232,7 +232,7 @@ Docker Desktop does not start automatically after installation. To start Docker > [!TIP] > -> As an IT administrator, you can use endpoint management (MDM) software to identify the number of Docker Desktop instances and their versions within your environment. This can provide accurate license reporting, help ensure your machines use the latest version of Docker Desktop, and enable you to [enforce sign-in](/manuals/enterprise/security/enforce-sign-in/_index.md). +> As an IT administrator, you can use endpoint management (MDM) software to identify the number of Docker Desktop instances and their versions within your environment. This can provide accurate license reporting, help ensure your machines use the latest version of Docker Desktop, and enable you to [enforce sign-in](/manuals/platform/security/authentication/enforce-sign-in/_index.md). > - [Intune](https://learn.microsoft.com/en-us/mem/intune/apps/app-discovered-apps) > - [Jamf](https://docs.jamf.com/10.25.0/jamf-pro/administrator-guide/Application_Usage.html) > - [Kandji](https://support.kandji.io/support/solutions/articles/72000559793-view-a-device-application-list) @@ -294,7 +294,7 @@ If Microsoft Store access is blocked due to security policies: #### Security and access control - `--allowed-org=`: Requires the user to sign in and be part of the specified Docker Hub organization when running the application -- `--admin-settings`: Automatically creates an `admin-settings.json` file which is used by admins to control certain Docker Desktop settings on client machines within their organization. For more information, see [Settings Management](/manuals/enterprise/security/hardened-desktop/settings-management/_index.md). +- `--admin-settings`: Automatically creates an `admin-settings.json` file which is used by admins to control certain Docker Desktop settings on client machines within their organization. For more information, see [Settings Management](/manuals/enterprise/hardened-desktop/settings-management/_index.md). - It must be used together with the `--allowed-org=` flag. - For example:`--allowed-org= --admin-settings="{'configurationFileVersion': 2, 'enhancedContainerIsolation': {'value': true, 'locked': false}}"` - `--no-windows-containers`: Disables the Windows containers integration. This can improve security. For more information, see [Windows containers](/manuals/desktop/setup/install/windows-permission-requirements.md#windows-containers). diff --git a/content/manuals/desktop/setup/install/windows-permission-requirements.md b/content/manuals/desktop/setup/install/windows-permission-requirements.md index c4b06f1be930..e0b0c05aff20 100644 --- a/content/manuals/desktop/setup/install/windows-permission-requirements.md +++ b/content/manuals/desktop/setup/install/windows-permission-requirements.md @@ -93,7 +93,7 @@ into Docker containers still retain their original permissions. Containers don' ## Enhanced Container Isolation In addition, Docker Desktop supports [Enhanced Container Isolation -mode](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/_index.md) (ECI), +mode](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/_index.md) (ECI), available to Business customers only, which further secures containers without impacting developer workflows. diff --git a/content/manuals/desktop/setup/sign-in.md b/content/manuals/desktop/setup/sign-in.md index 01b04cab60d5..9d7c6282483f 100644 --- a/content/manuals/desktop/setup/sign-in.md +++ b/content/manuals/desktop/setup/sign-in.md @@ -17,7 +17,7 @@ aliases: Docker recommends signing in with the **Sign in** option in the top-right corner of the Docker Dashboard. -In large enterprises where admin access is restricted, administrators can [enforce sign-in](/manuals/enterprise/security/enforce-sign-in/_index.md). +In large enterprises where admin access is restricted, administrators can [enforce sign-in](/manuals/platform/security/authentication/enforce-sign-in/_index.md). > [!TIP] > @@ -29,7 +29,7 @@ In large enterprises where admin access is restricted, administrators can [enfor - Increase your pull rate limit compared to anonymous users. See [Usage and limits](/manuals/docker-hub/usage/_index.md). -- Enhance your organization’s security posture for containerized development with [Hardened Desktop](/manuals/enterprise/security/hardened-desktop/_index.md). +- Enhance your organization’s security posture for containerized development with [Hardened Desktop](/manuals/enterprise/hardened-desktop/_index.md). > [!NOTE] > diff --git a/content/manuals/desktop/use-desktop/kubernetes.md b/content/manuals/desktop/use-desktop/kubernetes.md index c5429aebc88d..38e74e8f23a7 100644 --- a/content/manuals/desktop/use-desktop/kubernetes.md +++ b/content/manuals/desktop/use-desktop/kubernetes.md @@ -53,7 +53,7 @@ Docker Desktop Kubernetes can be provisioned with either the `kubeadm` or `kind` provisioners. `kubeadm` is the older provisioner. It supports a single-node cluster, you can't select the kubernetes -version, it's slower to provision than `kind`, and it's not supported by [Enhanced Container Isolation](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/index.md) (ECI), +version, it's slower to provision than `kind`, and it's not supported by [Enhanced Container Isolation](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/index.md) (ECI), meaning that if ECI is enabled the cluster works but it's not protected by ECI. `kind` is the newer provisioner. It supports multi-node clusters (for @@ -156,7 +156,7 @@ factors, including the version of Kubernetes being used. The tags vary for each To accommodate scenarios where access to Docker Hub is not allowed, admins can configure Docker Desktop to pull the above listed images from a different registry (e.g., a mirror) -using the [KubernetesImagesRepository](/manuals/enterprise/security/hardened-desktop/settings-management/configure-json-file.md#kubernetes) setting as follows. +using the [KubernetesImagesRepository](/manuals/enterprise/hardened-desktop/settings-management/configure-json-file.md#kubernetes) setting as follows. An image name can be broken into `[registry[:port]/][namespace/]repository[:tag]` components. The `KubernetesImagesRepository` setting allows users to override the `[registry[:port]/][namespace]` @@ -195,8 +195,8 @@ The recommended approach to set this up is the following: > [!NOTE] > -> In Docker Desktop versions 4.43 or earlier, when using `KubernetesImagesRepository` and [Enhanced Container Isolation (ECI)](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/_index.md) -> is enabled, add the following images to the [ECI Docker socket mount image list](/manuals/enterprise/security/hardened-desktop/settings-management/configure-json-file.md#enhanced-container-isolation): +> In Docker Desktop versions 4.43 or earlier, when using `KubernetesImagesRepository` and [Enhanced Container Isolation (ECI)](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/_index.md) +> is enabled, add the following images to the [ECI Docker socket mount image list](/manuals/enterprise/hardened-desktop/settings-management/configure-json-file.md#enhanced-container-isolation): > > `[imagesRepository]/desktop-cloud-provider-kind:` > `[imagesRepository]/desktop-containerd-registry-mirror:` diff --git a/content/manuals/dhi/how-to/customize.md b/content/manuals/dhi/how-to/customize.md index fbb17a2d4f89..e4129e9cac29 100644 --- a/content/manuals/dhi/how-to/customize.md +++ b/content/manuals/dhi/how-to/customize.md @@ -161,9 +161,9 @@ You can create customizations using either the DHI CLI or the Docker Hub web int {{< tab name="CLI" >}} Authenticate with `docker login` using your Docker credentials or a [personal -access token (PAT)](../../security/access-tokens.md) with **Read & Write** +access token (PAT)](../../platform/security/access-tokens/personal-access-tokens.md) with **Read & Write** permissions, or an [organization access token -(OAT)](../../enterprise/security/access-tokens.md). When using an OAT, the +(OAT)](../../platform/security/access-tokens/organization-access-tokens.md). When using an OAT, the available operations depend on the token's permission scope: - To list or get customizations, or to view build logs, the OAT must have read diff --git a/content/manuals/dhi/how-to/helm.md b/content/manuals/dhi/how-to/helm.md index 0afdf0d80249..cfc3ba372162 100644 --- a/content/manuals/dhi/how-to/helm.md +++ b/content/manuals/dhi/how-to/helm.md @@ -53,8 +53,8 @@ registry, you still need to create this secret if the registry requires authentication. 1. For `dhi.io` or Docker Hub, create a [personal access token - (PAT)](/security/access-tokens/) using your Docker account or an - [organization access token (OAT)](/enterprise/security/access-tokens/). + (PAT)](/platform/security/access-tokens/personal-access-tokens/) using your Docker account or an + [organization access token (OAT)](/platform/security/access-tokens/organization-access-tokens/). Ensure the token has at least read-only access to the Docker Hardened Image repositories. 2. Create a secret in Kubernetes using the following command. Replace ``, ``, diff --git a/content/manuals/dhi/how-to/mirror.md b/content/manuals/dhi/how-to/mirror.md index b942a01862a5..3c89c3b7e375 100644 --- a/content/manuals/dhi/how-to/mirror.md +++ b/content/manuals/dhi/how-to/mirror.md @@ -34,10 +34,10 @@ repositories: ## Mirror a DHI repository to your organization -Organization owners, editors, and members with a [custom role](../../enterprise/security/roles-and-permissions/custom-roles/_index.md) +Organization owners, editors, and members with a [custom role](../../platform/security/roles-and-permissions/custom-roles/_index.md) that includes the DHI mirroring permission can create, view, and manage mirrors. When using the CLI or Terraform, you can also mirror using an [organization -access token (OAT)](../../enterprise/security/access-tokens.md) with the +access token (OAT)](../../platform/security/access-tokens/organization-access-tokens.md) with the appropriate permission scopes, without requiring role-based access. When a member with a custom role that includes the DHI mirroring permission @@ -83,9 +83,9 @@ It may take a few minutes for all the tags to finish mirroring. {{< tab name="CLI" >}} Authenticate with `docker login` using your Docker credentials, a [personal -access token (PAT)](../../security/access-tokens.md) with **Read & Write** +access token (PAT)](../../platform/security/access-tokens/personal-access-tokens.md) with **Read & Write** permissions, or an [organization access token -(OAT)](../../enterprise/security/access-tokens.md). When using an OAT, the +(OAT)](../../platform/security/access-tokens/organization-access-tokens.md). When using an OAT, the available operations depend on the token's permission scope: - To list mirrored repositories, the OAT must have read (pull) access to the @@ -200,9 +200,9 @@ updates. You can still use the last images or charts that were mirrored. {{< tab name="CLI" >}} Authenticate with `docker login` using your Docker credentials, a [personal -access token (PAT)](../../security/access-tokens.md) with **Read & Write** +access token (PAT)](../../platform/security/access-tokens/personal-access-tokens.md) with **Read & Write** permissions, or an [organization access token -(OAT)](../../enterprise/security/access-tokens.md) with push access to the +(OAT)](../../platform/security/access-tokens/organization-access-tokens.md) with push access to the relevant repository. Use the [`docker dhi mirror`](/reference/cli/docker/dhi/mirror/) command: @@ -303,11 +303,11 @@ same steps to a non-mirrored image by updating the `SRC_ATT_REPO` and In this example, you authenticate as your Docker organization using an [organization access token - (OAT)](../../enterprise/security/access-tokens.md). The OAT must have at + (OAT)](../../platform/security/access-tokens/organization-access-tokens.md). The OAT must have at least pull access to every DHI repository you want to mirror. Only repositories in the token's scope are accessible. Alternatively, you can authenticate as a Docker Hub user with a [personal access token - (PAT)](../../security/access-tokens.md) that has `read only` access. + (PAT)](../../platform/security/access-tokens/personal-access-tokens.md) that has `read only` access. > [!WARNING] > diff --git a/content/manuals/dhi/how-to/policies.md b/content/manuals/dhi/how-to/policies.md index e909dfdfadc7..bbf0caff7059 100644 --- a/content/manuals/dhi/how-to/policies.md +++ b/content/manuals/dhi/how-to/policies.md @@ -215,7 +215,7 @@ jobs: The `docker/login-action` step authenticates with Docker Hub so the runner can pull the DHI base image and the `dhi/policies` bundle. Store your Docker Hub -username and a [personal access token](/manuals/security/access-tokens.md) as the +username and a [personal access token](/manuals/platform/security/access-tokens/personal-access-tokens.md) as the `DOCKER_USER` and `DOCKER_PAT` repository secrets. Set `exit-code: true` to fail the step when any policy isn't met. The diff --git a/content/manuals/dhi/how-to/use.md b/content/manuals/dhi/how-to/use.md index 73bf38594ea0..5df029daa0d6 100644 --- a/content/manuals/dhi/how-to/use.md +++ b/content/manuals/dhi/how-to/use.md @@ -26,9 +26,9 @@ package manager, and may run as a non-root user by default. > you don't have a Docker account, [create one](../../accounts/create-account.md) > for free. > - **Access token:** Use a [personal access token -> (PAT)](../../security/access-tokens.md) for personal accounts, or an +> (PAT)](../../platform/security/access-tokens/personal-access-tokens.md) for personal accounts, or an > [organization access token -> (OAT)](../../enterprise/security/access-tokens.md) with your organization +> (OAT)](../../platform/security/access-tokens/organization-access-tokens.md) with your organization > name as the username. > > Run `docker login dhi.io` to authenticate. @@ -109,14 +109,14 @@ attached to Docker Hardened Images. This is particularly useful in CI/CD pipelines for supply chain security validation and compliance checks. For automated workflows, authenticate using an [organization access token -(OAT)](../../enterprise/security/access-tokens.md). OATs are owned by the +(OAT)](../../platform/security/access-tokens/organization-access-tokens.md). OATs are owned by the organization rather than an individual user, making them better suited for CI/CD pipelines. To discover attestations with ORAS: 1. [Generate an organization access - token](../../enterprise/security/access-tokens.md) with **Read public + token](../../platform/security/access-tokens/organization-access-tokens.md) with **Read public repositories** scope. The following example shows how to discover attestations on DHI community @@ -268,8 +268,8 @@ For the `--docker-server` value: #### Using an access token Create a secret using a [Personal Access Token -(PAT)](../../security/access-tokens.md) or [Organization Access Token -(OAT)](../../enterprise/security/access-tokens.md). Ensure the token has at +(PAT)](../../platform/security/access-tokens/personal-access-tokens.md) or [Organization Access Token +(OAT)](../../platform/security/access-tokens/organization-access-tokens.md). Ensure the token has at least read-only access to the repositories. ```console diff --git a/content/manuals/dhi/how-to/verify.md b/content/manuals/dhi/how-to/verify.md index ab4602e0deb7..9021b47bc940 100644 --- a/content/manuals/dhi/how-to/verify.md +++ b/content/manuals/dhi/how-to/verify.md @@ -62,11 +62,11 @@ This command shows all available attestations, including SBOMs, provenance, vuln First, authenticate to both registries. This example authenticates as your Docker organization using an [organization access token -(OAT)](../../enterprise/security/access-tokens.md). The OAT must have at least +(OAT)](../../platform/security/access-tokens/organization-access-tokens.md). The OAT must have at least pull access to the DHI repositories you want to verify. Only repositories in the token's scope are accessible. Alternatively, you can authenticate as a Docker Hub user with a [personal access token -(PAT)](../../security/access-tokens.md) that has `read only` access. +(PAT)](../../platform/security/access-tokens/personal-access-tokens.md) that has `read only` access. > [!WARNING] > diff --git a/content/manuals/dhi/tools/api.md b/content/manuals/dhi/tools/api.md index be29c3ce9d6b..7062770f541f 100644 --- a/content/manuals/dhi/tools/api.md +++ b/content/manuals/dhi/tools/api.md @@ -40,7 +40,7 @@ Every query takes a `Context` argument (conventionally named `ctx` in the ## Authentication -An [organization access token](/manuals/enterprise/security/access-tokens.md) +An [organization access token](/manuals/platform/security/access-tokens/organization-access-tokens.md) (OAT) or personal access token (PAT) isn't used directly as the bearer token. Exchange it first for an access token: diff --git a/content/manuals/dhi/tools/mcp.md b/content/manuals/dhi/tools/mcp.md index bc71dae76de6..ebf014575c99 100644 --- a/content/manuals/dhi/tools/mcp.md +++ b/content/manuals/dhi/tools/mcp.md @@ -148,7 +148,7 @@ based on what you ask: ## Authenticate for mirror tools The mirror tools require a Docker Hub username and [personal access token -(PAT)](/security/access-tokens/) with owner access to the target organization, +(PAT)](/platform/security/access-tokens/personal-access-tokens/) with owner access to the target organization, passed as an HTTP Basic auth header. Generate the value with: ```console diff --git a/content/manuals/docker-hub/release-notes.md b/content/manuals/docker-hub/release-notes.md index 4b45b5eb3b74..da93573e506f 100644 --- a/content/manuals/docker-hub/release-notes.md +++ b/content/manuals/docker-hub/release-notes.md @@ -110,7 +110,7 @@ known issues for each Docker Hub release. ### New -- Organizations can assign the [editor role](/manuals/enterprise/security/roles-and-permissions/_index.md) to members to grant additional permissions without full administrative access. +- Organizations can assign the [editor role](/manuals/platform/security/roles-and-permissions/_index.md) to members to grant additional permissions without full administrative access. ## 2023-05-09 @@ -140,7 +140,7 @@ known issues for each Docker Hub release. ### Bug fixes and enhancements -- In Docker Hub, you can now download a [registry.json](/manuals/enterprise/security/enforce-sign-in/_index.md) file or copy the commands to create a registry.json file to enforce sign-in for your organization. +- In Docker Hub, you can now download a [registry.json](/manuals/platform/security/authentication/enforce-sign-in/_index.md) file or copy the commands to create a registry.json file to enforce sign-in for your organization. ## 2022-09-19 @@ -170,7 +170,7 @@ known issues for each Docker Hub release. ### New -- [Registry Access Management](/manuals/enterprise/security/hardened-desktop/registry-access-management.md) is now available for all Docker Business subscriptions. When enabled, your users can access specific registries in Docker Hub. +- [Registry Access Management](/manuals/enterprise/hardened-desktop/registry-access-management.md) is now available for all Docker Business subscriptions. When enabled, your users can access specific registries in Docker Hub. ## 2022-05-03 @@ -318,7 +318,7 @@ Docker introduces Hub Vulnerability Scanning which enables you to automatically ### New features -- You can now [create personal access tokens](/security/access-tokens/) in Docker Hub and use them to authenticate from the Docker CLI. Find them in your account settings, under the new **[Security](https://hub.docker.com/settings/security)** section. +- You can now [create personal access tokens](/platform/security/access-tokens/personal-access-tokens/) in Docker Hub and use them to authenticate from the Docker CLI. Find them in your account settings, under the new **[Security](https://hub.docker.com/settings/security)** section. ### Known Issues diff --git a/content/manuals/docker-hub/repos/create.md b/content/manuals/docker-hub/repos/create.md index 9e20df6710c0..d21171cd5bf6 100644 --- a/content/manuals/docker-hub/repos/create.md +++ b/content/manuals/docker-hub/repos/create.md @@ -39,7 +39,7 @@ weight: 20 is only accessible to you and collaborators. In addition, if you selected an organization's namespace, then the repository is accessible to those with applicable roles or permissions. For more details, see [Roles and - permissions](/manuals/enterprise/security/roles-and-permissions.md). + permissions](/manuals/platform/security/roles-and-permissions.md). > [!NOTE] > diff --git a/content/manuals/docker-hub/repos/manage/access.md b/content/manuals/docker-hub/repos/manage/access.md index c88d3492cfb3..0124d2bc28fc 100644 --- a/content/manuals/docker-hub/repos/manage/access.md +++ b/content/manuals/docker-hub/repos/manage/access.md @@ -94,7 +94,7 @@ repository from that repository's **Settings** page. Organizations can use roles for individuals, giving them different permissions in the organization. For more details, see [Roles and -permissions](/manuals/enterprise/security/roles-and-permissions.md). +permissions](/manuals/platform/security/roles-and-permissions.md). ## Organization teams @@ -131,7 +131,7 @@ To configure team repository permissions: Organizations can use OATs. OATs let you assign fine-grained repository access permissions to tokens. For more details, see [Organization access -tokens](/manuals/enterprise/security/access-tokens.md). +tokens](/manuals/platform/security/access-tokens/organization-access-tokens.md). ## Gated distribution @@ -156,7 +156,7 @@ If you are interested in Gated Distribution contact the }} diff --git a/content/manuals/enterprise/security/hardened-desktop/air-gapped-containers.md b/content/manuals/enterprise/hardened-desktop/air-gapped-containers.md similarity index 88% rename from content/manuals/enterprise/security/hardened-desktop/air-gapped-containers.md rename to content/manuals/enterprise/hardened-desktop/air-gapped-containers.md index 36eb900d1e10..54758d90a0c9 100644 --- a/content/manuals/enterprise/security/hardened-desktop/air-gapped-containers.md +++ b/content/manuals/enterprise/hardened-desktop/air-gapped-containers.md @@ -4,6 +4,7 @@ description: Restrict outbound container traffic using proxy rules, PAC files, a keywords: air gapped containers, network security, proxy configuration, container isolation, docker desktop, PAC file, network isolation aliases: - /security/for-admins/hardened-desktop/air-gapped-containers/ + - /enterprise/security/hardened-desktop/air-gapped-containers/ weight: 30 --- @@ -41,13 +42,13 @@ Other considerations: Before configuring air-gapped containers, you must have: -- [Enforce sign-in](/manuals/enterprise/security/enforce-sign-in/_index.md) enabled to ensure users authenticate with your organization +- [Enforce sign-in](/manuals/platform/security/authentication/enforce-sign-in/_index.md) enabled to ensure users authenticate with your organization - A Docker Business subscription -- Configured [Settings Management](/manuals/enterprise/security/hardened-desktop/settings-management/_index.md) with the `admin-settings.json` file to manage organization policies +- Configured [Settings Management](/manuals/enterprise/hardened-desktop/settings-management/_index.md) with the `admin-settings.json` file to manage organization policies ## Configure air-gapped containers -Add the container proxy to your [`admin-settings.json` file](/manuals/enterprise/security/hardened-desktop/settings-management/configure-json-file.md). For example: +Add the container proxy to your [`admin-settings.json` file](/manuals/enterprise/hardened-desktop/settings-management/configure-json-file.md). For example: ```json { @@ -140,10 +141,11 @@ function FindProxyForURL(url, host) { ### General considerations - `FindProxyForURL` function URL parameter format is `http://host_or_ip:port` or `https://host_or_ip:port` - - If you have an internal container trying to access `https://docs.docker.com/enterprise/security/hardened-desktop/air-gapped-containers` the Docker proxy service will submit docs.docker.com for the host value and https://docs.docker.com:443 for the url value to `FindProxyForURL`, if you are using `shExpMatch` function in your PAC file as follows: + - If you have an internal container trying to access `https://docs.docker.com/enterprise/hardened-desktop/air-gapped-containers` the Docker proxy service will submit docs.docker.com for the host value and https://docs.docker.com:443 for the URL value to `FindProxyForURL`, if you are using `shExpMatch` function in your PAC file as follows: + ```console - if(shExpMatch(url, "https://docs.docker.com:443/enterprise/security/*")) return "DIRECT"; + if(shExpMatch(url, "https://docs.docker.com:443/enterprise/hardened-desktop/*")) return "DIRECT"; ``` `shExpMatch` function will fail, instead use: @@ -151,6 +153,7 @@ function FindProxyForURL(url, host) { ```console if (host == docs.docker.com && url.indexOf(":443") > 0) return "DIRECT"; ``` + ### PAC file return values @@ -227,5 +230,5 @@ $ docker run --rm alpine wget -O- https://docker.io ## Next steps -- [Explore Enhanced Container Isolation](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/_index.md) to further restrict what containers can do at runtime +- [Explore Enhanced Container Isolation](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/_index.md) to further restrict what containers can do at runtime - [Understand how Docker Desktop handles host and container networking](/manuals/desktop/features/networking/_index.md) \ No newline at end of file diff --git a/content/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/_index.md b/content/manuals/enterprise/hardened-desktop/enhanced-container-isolation/_index.md similarity index 97% rename from content/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/_index.md rename to content/manuals/enterprise/hardened-desktop/enhanced-container-isolation/_index.md index 6651dcd4f208..d2b4487fb835 100644 --- a/content/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/_index.md +++ b/content/manuals/enterprise/hardened-desktop/enhanced-container-isolation/_index.md @@ -6,6 +6,7 @@ keywords: enhanced container isolation, container security, sysbox runtime, linu aliases: - /desktop/hardened-desktop/enhanced-container-isolation/ - /security/for-admins/hardened-desktop/enhanced-container-isolation/ + - /enterprise/security/hardened-desktop/enhanced-container-isolation/ weight: 10 --- @@ -13,7 +14,7 @@ weight: 10 Enhanced Container Isolation (ECI) prevents malicious containers from compromising Docker Desktop or the host system. It applies advanced security techniques automatically while maintaining full developer productivity and workflow compatibility. -- ECI strengthens container isolation and locks in security configurations created by administrators, such as [Registry Access Management policies](/manuals/enterprise/security/hardened-desktop/registry-access-management.md) and [Settings Management](../settings-management/_index.md) controls. +- ECI strengthens container isolation and locks in security configurations created by administrators, such as [Registry Access Management policies](/manuals/enterprise/hardened-desktop/registry-access-management.md) and [Settings Management](../settings-management/_index.md) controls. - ECI works alongside other Docker security features like reduced Linux capabilities, seccomp, and AppArmor. If you are using WSL2 backend, ensure you’re running WSL version 2.6 or later. This is required because ECI depends on a Linux kernel version of at least 6.3.0, and WSL 2.6+ includes kernel version 6.6. @@ -212,4 +213,4 @@ Enhanced Container Isolation maintains optimized performance and full compatibil > [!IMPORTANT] > -> ECI protection varies by Docker Desktop version and doesn't yet protect extension containers. Docker builds and Kubernetes in Docker Desktop have varying protection levels depending on the version. For details, see [Enhanced Container Isolation limitations](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/limitations.md). +> ECI protection varies by Docker Desktop version and doesn't yet protect extension containers. Docker builds and Kubernetes in Docker Desktop have varying protection levels depending on the version. For details, see [Enhanced Container Isolation limitations](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/limitations.md). diff --git a/content/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/config.md b/content/manuals/enterprise/hardened-desktop/enhanced-container-isolation/config.md similarity index 94% rename from content/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/config.md rename to content/manuals/enterprise/hardened-desktop/enhanced-container-isolation/config.md index 2ce32c791dd2..3b21936bf31d 100644 --- a/content/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/config.md +++ b/content/manuals/enterprise/hardened-desktop/enhanced-container-isolation/config.md @@ -5,6 +5,7 @@ description: Configure Docker socket exceptions and advanced settings for Enhanc keywords: enhanced container isolation, docker socket, configuration, testcontainers, admin settings aliases: - /security/for-admins/hardened-desktop/enhanced-container-isolation/config/ + - /enterprise/security/hardened-desktop/enhanced-container-isolation/config/ weight: 20 --- @@ -32,7 +33,7 @@ Configure Docker socket exceptions using Settings Management: 1. Sign in to [Docker Home](https://app.docker.com) and select your organization from the top-left account drop-down. 1. Select **Docker Desktop**, then **Settings Management**. -1. [Create or edit a setting policy](/manuals/enterprise/security/hardened-desktop/settings-management/configure-admin-console.md). +1. [Create or edit a setting policy](/manuals/enterprise/hardened-desktop/settings-management/configure-admin-console.md). 1. Find **Enhanced Container Isolation** settings. 1. Configure **Docker socket access control** with your trusted images and command restrictions. @@ -40,7 +41,7 @@ command restrictions. {{< /tab >}} {{< tab name="JSON file" >}} -Create an [`admin-settings.json` file](/manuals/enterprise/security/hardened-desktop/settings-management/configure-json-file.md) and add: +Create an [`admin-settings.json` file](/manuals/enterprise/hardened-desktop/settings-management/configure-json-file.md) and add: ```json { @@ -278,5 +279,5 @@ This resolves digest mismatches when upstream images are updated. ## Next steps -- Review [Enhanced Container Isolation limitations](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/limitations.md). -- Review [Enhanced Container Isolation FAQs](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/faq.md). +- Review [Enhanced Container Isolation limitations](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/limitations.md). +- Review [Enhanced Container Isolation FAQs](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/faq.md). diff --git a/content/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/enable-eci.md b/content/manuals/enterprise/hardened-desktop/enhanced-container-isolation/enable-eci.md similarity index 85% rename from content/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/enable-eci.md rename to content/manuals/enterprise/hardened-desktop/enhanced-container-isolation/enable-eci.md index 6b554f4b28a2..0d1700b41438 100644 --- a/content/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/enable-eci.md +++ b/content/manuals/enterprise/hardened-desktop/enhanced-container-isolation/enable-eci.md @@ -4,6 +4,8 @@ linkTitle: Enable ECI description: Enable Enhanced Container Isolation to secure containers in Docker Desktop keywords: enhanced container isolation, enable eci, container security, docker desktop setup weight: 15 +aliases: + - /enterprise/security/hardened-desktop/enhanced-container-isolation/enable-eci/ --- {{< summary-bar feature_name="Hardened Docker Desktop" >}} @@ -17,7 +19,7 @@ This page shows you how to turn on Enhanced Container Isolation (ECI) and verify Before you begin, you must have: - A Docker Business subscription -- [Enforced sign-in](/manuals/enterprise/security/enforce-sign-in/_index.md) (for administrators managing organization-wide settings only) +- [Enforced sign-in](/manuals/platform/security/authentication/enforce-sign-in/_index.md) (for administrators managing organization-wide settings only) ## Enable Enhanced Container Isolation @@ -51,13 +53,13 @@ Configure Enhanced Container Isolation organization-wide using Settings Manageme 1. Sign in to [Docker Home](https://app.docker.com) and select your organization from the top-left account drop-down. 1. Select **Docker Desktop**, then **Settings Management**. -1. [Create or edit a setting policy](/manuals/enterprise/security/hardened-desktop/settings-management/configure-admin-console.md). +1. [Create or edit a setting policy](/manuals/enterprise/hardened-desktop/settings-management/configure-admin-console.md). 1. Set **Enhanced Container Isolation** to **Always enabled**. {{< /tab >}} {{< tab name="JSON file" >}} -1. Create an [`admin-settings.json` file](/manuals/enterprise/security/hardened-desktop/settings-management/configure-json-file.md) and add: +1. Create an [`admin-settings.json` file](/manuals/enterprise/hardened-desktop/settings-management/configure-json-file.md) and add: ```json { @@ -88,7 +90,7 @@ For ECI settings to take effect: > > Restarting from the Docker Desktop menu isn't sufficient. Users must completely quit and reopen Docker Desktop. -You can also configure [Docker socket mount permissions](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/config.md) for trusted images that need Docker API access. +You can also configure [Docker socket mount permissions](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/config.md) for trusted images that need Docker API access. ## Verify Enhanced Container Isolation is active @@ -164,5 +166,5 @@ Docker Desktop settings. ## Next steps -- Review [Configure Docker socket exceptions and advanced settings](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/config.md). -- Review [Enhanced Container Isolation limitations](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/limitations.md). +- Review [Configure Docker socket exceptions and advanced settings](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/config.md). +- Review [Enhanced Container Isolation limitations](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/limitations.md). diff --git a/content/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/faq.md b/content/manuals/enterprise/hardened-desktop/enhanced-container-isolation/faq.md similarity index 89% rename from content/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/faq.md rename to content/manuals/enterprise/hardened-desktop/enhanced-container-isolation/faq.md index 3dee031d634c..d1af00951bea 100644 --- a/content/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/faq.md +++ b/content/manuals/enterprise/hardened-desktop/enhanced-container-isolation/faq.md @@ -6,6 +6,7 @@ keywords: enhanced container isolation, faq, troubleshooting, docker desktop toc_max: 2 aliases: - /security/for-admins/hardened-desktop/enhanced-container-isolation/faq/ + - /enterprise/security/hardened-desktop/enhanced-container-isolation/faq/ weight: 40 --- @@ -19,7 +20,7 @@ No. ECI works automatically in the background by creating more secure containers ## Do all container workloads work well with ECI? -Most container workloads run without issues when ECI is turned on. However, some advanced workloads that require specific kernel-level access may not work. For details about which workloads are affected, see [ECI limitations](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/limitations.md). +Most container workloads run without issues when ECI is turned on. However, some advanced workloads that require specific kernel-level access may not work. For details about which workloads are affected, see [ECI limitations](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/limitations.md). ## Why not just restrict usage of the `--privileged` flag? @@ -50,7 +51,7 @@ $ docker stop $(docker ps -q) $ docker rm $(docker ps -aq) ``` -For more details, see [Enable Enhanced Container Isolation](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/enable-eci.md). +For more details, see [Enable Enhanced Container Isolation](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/enable-eci.md). ## Which containers does ECI protect? @@ -72,13 +73,13 @@ ECI protection varies by container type and Docker Desktop version: - Docker Debug containers - Kubernetes with Kubeadm provisioner -For complete details, see [ECI limitations](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/limitations.md). +For complete details, see [ECI limitations](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/limitations.md). ## Can I mount the Docker socket with ECI turned on? By default, no. ECI blocks Docker socket bind mounts for security. However, you can configure exceptions for trusted images like Testcontainers. -For configuration details, see [Configure Docker socket exceptions](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/config.md). +For configuration details, see [Configure Docker socket exceptions](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/config.md). ## What bind mounts does ECI restrict? diff --git a/content/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/limitations.md b/content/manuals/enterprise/hardened-desktop/enhanced-container-isolation/limitations.md similarity index 98% rename from content/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/limitations.md rename to content/manuals/enterprise/hardened-desktop/enhanced-container-isolation/limitations.md index e7a2f63736b4..119c7ce3b403 100644 --- a/content/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/limitations.md +++ b/content/manuals/enterprise/hardened-desktop/enhanced-container-isolation/limitations.md @@ -7,6 +7,7 @@ toc_max: 3 weight: 30 aliases: - /security/for-admins/hardened-desktop/enhanced-container-isolation/limitations/ + - /enterprise/security/hardened-desktop/enhanced-container-isolation/limitations/ --- {{< summary-bar feature_name="Hardened Docker Desktop" >}} diff --git a/content/manuals/enterprise/security/hardened-desktop/image-access-management.md b/content/manuals/enterprise/hardened-desktop/image-access-management.md similarity index 92% rename from content/manuals/enterprise/security/hardened-desktop/image-access-management.md rename to content/manuals/enterprise/hardened-desktop/image-access-management.md index e77af278b2a3..9b725127d8a1 100644 --- a/content/manuals/enterprise/security/hardened-desktop/image-access-management.md +++ b/content/manuals/enterprise/hardened-desktop/image-access-management.md @@ -7,6 +7,7 @@ aliases: - /admin/organization/image-access/ - /security/for-admins/image-access-management/ - /security/for-admins/hardened-desktop/image-access-management/ + - /enterprise/security/hardened-desktop/image-access-management/ weight: 50 --- @@ -44,8 +45,8 @@ Use the repository allowlist when you need to: Before configuring Image Access Management, you must: -- [Enforce sign-in](/manuals/enterprise/security/enforce-sign-in/_index.md). Image Access Management only takes effect when users are signed in to Docker Desktop with organization credentials. -- Use [personal access tokens (PATs)](/manuals/security/access-tokens.md) for authentication (Organization access tokens aren't supported) +- [Enforce sign-in](/manuals/platform/security/authentication/enforce-sign-in/_index.md). Image Access Management only takes effect when users are signed in to Docker Desktop with organization credentials. +- Use [personal access tokens (PATs)](/manuals/platform/security/access-tokens/personal-access-tokens.md) for authentication (Organization access tokens aren't supported) - Have a Docker Business subscription ## Configure image access @@ -109,7 +110,7 @@ Image access restrictions apply to all Docker Hub operations including pulls, bu ## Scope and bypass considerations -- Image Access Management only controls access to Docker Hub images. Images from other registries aren't affected by these policies. Use [Registry Access Management](/manuals/enterprise/security/hardened-desktop/registry-access-management.md) to control access to other registries. +- Image Access Management only controls access to Docker Hub images. Images from other registries aren't affected by these policies. Use [Registry Access Management](/manuals/enterprise/hardened-desktop/registry-access-management.md) to control access to other registries. - Users can potentially bypass Image Access Management by signing out of Docker Desktop (unless sign-in is enforced), using images from other registries that aren't restricted, or using registry mirrors or proxies. Enforce sign-in and combine with Registry Access Management for comprehensive control. - Image restrictions apply to Dockerfile `FROM` instructions, Docker Compose services using restricted images will fail, multi-stage builds may be affected if intermediate images are restricted, and CI/CD pipelines using diverse image types may be impacted. diff --git a/content/manuals/enterprise/security/hardened-desktop/namespace-access.md b/content/manuals/enterprise/hardened-desktop/namespace-access.md similarity index 97% rename from content/manuals/enterprise/security/hardened-desktop/namespace-access.md rename to content/manuals/enterprise/hardened-desktop/namespace-access.md index 14c81e03fe51..9d502100fda8 100644 --- a/content/manuals/enterprise/security/hardened-desktop/namespace-access.md +++ b/content/manuals/enterprise/hardened-desktop/namespace-access.md @@ -5,6 +5,8 @@ description: Control whether organization members can push content to their pers keywords: namespace access, docker hub, personal namespace, organization security, docker business tags: [admin] weight: 60 +aliases: + - /enterprise/security/hardened-desktop/namespace-access/ --- {{< summary-bar feature_name="Namespace access" >}} diff --git a/content/manuals/enterprise/security/hardened-desktop/registry-access-management.md b/content/manuals/enterprise/hardened-desktop/registry-access-management.md similarity index 92% rename from content/manuals/enterprise/security/hardened-desktop/registry-access-management.md rename to content/manuals/enterprise/hardened-desktop/registry-access-management.md index c4bd8e2dd60e..f9f4714e42bf 100644 --- a/content/manuals/enterprise/security/hardened-desktop/registry-access-management.md +++ b/content/manuals/enterprise/hardened-desktop/registry-access-management.md @@ -12,6 +12,7 @@ aliases: - /security/for-admins/registry-access-management/ - /security/for-admins/hardened-desktop/registry-access-management/ - /docker-hub/registry-access-management/ + - /enterprise/security/hardened-desktop/registry-access-management/ weight: 40 --- @@ -41,11 +42,11 @@ Registry Access Management works with any container registry, including: Before configuring Registry Access Management, you must: -- [Enforce sign-in](/manuals/enterprise/security/enforce-sign-in/_index.md). +- [Enforce sign-in](/manuals/platform/security/authentication/enforce-sign-in/_index.md). Registry Access Management only takes effect when users are signed in to Docker Desktop with organization credentials. - Use - [Organization access tokens (OATs)](/manuals/enterprise/security/access-tokens.md) + [Organization access tokens (OATs)](/manuals/platform/security/access-tokens/organization-access-tokens.md) for authentication - Have a Docker Business subscription @@ -138,7 +139,7 @@ Users can potentially bypass Registry Access Management through: To maximize security effectiveness: -- [Enforce sign-in](/manuals/enterprise/security/enforce-sign-in/_index.md) to +- [Enforce sign-in](/manuals/platform/security/authentication/enforce-sign-in/_index.md) to prevent bypass through sign-out - Implement additional network-level controls for complete protection - Use Registry Access Management as part of a broader security strategy @@ -164,5 +165,5 @@ To maximize security effectiveness: - Confirm all necessary redirect domains are included - Ensure development workflows aren't disrupted - Combine with - [Enhanced Container Isolation](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/_index.md) + [Enhanced Container Isolation](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/_index.md) for broader Desktop security \ No newline at end of file diff --git a/content/manuals/enterprise/security/hardened-desktop/settings-management/_index.md b/content/manuals/enterprise/hardened-desktop/settings-management/_index.md similarity index 81% rename from content/manuals/enterprise/security/hardened-desktop/settings-management/_index.md rename to content/manuals/enterprise/hardened-desktop/settings-management/_index.md index 86915d861306..ffa01f671e6f 100644 --- a/content/manuals/enterprise/security/hardened-desktop/settings-management/_index.md +++ b/content/manuals/enterprise/hardened-desktop/settings-management/_index.md @@ -6,6 +6,7 @@ title: Settings Management linkTitle: Settings Management aliases: - /security/for-admins/hardened-desktop/settings-management/ + - /enterprise/security/hardened-desktop/settings-management/ weight: 10 --- @@ -25,9 +26,9 @@ Settings Management is designed for organizations that: Administrators can define settings using one of these methods: -- [Docker Home](/manuals/enterprise/security/hardened-desktop/settings-management/configure-admin-console.md): Create and assign settings policies via Docker Home. This provides a web-based interface for managing settings +- [Docker Home](/manuals/enterprise/hardened-desktop/settings-management/configure-admin-console.md): Create and assign settings policies via Docker Home. This provides a web-based interface for managing settings across your organization. -- [`admin-settings.json` file](/manuals/enterprise/security/hardened-desktop/settings-management/configure-json-file.md): Place a configuration file on the +- [`admin-settings.json` file](/manuals/enterprise/hardened-desktop/settings-management/configure-json-file.md): Place a configuration file on the user's machine to enforce settings. This method works well for automated deployments and scripted installations. @@ -45,7 +46,7 @@ Settings Management supports a wide range of Docker Desktop features, including: - Security policies - Cloud policies -For a complete list of settings you can enforce, see the [Settings reference](/manuals/enterprise/security/hardened-desktop/settings-management/settings-reference.md). +For a complete list of settings you can enforce, see the [Settings reference](/manuals/enterprise/hardened-desktop/settings-management/settings-reference.md). ## Policy precedence @@ -54,18 +55,18 @@ When multiple policies exist, Docker Desktop applies them in this order: 1. User-specific policies: Highest priority 1. Organization default policy: Applied when no user-specific policy exists 1. Local `admin-settings.json` file: Lowest priority, overridden by Docker Home policies -1. [Configuration profiles](/manuals/enterprise/security/enforce-sign-in/methods.md#configuration-profiles-method-mac-only) when used to control proxy settings +1. [Configuration profiles](/manuals/platform/security/authentication/enforce-sign-in/methods.md#configuration-profiles-method-mac-only) when used to control proxy settings ## Set up Settings Management You can create settings management policies at any time, but your organization needs to verify a domain before the policies take effect. -1. Check that you have [added and verified](/manuals/enterprise/security/domain-management.md#add-and-verify-a-domain) your organization's domain. -2. [Enforce sign-in](/manuals/enterprise/security/enforce-sign-in/_index.md) to +1. Check that you have [added and verified](/manuals/platform/security/provisioning/domain-management.md#add-and-verify-a-domain) your organization's domain. +2. [Enforce sign-in](/manuals/platform/security/authentication/enforce-sign-in/_index.md) to ensure all developers authenticate with your organization. 3. Choose a configuration method: - Use the `--admin-settings` installer flag on [macOS](/manuals/desktop/setup/install/mac-install.md#install-from-the-command-line) or [Windows](/manuals/desktop/setup/install/windows-install.md#install-from-the-command-line) to automatically create the `admin-settings.json`. - - Manually create and configure the [`admin-settings.json` file](/manuals/enterprise/security/hardened-desktop/settings-management/configure-json-file.md). + - Manually create and configure the [`admin-settings.json` file](/manuals/enterprise/hardened-desktop/settings-management/configure-json-file.md). - Create a settings policy in the [Docker Home](configure-admin-console.md). After configuration, developers receive the enforced settings when they: diff --git a/content/manuals/enterprise/security/hardened-desktop/settings-management/compliance-reporting.md b/content/manuals/enterprise/hardened-desktop/settings-management/compliance-reporting.md similarity index 94% rename from content/manuals/enterprise/security/hardened-desktop/settings-management/compliance-reporting.md rename to content/manuals/enterprise/hardened-desktop/settings-management/compliance-reporting.md index 95bba780115c..82e455832d94 100644 --- a/content/manuals/enterprise/security/hardened-desktop/settings-management/compliance-reporting.md +++ b/content/manuals/enterprise/hardened-desktop/settings-management/compliance-reporting.md @@ -6,6 +6,7 @@ keywords: settings management, compliance reporting, docker home, policy enforce weight: 30 aliases: - /security/for-admins/hardened-desktop/settings-management/compliance-reporting/ + - /enterprise/security/hardened-desktop/settings-management/compliance-reporting/ --- {{< summary-bar feature_name="Compliance reporting" >}} @@ -17,8 +18,8 @@ Desktop settings reporting tracks user compliance with Docker Desktop settings p Before you can use Docker Desktop settings reporting, make sure you have: - [Docker Desktop](/manuals/desktop/release-notes.md) installed across your organization -- [A verified domain](/manuals/enterprise/security/single-sign-on/connect.md) -- [Enforced sign-in](/manuals/enterprise/security/enforce-sign-in/_index.md) for your organization +- [A verified domain](/manuals/platform/security/authentication/single-sign-on/connect.md) +- [Enforced sign-in](/manuals/platform/security/authentication/enforce-sign-in/_index.md) for your organization - A Docker Business subscription - At least one settings policy configured diff --git a/content/manuals/enterprise/security/hardened-desktop/settings-management/configure-admin-console.md b/content/manuals/enterprise/hardened-desktop/settings-management/configure-admin-console.md similarity index 93% rename from content/manuals/enterprise/security/hardened-desktop/settings-management/configure-admin-console.md rename to content/manuals/enterprise/hardened-desktop/settings-management/configure-admin-console.md index e787818cd0ab..5a3e267b7b70 100644 --- a/content/manuals/enterprise/security/hardened-desktop/settings-management/configure-admin-console.md +++ b/content/manuals/enterprise/hardened-desktop/settings-management/configure-admin-console.md @@ -6,6 +6,7 @@ keywords: docker home, settings management, policy configuration, enterprise con weight: 20 aliases: - /security/for-admins/hardened-desktop/settings-management/configure-admin-console/ + - /enterprise/security/hardened-desktop/settings-management/configure-admin-console/ --- {{< summary-bar feature_name="Admin Console" >}} @@ -17,8 +18,8 @@ Use Docker Home to create and manage settings policies for Docker Desktop across Before you begin, make sure you have: - [Docker Desktop](/manuals/desktop/release-notes.md) installed -- [A verified domain](/enterprise/security/single-sign-on/connect/#step-1-add-a-domain) -- [Enforced sign-in](/manuals/enterprise/security/enforce-sign-in/_index.md) for your organization +- [A verified domain](/platform/security/authentication/single-sign-on/connect/#step-1-add-a-domain) +- [Enforced sign-in](/manuals/platform/security/authentication/enforce-sign-in/_index.md) for your organization - A Docker Business subscription > [!IMPORTANT] diff --git a/content/manuals/enterprise/security/hardened-desktop/settings-management/configure-json-file.md b/content/manuals/enterprise/hardened-desktop/settings-management/configure-json-file.md similarity index 99% rename from content/manuals/enterprise/security/hardened-desktop/settings-management/configure-json-file.md rename to content/manuals/enterprise/hardened-desktop/settings-management/configure-json-file.md index 8426e587b7ee..8438fe0cd492 100644 --- a/content/manuals/enterprise/security/hardened-desktop/settings-management/configure-json-file.md +++ b/content/manuals/enterprise/hardened-desktop/settings-management/configure-json-file.md @@ -7,6 +7,7 @@ weight: 10 aliases: - /security/for-admins/hardened-desktop/settings-management/configure/ - /security/for-admins/hardened-desktop/settings-management/configure-json-file/ + - /enterprise/security/hardened-desktop/settings-management/configure-json-file/ --- {{< summary-bar feature_name="Hardened Docker Desktop" >}} @@ -17,7 +18,7 @@ Settings Management lets you configure and enforce Docker Desktop settings acros Before you begin, make sure you have: -- [Enforce sign-in](/manuals/enterprise/security/enforce-sign-in/_index.md) for +- [Enforce sign-in](/manuals/platform/security/authentication/enforce-sign-in/_index.md) for your organization - A Docker Business subscription diff --git a/content/manuals/enterprise/security/hardened-desktop/settings-management/settings-reference.md b/content/manuals/enterprise/hardened-desktop/settings-management/settings-reference.md similarity index 98% rename from content/manuals/enterprise/security/hardened-desktop/settings-management/settings-reference.md rename to content/manuals/enterprise/hardened-desktop/settings-management/settings-reference.md index 80b254341fcc..1462378fdad6 100644 --- a/content/manuals/enterprise/security/hardened-desktop/settings-management/settings-reference.md +++ b/content/manuals/enterprise/hardened-desktop/settings-management/settings-reference.md @@ -6,9 +6,10 @@ keywords: docker desktop settings, configuration reference, admin controls, sett toc_max: 2 aliases: - /security/for-admins/hardened-desktop/settings-management/settings-reference/ + - /enterprise/security/hardened-desktop/settings-management/settings-reference/ --- -This reference documents Docker Desktop settings that administrators can configure using [Settings Management](/manuals/enterprise/security/hardened-desktop/settings-management/_index.md). Use this page to understand which settings are available, their accepted values, platform compatibility, and which configuration methods apply. +This reference documents Docker Desktop settings that administrators can configure using [Settings Management](/manuals/enterprise/hardened-desktop/settings-management/_index.md). Use this page to understand which settings are available, their accepted values, platform compatibility, and which configuration methods apply. > [!NOTE] > @@ -431,7 +432,7 @@ The [`proxy`](#proxy) setting governs Docker Desktop host-level traffic: the Des } ``` -For more information, see [Air-gapped containers](/manuals/enterprise/security/hardened-desktop/air-gapped-containers.md). +For more information, see [Air-gapped containers](/manuals/enterprise/hardened-desktop/air-gapped-containers.md). ## LinuxVM diff --git a/content/manuals/enterprise/security/_index.md b/content/manuals/enterprise/security/_index.md deleted file mode 100644 index 410dab7878b9..000000000000 --- a/content/manuals/enterprise/security/_index.md +++ /dev/null @@ -1,78 +0,0 @@ ---- -linkTitle: Security -title: Security for enterprises -description: Learn about enterprise level security features Docker has to offer and explore best practices -keywords: docker, docker hub, docker desktop, security, enterprises, scale -weight: 10 -params: - sidebar: - group: Enterprise -grid_admins: - - title: Settings Management - description: Learn how Settings Management can secure your developers' workflows. - icon: shield-check - link: /enterprise/security/hardened-desktop/settings-management/ - - title: Enhanced Container Isolation - description: Understand how Enhanced Container Isolation can prevent container attacks. - icon: shield-check - link: /enterprise/security/hardened-desktop/enhanced-container-isolation/ - - title: Registry Access Management - description: Control the registries developers can access while using Docker Desktop. - icon: server - link: /enterprise/security/hardened-desktop/registry-access-management/ - - title: Image Access Management - description: Control the images developers can pull from Docker Hub. - icon: photo - link: /enterprise/security/hardened-desktop/image-access-management/ - - title: "Air-Gapped Containers" - description: Restrict containers from accessing unwanted network resources. - icon: lock-closed - link: /enterprise/security/hardened-desktop/air-gapped-containers/ - - title: Enforce sign-in - description: Configure sign-in for members of your teams and organizations. - link: /enterprise/security/enforce-sign-in/ - icon: finger-print - - title: OIDC connections - description: Configure OpenID Connect connections for automated workload authentication. - link: /enterprise/security/oidc-connections/ - icon: link - - title: Domain management - description: Identify uncaptured users in your organization. - link: /enterprise/security/domain-management/ - icon: magnifying-glass - - title: Docker Scout - description: Explore how Docker Scout can help you create a more secure software supply chain. - icon: chart-bar - link: /scout/ - - title: SSO - description: Learn how to configure SSO for your company or organization. - icon: key - link: /enterprise/security/single-sign-on/ - - title: SCIM - description: Set up SCIM to automatically provision and deprovision users. - icon: clipboard-document-check - link: /enterprise/security/provisioning/scim/ - - title: Roles and permissions - description: Assign roles to individuals giving them different permissions within an organization. - icon: identification - link: /enterprise/security/roles-and-permissions/ - - title: Private marketplace for Extensions (Beta) - description: Learn how to configure and set up a private marketplace with a curated list of extensions for your Docker Desktop users. - icon: building-storefront - link: /extensions/private-marketplace/ - - title: Organization access tokens - description: Create organization access tokens as an alternative to a password. - link: /enterprise/security/access-tokens/ - icon: lock-closed ---- - -Docker provides security guardrails for both administrators and developers. - -If you're an administrator, you can enforce sign-in across Docker products for your developers, and -scale, manage, and secure your instances of Docker Desktop with DevOps security controls like Enhanced Container Isolation and Registry Access Management. - -## For administrators - -Explore the security features Docker offers to satisfy your company's security policies. - -{{< grid items="grid_admins" >}} diff --git a/content/manuals/enterprise/security/single-sign-on/FAQs/_index.md b/content/manuals/enterprise/security/single-sign-on/FAQs/_index.md deleted file mode 100644 index 224304008d4e..000000000000 --- a/content/manuals/enterprise/security/single-sign-on/FAQs/_index.md +++ /dev/null @@ -1,6 +0,0 @@ ---- -build: - render: never -title: FAQs -weight: 50 ---- \ No newline at end of file diff --git a/content/manuals/enterprise/security/single-sign-on/FAQs/general.md b/content/manuals/enterprise/security/single-sign-on/FAQs/general.md deleted file mode 100644 index ce25481d4df8..000000000000 --- a/content/manuals/enterprise/security/single-sign-on/FAQs/general.md +++ /dev/null @@ -1,35 +0,0 @@ ---- -description: Frequently asked questions about Docker single sign-on -keywords: Docker, Docker Hub, SSO FAQs, single sign-on, administration, security -title: General SSO FAQs -linkTitle: General -weight: 20 -tags: [FAQ] -aliases: -- /single-sign-on/faqs/ -- /faq/security/single-sign-on/faqs/ -- /single-sign-on/saml-faqs/ -- /faq/security/single-sign-on/saml-faqs/ -- /security/faqs/single-sign-on/saml-faqs/ -- /security/faqs/single-sign-on/faqs/ ---- - -## What SSO flows does Docker support? - -Docker supports Service Provider Initiated (SP-initiated) SSO flow. Users must sign in to Docker Hub or Docker Desktop to initiate the SSO authentication process. - -## Does Docker SSO support multi-factor authentication? - -When an organization uses SSO, multi-factor authentication is controlled at the identity provider level, not on the Docker platform. - -## Can I retain my Docker ID when using SSO? - -Users with personal Docker IDs retain ownership of their repositories, images, and assets. When SSO is enforced, existing accounts with company domain emails are connected to the organization. Users signing in without existing accounts automatically have new accounts and Docker IDs created. - -## Are there any firewall rules required for SSO configuration? - -No specific firewall rules are required as long as `login.docker.com` is accessible. This domain is commonly accessible by default, but some organizations may need to allow it in their firewall settings if SSO setup encounters issues. - -## Does Docker use my IdP's default session timeout? - -Yes, Docker supports your IdP's session timeout using a custom `dockerSessionMinutes` SAML attribute instead of the standard `SessionNotOnOrAfter` element. See [SSO attributes](/manuals/enterprise/security/provisioning/_index.md#sso-attributes) for more information. diff --git a/content/manuals/enterprise/security/single-sign-on/FAQs/idp-faqs.md b/content/manuals/enterprise/security/single-sign-on/FAQs/idp-faqs.md deleted file mode 100644 index 9559a972da18..000000000000 --- a/content/manuals/enterprise/security/single-sign-on/FAQs/idp-faqs.md +++ /dev/null @@ -1,53 +0,0 @@ ---- -title: SSO identity provider FAQs -linkTitle: Identity providers -description: Frequently asked questions about Docker SSO and identity provider configuration -keywords: identity providers, SSO IdP, SAML, Azure AD, Entra ID, certificate management -tags: [FAQ] -aliases: - - /single-sign-on/idp-faqs/ - - /faq/security/single-sign-on/idp-faqs/ - - /security/faqs/single-sign-on/idp-faqs/ ---- - -## Can I use multiple identity providers with Docker SSO? - -Yes, Docker supports multiple IdP configurations. A domain can be associated with multiple IdPs. Docker supports Entra ID (formerly Azure AD) and identity providers that support SAML 2.0. - -## Can I change my identity provider after configuring SSO? - -Yes. Delete your existing IdP configuration in your Docker SSO connection, then [configure SSO using your new IdP](/manuals/enterprise/security/single-sign-on/connect.md). If you had already turned on enforcement, turn off enforcement before updating the provider connection. - -## What information do I need from my identity provider to configure SSO? - -To turn on SSO in Docker, you need the following from your IdP: - -- SAML: Entity ID, ACS URL, Single Logout URL, and the public X.509 certificate -- Entra ID (formerly Azure AD): Client ID, Client Secret, AD Domain - -## What happens if my existing certificate expires? - -Contact your identity provider to retrieve a new X.509 certificate. Update with the new certificate in [SSO configuration settings](/manuals/enterprise/security/single-sign-on/manage.md#manage-sso-connections) from Docker Home. - -- If your organization enforces SSO, username and password credentials won't work. -- If your organization doesn't enforce SSO, users can sign in with their username and password credentials. - -If you need additional help, contact [Docker support](https://app.docker.com/support/contact). - -## What happens if my IdP goes down when SSO is turned on? - -If SSO is enforced, users can't access Docker Hub when your IdP is down. Users can still access Docker Hub images from the CLI using personal access tokens. - -If SSO is turned on but not enforced, users can fall back to username/password authentication. - -## Do bot accounts need seats to access organizations using SSO? - -Yes, bot accounts need seats like regular users, requiring a non-aliased domain email in the IdP and using a seat in Docker Hub. You can add bot accounts to your IdP and create access tokens to replace other credentials. - -## Does SAML SSO use Just-in-Time provisioning? - -The SSO implementation uses Just-in-Time (JIT) provisioning by default. You can optionally turn off JIT in Docker Home if you turn on auto-provisioning using SCIM. See [Just-in-Time provisioning](/manuals/enterprise/security/provisioning/just-in-time.md). - -## My Entra ID SSO connection isn't working and shows an error. How can I troubleshoot this? - -Confirm that you've configured the necessary API permissions in Entra ID for your SSO connection. You need to grant administrator consent within your Entra ID tenant. See [Entra ID (formerly Azure AD) documentation](https://learn.microsoft.com/en-us/azure/active-directory/manage-apps/grant-admin-consent?pivots=portal#grant-admin-consent-in-app-registrations). diff --git a/content/manuals/enterprise/security/single-sign-on/FAQs/users-faqs.md b/content/manuals/enterprise/security/single-sign-on/FAQs/users-faqs.md deleted file mode 100644 index a89bbe4ca5f8..000000000000 --- a/content/manuals/enterprise/security/single-sign-on/FAQs/users-faqs.md +++ /dev/null @@ -1,62 +0,0 @@ ---- -title: SSO user management FAQs -linkTitle: User management -description: Frequently asked questions about managing users with Docker single sign-ons -keywords: SSO user management, user provisioning, SCIM, just-in-time provisioning, organization members -tags: [FAQ] -aliases: - - /single-sign-on/users-faqs/ - - /faq/security/single-sign-on/users-faqs/ - - /security/faqs/single-sign-on/users-faqs/ ---- - -## Do I need to manually add users to my organization? - -No, you don't need to manually add users to your organization. Just ensure user accounts exist in your IdP. When users sign in to Docker with their domain email address, they're automatically added to the organization after successful authentication. - -## Can users use different email addresses to authenticate through SSO? - -All users must authenticate using the email domain specified during SSO setup. Users with email addresses that don't match the verified domain can sign in as guests with username and password if SSO isn't enforced, but only if they've been invited. - -## How will users know they're being added to a Docker organization? - -When SSO is turned on, users are prompted to authenticate through SSO the next time they sign in to Docker Hub or Docker Desktop. The system detects their domain email and prompts them to sign in with SSO credentials instead. - -For CLI access, users must authenticate using personal access tokens. - -## Can I convert existing users from non-SSO to SSO accounts? - -Yes, you can convert existing users to SSO accounts. Ensure users have: - -- Company domain email addresses and accounts in your IdP -- Docker Desktop version 4.4.2 or later -- Personal access tokens created to replace passwords for CLI access -- CI/CD pipelines updated to use PATs instead of passwords - -For detailed instructions, see [Configure single sign-on](/manuals/enterprise/security/single-sign-on/connect.md). - -## Is Docker SSO fully synced with the IdP? - -Docker SSO provides Just-in-Time (JIT) provisioning by default. Users are provisioned when they authenticate with SSO. If users leave the organization, administrators must manually [remove the user](/manuals/admin/organization/manage/members.md#remove-members-from-teams) from the organization. - -[SCIM](/manuals/enterprise/security/provisioning/scim/_index.md) provides full synchronization with users and groups. When using SCIM, the recommended configuration is to turn off JIT so all auto-provisioning is handled by SCIM. - -Additionally, you can use the [Docker Hub API](/reference/api/hub/latest.md) to complete this process. - -## How does turning off Just-in-Time provisioning affect user sign-in? - -When JIT is turned off (available with SCIM in Docker Home), users must be organization members or have pending invitations to access Docker. Users who don't meet these criteria get an "Access denied" error and need administrator invitations. - -See [SSO authentication with JIT provisioning disabled](/manuals/enterprise/security/provisioning/just-in-time.md#sso-authentication-with-jit-provisioning-disabled). - -## Can someone join an organization without an invitation? - -Not without SSO. Joining requires an invite from an organization owner. When SSO is enforced, users with verified domain emails can automatically join the organization when they sign in. - -## What happens to existing licensed users when SCIM is turned on? - -Turning on SCIM doesn't immediately remove or modify existing licensed users. They retain current access and roles, but you'll manage them through your IdP after SCIM is active. If SCIM is later turned off, previously SCIM-managed users remain in Docker but are no longer automatically updated based on your IdP. - -## Is user information visible in Docker Hub? - -All Docker accounts have public profiles associated with their namespace. If you don't want user information (like full names) to be visible, remove those attributes from your SSO and SCIM mappings, or use different identifiers to replace users' full names. diff --git a/content/manuals/extensions/private-marketplace.md b/content/manuals/extensions/private-marketplace.md index 593546e67d40..9cd28a1783b9 100644 --- a/content/manuals/extensions/private-marketplace.md +++ b/content/manuals/extensions/private-marketplace.md @@ -11,7 +11,7 @@ weight: 30 Learn how to configure and set up a private marketplace with a curated list of extensions for your Docker Desktop users. -Docker Extensions' private marketplace is designed specifically for organizations who don’t give developers root access to their machines. It makes use of [Settings Management](/manuals/enterprise/security/hardened-desktop/settings-management/_index.md) so administrators have complete control over the private marketplace. +Docker Extensions' private marketplace is designed specifically for organizations who don’t give developers root access to their machines. It makes use of [Settings Management](/manuals/enterprise/hardened-desktop/settings-management/_index.md) so administrators have complete control over the private marketplace. ## Prerequisites @@ -65,7 +65,7 @@ This creates 2 files: > [!IMPORTANT] > -> If your org is using [Settings Management](/manuals/enterprise/security/hardened-desktop/settings-management/_index.md) via [Docker Home](manuals/enterprise/security/hardened-desktop/settings-management/configure-admin-console/_index.md), you will not need the `admin-settings.json` file. Delete the generated file and keep only the `extensions.txt` file. +> If your org is using [Settings Management](/manuals/enterprise/hardened-desktop/settings-management/_index.md) via [Docker Home](manuals/enterprise/hardened-desktop/settings-management/configure-admin-console/_index.md), you will not need the `admin-settings.json` file. Delete the generated file and keep only the `extensions.txt` file. ## Step two: Set the behaviour @@ -73,7 +73,7 @@ The generated `admin-settings.json` file includes various settings you can modif > [!IMPORTANT] > -> If your org is managing settings via [Docker Home](manuals/enterprise/security/hardened-desktop/settings-management/configure-admin-console/_index.md), you will define the same settings in Docker Home instead of the `admin-settings.json` file. +> If your org is managing settings via [Docker Home](manuals/enterprise/hardened-desktop/settings-management/configure-admin-console/_index.md), you will define the same settings in Docker Home instead of the `admin-settings.json` file. Each setting has a `value` that you can set, including a `locked` field that lets you lock the setting and make it unchangeable by your developers. @@ -89,7 +89,7 @@ Each setting has a `value` that you can set, including a `locked` field that let } ``` -To find out more information about the `admin-settings.json` file, see [Settings Management](/manuals/enterprise/security/hardened-desktop/settings-management/_index.md). +To find out more information about the `admin-settings.json` file, see [Settings Management](/manuals/enterprise/hardened-desktop/settings-management/_index.md). ## Step three: List allowed extensions @@ -194,7 +194,7 @@ It's recommended that you try the private marketplace on your Docker Desktop ins > [!IMPORTANT] > -> > If your org is managing settings via [Docker Home](manuals/enterprise/security/hardened-desktop/settings-management/configure-admin-console/_index.md), in Docker Desktop 4.59 and earlier, you must manually delete the `admin-settings.json` file created in the target folder by the `apply` command before step 2. In Docker Desktop 4.60 and later, this step is no longer necessary. +> > If your org is managing settings via [Docker Home](manuals/enterprise/hardened-desktop/settings-management/configure-admin-console/_index.md), in Docker Desktop 4.59 and earlier, you must manually delete the `admin-settings.json` file created in the target folder by the `apply` command before step 2. In Docker Desktop 4.60 and later, this step is no longer necessary. When you select the **Extensions** tab, you should see the private marketplace listing only the extensions you have allowed in `extensions.txt`. @@ -205,7 +205,7 @@ When you select the **Extensions** tab, you should see the private marketplace l Once you’ve confirmed that the private marketplace configuration works, the final step is to distribute the files to the developers’ machines with the MDM software your organization uses. For example, [Jamf](https://www.jamf.com/). The files to distribute are: -* `admin-settings.json` (except if your org is managing settings via [Docker Home](manuals/enterprise/security/hardened-desktop/settings-management/configure-admin-console/_index.md)) +* `admin-settings.json` (except if your org is managing settings via [Docker Home](manuals/enterprise/hardened-desktop/settings-management/configure-admin-console/_index.md)) * the entire `extension-marketplace` folder and its subfolders These files must be placed on developer's machines. Depending on your operating system, the target location is (as mentioned above): @@ -214,7 +214,7 @@ These files must be placed on developer's machines. Depending on your operating - Windows: `C:\ProgramData\DockerDesktop` - Linux: `/usr/share/docker-desktop` -Make sure your developers are signed in to Docker Desktop in order for the private marketplace configuration to take effect. As an administrator, you should [enforce sign-in](/manuals/enterprise/security/enforce-sign-in/_index.md). +Make sure your developers are signed in to Docker Desktop in order for the private marketplace configuration to take effect. As an administrator, you should [enforce sign-in](/manuals/platform/security/authentication/enforce-sign-in/_index.md). ## Feedback diff --git a/content/manuals/extensions/settings-feedback.md b/content/manuals/extensions/settings-feedback.md index c585fd009eaf..fcc00f304ba1 100644 --- a/content/manuals/extensions/settings-feedback.md +++ b/content/manuals/extensions/settings-feedback.md @@ -24,7 +24,7 @@ Docker Extensions is switched off by default. To change your settings: > - `~/Library/Group Containers/group.com.docker/settings-store.json` on Mac > - `C:\Users\[USERNAME]\AppData\Roaming\Docker\settings-store.json` on Windows > -> This can also be done with [Hardened Docker Desktop](/manuals/enterprise/security/hardened-desktop/_index.md) +> This can also be done with [Hardened Docker Desktop](/manuals/enterprise/hardened-desktop/_index.md) ### Turn on or turn off extensions not available in the Marketplace diff --git a/content/manuals/faqs/_index.md b/content/manuals/faqs/_index.md new file mode 100644 index 000000000000..69343b7ce5c7 --- /dev/null +++ b/content/manuals/faqs/_index.md @@ -0,0 +1,15 @@ +--- +title: FAQs +linkTitle: FAQs +description: Frequently asked questions about Docker security, authentication, provisioning, and containers. +keywords: security FAQs, SSO FAQs, container security, Docker security +weight: 45 +params: + sidebar: + group: Platform +aliases: + - /platform/security/faqs/ + - /faq/security/ +--- + +Find answers to common questions about Docker security, authentication, provisioning, and related topics. diff --git a/content/manuals/security/faqs/containers.md b/content/manuals/faqs/containers.md similarity index 94% rename from content/manuals/security/faqs/containers.md rename to content/manuals/faqs/containers.md index 5c3496f338eb..cdc3035b6a60 100644 --- a/content/manuals/security/faqs/containers.md +++ b/content/manuals/faqs/containers.md @@ -7,6 +7,9 @@ weight: 20 tags: [FAQ] aliases: - /faq/security/containers/ +- /security/faqs/containers/ +- /platform/security/resources/faqs/containers/ +- /platform/security/faqs/containers/ --- ## How are containers isolated from the host in Docker Desktop? diff --git a/content/manuals/enterprise/security/single-sign-on/FAQs/domain-faqs.md b/content/manuals/faqs/domain-faqs.md similarity index 89% rename from content/manuals/enterprise/security/single-sign-on/FAQs/domain-faqs.md rename to content/manuals/faqs/domain-faqs.md index ace6b06cad66..b793cf8fb7b6 100644 --- a/content/manuals/enterprise/security/single-sign-on/FAQs/domain-faqs.md +++ b/content/manuals/faqs/domain-faqs.md @@ -1,13 +1,16 @@ --- title: SSO domain FAQs -linkTitle: Domains +linkTitle: Domain description: Frequently asked questions about domain verification and management for Docker single sign-on keywords: SSO domains, domain verification, DNS, TXT records, single sign-on tags: [FAQ] +weight: 50 aliases: - /single-sign-on/domain-faqs/ - /faq/security/single-sign-on/domain-faqs/ - /security/faqs/single-sign-on/domain-faqs/ +- /platform/security/authentication/single-sign-on/FAQs/domain-faqs/ +- /platform/security/faqs/domain-faqs/ --- ## Can I add sub-domains? diff --git a/content/manuals/enterprise/security/single-sign-on/FAQs/enforcement-faqs.md b/content/manuals/faqs/enforcement-faqs.md similarity index 70% rename from content/manuals/enterprise/security/single-sign-on/FAQs/enforcement-faqs.md rename to content/manuals/faqs/enforcement-faqs.md index 39e87fbb471c..b950c967b98d 100644 --- a/content/manuals/enterprise/security/single-sign-on/FAQs/enforcement-faqs.md +++ b/content/manuals/faqs/enforcement-faqs.md @@ -4,21 +4,24 @@ linkTitle: Enforcement description: Frequently asked questions about Docker single sign-on enforcement and its effects on users keywords: SSO enforcement, single sign-on, personal access tokens, CLI authentication, guest users tags: [FAQ] +weight: 60 aliases: - /single-sign-on/enforcement-faqs/ - /faq/security/single-sign-on/enforcement-faqs/ - /security/faqs/single-sign-on/enforcement-faqs/ + - /platform/security/authentication/single-sign-on/FAQs/enforcement-faqs/ + - /platform/security/faqs/enforcement-faqs/ --- ## Does Docker SSO support authenticating through the command line? -When SSO is enforced, [passwords are prevented from accessing the Docker CLI](/manuals/security/security-announcements.md#deprecation-of-password-logins-on-cli-when-sso-enforced). You must use a personal access token (PAT) for CLI authentication instead. +When SSO is enforced, [passwords are prevented from accessing the Docker CLI](/manuals/platform/security/security-announcements.md#deprecation-of-password-logins-on-cli-when-sso-enforced). You must use a personal access token (PAT) for CLI authentication instead. -Each user must create a PAT to access the CLI. To learn how to create a PAT, see [Manage personal access tokens](/manuals/security/access-tokens.md). Users who already used a PAT before SSO enforcement can continue using that PAT. +Each user must create a PAT to access the CLI. To learn how to create a PAT, see [Manage personal access tokens](/manuals/platform/security/access-tokens/personal-access-tokens.md). Users who already used a PAT before SSO enforcement can continue using that PAT. ## How does SSO affect automation systems and CI/CD pipelines? -Before enforcing SSO, you must [create personal access tokens](/manuals/security/access-tokens.md) to replace passwords in automation systems and CI/CD pipelines. +Before enforcing SSO, you must [create personal access tokens](/manuals/platform/security/access-tokens/personal-access-tokens.md) to replace passwords in automation systems and CI/CD pipelines. ## Can I turn on SSO without enforcing it immediately? @@ -39,4 +42,4 @@ These are separate features you can use independently or together: - Enforcing SSO ensures users sign in using SSO credentials instead of their Docker ID, enabling better credential management. - Enforcing sign-in to Docker Desktop ensures users always sign in to accounts that are members of your organization, so security settings and subscription benefits are always applied. -For more details, see [Enforce sign-in for Desktop](/manuals/enterprise/security/enforce-sign-in/_index.md#enforcing-sign-in-versus-enforcing-single-sign-on-sso). +For more details, see [Enforce sign-in for Desktop](/manuals/platform/security/authentication/enforce-sign-in/_index.md#enforcing-sign-in-versus-enforcing-single-sign-on-sso). diff --git a/content/manuals/security/faqs/general.md b/content/manuals/faqs/general.md similarity index 85% rename from content/manuals/security/faqs/general.md rename to content/manuals/faqs/general.md index 89ed07dfabde..bc4b024f72db 100644 --- a/content/manuals/security/faqs/general.md +++ b/content/manuals/faqs/general.md @@ -7,6 +7,9 @@ weight: 10 tags: [FAQ] aliases: - /faq/security/general/ +- /security/faqs/general/ +- /platform/security/resources/faqs/general/ +- /platform/security/faqs/general/ --- ## How do I report a vulnerability? @@ -28,7 +31,7 @@ Docker uses tokens to manage user sessions with different expiration periods: - Docker Desktop: Signs you out after 90 days, or 30 days of inactivity - Docker Hub and Docker Home: Sign you out after 24 hours -Docker also supports your IdP's default session timeout through SAML attributes. For more information, see [SSO attributes](/manuals/enterprise/security/provisioning/_index.md#sso-attributes). +Docker also supports your IdP's default session timeout through SAML attributes. For more information, see [SSO attributes](/manuals/platform/security/provisioning/_index.md#sso-attributes). ## How does Docker distinguish between employee users and contractor users? @@ -40,7 +43,7 @@ Docker activity logs are available for 90 days. You're responsible for exporting ## Can I export a list of users with their roles and privileges? -Yes, use the [Export Members](../../admin/organization/manage/members.md#export-members-csv-file) feature to export a CSV file containing your organization's users with role and team information. +Yes, use the [Export Members](../admin/organization/manage/members.md#export-members-csv-file) feature to export a CSV file containing your organization's users with role and team information. ## How does Docker Desktop handle authentication information? @@ -66,4 +69,4 @@ Security vetting for extensions isn't implemented. Extensions aren't covered as ## Can I prevent users from pushing images to Docker Hub private repositories? -No direct setting exists to disable private repositories. However, [Registry Access Management](/manuals/enterprise/security/hardened-desktop/registry-access-management.md) lets administrators control which registries developers can access through Docker Desktop via Docker Home. +No direct setting exists to disable private repositories. However, [Registry Access Management](/manuals/enterprise/hardened-desktop/registry-access-management.md) lets administrators control which registries developers can access through Docker Desktop via Docker Home. diff --git a/content/manuals/security/faqs/networking-and-vms.md b/content/manuals/faqs/networking-and-vms.md similarity index 87% rename from content/manuals/security/faqs/networking-and-vms.md rename to content/manuals/faqs/networking-and-vms.md index 668697d482a5..dd2e912451b3 100644 --- a/content/manuals/security/faqs/networking-and-vms.md +++ b/content/manuals/faqs/networking-and-vms.md @@ -7,13 +7,16 @@ weight: 30 tags: [FAQ] aliases: - /faq/security/networking-and-vms/ +- /security/faqs/networking-and-vms/ +- /platform/security/resources/faqs/networking-and-vms/ +- /platform/security/faqs/networking-and-vms/ --- ## How can I limit container internet access? Docker Desktop doesn't have a built-in mechanism for this, but you can use process-level firewalls on the host. Apply rules to the `com.docker.vpnkit` user-space process to control where it can connect (DNS allowlists, packet filters) and which ports/protocols it can use. -For enterprise environments, consider [Air-gapped containers](/manuals/enterprise/security/hardened-desktop/air-gapped-containers.md) which provide network access controls for containers. +For enterprise environments, consider [Air-gapped containers](/manuals/enterprise/hardened-desktop/air-gapped-containers.md) which provide network access controls for containers. ## Can I apply firewall rules to container network traffic? diff --git a/content/manuals/faqs/sso-faqs.md b/content/manuals/faqs/sso-faqs.md new file mode 100644 index 000000000000..030a535d7c69 --- /dev/null +++ b/content/manuals/faqs/sso-faqs.md @@ -0,0 +1,140 @@ +--- +description: Frequently asked questions about Docker single sign-on, identity providers, and user management +keywords: Docker, Docker Hub, SSO FAQs, single sign-on, identity providers, IdP, SAML, Entra ID, user management, SCIM, JIT, administration, security +title: SSO FAQs +linkTitle: SSO +weight: 40 +tags: [FAQ] +aliases: +- /single-sign-on/faqs/ +- /faq/security/single-sign-on/faqs/ +- /single-sign-on/saml-faqs/ +- /faq/security/single-sign-on/saml-faqs/ +- /security/faqs/single-sign-on/saml-faqs/ +- /security/faqs/single-sign-on/faqs/ +- /platform/security/authentication/single-sign-on/FAQs/general/ +- /single-sign-on/idp-faqs/ +- /faq/security/single-sign-on/idp-faqs/ +- /security/faqs/single-sign-on/idp-faqs/ +- /platform/security/authentication/single-sign-on/FAQs/idp-faqs/ +- /platform/security/faqs/idp-faqs/ +- /single-sign-on/users-faqs/ +- /faq/security/single-sign-on/users-faqs/ +- /security/faqs/single-sign-on/users-faqs/ +- /platform/security/authentication/single-sign-on/FAQs/users-faqs/ +- /platform/security/faqs/users-faqs/ +- /platform/security/faqs/sso-faqs/ +--- + +## What SSO flows does Docker support? + +Docker supports Service Provider Initiated (SP-initiated) SSO flow. Users must sign in to Docker Hub or Docker Desktop to initiate the SSO authentication process. + +## Does Docker SSO support multi-factor authentication? + +When an organization uses SSO, multi-factor authentication is controlled at the identity provider level, not on the Docker platform. + +## Can I retain my Docker ID when using SSO? + +Users with personal Docker IDs retain ownership of their repositories, images, and assets. When SSO is enforced, existing accounts with company domain emails are connected to the organization. Users signing in without existing accounts automatically have new accounts and Docker IDs created. + +## Are there any firewall rules required for SSO configuration? + +No specific firewall rules are required as long as `login.docker.com` is accessible. This domain is commonly accessible by default, but some organizations may need to allow it in their firewall settings if SSO setup encounters issues. + +## Does Docker use my IdP's default session timeout? + +Yes, Docker supports your IdP's session timeout using a custom `dockerSessionMinutes` SAML attribute instead of the standard `SessionNotOnOrAfter` element. See [SSO attributes](/manuals/platform/security/provisioning/_index.md#sso-attributes) for more information. + +## Can I use multiple identity providers with Docker SSO? + +Yes, Docker supports multiple IdP configurations. A domain can be associated with multiple IdPs. Docker supports Entra ID (formerly Azure AD) and identity providers that support SAML 2.0. + +## Can I change my identity provider after configuring SSO? + +Yes. Delete your existing IdP configuration in your Docker SSO connection, then [configure SSO using your new IdP](/manuals/platform/security/authentication/single-sign-on/connect.md). If you had already turned on enforcement, turn off enforcement before updating the provider connection. + +## What information do I need from my identity provider to configure SSO? + +To turn on SSO in Docker, you need the following from your IdP: + +- SAML: Entity ID, ACS URL, Single Logout URL, and the public X.509 certificate +- Entra ID (formerly Azure AD): Client ID, Client Secret, AD Domain + +## What happens if my existing certificate expires? + +Contact your identity provider to retrieve a new X.509 certificate. Update with the new certificate in [SSO configuration settings](/manuals/platform/security/authentication/single-sign-on/manage.md#manage-sso-connections) from Docker Home. + +- If your organization enforces SSO, username and password credentials won't work. +- If your organization doesn't enforce SSO, users can sign in with their username and password credentials. + +If you need additional help, contact [Docker support](https://app.docker.com/support/contact). + +## What happens if my IdP goes down when SSO is turned on? + +If SSO is enforced, users can't access Docker Hub when your IdP is down. Users can still access Docker Hub images from the CLI using personal access tokens. + +If SSO is turned on but not enforced, users can fall back to username/password authentication. + +## Do bot accounts need seats to access organizations using SSO? + +Yes, bot accounts need seats like regular users, requiring a non-aliased domain email in the IdP and using a seat in Docker Hub. You can add bot accounts to your IdP and create access tokens to replace other credentials. + +## Does SAML SSO use Just-in-Time provisioning? + +The SSO implementation uses Just-in-Time (JIT) provisioning by default. You can optionally turn off JIT in Docker Home if you turn on auto-provisioning using SCIM. See [Just-in-Time provisioning](/manuals/platform/security/provisioning/just-in-time.md). + +## How can I troubleshoot an Entra ID SSO connection error? + +Confirm that you've configured the necessary API permissions in Entra ID for your SSO connection. You need to grant administrator consent within your Entra ID tenant. See [Entra ID (formerly Azure AD) documentation](https://learn.microsoft.com/en-us/azure/active-directory/manage-apps/grant-admin-consent?pivots=portal#grant-admin-consent-in-app-registrations). + +## Do I need to manually add users to my organization? + +No, you don't need to manually add users to your organization. Just ensure user accounts exist in your IdP. When users sign in to Docker with their domain email address, they're automatically added to the organization after successful authentication. + +## Can users use different email addresses to authenticate through SSO? + +All users must authenticate using the email domain specified during SSO setup. Users with email addresses that don't match the verified domain can sign in as guests with username and password if SSO isn't enforced, but only if they've been invited. + +## How will users know they're being added to a Docker organization? + +When SSO is turned on, users are prompted to authenticate through SSO the next time they sign in to Docker Hub or Docker Desktop. The system detects their domain email and prompts them to sign in with SSO credentials instead. + +For CLI access, users must authenticate using personal access tokens. + +## Can I convert existing users from non-SSO to SSO accounts? + +Yes, you can convert existing users to SSO accounts. Ensure users have: + +- Company domain email addresses and accounts in your IdP +- Docker Desktop version 4.4.2 or later +- Personal access tokens created to replace passwords for CLI access +- CI/CD pipelines updated to use PATs instead of passwords + +For detailed instructions, see [Configure single sign-on](/manuals/platform/security/authentication/single-sign-on/connect.md). + +## Is Docker SSO fully synced with the IdP? + +Docker SSO provides Just-in-Time (JIT) provisioning by default. Users are provisioned when they authenticate with SSO. If users leave the organization, administrators must manually [remove the user](/manuals/admin/organization/manage/members.md#remove-members-from-teams) from the organization. + +[SCIM](/manuals/platform/security/provisioning/scim/_index.md) provides full synchronization with users and groups. When using SCIM, the recommended configuration is to turn off JIT so all auto-provisioning is handled by SCIM. + +Additionally, you can use the [Docker Hub API](/reference/api/hub/latest.md) to complete this process. + +## How does turning off Just-in-Time provisioning affect user sign-in? + +When JIT is turned off (available with SCIM in Docker Home), users must be organization members or have pending invitations to access Docker. Users who don't meet these criteria get an "Access denied" error and need administrator invitations. + +See [SSO authentication with JIT provisioning disabled](/manuals/platform/security/provisioning/just-in-time.md#sso-authentication-with-jit-provisioning-disabled). + +## Can someone join an organization without an invitation? + +Not without SSO. Joining requires an invite from an organization owner. When SSO is enforced, users with verified domain emails can automatically join the organization when they sign in. + +## What happens to existing licensed users when SCIM is turned on? + +Turning on SCIM doesn't immediately remove or modify existing licensed users. They retain current access and roles, but you'll manage them through your IdP after SCIM is active. If SCIM is later turned off, previously SCIM-managed users remain in Docker but are no longer automatically updated based on your IdP. + +## Is user information visible in Docker Hub? + +All Docker accounts have public profiles associated with their namespace. If you don't want user information (like full names) to be visible, remove those attributes from your SSO and SCIM mappings, or use different identifiers to replace users' full names. diff --git a/content/manuals/platform-release-notes.md b/content/manuals/platform-release-notes.md index dc7026bcf64d..68f2eb70c799 100644 --- a/content/manuals/platform-release-notes.md +++ b/content/manuals/platform-release-notes.md @@ -18,7 +18,7 @@ This page provides details on new features, enhancements, known issues, and bug - Administrators can now control whether organization members can push content to their personal namespaces on Docker Hub with [namespace access - control](/manuals/enterprise/security/hardened-desktop/namespace-access.md). + control](/manuals/enterprise/hardened-desktop/namespace-access.md). - Administrators can now prevent creating public repositories within organization namespaces using the [Disable public repositories](/manuals/docker-hub/settings.md#disable-creation-of-public-repos) setting. @@ -28,7 +28,7 @@ This page provides details on new features, enhancements, known issues, and bug ### New - Administrators can now use an allow list with [Image Access - Management](/manuals/enterprise/security/hardened-desktop/image-access-management.md) + Management](/manuals/enterprise/hardened-desktop/image-access-management.md) to approve specific repositories that bypass image access controls. ## 2025-01-30 @@ -52,22 +52,22 @@ This page provides details on new features, enhancements, known issues, and bug ### New - Administrators can now: - - Enforce sign-in with [configuration profiles](/manuals/enterprise/security/enforce-sign-in/methods.md#configuration-profiles-method-mac-only) (Early Access). + - Enforce sign-in with [configuration profiles](/manuals/platform/security/authentication/enforce-sign-in/methods.md#configuration-profiles-method-mac-only) (Early Access). - Enforce sign-in for more than one organization at a time (Early Access). - Deploy Docker Desktop for Mac in bulk with the [PKG installer](/manuals/enterprise/enterprise-deployment/pkg-install-and-configure.md) (Early Access). - - [Use Desktop Settings Management via the Docker Admin Console](/manuals/enterprise/security/hardened-desktop/settings-management/configure-admin-console.md) (Early Access). + - [Use Desktop Settings Management via the Docker Admin Console](/manuals/enterprise/hardened-desktop/settings-management/configure-admin-console.md) (Early Access). ### Bug fixes and enhancements - Enhance Container Isolation (ECI) has been improved to: - - Permit admins to [turn off Docker socket mount restrictions](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/config.md#allowing-all-containers-to-mount-the-docker-socket). - - Support wildcard tags when using the [`allowedDerivedImages` setting](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/config.md#docker-socket-mount-permissions-for-derived-images). + - Permit admins to [turn off Docker socket mount restrictions](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/config.md#allowing-all-containers-to-mount-the-docker-socket). + - Support wildcard tags when using the [`allowedDerivedImages` setting](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/config.md#docker-socket-mount-permissions-for-derived-images). ## 2024-11-11 ### New -- [Personal access tokens](/security/access-tokens/) (PATs) now support expiration dates. +- [Personal access tokens](/platform/security/access-tokens/personal-access-tokens/) (PATs) now support expiration dates. ## 2024-10-15 @@ -80,7 +80,7 @@ This page provides details on new features, enhancements, known issues, and bug ### New - Deploying Docker Desktop via the [MSI installer](/manuals/enterprise/enterprise-deployment/msi-install-and-configure.md) is now generally available. -- Two new methods to [enforce sign-in](/manuals/enterprise/security/enforce-sign-in/_index.md) (Windows registry key and `.plist` file) are now generally available. +- Two new methods to [enforce sign-in](/manuals/platform/security/authentication/enforce-sign-in/_index.md) (Windows registry key and `.plist` file) are now generally available. ## 2024-08-24 diff --git a/content/manuals/security/_index.md b/content/manuals/platform/security/_index.md similarity index 92% rename from content/manuals/security/_index.md rename to content/manuals/platform/security/_index.md index e8a3f9e8ad9c..da2ed58dbc42 100644 --- a/content/manuals/security/_index.md +++ b/content/manuals/platform/security/_index.md @@ -4,18 +4,21 @@ linkTitle: Security description: Learn about developer-level security features like 2FA and access tokens keywords: docker, docker hub, docker desktop, security, developer security, 2FA, access tokens weight: 40 +aliases: + - /security/ + - /security/for-developers/ params: sidebar: group: Platform grid_developers: - title: Set up two-factor authentication description: Add an extra layer of authentication to your Docker account. - link: /security/2fa/ + link: /platform/security/authentication/2fa/ icon: device-phone-mobile - title: Manage access tokens description: Create personal access tokens as an alternative to your password. icon: lock-closed - link: /security/access-tokens/ + link: /platform/security/access-tokens/personal-access-tokens/ - title: Static vulnerability scanning description: Automatically run a point-in-time scan on your Docker images for vulnerabilities. icon: magnifying-glass @@ -29,10 +32,6 @@ grid_developers: icon: shield-exclamation link: /compose/how-tos/use-secrets/ grid_resources: -- title: Security FAQs - description: Explore common security FAQs. - icon: question-mark-circle - link: /faq/security/general/ - title: Security best practices description: Understand the steps you can take to improve the security of your container. icon: squares-2x2 diff --git a/content/manuals/platform/security/access-tokens/_index.md b/content/manuals/platform/security/access-tokens/_index.md new file mode 100644 index 000000000000..2f7bbf486681 --- /dev/null +++ b/content/manuals/platform/security/access-tokens/_index.md @@ -0,0 +1,9 @@ +--- +build: + render: never +title: Access tokens +linkTitle: Access tokens +description: Create and manage personal and organization access tokens for Docker Hub authentication. +keywords: access tokens, personal access tokens, organization access tokens, PAT, OAT, Docker security +weight: 10 +--- diff --git a/content/manuals/enterprise/security/access-tokens.md b/content/manuals/platform/security/access-tokens/organization-access-tokens.md similarity index 98% rename from content/manuals/enterprise/security/access-tokens.md rename to content/manuals/platform/security/access-tokens/organization-access-tokens.md index a65b78499397..b13691f659f5 100644 --- a/content/manuals/enterprise/security/access-tokens.md +++ b/content/manuals/platform/security/access-tokens/organization-access-tokens.md @@ -5,6 +5,7 @@ description: Create and manage organization access tokens to securely authentica keywords: organization access tokens, OAT, docker hub security, programmatic access, automation aliases: - /security/for-admins/access-tokens/ + - /enterprise/security/access-tokens/ --- {{< summary-bar feature_name="OATs" >}} @@ -13,7 +14,7 @@ Organization access tokens (OATs) provide secure, programmatic access to Docker > [!WARNING] > -> Organization access tokens are incompatible with Docker Desktop and Image Access Management. If you use these features, use [personal access tokens](/manuals/security/access-tokens.md) instead. +> Organization access tokens are incompatible with Docker Desktop and Image Access Management. If you use these features, use [personal access tokens](/manuals/platform/security/access-tokens/personal-access-tokens.md) instead. ## Who should use organization access tokens? diff --git a/content/manuals/security/access-tokens.md b/content/manuals/platform/security/access-tokens/personal-access-tokens.md similarity index 93% rename from content/manuals/security/access-tokens.md rename to content/manuals/platform/security/access-tokens/personal-access-tokens.md index 380b93383dd6..e3d35140095d 100644 --- a/content/manuals/security/access-tokens.md +++ b/content/manuals/platform/security/access-tokens/personal-access-tokens.md @@ -6,6 +6,8 @@ keywords: personal access tokens, PAT, docker cli authentication, docker hub sec weight: 10 aliases: - /docker-hub/access-tokens/ + - /security/access-tokens/ + - /security/personal-access-tokens/ - /security/for-developers/access-tokens/ --- @@ -32,7 +34,7 @@ Use PATs for these common scenarios: > [!NOTE] > -> For organization-wide automation, consider [organization access tokens](/manuals/enterprise/security/access-tokens.md) which aren't tied to individual user accounts. +> For organization-wide automation, consider [organization access tokens](/manuals/platform/security/access-tokens/organization-access-tokens.md) which aren't tied to individual user accounts. ## Create a personal access token @@ -101,5 +103,5 @@ Best practices for fair use include: - Reuse tokens across similar use cases instead of creating many single-purpose tokens - Delete unused tokens regularly -- Use [organization access tokens](/manuals/enterprise/security/access-tokens.md) for organization-wide automation +- Use [organization access tokens](/manuals/platform/security/access-tokens/organization-access-tokens.md) for organization-wide automation - Monitor token usage to identify optimization opportunities diff --git a/content/manuals/security/2fa/_index.md b/content/manuals/platform/security/authentication/2fa/_index.md similarity index 99% rename from content/manuals/security/2fa/_index.md rename to content/manuals/platform/security/authentication/2fa/_index.md index 688c3449d800..1cb2332cc7c1 100644 --- a/content/manuals/security/2fa/_index.md +++ b/content/manuals/platform/security/authentication/2fa/_index.md @@ -9,6 +9,7 @@ aliases: - /security/2fa/disable-2fa/ - /security/for-developers/2fa/ - /security/for-developers/2fa/disable-2fa/ + - /security/2fa/ --- Two-factor authentication (2FA) adds an essential security layer to your Docker account by requiring a unique security code in addition to your password when signing in. This prevents unauthorized access even if your password is compromised. diff --git a/content/manuals/security/2fa/recover-hub-account.md b/content/manuals/platform/security/authentication/2fa/recover-hub-account.md similarity index 100% rename from content/manuals/security/2fa/recover-hub-account.md rename to content/manuals/platform/security/authentication/2fa/recover-hub-account.md diff --git a/content/manuals/platform/security/authentication/_index.md b/content/manuals/platform/security/authentication/_index.md new file mode 100644 index 000000000000..fd683d953cd5 --- /dev/null +++ b/content/manuals/platform/security/authentication/_index.md @@ -0,0 +1,9 @@ +--- +build: + render: never +title: Authentication +linkTitle: Authentication +description: Configure single sign-on, OIDC connections, two-factor authentication, and sign-in enforcement. +keywords: authentication, SSO, OIDC, two-factor authentication, 2FA, enforce sign-in, Docker security +weight: 20 +--- diff --git a/content/manuals/enterprise/security/enforce-sign-in/_index.md b/content/manuals/platform/security/authentication/enforce-sign-in/_index.md similarity index 91% rename from content/manuals/enterprise/security/enforce-sign-in/_index.md rename to content/manuals/platform/security/authentication/enforce-sign-in/_index.md index 82497c724f6f..87121af63822 100644 --- a/content/manuals/enterprise/security/enforce-sign-in/_index.md +++ b/content/manuals/platform/security/authentication/enforce-sign-in/_index.md @@ -8,6 +8,7 @@ tags: [admin] aliases: - /security/for-admins/configure-sign-in/ - /security/for-admins/enforce-sign-in/ + - /enterprise/security/enforce-sign-in/ weight: 30 --- @@ -55,7 +56,7 @@ On the next Docker Desktop restart: ## Enforcing sign-in versus enforcing single sign-on (SSO) -Enforcing Docker Desktop sign-in and [enforcing SSO](/manuals/enterprise/security/single-sign-on/connect.md#optional-enforce-sso) are different features that serve different purposes: +Enforcing Docker Desktop sign-in and [enforcing SSO](/manuals/platform/security/authentication/single-sign-on/connect.md#optional-enforce-sso) are different features that serve different purposes: | Enforcement | Description | Benefits | @@ -67,5 +68,5 @@ Enforcing Docker Desktop sign-in and [enforcing SSO](/manuals/enterprise/securit ## Next steps -- To set up sign-in enforcement, see [Configure sign-in enforcement](/manuals/enterprise/security/enforce-sign-in/methods.md). -- To configure SSO enforcement, see [Enforce SSO](/manuals/enterprise/security/single-sign-on/connect.md). +- To set up sign-in enforcement, see [Configure sign-in enforcement](/manuals/platform/security/authentication/enforce-sign-in/methods.md). +- To configure SSO enforcement, see [Enforce SSO](/manuals/platform/security/authentication/single-sign-on/connect.md). diff --git a/content/manuals/enterprise/security/enforce-sign-in/methods.md b/content/manuals/platform/security/authentication/enforce-sign-in/methods.md similarity index 99% rename from content/manuals/enterprise/security/enforce-sign-in/methods.md rename to content/manuals/platform/security/authentication/enforce-sign-in/methods.md index 09648085c141..6c97f2bac7d9 100644 --- a/content/manuals/enterprise/security/enforce-sign-in/methods.md +++ b/content/manuals/platform/security/authentication/enforce-sign-in/methods.md @@ -6,6 +6,7 @@ keywords: authentication, registry.json, configure, enforce sign-in, docker desk tags: [admin] aliases: - /security/for-admins/enforce-sign-in/methods/ + - /enterprise/security/enforce-sign-in/methods/ --- {{< summary-bar feature_name="Enforce sign-in" >}} diff --git a/content/manuals/enterprise/security/oidc-connections/_index.md b/content/manuals/platform/security/authentication/oidc-connections/_index.md similarity index 83% rename from content/manuals/enterprise/security/oidc-connections/_index.md rename to content/manuals/platform/security/authentication/oidc-connections/_index.md index 72d19efd3019..9d349e929b3d 100644 --- a/content/manuals/enterprise/security/oidc-connections/_index.md +++ b/content/manuals/platform/security/authentication/oidc-connections/_index.md @@ -5,6 +5,8 @@ description: Authenticate GitHub Actions to Docker with short-lived OpenID Conne keywords: oidc connections, openid connect, github actions, jwt, subject claims, rulesets, enterprise security, workload authentication tags: [admin] weight: 35 +aliases: + - /enterprise/security/oidc-connections/ --- {{< summary-bar feature_name="OIDC connections" >}} @@ -34,7 +36,7 @@ and issued on a per-workflow basis. ## OIDC connections and OATs -[Organization access tokens (OATs)](/manuals/enterprise/security/access-tokens.md) +[Organization access tokens (OATs)](/manuals/platform/security/access-tokens/organization-access-tokens.md) provide programmatic access to your Docker resources at the organization level. Unlike personal access tokens, OATs aren't tied to individual members, so access continues when membership changes. @@ -48,5 +50,5 @@ they request a change to your Docker resources. ## Next steps -- [Create an OIDC connection](/manuals/enterprise/security/oidc-connections/create-manage.md) -- [OIDC rulesets and subject claims](/manuals/enterprise/security/oidc-connections/rulesets-claims.md) +- [Create an OIDC connection](/manuals/platform/security/authentication/oidc-connections/create-manage.md) +- [OIDC rulesets and subject claims](/manuals/platform/security/authentication/oidc-connections/rulesets-claims.md) diff --git a/content/manuals/enterprise/security/oidc-connections/create-manage.md b/content/manuals/platform/security/authentication/oidc-connections/create-manage.md similarity index 92% rename from content/manuals/enterprise/security/oidc-connections/create-manage.md rename to content/manuals/platform/security/authentication/oidc-connections/create-manage.md index f87c9823e604..581fa014ae39 100644 --- a/content/manuals/enterprise/security/oidc-connections/create-manage.md +++ b/content/manuals/platform/security/authentication/oidc-connections/create-manage.md @@ -25,7 +25,7 @@ with a short-lived token. 1. Select **Create OIDC connection** and fill in the OIDC connection form. - Provide rulesets and subject claims. Other values are optional. - For rulesets, subject claims, and resources, see - [OIDC connections rulesets and subject claims](/manuals/enterprise/security/oidc-connections/rulesets-claims.md). + [OIDC connections rulesets and subject claims](/manuals/platform/security/authentication/oidc-connections/rulesets-claims.md). 1. Select **Create connection**. 1. Copy your OIDC connection ID. @@ -90,4 +90,4 @@ fails at the token-exchange step until you activate the connection. ## Next steps -- [OIDC connections rulesets and subject claims](/manuals/enterprise/security/oidc-connections/rulesets-claims.md) +- [OIDC connections rulesets and subject claims](/manuals/platform/security/authentication/oidc-connections/rulesets-claims.md) diff --git a/content/manuals/enterprise/security/oidc-connections/rulesets-claims.md b/content/manuals/platform/security/authentication/oidc-connections/rulesets-claims.md similarity index 94% rename from content/manuals/enterprise/security/oidc-connections/rulesets-claims.md rename to content/manuals/platform/security/authentication/oidc-connections/rulesets-claims.md index 6e14e038bc48..104d06667da4 100644 --- a/content/manuals/enterprise/security/oidc-connections/rulesets-claims.md +++ b/content/manuals/platform/security/authentication/oidc-connections/rulesets-claims.md @@ -91,5 +91,5 @@ Docker Hub repositories and Docker Build Cloud are supported resources. ## Next steps -- [OIDC connections overview](/manuals/enterprise/security/oidc-connections/_index.md) -- [Create or manage OIDC connections](/manuals/enterprise/security/oidc-connections/create-manage.md) +- [OIDC connections overview](/manuals/platform/security/authentication/oidc-connections/_index.md) +- [Create or manage OIDC connections](/manuals/platform/security/authentication/oidc-connections/create-manage.md) diff --git a/content/manuals/enterprise/security/single-sign-on/_index.md b/content/manuals/platform/security/authentication/single-sign-on/_index.md similarity index 86% rename from content/manuals/enterprise/security/single-sign-on/_index.md rename to content/manuals/platform/security/authentication/single-sign-on/_index.md index c7cfa70db0b7..8abb723f1ef6 100644 --- a/content/manuals/enterprise/security/single-sign-on/_index.md +++ b/content/manuals/platform/security/authentication/single-sign-on/_index.md @@ -8,6 +8,7 @@ aliases: - /admin/company/settings/sso/ - /admin/organization/security-settings/sso-management/ - /security/for-admins/single-sign-on/ + - /enterprise/security/single-sign-on/ weight: 10 --- @@ -50,10 +51,10 @@ assigned to an organization, and added to a team. > > When SSO is enforced, CLI password-based sign-in is no longer supported. > Use a personal access token (PAT) for CLI access. For more information, see the -> [security announcement](/manuals/security/security-announcements.md#deprecation-of-password-logins-on-cli-when-sso-enforced). +> [security announcement](/manuals/platform/security/security-announcements.md#deprecation-of-password-logins-on-cli-when-sso-enforced). ## Next steps - Start [configuring SSO](connect.md). -- Read the [FAQs](/manuals/enterprise/security/single-sign-on/FAQs/general.md). -- [Troubleshoot](/manuals/enterprise/security/single-sign-on/troubleshoot-sso.md) SSO issues. +- Read the [FAQs](/manuals/faqs/sso-faqs.md). +- [Troubleshoot](/manuals/platform/security/authentication/single-sign-on/troubleshoot-sso.md) SSO issues. diff --git a/content/manuals/enterprise/security/single-sign-on/connect.md b/content/manuals/platform/security/authentication/single-sign-on/connect.md similarity index 92% rename from content/manuals/enterprise/security/single-sign-on/connect.md rename to content/manuals/platform/security/authentication/single-sign-on/connect.md index 52630a29786f..85eb77d6cc3b 100644 --- a/content/manuals/enterprise/security/single-sign-on/connect.md +++ b/content/manuals/platform/security/authentication/single-sign-on/connect.md @@ -13,7 +13,7 @@ aliases: - /admin/company/settings/sso-configuration/ - /admin/organization/security-settings/sso-configuration/ - /security/for-admins/single-sign-on/configure/ - - /enterprise/security/single-sign-on/configure + - /enterprise/security/single-sign-on/connect/ --- {{< summary-bar feature_name="SSO" >}} @@ -22,7 +22,7 @@ To set up a single sign-on (SSO), you need to establish a connection between Doc and your identity provider (IdP). While this guide uses Okta and Microsoft Entra ID as a working example, the general process remains the same for other IdPs. -If you're unfamiliar with the SSO process, first review [SSO overview](/manuals/enterprise/security/single-sign-on/_index.md) to learn about how SSO works. +If you're unfamiliar with the SSO process, first review [SSO overview](/manuals/platform/security/authentication/single-sign-on/_index.md) to learn about how SSO works. ## Prerequisites @@ -124,7 +124,7 @@ You need [super admin permissions](https://help.okta.com/en-us/content/topics/se - For **Name ID format**, choose `EmailAddress` - For **Application username**, choose `Email` - For **Update application username on**, choose `Create and update` - - Optional. Add [SAML attributes](/manuals/enterprise/security/provisioning/_index.md#sso-attributes), if required by your org. + - Optional. Add [SAML attributes](/manuals/platform/security/provisioning/_index.md#sso-attributes), if required by your org. 1. For **Feedback**, choose **This is an internal app that we have created** checkbox before finishing. Keep your Okta window open for the next step. @@ -140,7 +140,7 @@ To enable SSO with Microsoft Entra, you need [Cloud Application Administrator](h 1. Select **Edit** on the **Basic SAML configuration** section. From **Basic SAML configuration**, choose **Edit** and paste the values you copied from creating an SSO connection in Docker: - For the **Identifier** value, paste the Docker Entity ID. - For the **Reply URL** value, paste Docker ACS URL. -1. Optional. Add [SAML attributes](/manuals/enterprise/security/provisioning/_index.md#sso-attributes), if required by your org. +1. Optional. Add [SAML attributes](/manuals/platform/security/provisioning/_index.md#sso-attributes), if required by your org. 1. From the **SAML Signing Certificate** section, download your **Certificate (Base64)**. {{< /tab >}} @@ -233,7 +233,7 @@ Docker supports multiple identity provider (IdP) configurations by letting you a To add multiple IdPs: 1. Use the same domain for each connection. -1. Repeat steps 3-6 from the [Set up an SSO connection](/manuals/enterprise/security/single-sign-on/connect.md#set-up-an-sso-connection) procedures on this page. Repeat these steps for each IdP your organization intends to use. +1. Repeat steps 3-6 from the [Set up an SSO connection](/manuals/platform/security/authentication/single-sign-on/connect.md#set-up-an-sso-connection) procedures on this page. Repeat these steps for each IdP your organization intends to use. Because you must use the same domain for each IdP, you won't need to repeat steps to add and verify your domains. @@ -241,7 +241,7 @@ Because you must use the same domain for each IdP, you won't need to repeat step If SSO is not enforced, users can still sign in using Docker usernames and passwords. Enforcing SSO requires users to use SSO when signing into Docker, which centralizes authentication and enforces policies set by the IdP. -Before enforcing SSO, users accessing Docker through the CLI must [create a personal access token (PAT)](/manuals/security/access-tokens.md). The PAT replaces their username and password for authentication. +Before enforcing SSO, users accessing Docker through the CLI must [create a personal access token (PAT)](/manuals/platform/security/access-tokens/personal-access-tokens.md). The PAT replaces their username and password for authentication. 1. Sign in to [Docker Home](https://app.docker.com/) and select your organization or company. @@ -256,7 +256,7 @@ Docker Hub. If you want to use 2FA, you must enable 2FA through your IdP. ## Next steps -- [Provision users](/manuals/enterprise/security/provisioning/_index.md). +- [Provision users](/manuals/platform/security/provisioning/_index.md). - [Enforce sign-in](../enforce-sign-in/_index.md). -- [Create personal access tokens](/manuals/security/access-tokens.md). -- [Troubleshoot SSO](/manuals/enterprise/security/single-sign-on/troubleshoot-sso.md) issues. +- [Create personal access tokens](/manuals/platform/security/access-tokens/personal-access-tokens.md). +- [Troubleshoot SSO](/manuals/platform/security/authentication/single-sign-on/troubleshoot-sso.md) issues. diff --git a/content/manuals/enterprise/security/single-sign-on/images/SSO.png b/content/manuals/platform/security/authentication/single-sign-on/images/SSO.png similarity index 100% rename from content/manuals/enterprise/security/single-sign-on/images/SSO.png rename to content/manuals/platform/security/authentication/single-sign-on/images/SSO.png diff --git a/content/manuals/enterprise/security/single-sign-on/manage.md b/content/manuals/platform/security/authentication/single-sign-on/manage.md similarity index 98% rename from content/manuals/enterprise/security/single-sign-on/manage.md rename to content/manuals/platform/security/authentication/single-sign-on/manage.md index c5f71844e459..71d34c1c63a9 100644 --- a/content/manuals/enterprise/security/single-sign-on/manage.md +++ b/content/manuals/platform/security/authentication/single-sign-on/manage.md @@ -8,6 +8,7 @@ aliases: - /admin/company/settings/sso-management/ - /single-sign-on/manage/ - /security/for-admins/single-sign-on/manage/ +- /enterprise/security/single-sign-on/manage/ --- {{< summary-bar feature_name="SSO" >}} @@ -106,7 +107,7 @@ when they sign in via SSO - Group mapping: Sync user groups from your identity provider with teams in your Docker organization - Manual provisioning: Turn off automatic provisioning and manually invite users -For more information on provisioning methods, see [Provision users](/manuals/enterprise/security/provisioning/_index.md). +For more information on provisioning methods, see [Provision users](/manuals/platform/security/provisioning/_index.md). ### Add guest users diff --git a/content/manuals/enterprise/security/single-sign-on/troubleshoot-sso.md b/content/manuals/platform/security/authentication/single-sign-on/troubleshoot-sso.md similarity index 97% rename from content/manuals/enterprise/security/single-sign-on/troubleshoot-sso.md rename to content/manuals/platform/security/authentication/single-sign-on/troubleshoot-sso.md index ebd616e7f6c4..22e091433e09 100644 --- a/content/manuals/enterprise/security/single-sign-on/troubleshoot-sso.md +++ b/content/manuals/platform/security/authentication/single-sign-on/troubleshoot-sso.md @@ -117,7 +117,7 @@ If you have SCIM enabled, troubleshoot your SCIM connection using the following 1. Navigate back to **Identity & auth**, then **SSO and SCIM**, and verify your SCIM configuration: - Ensure that the SCIM Base URL and API Token in your IdP match those provided in Docker. - Verify that SCIM is enabled in both Docker and your IdP. -1. Ensure that the attributes being synced from your IdP match Docker's [supported attributes](/manuals/enterprise/security/provisioning/scim/provision-scim.md#supported-attributes) for SCIM. +1. Ensure that the attributes being synced from your IdP match Docker's [supported attributes](/manuals/platform/security/provisioning/scim/provision-scim.md#supported-attributes) for SCIM. 1. Test user provisioning by trying to provision a test user through your IdP and verify if they appear in Docker. ## IdP-initiated sign in is not enabled for connection @@ -192,7 +192,7 @@ Ensure that the IdP SSO connection is returning the correct UPN value in the ass **Add and verify all domains** -Add and verify all domains and subdomains used as UPN by your IdP and associate them with your Docker SSO connection. For details, see [Configure single sign-on](/manuals/enterprise/security/single-sign-on/connect.md). +Add and verify all domains and subdomains used as UPN by your IdP and associate them with your Docker SSO connection. For details, see [Configure single sign-on](/manuals/platform/security/authentication/single-sign-on/connect.md). ## Unable to find session diff --git a/content/manuals/enterprise/security/images/jit-disabled-flow.svg b/content/manuals/platform/security/images/jit-disabled-flow.svg similarity index 100% rename from content/manuals/enterprise/security/images/jit-disabled-flow.svg rename to content/manuals/platform/security/images/jit-disabled-flow.svg diff --git a/content/manuals/enterprise/security/images/jit-enabled-flow.svg b/content/manuals/platform/security/images/jit-enabled-flow.svg similarity index 100% rename from content/manuals/enterprise/security/images/jit-enabled-flow.svg rename to content/manuals/platform/security/images/jit-enabled-flow.svg diff --git a/content/manuals/enterprise/security/provisioning/_index.md b/content/manuals/platform/security/provisioning/_index.md similarity index 95% rename from content/manuals/enterprise/security/provisioning/_index.md rename to content/manuals/platform/security/provisioning/_index.md index 923731988856..62c0fdfbdd28 100644 --- a/content/manuals/enterprise/security/provisioning/_index.md +++ b/content/manuals/platform/security/provisioning/_index.md @@ -3,10 +3,15 @@ description: Learn about provisioning users for your SSO configuration. keywords: provision users, provisioning, JIT, SCIM, group mapping, sso, docker admin, admin, security title: Provision users linkTitle: Provision -weight: 20 +weight: 30 aliases: - /security/for-admins/provisioning/ + - /enterprise/security/provisioning/ grid: + - title: "Add and manage domains" + description: "Add, verify, and manage domains to control user access and enable auto-provisioning." + icon: globe-alt + link: "domain-management/" - title: "SCIM provisioning" description: "Enable continuous user data synchronization between your IdP and Docker. Best for larger organizations." icon: arrow-path diff --git a/content/manuals/enterprise/security/provisioning/auto-provisioning.md b/content/manuals/platform/security/provisioning/auto-provisioning.md similarity index 91% rename from content/manuals/enterprise/security/provisioning/auto-provisioning.md rename to content/manuals/platform/security/provisioning/auto-provisioning.md index a0ab4c209362..f0de99448de3 100644 --- a/content/manuals/enterprise/security/provisioning/auto-provisioning.md +++ b/content/manuals/platform/security/provisioning/auto-provisioning.md @@ -54,5 +54,5 @@ To disable auto-provisioning for a user: To choose a different method to provision users, you can set up: -- [SCIM provisioning](/manuals/enterprise/security/provisioning/scim/_index.md) for advanced user management. -- [Group mapping](/manuals/enterprise/security/provisioning/scim/group-mapping.md) to assign users to teams automatically. +- [SCIM provisioning](/manuals/platform/security/provisioning/scim/_index.md) for advanced user management. +- [Group mapping](/manuals/platform/security/provisioning/scim/group-mapping.md) to assign users to teams automatically. diff --git a/content/manuals/enterprise/security/domain-management.md b/content/manuals/platform/security/provisioning/domain-management.md similarity index 90% rename from content/manuals/enterprise/security/domain-management.md rename to content/manuals/platform/security/provisioning/domain-management.md index 767f58deaa27..55679bea5ffd 100644 --- a/content/manuals/enterprise/security/domain-management.md +++ b/content/manuals/platform/security/provisioning/domain-management.md @@ -2,9 +2,11 @@ title: Add and manage domains description: Add, verify, and manage domains to control user access and enable auto-provisioning in Docker organizations keywords: domain management, domain verification, auto-provisioning, user management, DNS, TXT record, Docker Home -weight: 10 +weight: 5 aliases: - /security/for-admins/domain-management/ + - /enterprise/security/domain-management/ + - /platform/security/domains/domain-management/ --- {{< summary-bar feature_name="Domain management" >}} @@ -90,7 +92,7 @@ Domain audit can't identify: - Users who authenticate using an account that doesn't have an email address associated with one of your verified domains -To prevent unidentifiable users from accessing Docker Desktop, [enforce sign-in](/manuals/enterprise/security/enforce-sign-in/_index.md). +To prevent unidentifiable users from accessing Docker Desktop, [enforce sign-in](/manuals/platform/security/authentication/enforce-sign-in/_index.md). ### Run a domain audit @@ -114,10 +116,10 @@ CSV file. For more information on bulk inviting users, see ## Auto-provisioning -[Auto-provisioning](/manuals/enterprise/security/provisioning/auto-provisioning.md) uses verified domains to associate organization members with email address that match the verified domains. To override auto-provisioning, you can configure one of the two alternative methods: +[Auto-provisioning](/manuals/platform/security/provisioning/auto-provisioning.md) uses verified domains to associate organization members with email address that match the verified domains. To override auto-provisioning, you can configure one of the two alternative methods: -- [Just-in-Time (JIT)](/manuals/enterprise/security/provisioning/just-in-time.md) provisioning -- [System for Cross-domain Identity Management (SCIM)](/manuals/enterprise/security/provisioning/scim/_index.md) +- [Just-in-Time (JIT)](/manuals/platform/security/provisioning/just-in-time.md) provisioning +- [System for Cross-domain Identity Management (SCIM)](/manuals/platform/security/provisioning/scim/_index.md) ## Delete a domain diff --git a/content/manuals/enterprise/security/provisioning/just-in-time.md b/content/manuals/platform/security/provisioning/just-in-time.md similarity index 93% rename from content/manuals/enterprise/security/provisioning/just-in-time.md rename to content/manuals/platform/security/provisioning/just-in-time.md index e2ed13bf3f8e..9faf96896460 100644 --- a/content/manuals/enterprise/security/provisioning/just-in-time.md +++ b/content/manuals/platform/security/provisioning/just-in-time.md @@ -79,6 +79,6 @@ Users are provisioned with JIT by default. If you enable SCIM, you can disable J ## Next steps -- Configure [SCIM provisioning](/manuals/enterprise/security/provisioning/scim/_index.md) for advanced user management. -- Set up [group mapping](/manuals/enterprise/security/provisioning/scim/group-mapping.md) to automatically assign users to teams. -- Review [Troubleshoot provisioning](/manuals/enterprise/security/provisioning/troubleshoot-provisioning.md). +- Configure [SCIM provisioning](/manuals/platform/security/provisioning/scim/_index.md) for advanced user management. +- Set up [group mapping](/manuals/platform/security/provisioning/scim/group-mapping.md) to automatically assign users to teams. +- Review [Troubleshoot provisioning](/manuals/platform/security/provisioning/troubleshoot-provisioning.md). diff --git a/content/manuals/enterprise/security/provisioning/scim/_index.md b/content/manuals/platform/security/provisioning/scim/_index.md similarity index 82% rename from content/manuals/enterprise/security/provisioning/scim/_index.md rename to content/manuals/platform/security/provisioning/scim/_index.md index ace0770e759d..38841d4f8f8f 100644 --- a/content/manuals/enterprise/security/provisioning/scim/_index.md +++ b/content/manuals/platform/security/provisioning/scim/_index.md @@ -59,6 +59,6 @@ SCIM automates: ## Next steps -- [Migrate JIT to SCIM](/manuals/enterprise/security/provisioning/scim/migrate-scim.md) if users were provisioned with Just-in-Time (JIT) before you enabled SCIM. -- [Group mapping](/manuals/enterprise/security/provisioning/scim/group-mapping.md) to sync identity provider groups with members. -- [Troubleshoot provisioning](/manuals/enterprise/security/provisioning/troubleshoot-provisioning.md) for SCIM, JIT, and attribute issues. +- [Migrate JIT to SCIM](/manuals/platform/security/provisioning/scim/migrate-scim.md) if users were provisioned with Just-in-Time (JIT) before you enabled SCIM. +- [Group mapping](/manuals/platform/security/provisioning/scim/group-mapping.md) to sync identity provider groups with members. +- [Troubleshoot provisioning](/manuals/platform/security/provisioning/troubleshoot-provisioning.md) for SCIM, JIT, and attribute issues. diff --git a/content/manuals/enterprise/security/provisioning/scim/group-mapping.md b/content/manuals/platform/security/provisioning/scim/group-mapping.md similarity index 97% rename from content/manuals/enterprise/security/provisioning/scim/group-mapping.md rename to content/manuals/platform/security/provisioning/scim/group-mapping.md index 308cad4a8e7e..00cce8cbcee7 100644 --- a/content/manuals/enterprise/security/provisioning/scim/group-mapping.md +++ b/content/manuals/platform/security/provisioning/scim/group-mapping.md @@ -7,7 +7,7 @@ aliases: - /admin/organization/security-settings/group-mapping/ - /security/for-admins/group-mapping/ - /security/for-admins/provisioning/scim/group-mapping/ -- /enterprise/security/provisioning/group-mapping/ +- /platform/security/provisioning/group-mapping/ weight: 20 --- @@ -194,5 +194,5 @@ Once complete, a user who signs in to Docker through SSO is automatically added ## Next steps -- [Assign roles](/manuals/enterprise/security/roles-and-permissions/core-roles.md) to members of your org. -- [Enforce sign in](/manuals/enterprise/security/enforce-sign-in.md), if needed. +- [Assign roles](/manuals/platform/security/roles-and-permissions/core-roles.md) to members of your org. +- [Enforce sign in](/manuals/platform/security/authentication/enforce-sign-in.md), if needed. diff --git a/content/manuals/enterprise/security/provisioning/scim/migrate-scim.md b/content/manuals/platform/security/provisioning/scim/migrate-scim.md similarity index 94% rename from content/manuals/enterprise/security/provisioning/scim/migrate-scim.md rename to content/manuals/platform/security/provisioning/scim/migrate-scim.md index 00b62c4f3bbf..fa31fa18a97b 100644 --- a/content/manuals/enterprise/security/provisioning/scim/migrate-scim.md +++ b/content/manuals/platform/security/provisioning/scim/migrate-scim.md @@ -171,10 +171,10 @@ If a user fails to reappear after removal: 4. Check provisioning logs in your identity provider for errors. For more troubleshooting guidance, see -[Troubleshoot provisioning](/manuals/enterprise/security/provisioning/troubleshoot-provisioning.md). +[Troubleshoot provisioning](/manuals/platform/security/provisioning/troubleshoot-provisioning.md). ## Next steps -- Set up [Group mapping](/manuals/enterprise/security/provisioning/scim/group-mapping.md). -- [Assign roles](/manuals/enterprise/security/roles-and-permissions/core-roles.md) to members of your org. -- [Enforce sign in](/manuals/enterprise/security/enforce-sign-in.md), if needed. +- Set up [Group mapping](/manuals/platform/security/provisioning/scim/group-mapping.md). +- [Assign roles](/manuals/platform/security/roles-and-permissions/core-roles.md) to members of your org. +- [Enforce sign in](/manuals/platform/security/authentication/enforce-sign-in.md), if needed. diff --git a/content/manuals/enterprise/security/provisioning/scim/provision-scim.md b/content/manuals/platform/security/provisioning/scim/provision-scim.md similarity index 94% rename from content/manuals/enterprise/security/provisioning/scim/provision-scim.md rename to content/manuals/platform/security/provisioning/scim/provision-scim.md index 5f7a24703547..069bf870c131 100644 --- a/content/manuals/enterprise/security/provisioning/scim/provision-scim.md +++ b/content/manuals/platform/security/provisioning/scim/provision-scim.md @@ -4,7 +4,7 @@ linkTitle: Setup description: Learn how System for Cross-domain Identity Management works and how to set it up. weight: 10 aliases: - - /enterprise/security/provisioning/scim/ + - /platform/security/provisioning/scim/ --- {{< summary-bar feature_name="SSO" >}} @@ -37,7 +37,7 @@ For additional details about supported attributes and SCIM, see > your SCIM values. > > Alternatively, you can disable JIT provisioning to rely solely on SCIM. -> For details, see [Just-in-Time](/manuals/enterprise/security/provisioning/just-in-time.md). +> For details, see [Just-in-Time](/manuals/platform/security/provisioning/just-in-time.md). ## Enable SCIM in Docker @@ -152,7 +152,7 @@ Next, [set up role mapping](#set-up-role-mapping). ## Set up role mapping -You can assign [Docker roles](/manuals/enterprise/security/roles-and-permissions/_index.md) to +You can assign [Docker roles](/manuals/platform/security/roles-and-permissions/_index.md) to users by adding optional SCIM attributes in your IdP. These attributes override default role and team values set in your SSO configuration. @@ -166,7 +166,7 @@ The following table lists the supported optional user-level attributes: | Attribute | Possible values | Notes | | ------------ | ---------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| `dockerRole` | `member`, `editor`, or `owner` | If not set, the user defaults to the `member` role. Setting this attribute overrides the default.

For role definitions, see [Roles and permissions](/manuals/enterprise/security/roles-and-permissions/_index.md). | +| `dockerRole` | `member`, `editor`, or `owner` | If not set, the user defaults to the `member` role. Setting this attribute overrides the default.

For role definitions, see [Roles and permissions](/manuals/platform/security/roles-and-permissions/_index.md). | | `dockerOrg` | Docker `organizationName` (e.g., `moby`) | Overrides the default organization configured in your SSO connection.

If unset, the user is provisioned to the default organization. If `dockerOrg` and `dockerTeam` are both set, the user is provisioned to the team within the specified organization. | | `dockerTeam` | Docker `teamName` (e.g., `developers`) | Provisions the user to the specified team in the default or specified organization. If the team doesn't exist, it is automatically created.

You can still use [group mapping](group-mapping.md) to assign users to multiple teams across organizations. | @@ -178,7 +178,7 @@ This value is required in your identity provider when creating custom SCIM attri ### Step one: Set up role mapping in Okta -1. Setup [SSO](/manuals/enterprise/security/single-sign-on/connect.md) and SCIM first. +1. Setup [SSO](/manuals/platform/security/authentication/single-sign-on/connect.md) and SCIM first. 1. In the Okta admin portal, go to **Directory**, select **Profile Editor**, and then **User (Default)**. 1. Select **Add Attribute** and configure the values for the role, organization, @@ -221,7 +221,7 @@ group will inherit these attributes upon provisioning. ### Step one: Configure attribute mappings -1. Complete the [SCIM provisioning setup](/manuals/enterprise/security/provisioning/scim/provision-scim.md#enable-scim-in-docker). +1. Complete the [SCIM provisioning setup](/manuals/platform/security/provisioning/scim/provision-scim.md#enable-scim-in-docker). 1. In the Azure Portal, open **Microsoft Entra ID** > **Enterprise Applications**, and select your SCIM application. 1. Go to **Provisioning** > **Mappings** > @@ -230,7 +230,7 @@ group will inherit these attributes upon provisioning. - `userPrincipalName` -> `userName` - `mail` -> `emails.value` - Optional. Map `dockerRole`, `dockerOrg`, or `dockerTeam` using one of the - [mapping methods](/manuals/enterprise/security/provisioning/scim/provision-scim.md#set-up-role-mapping). + [mapping methods](/manuals/platform/security/provisioning/scim/provision-scim.md#set-up-role-mapping). 1. Remove any unsupported attributes to prevent sync errors. 1. Optional. Go to **Mappings** > **Provision Azure Active Directory Groups**: - If group provisioning causes errors, set **Enabled** to **No**. @@ -370,5 +370,5 @@ To disable SCIM: ## Next steps -- Set up [Group mapping](/manuals/enterprise/security/provisioning/scim/group-mapping.md). -- [Troubleshoot provisioning](/manuals/enterprise/security/provisioning/troubleshoot-provisioning.md). +- Set up [Group mapping](/manuals/platform/security/provisioning/scim/group-mapping.md). +- [Troubleshoot provisioning](/manuals/platform/security/provisioning/troubleshoot-provisioning.md). diff --git a/content/manuals/enterprise/security/provisioning/troubleshoot-provisioning.md b/content/manuals/platform/security/provisioning/troubleshoot-provisioning.md similarity index 100% rename from content/manuals/enterprise/security/provisioning/troubleshoot-provisioning.md rename to content/manuals/platform/security/provisioning/troubleshoot-provisioning.md diff --git a/content/manuals/enterprise/security/roles-and-permissions/_index.md b/content/manuals/platform/security/roles-and-permissions/_index.md similarity index 89% rename from content/manuals/enterprise/security/roles-and-permissions/_index.md rename to content/manuals/platform/security/roles-and-permissions/_index.md index 54d7e0239879..abd3689982ab 100644 --- a/content/manuals/enterprise/security/roles-and-permissions/_index.md +++ b/content/manuals/platform/security/roles-and-permissions/_index.md @@ -8,27 +8,28 @@ keywords: >- Docker organization roles, permissions, core roles, custom roles, Member, Editor, Owner, access control, least privilege, Docker Business, security tags: [admin] +weight: 40 aliases: - /admin/organization/roles/ - /security/for-admins/roles-and-permissions/ - /docker-hub/roles-and-permissions/ + - /enterprise/security/roles-and-permissions/ grid: - title: Core roles description: >- Compare permissions for the built-in Member, Editor, and Owner roles. icon: shield-check - link: /enterprise/security/roles-and-permissions/core-roles/ + link: /platform/security/roles-and-permissions/core-roles/ - title: Custom roles description: >- Build permission sets that match your organization's access control needs. icon: adjustments-horizontal - link: /enterprise/security/roles-and-permissions/custom-roles/ + link: /platform/security/roles-and-permissions/custom-roles/ - title: Custom roles permissions description: >- Review every permission you can assign to a custom role. icon: list-bullet - link: /enterprise/security/roles-and-permissions/custom-roles/permissions-reference/ -weight: 40 + link: /platform/security/roles-and-permissions/custom-roles/permissions-reference/ --- {{< summary-bar feature_name="General admin" >}} diff --git a/content/manuals/enterprise/security/roles-and-permissions/core-roles.md b/content/manuals/platform/security/roles-and-permissions/core-roles.md similarity index 96% rename from content/manuals/enterprise/security/roles-and-permissions/core-roles.md rename to content/manuals/platform/security/roles-and-permissions/core-roles.md index fe2036836c77..a6dabb8ceda9 100644 --- a/content/manuals/enterprise/security/roles-and-permissions/core-roles.md +++ b/content/manuals/platform/security/roles-and-permissions/core-roles.md @@ -15,7 +15,7 @@ weight: 10 Docker organizations use built-in Member, Editor, and Owner roles with predefined permissions. This reference compares their permissions across Docker products. To assign a different combination of permissions, use -[custom roles](/manuals/enterprise/security/roles-and-permissions/custom-roles/_index.md) +[custom roles](/manuals/platform/security/roles-and-permissions/custom-roles/_index.md) instead. ## Core roles @@ -103,7 +103,7 @@ Use team permissions for that. > > For more granular access control, > [upgrade to a Docker Business plan](https://www.docker.com/pricing?ref=Docs&refAction=DocsEnterpriseCoreRoles) -> to use [custom roles](/manuals/enterprise/security/roles-and-permissions/custom-roles/_index.md). +> to use [custom roles](/manuals/platform/security/roles-and-permissions/custom-roles/_index.md). _\* If not part of a company_ @@ -129,7 +129,7 @@ _\* If not part of a company_ ## Next steps -- [Custom roles](/manuals/enterprise/security/roles-and-permissions/custom-roles/_index.md): +- [Custom roles](/manuals/platform/security/roles-and-permissions/custom-roles/_index.md): Create tailored permission sets on a Docker Business plan - [Manage organization members](/manuals/admin/organization/manage/members.md): Invite users and assign roles diff --git a/content/manuals/enterprise/security/roles-and-permissions/custom-roles/_index.md b/content/manuals/platform/security/roles-and-permissions/custom-roles/_index.md similarity index 87% rename from content/manuals/enterprise/security/roles-and-permissions/custom-roles/_index.md rename to content/manuals/platform/security/roles-and-permissions/custom-roles/_index.md index 5df1b9ac6ef5..fd5fa2c469ca 100644 --- a/content/manuals/enterprise/security/roles-and-permissions/custom-roles/_index.md +++ b/content/manuals/platform/security/roles-and-permissions/custom-roles/_index.md @@ -14,11 +14,11 @@ grid: - title: Manage custom roles description: Create, edit, assign, and delete custom roles for users and teams. icon: adjustments-horizontal - link: /enterprise/security/roles-and-permissions/custom-roles/manage/ + link: /platform/security/roles-and-permissions/custom-roles/manage/ - title: Permissions reference description: Review every permission you can assign when building a custom role. icon: list-bullet - link: /enterprise/security/roles-and-permissions/custom-roles/permissions-reference/ + link: /platform/security/roles-and-permissions/custom-roles/permissions-reference/ --- {{< summary-bar feature_name="Custom roles" >}} @@ -32,7 +32,7 @@ Custom roles are permission sets that you choose to grant access to users or tea If Docker's predefined permission sets meet your needs, use -[core roles](/manuals/enterprise/security/roles-and-permissions/core-roles.md) +[core roles](/manuals/platform/security/roles-and-permissions/core-roles.md) instead. ## Prerequisites diff --git a/content/manuals/enterprise/security/roles-and-permissions/custom-roles/manage.md b/content/manuals/platform/security/roles-and-permissions/custom-roles/manage.md similarity index 98% rename from content/manuals/enterprise/security/roles-and-permissions/custom-roles/manage.md rename to content/manuals/platform/security/roles-and-permissions/custom-roles/manage.md index 3dbf85e77731..1f1844c259d2 100644 --- a/content/manuals/enterprise/security/roles-and-permissions/custom-roles/manage.md +++ b/content/manuals/platform/security/roles-and-permissions/custom-roles/manage.md @@ -158,7 +158,7 @@ To see which users and teams are assigned to roles: - [Custom roles permissions reference](permissions-reference.md): Review permissions you can grant to a custom role -- [Core roles and permissions](/manuals/enterprise/security/roles-and-permissions/core-roles.md): +- [Core roles and permissions](/manuals/platform/security/roles-and-permissions/core-roles.md): Compare built-in Member, Editor, and Owner permissions - [Manage organization members](/manuals/admin/organization/manage/members.md): Invite and manage users in your organization diff --git a/content/manuals/enterprise/security/roles-and-permissions/custom-roles/permissions-reference.md b/content/manuals/platform/security/roles-and-permissions/custom-roles/permissions-reference.md similarity index 98% rename from content/manuals/enterprise/security/roles-and-permissions/custom-roles/permissions-reference.md rename to content/manuals/platform/security/roles-and-permissions/custom-roles/permissions-reference.md index fe210416c740..0871da550e96 100644 --- a/content/manuals/enterprise/security/roles-and-permissions/custom-roles/permissions-reference.md +++ b/content/manuals/platform/security/roles-and-permissions/custom-roles/permissions-reference.md @@ -81,5 +81,5 @@ the following tables to [create or edit a custom role](manage.md). - [Manage custom roles](manage.md): Create, assign, and delete custom roles -- [Core roles and permissions](/manuals/enterprise/security/roles-and-permissions/core-roles.md): +- [Core roles and permissions](/manuals/platform/security/roles-and-permissions/core-roles.md): Compare built-in Member, Editor, and Owner permissions diff --git a/content/manuals/security/security-announcements.md b/content/manuals/platform/security/security-announcements.md similarity index 91% rename from content/manuals/security/security-announcements.md rename to content/manuals/platform/security/security-announcements.md index ec3536d9945b..58ba226274c1 100644 --- a/content/manuals/security/security-announcements.md +++ b/content/manuals/platform/security/security-announcements.md @@ -2,15 +2,19 @@ description: Docker security announcements keywords: Docker, CVEs, security, notice, Log4J 2, Log4Shell, Text4Shell, announcements title: Docker security announcements -linkTitle: Security announcements +linkTitle: Announcements outputs: ["HTML", "markdown", "RSS"] layout: security-announcements -weight: 80 +weight: 1 toc_min: 1 toc_max: 2 +aliases: + - /security/security-announcements/ + - /platform/security/resources/security-announcements/ + - /security-announcements/ --- -[Subscribe to security RSS feed](/security/security-announcements/index.xml) +[Subscribe to security RSS feed](/platform/security/security-announcements/index.xml) ## Docker Desktop 4.86.0 security update: CVE-2026-17106 @@ -64,7 +68,7 @@ A vulnerability in Docker Desktop for Windows was fixed on October 23 in the [4. A vulnerability in Docker Desktop was fixed on September 25 in the [4.47.0](/manuals/desktop/release-notes.md#4470) release: -- Fixed [CVE-2025-10657](https://www.cve.org/CVERecord?id=CVE-2025-10657) where the Enhanced Container Isolation [Docker Socket command restrictions](../enterprise/security/hardened-desktop/enhanced-container-isolation/config.md#command-restrictions) feature was not working properly in Docker Desktop 4.46.0 only (the configuration for it was being ignored). +- Fixed [CVE-2025-10657](https://www.cve.org/CVERecord?id=CVE-2025-10657) where the Enhanced Container Isolation [Docker Socket command restrictions](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/config.md#command-restrictions) feature was not working properly in Docker Desktop 4.46.0 only (the configuration for it was being ignored). ## Docker Desktop 4.44.3 security update: CVE-2025-9074 @@ -117,7 +121,7 @@ We strongly encourage you to update to Docker Desktop [4.34.2](/manuals/desktop/ _Last updated July, 2024_ -When [SSO enforcement](/manuals/enterprise/security/single-sign-on/connect.md) was first introduced, Docker provided a grace period to continue to let passwords be used on the Docker CLI when authenticating to Docker Hub. This was allowed so organizations could more easily use SSO enforcement. It is recommended that administrators configuring SSO encourage users using the CLI [to switch over to Personal Access Tokens](/manuals/enterprise/security/single-sign-on/_index.md#prerequisites) in anticipation of this grace period ending. +When [SSO enforcement](/manuals/platform/security/authentication/single-sign-on/connect.md) was first introduced, Docker provided a grace period to continue to let passwords be used on the Docker CLI when authenticating to Docker Hub. This was allowed so organizations could more easily use SSO enforcement. It is recommended that administrators configuring SSO encourage users using the CLI [to switch over to Personal Access Tokens](/manuals/platform/security/authentication/single-sign-on/_index.md#prerequisites) in anticipation of this grace period ending. On September 16, 2024, the grace period ended and passwords can no longer authenticate to Docker Hub via the Docker CLI when SSO is enforced. Affected users are required to switch over to using PATs to continue signing in. @@ -161,11 +165,11 @@ If you are using affected versions of runc, BuildKit, Moby, or Docker Desktop, m If you are unable to update to an unaffected version promptly, follow these best practices to mitigate risk: -- Only use trusted Docker images (such as [Docker Official Images](../docker-hub/image-library/trusted-content.md#docker-official-images)). +- Only use trusted Docker images (such as [Docker Official Images](/manuals/docker-hub/image-library/trusted-content.md#docker-official-images)). - Don't build Docker images from untrusted sources or untrusted Dockerfiles. -- If you are a Docker Business customer using Docker Desktop and unable to update to v4.27.1, make sure to enable [Hardened Docker Desktop](/manuals/enterprise/security/hardened-desktop/_index.md) features such as: - - [Enhanced Container Isolation](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/_index.md), which mitigates the impact of CVE-2024-21626 in the case of running containers from malicious images. - - [Image Access Management](/manuals/enterprise/security/hardened-desktop/image-access-management.md), and [Registry Access Management](/manuals/enterprise/security/hardened-desktop/registry-access-management.md), which give organizations control over which images and repositories their users can access. +- If you are a Docker Business customer using Docker Desktop and unable to update to v4.27.1, make sure to enable [Hardened Docker Desktop](/manuals/enterprise/hardened-desktop/_index.md) features such as: + - [Enhanced Container Isolation](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/_index.md), which mitigates the impact of CVE-2024-21626 in the case of running containers from malicious images. + - [Image Access Management](/manuals/enterprise/hardened-desktop/image-access-management.md), and [Registry Access Management](/manuals/enterprise/hardened-desktop/registry-access-management.md), which give organizations control over which images and repositories their users can access. - For CVE-2024-23650, CVE-2024-23651, CVE-2024-23652, and CVE-2024-23653, avoid using BuildKit frontend from an untrusted source. A frontend image is usually specified as the #syntax line on your Dockerfile, or with `--frontend` flag when using the `buildctl build` command. - To mitigate CVE-2024-24557, make sure to either use BuildKit or disable caching when building images. From the CLI this can be done via the `DOCKER_BUILDKIT=1` environment variable (default for Moby >= v23.0 if the buildx plugin is installed) or the `--no-cache flag`. If you are using the HTTP API directly or through a client, the same can be done by setting `nocache` to `true` or `version` to `2` for the [/build API endpoint](https://docs.docker.com/reference/api/engine/version/v1.44/#tag/Image/operation/ImageBuild). @@ -247,11 +251,11 @@ Docker Hub security scans triggered after 1200 UTC 21 October 2021 are now correctly identifying the Text4Shell CVE. Scans before this date do not currently reflect the status of this vulnerability. Therefore, we recommend that you trigger scans by pushing new images to Docker Hub to view the status of -the Text4Shell CVE in the vulnerability report. For detailed instructions, see [Scan images on Docker Hub](../docker-hub/repos/manage/vulnerability-scanning.md). +the Text4Shell CVE in the vulnerability report. For detailed instructions, see [Scan images on Docker Hub](/manuals/docker-hub/repos/manage/vulnerability-scanning.md). ### Docker Official Images impacted by CVE-2022-42889 -A number of [Docker Official Images](../docker-hub/image-library/trusted-content.md#docker-official-images) contain the vulnerable versions of +A number of [Docker Official Images](/manuals/docker-hub/image-library/trusted-content.md#docker-official-images) contain the vulnerable versions of Apache Commons Text. The following lists Docker Official Images that may contain the vulnerable versions of Apache Commons Text: @@ -297,13 +301,13 @@ Docker Hub security scans triggered after 1700 UTC 13 December 2021 are now correctly identifying the Log4j 2 CVEs. Scans before this date do not currently reflect the status of this vulnerability. Therefore, we recommend that you trigger scans by pushing new images to Docker Hub to view the status of -Log4j 2 CVE in the vulnerability report. For detailed instructions, see [Scan images on Docker Hub](../docker-hub/repos/manage/vulnerability-scanning.md). +Log4j 2 CVE in the vulnerability report. For detailed instructions, see [Scan images on Docker Hub](/manuals/docker-hub/repos/manage/vulnerability-scanning.md). ## Docker Official Images impacted by Log4j 2 CVE _Last updated December 2021_ -A number of [Docker Official Images](../docker-hub/image-library/trusted-content.md#docker-official-images) contain the vulnerable versions of +A number of [Docker Official Images](/manuals/docker-hub/image-library/trusted-content.md#docker-official-images) contain the vulnerable versions of Log4j 2 CVE-2021-44228. The following table lists Docker Official Images that may contained the vulnerable versions of Log4j 2. We updated Log4j 2 in these images to the latest version. Some of these images may not be vulnerable for other reasons. We recommend that you also review the guidelines published on the upstream websites. diff --git a/content/manuals/retired.md b/content/manuals/retired.md index 2b5401bfd6b7..5196d0873fcb 100644 --- a/content/manuals/retired.md +++ b/content/manuals/retired.md @@ -195,7 +195,7 @@ Enhanced Service Account add-ons provided tiered pull rate limits for automated workflows and service accounts accessing Docker Hub. Docker recommends transitioning to [Organization Access Tokens -(OATs)](/manuals/enterprise/security/access-tokens.md), which provide secure, +(OATs)](/manuals/platform/security/access-tokens/organization-access-tokens.md), which provide secure, programmatic access to Docker Hub with granular repository permissions, token expiration, and better security auditing. OATs are included with Docker Team and Business subscriptions and offer similar functionality without requiring diff --git a/content/manuals/scout/explore/metrics-exporter.md b/content/manuals/scout/explore/metrics-exporter.md index 8141eef331a4..664edfab8e72 100644 --- a/content/manuals/scout/explore/metrics-exporter.md +++ b/content/manuals/scout/explore/metrics-exporter.md @@ -40,7 +40,7 @@ To export metrics from your organization, first make sure your organization is e Then, create a Personal Access Token (PAT) - a secret token that allows the exporter to authenticate with the Docker Scout API. The PAT does not require any specific permissions, but it must be created by a user who is an owner of the Docker organization. -To create a PAT, follow the steps in [Create an access token](/manuals/security/access-tokens.md). +To create a PAT, follow the steps in [Create an access token](/manuals/platform/security/access-tokens/personal-access-tokens.md). Once you have created the PAT, store it in a secure location. You will need to provide this token to the exporter when scraping metrics. @@ -108,7 +108,7 @@ alongside Grafana with a pre-configured dashboard to visualize the vulnerability $ cd scout-metrics-exporter/prometheus ``` -2. [Create a Docker access token](/manuals/security/access-tokens.md) +2. [Create a Docker access token](/manuals/platform/security/access-tokens/personal-access-tokens.md) and store it in a plain text file at `/prometheus/prometheus/token` under the template directory. ```plaintext {title=token} @@ -241,7 +241,7 @@ and a Datadog site. $ cd scout-metrics-exporter/datadog ``` -2. [Create a Docker access token](/manuals/security/access-tokens.md) +2. [Create a Docker access token](/manuals/platform/security/access-tokens/personal-access-tokens.md) and store it in a plain text file at `/datadog/token` under the template directory. ```plaintext {title=token} @@ -347,7 +347,7 @@ To change the scrape interval: ## Revoke an access token If you suspect that your PAT has been compromised or is no longer needed, you can revoke it at any time. -To revoke a PAT, follow the steps in the [Create and manage access tokens](/manuals/security/access-tokens.md). +To revoke a PAT, follow the steps in the [Create and manage access tokens](/manuals/platform/security/access-tokens/personal-access-tokens.md). Revoking a PAT immediately invalidates the token, and prevents Prometheus from scraping metrics using that token. You will need to create a new PAT and update the Prometheus configuration to use the new token. diff --git a/content/manuals/scout/integrations/registry/acr.md b/content/manuals/scout/integrations/registry/acr.md index c0dc9b4d813c..8c4871ce0ce4 100644 --- a/content/manuals/scout/integrations/registry/acr.md +++ b/content/manuals/scout/integrations/registry/acr.md @@ -189,7 +189,7 @@ what the integration provided. 4. Set up your Scout credentials. 1. Generate an organization access token. For more details, see - [Create an organization access token](/enterprise/security/access-tokens/#create-an-organization-access-token). + [Create an organization access token](/platform/security/access-tokens/organization-access-tokens/#create-an-organization-access-token). 2. Sign in to Docker using the organization access token. ```console diff --git a/content/manuals/scout/integrations/registry/artifactory.md b/content/manuals/scout/integrations/registry/artifactory.md index 36cb7f2ffcb1..002e4daec75a 100644 --- a/content/manuals/scout/integrations/registry/artifactory.md +++ b/content/manuals/scout/integrations/registry/artifactory.md @@ -102,7 +102,7 @@ Scout. 1. Generate an organization access token for accessing Scout. For more details, see [Create an organization access - token](/enterprise/security/access-tokens/#create-an-organization-access-token). + token](/platform/security/access-tokens/organization-access-tokens/#create-an-organization-access-token). 2. Sign in to Docker using the organization access token. ```console diff --git a/content/manuals/scout/integrations/registry/ecr.md b/content/manuals/scout/integrations/registry/ecr.md index a326e485434e..cb02b03cd6e7 100644 --- a/content/manuals/scout/integrations/registry/ecr.md +++ b/content/manuals/scout/integrations/registry/ecr.md @@ -228,7 +228,7 @@ what the integration provided. 4. Set up your Scout credentials. 1. Generate an organization access token. For more details, see - [Create an organization access token](/enterprise/security/access-tokens/#create-an-organization-access-token). + [Create an organization access token](/platform/security/access-tokens/organization-access-tokens/#create-an-organization-access-token). 2. Sign in to Docker using the organization access token. ```console diff --git a/content/manuals/security/faqs/_index.md b/content/manuals/security/faqs/_index.md deleted file mode 100644 index 4aebbca68bbb..000000000000 --- a/content/manuals/security/faqs/_index.md +++ /dev/null @@ -1,6 +0,0 @@ ---- -build: - render: never -title: FAQs -weight: 70 ---- diff --git a/content/manuals/unassociated-machines/_index.md b/content/manuals/unassociated-machines/_index.md index 48e7e9986adb..cc8a9e0ea8fa 100644 --- a/content/manuals/unassociated-machines/_index.md +++ b/content/manuals/unassociated-machines/_index.md @@ -72,12 +72,12 @@ You can: > [!NOTE] > > Sign-in enforcement for unassociated machines is different from -> the [organization-level sign-in enforcement](/enterprise/security/enforce-sign-in/) +> the [organization-level sign-in enforcement](/platform/security/authentication/enforce-sign-in/) > available through `registry.json` and configuration profiles. This sign-in > enforcement only requires users to sign in so admins can identify who is > using the machine, meaning users can sign in with any email address. For more > stringent security controls that limit sign-ins to users who are already part -> of your organization, see [Enforce sign-in](/enterprise/security/enforce-sign-in/). +> of your organization, see [Enforce sign-in](/platform/security/authentication/enforce-sign-in/). Sign-in enforcement helps you identify who is using unassociated machines in your organization. When you enable enforcement, users on these machines will @@ -160,9 +160,9 @@ organization in two ways: - Auto-provisioning: If you have verified domains with auto-provisioning enabled, users who sign in with a matching email domain will automatically be added to your organization. For more information on verifying domains and - auto-provisioning, see [Domain management](/enterprise/security/domain-management). + auto-provisioning, see [Domain management](/platform/security/provisioning/domain-management). - SSO user provisioning: If you have SSO configured with - [Just-in-Time provisioning](/manuals/enterprise/security/provisioning/just-in-time.md), + [Just-in-Time provisioning](/manuals/platform/security/provisioning/just-in-time.md), users who sign in through your SSO connection will automatically be added to your organization. - Manual addition: If you don't have auto-provisioning or SSO set up, or if a diff --git a/content/reference/api/hub/latest.yaml b/content/reference/api/hub/latest.yaml index 23a3a63defeb..f5ffdf3e5175 100644 --- a/content/reference/api/hub/latest.yaml +++ b/content/reference/api/hub/latest.yaml @@ -101,7 +101,7 @@ tags: - name: access-tokens x-displayName: Personal Access Tokens description: | - The Personal Access Token endpoints lets you manage personal access tokens. For more information, see [Access Tokens](https://docs.docker.com/security/access-tokens/). + The Personal Access Token endpoints lets you manage personal access tokens. For more information, see [Access Tokens](https://docs.docker.com/platform/security/access-tokens/personal-access-tokens/). You can use a personal access token instead of a password in the [Docker CLI](https://docs.docker.com/engine/reference/commandline/cli/) or in the [Create an authentication token](#operation/PostUsersLogin) route to obtain a bearer token. diff --git a/data/redirects.yml b/data/redirects.yml index 456923e33322..5612772e4af0 100644 --- a/data/redirects.yml +++ b/data/redirects.yml @@ -10,7 +10,7 @@ # in its help output, which can be redirected to elsewhere in the documentation. "/learn/": - /learn -"/security/access-tokens/": +"/platform/security/access-tokens/personal-access-tokens/": - /go/access-tokens/ "/agentic-platform/": - /go/dap/ @@ -317,7 +317,7 @@ "/admin/organization/insights/#extensions": - /go/insights-extensions/ -"/enterprise/security/hardened-desktop/settings-management/": +"/enterprise/hardened-desktop/settings-management/": - /go/settings-management/ # Billing - cancellation From 91927934e04293fa7c3dc9964928209c87676d25 Mon Sep 17 00:00:00 2001 From: Alexa Date: Mon, 31 Aug 2026 10:24:49 -0500 Subject: [PATCH 02/19] docs: squash-merge accounts IA into platform-enterprise-IA Co-authored-by: Cursor --- .github/labeler.yml | 3 +- content/guides/admin-set-up.md | 10 +-- content/guides/admin-user-management.md | 14 +-- content/manuals/_index.md | 16 ++-- content/manuals/accounts/_index.md | 65 ++++---------- content/manuals/accounts/individual/_index.md | 62 ++++++++++++++ .../{ => individual}/create-account.md | 3 +- .../deactivate-user-account.md | 4 +- .../{ => individual}/manage-account.md | 10 ++- .../organization}/_index.md | 81 +++++++++++++----- .../organization}/activity-logs.md | 3 +- .../organization}/company/_index.md | 23 ++--- .../organization}/company/manage.md | 7 +- .../organization}/company/new-company.md | 1 + .../images/docker-admin-structure.webp | Bin .../organization}/images/org-structure.webp | Bin .../organization}/insights.md | 4 +- .../organization/manage/_index.md | 27 ++++-- .../manage}/deactivate-account.md | 6 +- .../organization/manage}/general-settings.md | 6 +- .../organization/manage/manage-a-team.md | 3 +- .../organization/manage/manage-licenses.md | 6 +- .../organization/manage/manage-products.md | 3 +- .../organization/manage/manage-seats.md | 1 + .../organization/manage/members.md | 5 +- .../organization/setup/_index.md | 23 +++-- .../organization/setup/convert-account.md | 5 +- .../organization/setup/onboard.md | 13 +-- .../organization/setup/orgs.md | 7 +- content/manuals/admin/organization/_index.md | 76 ---------------- .../access-controls/organization.md | 2 +- .../ai/sandboxes/governance/concepts.md | 2 +- content/manuals/billing/3d-secure.md | 2 +- content/manuals/build-cloud/_index.md | 2 +- .../previous-versions/edge-releases-mac.md | 2 +- content/manuals/desktop/setup/sign-in.md | 2 +- content/manuals/dhi/how-to/use.md | 2 +- content/manuals/dhi/how-to/verify.md | 2 +- .../manuals/dhi/migration/examples/dotnet.md | 2 +- content/manuals/dhi/migration/examples/go.md | 2 +- .../manuals/dhi/migration/examples/java.md | 2 +- .../manuals/dhi/migration/examples/node.md | 2 +- .../manuals/dhi/migration/examples/python.md | 2 +- .../manuals/dhi/migration/migrate-from-doi.md | 2 +- .../dhi/migration/migrate-from-ubuntu.md | 2 +- .../dhi/migration/migrate-from-wolfi.md | 2 +- content/manuals/docker-hub/_index.md | 2 +- content/manuals/docker-hub/release-notes.md | 4 +- .../manuals/docker-hub/repos/manage/access.md | 2 +- content/manuals/docker-hub/usage/pulls.md | 4 +- .../manuals/extensions/settings-feedback.md | 2 +- content/manuals/faqs/_index.md | 48 ++++++++++- .../{admin/company => faqs}/company-faqs.md | 10 ++- .../{accounts => faqs}/general-faqs.md | 16 ++-- content/manuals/faqs/general.md | 4 +- .../organization-faqs.md | 12 +-- content/manuals/faqs/sso-faqs.md | 2 +- content/manuals/offload/configuration.md | 2 +- content/manuals/offload/quickstart.md | 2 +- content/manuals/platform-release-notes.md | 2 +- .../single-sign-on/troubleshoot-sso.md | 6 +- .../provisioning/auto-provisioning.md | 2 +- .../provisioning/domain-management.md | 2 +- .../security/provisioning/scim/_index.md | 2 +- .../roles-and-permissions/core-roles.md | 6 +- .../custom-roles/manage.md | 2 +- .../subscription/plans/ai-governance.md | 2 +- content/manuals/subscription/plans/docker.md | 6 +- 68 files changed, 363 insertions(+), 296 deletions(-) create mode 100644 content/manuals/accounts/individual/_index.md rename content/manuals/accounts/{ => individual}/create-account.md (96%) rename content/manuals/accounts/{ => individual}/deactivate-user-account.md (95%) rename content/manuals/accounts/{ => individual}/manage-account.md (92%) rename content/manuals/{admin => accounts/organization}/_index.md (50%) rename content/manuals/{admin => accounts/organization}/activity-logs.md (99%) rename content/manuals/{admin => accounts/organization}/company/_index.md (77%) rename content/manuals/{admin => accounts/organization}/company/manage.md (93%) rename content/manuals/{admin => accounts/organization}/company/new-company.md (98%) rename content/manuals/{admin => accounts/organization}/images/docker-admin-structure.webp (100%) rename content/manuals/{admin => accounts/organization}/images/org-structure.webp (100%) rename content/manuals/{admin => accounts/organization}/insights.md (99%) rename content/manuals/{admin => accounts}/organization/manage/_index.md (63%) rename content/manuals/{admin/organization => accounts/organization/manage}/deactivate-account.md (92%) rename content/manuals/{admin/organization/setup => accounts/organization/manage}/general-settings.md (88%) rename content/manuals/{admin => accounts}/organization/manage/manage-a-team.md (98%) rename content/manuals/{admin => accounts}/organization/manage/manage-licenses.md (96%) rename content/manuals/{admin => accounts}/organization/manage/manage-products.md (97%) rename content/manuals/{admin => accounts}/organization/manage/manage-seats.md (98%) rename content/manuals/{admin => accounts}/organization/manage/members.md (97%) rename content/manuals/{admin => accounts}/organization/setup/_index.md (71%) rename content/manuals/{admin => accounts}/organization/setup/convert-account.md (95%) rename content/manuals/{admin => accounts}/organization/setup/onboard.md (94%) rename content/manuals/{admin => accounts}/organization/setup/orgs.md (94%) delete mode 100644 content/manuals/admin/organization/_index.md rename content/manuals/{admin/company => faqs}/company-faqs.md (84%) rename content/manuals/{accounts => faqs}/general-faqs.md (78%) rename content/manuals/{admin/organization => faqs}/organization-faqs.md (86%) diff --git a/.github/labeler.yml b/.github/labeler.yml index d7a4a910758e..32796e097775 100644 --- a/.github/labeler.yml +++ b/.github/labeler.yml @@ -153,7 +153,7 @@ area/subscription: area/admin: - changed-files: - any-glob-to-any-file: - - content/manuals/admin/** + - content/manuals/accounts/organization/** area/extensions: - changed-files: @@ -175,6 +175,7 @@ area/accounts: - changed-files: - any-glob-to-any-file: - content/manuals/accounts/** + - content/manuals/faqs/** area/copilot: - changed-files: diff --git a/content/guides/admin-set-up.md b/content/guides/admin-set-up.md index 8947dec46184..944e69161d3d 100644 --- a/content/guides/admin-set-up.md +++ b/content/guides/admin-set-up.md @@ -51,7 +51,7 @@ policies. This guide covers the following Docker features: -- [Organizations](/manuals/admin/organization/_index.md): The core structure +- [Organizations](/manuals/accounts/organization/_index.md): The core structure for managing your Docker environment, grouping users, teams, and image repositories. Your organization was created with your subscription and is managed by one or more owners. Users signed into the organization are @@ -130,7 +130,7 @@ files to be distributed to developer machines. Use MDM tools to deploy these con ### Identify Docker organizations Some companies may have more than one -[Docker organization](/manuals/admin/organization/_index.md) created. These +[Docker organization](/manuals/accounts/organization/_index.md) created. These organizations may have been created for specific purposes, or may not be needed anymore. @@ -185,8 +185,8 @@ settings, along with your chosen method for [enforcing sign-in](/manuals/platfor ### Manage your organizations If you have more than one organization, consider either [consolidating them -into one organization](/manuals/admin/organization/setup/orgs.md) or creating a -[Docker company](/manuals/admin/company/_index.md) to manage multiple +into one organization](/manuals/accounts/organization/setup/orgs.md) or creating a +[Docker company](/manuals/accounts/organization/company/_index.md) to manage multiple organizations. ### Begin setup @@ -325,6 +325,6 @@ for Docker. To continue optimizing your Docker environment: -- Review your [organization's usage data](/manuals/admin/insights.md) to track adoption +- Review your [organization's usage data](/manuals/accounts/organization/insights.md) to track adoption - Monitor [Docker Scout findings](/manuals/scout/explore/analysis.md) for security insights - Explore [additional security features](/manuals/enterprise/hardened-desktop/_index.md) to enhance your configuration diff --git a/content/guides/admin-user-management.md b/content/guides/admin-user-management.md index f054ad47717c..5975cc2becf7 100644 --- a/content/guides/admin-user-management.md +++ b/content/guides/admin-user-management.md @@ -46,7 +46,7 @@ With the right configurations, you can ensure your developers have easy access t Before setting up roles and permissions, it's important to have a clear understanding of who in your organization requires Docker access. Focus on gathering a comprehensive view of active users, their roles within projects, and how they interact with Docker resources. This process can be supported by tools like device management software or manual assessments. Encourage all users to update their Docker accounts to use organizational email addresses, ensuring seamless integration with your subscription. -For steps on how you can do this, see [step 1 of onboarding your organization](/manuals/admin/organization/setup/onboard.md). +For steps on how you can do this, see [step 1 of onboarding your organization](/manuals/accounts/organization/setup/onboard.md). ### Assign roles strategically @@ -68,7 +68,7 @@ Teams in Docker provide a structured way to manage member access and they provid - Assign permissions at the team level rather than individually. For instance, a development team might have "Read & Write" access to certain repositories, while a QA team has "Read-only" access. - As teams grow or responsibilities shift, you can easily update permissions or add new members, maintaining consistency without reconfiguring individual settings. -For more information, see [Create and manage a team](/manuals/admin/organization/manage/manage-a-team.md). +For more information, see [Create and manage a team](/manuals/accounts/organization/manage/manage-a-team.md). #### Example scenarios @@ -103,7 +103,7 @@ Members are granted controlled access to resources and enjoy enhanced organizati - Access to enhanced features: Members benefit from organization-wide perks, such as increased pull limits and access to premium Docker features. - Security control: Apply and enforce security settings at an organizational level, reducing risks associated with unmanaged accounts. -For detailed information, see [Manage organization members](/manuals/admin/organization/manage/members.md). +For detailed information, see [Manage organization members](/manuals/accounts/organization/manage/members.md). ### Future-proof user management @@ -168,7 +168,7 @@ Activity logs are available for Docker Team or Docker Business plans, with data - Team collaboration review: Logs show which team members pushed updates to a critical repository, ensuring accountability during a development sprint. - Billing adjustments: Track who added or removed subscription seats to maintain budgetary control and compliance. -For more information, see [Activity logs](/manuals/admin/activity-logs.md). +For more information, see [Activity logs](/manuals/accounts/organization/activity-logs.md). ### Insights @@ -186,13 +186,13 @@ Insights provide data-driven views of Docker usage to improve team productivity - Build efficiency: Track average build times and success rates to pinpoint bottlenecks in development processes. - Container utilization: Analyze container activity across departments to ensure proper resource distribution and cost efficiency. -For more information, see [Insights](/manuals/admin/insights.md). +For more information, see [Insights](/manuals/accounts/organization/insights.md). ### Next steps Now that you've mastered user and access management in Docker, you can: -- Review your [activity logs](/manuals/admin/activity-logs.md) regularly to maintain security awareness -- Check your [Insights dashboard](/manuals/admin/insights.md) to identify opportunities for optimization +- Review your [activity logs](/manuals/accounts/organization/activity-logs.md) regularly to maintain security awareness +- Check your [Insights dashboard](/manuals/accounts/organization/insights.md) to identify opportunities for optimization - Explore [advanced security features](/manuals/enterprise/hardened-desktop/_index.md) to further enhance your Docker environment - Share best practices with your team to ensure consistent adoption of security policies diff --git a/content/manuals/_index.md b/content/manuals/_index.md index befcaf0dd5f2..5e07f5f99230 100644 --- a/content/manuals/_index.md +++ b/content/manuals/_index.md @@ -79,22 +79,22 @@ params: icon: /icons/Scout.svg link: /scout/ platform: - - title: Administration - description: Centralized observability for companies and organizations. - icon: shield-check - link: /admin/ + - title: Accounts + description: Manage Docker individual and organization accounts. + icon: user-circle + link: /accounts/ - title: Billing description: Manage billing and payment methods. icon: credit-card link: /billing/ - - title: Accounts - description: Manage your Docker account. - icon: user-circle - link: /accounts/ - title: Security description: Security guardrails for both administrators and developers. icon: lock-closed link: /platform/security/ + - title: FAQs + description: Frequently asked questions about Docker accounts, organizations, companies, and security. + icon: question-mark-circle + link: /faqs/ - title: Subscription description: Commercial use licenses for Docker products. icon: credit-card diff --git a/content/manuals/accounts/_index.md b/content/manuals/accounts/_index.md index 0cb3765e2f38..d36e836c6684 100644 --- a/content/manuals/accounts/_index.md +++ b/content/manuals/accounts/_index.md @@ -1,63 +1,28 @@ --- -title: Docker accounts +title: Accounts description: > - Learn what a Docker account is, how Docker IDs, emails, and sign-in methods - relate, and how individual accounts connect to organizations -keywords: accounts, docker ID, username, email, Google, GitHub, sign-in, - authentication, account management, docker account, individual account, - organization account, account types, Docker Hub, SSO, deactivate account + Manage Docker individual accounts and organization administration, including + members, teams, and companies. +keywords: accounts, admin, Docker ID, organization, company, Docker Home, + account management weight: 10 params: sidebar: group: Platform grid: - - title: Create an account - description: Get started with Docker and create an account. - icon: finger-print - link: /accounts/create-account/ - - title: Manage account - description: Learn how to manage the settings for your account. - icon: cog - link: /accounts/manage-account/ - - title: Personal access tokens - description: Learn how to create and manage access tokens for your account. - icon: lock-closed - link: /platform/security/access-tokens/personal-access-tokens/ - - title: Set up two-factor authentication - description: Add an extra layer of authentication to your Docker account. - link: /platform/security/authentication/2fa/ - icon: device-phone-mobile - - title: Organization overview - description: Learn how to create and manage Docker organizations. + - title: Docker individual accounts + description: Create and manage your Docker ID, email, and sign-in methods. + icon: user-circle + link: /accounts/individual/ + - title: Organization accounts + description: Manage organizations, companies, members, and teams. icon: building-storefront - link: /admin/organization/ - - title: Account FAQs - description: Explore frequently asked questions about Docker accounts. - icon: question-mark-circle - link: /accounts/general-faqs/ + link: /accounts/organization/ --- -A Docker account is how Docker identifies you. Use it to access products like -Docker Hub and Docker Desktop, manage settings, and join organizations. - -Docker has two primary account types: individual and organization. You create -and administer organizations with your individual account. For organization -accounts, see [Organizations](/manuals/admin/organization/_index.md). For -organizations and companies, see [Administration](/manuals/admin/_index.md). - -## Docker ID, email, and sign-in - -When you create an account, you choose a Docker ID and a sign-in method. -Docker also ties a verified email to the account. - -- Docker account: Associates your plans, Hub repositories, and account - settings. -- Docker ID: A unique username that identifies you. -- Email: How Docker contacts you for notifications and security-related - communications. -- Sign-in method: Email and password, - [single sign-on (SSO)](/manuals/platform/security/authentication/single-sign-on/_index.md), - Google, or GitHub. +A Docker account identifies you and lets you access Docker products. Use an +individual account for your Docker ID and personal settings. Use an +organization account to manage members, teams, and company-wide settings. ## Next steps diff --git a/content/manuals/accounts/individual/_index.md b/content/manuals/accounts/individual/_index.md new file mode 100644 index 000000000000..33e5a40a46b1 --- /dev/null +++ b/content/manuals/accounts/individual/_index.md @@ -0,0 +1,62 @@ +--- +title: Docker individual accounts +linkTitle: Individual +description: > + Learn what a Docker account is, how Docker IDs, emails, and sign-in methods + relate, and how individual accounts connect to organizations +keywords: accounts, docker ID, username, email, Google, GitHub, sign-in, + authentication, account management, docker account, individual account, + organization account, account types, Docker Hub, SSO, deactivate account +weight: 10 +grid: + - title: Create an account + description: Get started with Docker and create an account. + icon: finger-print + link: /accounts/individual/create-account/ + - title: Manage account + description: Learn how to manage the settings for your account. + icon: cog + link: /accounts/individual/manage-account/ + - title: Personal access tokens + description: Learn how to create and manage access tokens for your account. + icon: lock-closed + link: /security/access-tokens/ + - title: Set up two-factor authentication + description: Add an extra layer of authentication to your Docker account. + link: /security/2fa/ + icon: device-phone-mobile + - title: Organization accounts + description: Learn how to create and manage Docker organizations. + icon: building-storefront + link: /accounts/organization/ + - title: Account FAQs + description: Explore frequently asked questions about Docker accounts. + icon: question-mark-circle + link: /faqs/general-faqs/ +--- + +A Docker account is how Docker identifies you. Use it to access products like +Docker Hub and Docker Desktop, manage settings, and join organizations. + +Docker has two primary account types: individual and organization. You create +and administer organizations with your individual account. For organization +accounts, including companies, see +[Organization accounts](/manuals/accounts/organization/_index.md). + +## Docker ID, email, and sign-in + +When you create an account, you choose a Docker ID and a sign-in method. +Docker also ties a verified email to the account. + +- Docker account: Associates your plans, Hub repositories, and account + settings. +- Docker ID: A unique username that identifies you. +- Email: How Docker contacts you for notifications and security-related + communications. +- Sign-in method: Email and password, + [single sign-on (SSO)](/manuals/enterprise/security/single-sign-on/_index.md), + Google, or GitHub. + +## Next steps + +{{< grid >}} diff --git a/content/manuals/accounts/create-account.md b/content/manuals/accounts/individual/create-account.md similarity index 96% rename from content/manuals/accounts/create-account.md rename to content/manuals/accounts/individual/create-account.md index c4986499e0cc..9501ed3e520b 100644 --- a/content/manuals/accounts/create-account.md +++ b/content/manuals/accounts/individual/create-account.md @@ -8,6 +8,7 @@ keywords: create docker account, docker ID, sign up, sign in, email, Google, GitHub, verification, OTP, password, docker login, username requirements aliases: + - /accounts/create-account/ - /docker-hub/accounts/ - /docker-id/ --- @@ -85,5 +86,5 @@ basis: ## Next steps -- [Manage a Docker account](/manuals/accounts/manage-account.md) +- [Manage a Docker account](/manuals/accounts/individual/manage-account.md) - [Enable two-factor authentication](/manuals/platform/security/authentication/2fa/_index.md) diff --git a/content/manuals/accounts/deactivate-user-account.md b/content/manuals/accounts/individual/deactivate-user-account.md similarity index 95% rename from content/manuals/accounts/deactivate-user-account.md rename to content/manuals/accounts/individual/deactivate-user-account.md index e7203eb6b47c..31c80a2bd908 100644 --- a/content/manuals/accounts/deactivate-user-account.md +++ b/content/manuals/accounts/individual/deactivate-user-account.md @@ -7,13 +7,15 @@ keywords: deactivate docker account, delete docker account, close docker account, disable docker account, account management, leave organization, privacy request, personal data +aliases: + - /accounts/deactivate-user-account/ --- Learn how to deactivate an individual Docker account, including the prerequisites required for deactivation. For information on deactivating an organization, see -[Deactivate an organization](/manuals/admin/organization/deactivate-account.md). +[Deactivate an organization](/manuals/accounts/organization/manage/deactivate-account.md). > [!WARNING] > diff --git a/content/manuals/accounts/manage-account.md b/content/manuals/accounts/individual/manage-account.md similarity index 92% rename from content/manuals/accounts/manage-account.md rename to content/manuals/accounts/individual/manage-account.md index 856cfae99c20..1e8b5c8dbc67 100644 --- a/content/manuals/accounts/manage-account.md +++ b/content/manuals/accounts/individual/manage-account.md @@ -8,6 +8,8 @@ keywords: manage docker account, account settings, update email, change password, Gravatar, two-factor authentication, personal access tokens, Google, GitHub, connected accounts, convert account, deactivate account, Docker Home +aliases: + - /accounts/manage-account/ --- You can manage your Docker account in Docker Home, including administrative @@ -116,15 +118,15 @@ or GitHub. See Google or GitHub's documentation for more information: For information on converting your account into an organization, see [Convert an account into an -organization](/manuals/admin/organization/setup/convert-account.md). +organization](/manuals/accounts/organization/setup/convert-account.md). ## Deactivate your account For information on deactivating your account, see -[Deactivate a Docker account](/manuals/accounts/deactivate-user-account.md). +[Deactivate a Docker account](/manuals/accounts/individual/deactivate-user-account.md). ## Next steps -- [Docker accounts overview](/manuals/accounts/_index.md) -- [Create a Docker account](/manuals/accounts/create-account.md) +- [Docker individual accounts overview](/manuals/accounts/individual/_index.md) +- [Create a Docker account](/manuals/accounts/individual/create-account.md) - [Enable two-factor authentication](/manuals/platform/security/authentication/2fa/_index.md) diff --git a/content/manuals/admin/_index.md b/content/manuals/accounts/organization/_index.md similarity index 50% rename from content/manuals/admin/_index.md rename to content/manuals/accounts/organization/_index.md index 224820580228..0b169def8fbd 100644 --- a/content/manuals/admin/_index.md +++ b/content/manuals/accounts/organization/_index.md @@ -1,30 +1,34 @@ --- -title: Administration +title: Organization accounts +linkTitle: Organization description: Overview of administration features and roles in Docker Home -keywords: admin, administration, company, organization, Docker Home, user accounts, account management -weight: 10 -params: - sidebar: - group: Enterprise +keywords: admin, administration, company, organization, Docker Home, user + accounts, account management, organizations, manage teams, roles, members, + permissions, organization settings, organization account, individual account, + Docker ID, account types, owners, teams +weight: 15 grid: + - title: Set up your organization + description: Create, onboard, and configure your organization. + icon: magnifying-glass-plus + link: /accounts/organization/setup/ + - title: Manage your organization + description: Manage members, teams, seats, and product access. + icon: user-plus + link: /accounts/organization/manage/ - title: Company administration description: Explore how to manage a company. icon: building-office-2 - link: /admin/company/ - - title: Organization administration - description: Learn about organization administration. - icon: building-storefront - link: /admin/organization/ - - title: Onboard your organization - description: Learn how to onboard and secure your organization. - icon: magnifying-glass-plus - link: /admin/organization/setup/onboard + link: /accounts/organization/company/ - title: Security description: Explore security features for administrators. icon: shield-check link: /platform/security/ aliases: + - /admin/ - /docker-hub/admin-overview + - /admin/organization/ + - /accounts/organization/overview/ --- Organization and company owners can manage members, control access, and enforce @@ -32,6 +36,10 @@ security across their Docker environments. You perform these tasks in Docker Home, which provides centralized observability, access management, and security controls. +A Docker organization is a collection of teams and repositories under +centralized management. Organization administrators group members and +assign repository access at scale. + As an organization or company owner, you can: - Create and manage companies and organizations @@ -40,6 +48,36 @@ As an organization or company owner, you can: - Set company-wide policies, including SCIM provisioning and security enforcement +## Individual and organization accounts + +Docker has two primary account types: + +- Individual accounts that are identified by a Docker ID. +- Organization accounts that are shared workspaces for teams and + repositories. + +Every organization is created and administered by one or more individual +accounts. You always sign in with your individual account, then work in the +organizations you own or belong to. Organization owners and members are +individual accounts that hold a role in that organization. For individual +accounts, see [Docker individual accounts](/manuals/accounts/individual/_index.md). + +## Organization structure + +The following diagram shows how organizations relate to teams and members. + +![Diagram showing how teams and members relate within a Docker +organization](./images/org-structure.webp) + +An organization includes owners, members, and optional teams. Organization +owners have full administrator access to manage members, roles, and teams. A +team is an optional grouping of members that share the same repository +permissions. + +For details about each role and its permissions, see +[Roles and +permissions](/manuals/enterprise/security/roles-and-permissions/_index.md). + ## Company and organization hierarchy To provide centralized administration, Docker organizes companies and @@ -49,13 +87,10 @@ organizations into the following hierarchy and roles. ### Company -A company groups multiple Docker organizations for centralized configuration. A -company owner can view and manage every organization in the company and its -company-wide settings, with the same access rights as an organization owner. For -the company owner role and how it affects seats, see -[Company roles](/manuals/admin/company/_index.md#company-roles). - -Companies are only available for Docker Business subscribers. +A company groups multiple Docker organizations for centralized configuration. +Companies are only available for Docker Business subscribers. For company +structure, owners, and seats, see +[Company overview](/manuals/accounts/organization/company/_index.md). ### Organization @@ -65,7 +100,7 @@ subscriber has at least one organization. Organization owners hold the organization owner administrator role and manage organization settings, users, and access controls. Each owner occupies a -[seat](/manuals/admin/organization/organization-faqs.md#what-is-the-difference-between-user-invitee-seat-and-member). +[seat](/manuals/faqs/organization-faqs.md#what-is-the-difference-between-user-invitee-seat-and-member). [Upgrading to a Docker Business plan](https://www.docker.com/pricing?ref=Docs&refAction=DocsAdmin) grants you the company owner role so you can manage multiple organizations. diff --git a/content/manuals/admin/activity-logs.md b/content/manuals/accounts/organization/activity-logs.md similarity index 99% rename from content/manuals/admin/activity-logs.md rename to content/manuals/accounts/organization/activity-logs.md index d4d97991d524..d4575f09d5d5 100644 --- a/content/manuals/admin/activity-logs.md +++ b/content/manuals/accounts/organization/activity-logs.md @@ -1,9 +1,10 @@ --- title: Activity logs -weight: 30 +weight: 40 description: Learn how to access and interpret Docker activity logs for organizations and repositories. keywords: audit log, organization activity, Docker business logs, repository activity, track changes Docker, security logs Docker, filter logs, log Docker events aliases: +- /admin/activity-logs/ - /docker-hub/audit-log/ - /admin/organization/activity-logs/ --- diff --git a/content/manuals/admin/company/_index.md b/content/manuals/accounts/organization/company/_index.md similarity index 77% rename from content/manuals/admin/company/_index.md rename to content/manuals/accounts/organization/company/_index.md index 5697d54e8be7..41e4b7082c8e 100644 --- a/content/manuals/admin/company/_index.md +++ b/content/manuals/accounts/organization/company/_index.md @@ -1,18 +1,18 @@ --- title: Company overview -linkTitle: Company -weight: 20 +linkTitle: Companies +weight: 30 description: Learn how to manage multiple organizations using companies, including managing users, owners, and security. keywords: company, multiple organizations, manage companies, Docker Home, Docker Business settings grid: - title: Create a company description: Get started by learning how to create a company. icon: building-office-2 - link: /admin/company/new-company/ + link: /accounts/organization/company/new-company/ - title: Manage your company description: Add organizations, manage company owners, and invite members. icon: building-storefront - link: /admin/company/manage/ + link: /accounts/organization/company/manage/ - title: Configure SSO and SCIM description: Set up single sign-on and SCIM provisioning for your company. icon: key @@ -23,16 +23,17 @@ grid: link: /platform/security/provisioning/domain-management/ - title: FAQs description: Explore frequently asked questions about companies. - link: /faq/admin/company-faqs/ + link: /faqs/company-faqs/ icon: question-mark-circle aliases: + - /admin/company/ - /docker-hub/creating-companies/ --- {{< summary-bar feature_name="Company" >}} -A company provides a single point of visibility across multiple -organizations, for centralized organization and settings management. +A company groups multiple Docker organizations for centralized configuration +and provides a single point of visibility across those organizations. Organization owners with a Docker Business subscription can create a company and manage it through Docker Home. @@ -41,10 +42,10 @@ and manage it through Docker Home. The following diagram shows how a company relates to its associated organizations. -![Diagram showing how companies relate to Docker organizations](/admin/images/docker-admin-structure.webp) +![Diagram showing how companies relate to Docker organizations](/accounts/organization/images/docker-admin-structure.webp) -For the full administration hierarchy, see the -[administration overview](/manuals/admin/_index.md#company-and-organization-hierarchy). +For the full administration hierarchy, see +[Company and organization hierarchy](/manuals/accounts/organization/_index.md#company-and-organization-hierarchy). ## Company roles @@ -62,7 +63,7 @@ organization owners. automatically adds them as an organization member. To add or remove company owners, see -[Manage your company](/manuals/admin/company/manage.md#company-owners). +[Manage your company](/manuals/accounts/organization/company/manage.md#company-owners). ## Next steps diff --git a/content/manuals/admin/company/manage.md b/content/manuals/accounts/organization/company/manage.md similarity index 93% rename from content/manuals/admin/company/manage.md rename to content/manuals/accounts/organization/company/manage.md index 4b91db7a0e2b..d7a1d3898eb4 100644 --- a/content/manuals/admin/company/manage.md +++ b/content/manuals/accounts/organization/company/manage.md @@ -5,6 +5,7 @@ weight: 20 description: Learn how to manage your company, including its organizations, owners, and members, using Docker Home. keywords: company, manage company, multiple organizations, company owners, company members, Docker Home, add organization, resend invites aliases: + - /admin/company/manage/ - /admin/company/manage/organizations/ - /admin/company/manage/owners/ - /admin/company/manage/users/ @@ -46,7 +47,7 @@ longer manage it through the company, and its owner must manage it separately. A company can have multiple owners who manage the company and all of its organizations. For details about the company owner role and how it affects -seats, see [Company roles](/manuals/admin/company/_index.md#company-roles). +seats, see [Company roles](/manuals/accounts/organization/company/_index.md#company-roles). ### Add a company owner @@ -108,7 +109,7 @@ To bulk resend invitations: If you have a self-serve subscription that has no pending subscription changes, you can add seats using Docker Home. For more information about adding seats, -see [Manage seats](/manuals/admin/organization/manage/manage-seats.md#add-seats-to-your-subscription). +see [Manage seats](/manuals/accounts/organization/manage/manage-seats.md#add-seats-to-your-subscription). If you have a sales-assisted subscription, you must contact Docker support or sales to add seats. @@ -118,4 +119,4 @@ sales to add seats. Teams exist at the organization level, not the company level. After inviting members to an organization, you can add them to teams within that organization. For more details, see -[Manage members on a team](/manuals/admin/organization/manage/members.md#manage-members-on-a-team). +[Manage members on a team](/manuals/accounts/organization/manage/members.md#manage-members-on-a-team). diff --git a/content/manuals/admin/company/new-company.md b/content/manuals/accounts/organization/company/new-company.md similarity index 98% rename from content/manuals/admin/company/new-company.md rename to content/manuals/accounts/organization/company/new-company.md index 38cd05e04842..0d28f76e3ef6 100644 --- a/content/manuals/admin/company/new-company.md +++ b/content/manuals/accounts/organization/company/new-company.md @@ -5,6 +5,7 @@ weight: 10 description: Learn how to create a company to centrally manage multiple organizations. keywords: company, hub, organization, company owner, Docker Home, company management, Docker Business, create company aliases: + - /admin/company/new-company/ - /docker-hub/new-company/ --- diff --git a/content/manuals/admin/images/docker-admin-structure.webp b/content/manuals/accounts/organization/images/docker-admin-structure.webp similarity index 100% rename from content/manuals/admin/images/docker-admin-structure.webp rename to content/manuals/accounts/organization/images/docker-admin-structure.webp diff --git a/content/manuals/admin/images/org-structure.webp b/content/manuals/accounts/organization/images/org-structure.webp similarity index 100% rename from content/manuals/admin/images/org-structure.webp rename to content/manuals/accounts/organization/images/org-structure.webp diff --git a/content/manuals/admin/insights.md b/content/manuals/accounts/organization/insights.md similarity index 99% rename from content/manuals/admin/insights.md rename to content/manuals/accounts/organization/insights.md index 8a6ff5d6567a..bd42b48d8357 100644 --- a/content/manuals/admin/insights.md +++ b/content/manuals/accounts/organization/insights.md @@ -1,8 +1,10 @@ --- title: Insights -weight: 40 +weight: 50 description: Gain insights about your organization's users and their Docker usage. keywords: organization, insights, Docker Desktop analytics, user usage statistics, Docker Business, track Docker activity +aliases: + - /admin/insights/ --- {{< summary-bar feature_name="Insights" >}} diff --git a/content/manuals/admin/organization/manage/_index.md b/content/manuals/accounts/organization/manage/_index.md similarity index 63% rename from content/manuals/admin/organization/manage/_index.md rename to content/manuals/accounts/organization/manage/_index.md index f6854f955395..86f5fcd499a4 100644 --- a/content/manuals/admin/organization/manage/_index.md +++ b/content/manuals/accounts/organization/manage/_index.md @@ -2,17 +2,25 @@ title: Manage your organization linkTitle: Manage weight: 20 -description: Learn how to manage your Docker organization, including members, teams, licenses, seats, and product access. -keywords: manage organization, members, teams, licenses, seats, product access, organization management, docker home +description: Learn how to manage your Docker organization, including members, teams, licenses, seats, product access, and settings. +keywords: manage organization, members, teams, licenses, seats, product access, organization management, docker home, organization settings, deactivate organization grid: - title: Members description: Invite, manage, and assign roles to your organization members. icon: user-plus - link: /admin/organization/manage/members/ + link: /accounts/organization/manage/members/ - title: Product access and usage description: Manage access and view usage for Docker products across your organization. icon: squares-2x2 - link: /admin/organization/manage/manage-products/ + link: /accounts/organization/manage/manage-products/ + - title: Change information + description: Update your organization's general information and settings. + icon: pencil-square + link: /accounts/organization/manage/general-settings/ + - title: Deactivate + description: Deactivate an organization after completing the required steps. + icon: minus-circle + link: /accounts/organization/manage/deactivate-account/ - title: Security description: Configure single sign-on, provisioning, and access management. icon: shield-check @@ -21,11 +29,14 @@ grid: description: Manage payment methods and view billing history. icon: credit-card link: /billing/ +aliases: + - /admin/organization/manage/ --- As an organization owner, you manage your organization's membership, access, -and product usage. You can invite members, group them into teams, assign or -revoke licenses and seats, and change access to Docker products. +product usage, and settings. You can invite members, group them into teams, +assign or revoke licenses and seats, change access to Docker products, update +organization information, and deactivate the organization. ## Managing your organization @@ -43,8 +54,8 @@ plans. The following table summarizes the difference. | Seat | Membership in your Docker Team or Business subscription | Docker Core subscription | Billing | | License | Access to a specific product or add-on | AI Governance, Docker Offload, and other add-ons | Members | -For details, see [Seats](/manuals/admin/organization/manage/manage-seats.md) -and [License assignment](/manuals/admin/organization/manage/manage-licenses.md). +For details, see [Seats](/manuals/accounts/organization/manage/manage-seats.md) +and [License assignment](/manuals/accounts/organization/manage/manage-licenses.md). ## Next steps diff --git a/content/manuals/admin/organization/deactivate-account.md b/content/manuals/accounts/organization/manage/deactivate-account.md similarity index 92% rename from content/manuals/admin/organization/deactivate-account.md rename to content/manuals/accounts/organization/manage/deactivate-account.md index a1bd7972d207..be62036d6c21 100644 --- a/content/manuals/admin/organization/deactivate-account.md +++ b/content/manuals/accounts/organization/manage/deactivate-account.md @@ -5,9 +5,11 @@ description: Learn how to deactivate a Docker organization and required prerequisite steps. keywords: deactivate organization, delete organization, organization management, Docker Home, cancel subscription, unlink GitHub, remove SSO -weight: 50 +weight: 70 aliases: + - /admin/organization/deactivate-account/ - /docker-hub/deactivate-account/ + - /accounts/organization/deactivate-account/ --- {{< summary-bar feature_name="General admin" >}} @@ -15,7 +17,7 @@ aliases: Learn how to deactivate a Docker organization, including required prerequisite steps. For information about deactivating user accounts, see [Deactivate a Docker -account](/manuals/accounts/deactivate-user-account.md). +account](/manuals/accounts/individual/deactivate-user-account.md). > [!WARNING] > diff --git a/content/manuals/admin/organization/setup/general-settings.md b/content/manuals/accounts/organization/manage/general-settings.md similarity index 88% rename from content/manuals/admin/organization/setup/general-settings.md rename to content/manuals/accounts/organization/manage/general-settings.md index 95b95b139e72..88ddd6fd81a1 100644 --- a/content/manuals/admin/organization/setup/general-settings.md +++ b/content/manuals/accounts/organization/manage/general-settings.md @@ -1,11 +1,13 @@ --- title: Change general organization information linkTitle: Change information -weight: 30 +weight: 60 description: Learn how to manage settings for organizations. keywords: organization, settings, Docker Home, manage, Docker organization, Gravatar, SCIM, SSO setup, domain management, organization settings aliases: + - /admin/organization/setup/general-settings/ - /admin/organization/general-settings/ + - /accounts/organization/setup/general-settings/ --- Learn how to update your organization information. @@ -36,4 +38,4 @@ After configuring your organization information, you can: - [Configure single sign-on (SSO)](/manuals/platform/security/authentication/single-sign-on/connect.md) - [Set up SCIM provisioning](/manuals/platform/security/provisioning/scim/_index.md) - [Manage domains](/manuals/platform/security/provisioning/domain-management.md) -- [Create a company](/manuals/admin/company/new-company.md) +- [Create a company](/manuals/accounts/organization/company/new-company.md) diff --git a/content/manuals/admin/organization/manage/manage-a-team.md b/content/manuals/accounts/organization/manage/manage-a-team.md similarity index 98% rename from content/manuals/admin/organization/manage/manage-a-team.md rename to content/manuals/accounts/organization/manage/manage-a-team.md index 58b7acf48b20..24ed758dc6a5 100644 --- a/content/manuals/admin/organization/manage/manage-a-team.md +++ b/content/manuals/accounts/organization/manage/manage-a-team.md @@ -6,6 +6,7 @@ description: Learn how to create and manage teams for your organization keywords: docker, registry, teams, organizations, plans, Dockerfile, Docker Hub, docs, documentation, repository permissions, configure repository access, team management aliases: + - /admin/organization/manage/manage-a-team/ - /docker-hub/manage-a-team/ - /admin/organization/manage-a-team/ --- @@ -60,7 +61,7 @@ For more information on roles, see You must create a team before you are able to configure repository permissions. For more details, see [Create and manage a -team](/manuals/admin/organization/manage/manage-a-team.md). +team](/manuals/accounts/organization/manage/manage-a-team.md). To set team repository permissions: diff --git a/content/manuals/admin/organization/manage/manage-licenses.md b/content/manuals/accounts/organization/manage/manage-licenses.md similarity index 96% rename from content/manuals/admin/organization/manage/manage-licenses.md rename to content/manuals/accounts/organization/manage/manage-licenses.md index 56ccc7bd0638..c4a99572e96f 100644 --- a/content/manuals/admin/organization/manage/manage-licenses.md +++ b/content/manuals/accounts/organization/manage/manage-licenses.md @@ -4,6 +4,8 @@ linkTitle: License assignment description: Manage product licenses for your organization, including invite-time assignment, revocation, and automatic assignment. keywords: licenses, organization, members, invite, invitation, Docker Core, Docker Offload, AI Governance, license assignment, docker home weight: 30 +aliases: + - /admin/organization/manage/manage-licenses/ --- Licenses let you choose which organization members can access supported Docker @@ -57,7 +59,7 @@ a member: For more about sending, resending, and removing invitations, including CSV file limits, see -[Manage organization members](/manuals/admin/organization/manage/members.md). +[Manage organization members](/manuals/accounts/organization/manage/members.md). ### Accept invites @@ -116,7 +118,7 @@ Explore Docker Core add-ons and products that need licenses: - [Docker plans](/manuals/subscription/plans/_index.md) to learn about different add-ons -- [Manage seats](/manuals/admin/organization/manage/manage-seats.md) to add more +- [Manage seats](/manuals/accounts/organization/manage/manage-seats.md) to add more seats to your Docker Core subscription - [AI Governance plan](/manuals/subscription/plans/ai-governance.md) to learn about AI Governance license usage and billing diff --git a/content/manuals/admin/organization/manage/manage-products.md b/content/manuals/accounts/organization/manage/manage-products.md similarity index 97% rename from content/manuals/admin/organization/manage/manage-products.md rename to content/manuals/accounts/organization/manage/manage-products.md index 4ed394b5a99e..8b73156ae329 100644 --- a/content/manuals/admin/organization/manage/manage-products.md +++ b/content/manuals/accounts/organization/manage/manage-products.md @@ -5,6 +5,7 @@ weight: 50 description: Learn how to manage access and usage for Docker products for your organization keywords: organization, product access, product usage, access control, docker desktop, docker hub, docker scout, docker build cloud, docker offload, testcontainers cloud aliases: + - /admin/organization/manage/manage-products/ - /admin/organization/manage-products/ --- @@ -132,7 +133,7 @@ following table to learn where you can monitor organization usage: | Product | Monitor usage | | -------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | -| Docker Desktop | From [Docker Home](https://app.docker.com/), view the [**Insights**](../../insights.md) page. | +| Docker Desktop | From [Docker Home](https://app.docker.com/), view the [**Insights**](/manuals/accounts/organization/insights.md) page. | | Docker Hub | From Docker Hub, view the [**Usage** page](https://hub.docker.com/usage). | | Docker Build Cloud | From [Docker Build Cloud](http://app.docker.com/build), view the **Build minutes** page. | | Docker Scout | From [Docker Home](https://app.docker.com/), select **Go to Scout** to view the [**Repository settings** page](https://scout.docker.com/settings/repos). | diff --git a/content/manuals/admin/organization/manage/manage-seats.md b/content/manuals/accounts/organization/manage/manage-seats.md similarity index 98% rename from content/manuals/admin/organization/manage/manage-seats.md rename to content/manuals/accounts/organization/manage/manage-seats.md index c67156f5224a..15747bf01854 100644 --- a/content/manuals/admin/organization/manage/manage-seats.md +++ b/content/manuals/accounts/organization/manage/manage-seats.md @@ -4,6 +4,7 @@ linkTitle: Seats description: Add or remove seats for Docker Team and Business subscriptions keywords: manage seats, add seats, remove seats, subscription billing, team members aliases: + - /admin/organization/manage/manage-seats/ - /docker-hub/billing/add-seats/ - /subscription/add-seats/ - /docker-hub/billing/remove-seats/ diff --git a/content/manuals/admin/organization/manage/members.md b/content/manuals/accounts/organization/manage/members.md similarity index 97% rename from content/manuals/admin/organization/manage/members.md rename to content/manuals/accounts/organization/manage/members.md index 75656ddc5913..2ffc51e5abcc 100644 --- a/content/manuals/admin/organization/manage/members.md +++ b/content/manuals/accounts/organization/manage/members.md @@ -7,6 +7,7 @@ description: Manage organization members, including invitations, roles, teams, keywords: members, organization members, invitations, teams, manage team members, export member list, edit roles, user management aliases: + - /admin/organization/manage/members/ - /docker-hub/members/ - /admin/organization/members/ --- @@ -25,7 +26,7 @@ You can also select one or more product licenses for an invitee; Docker assigns available licenses when they accept. Unlike a seat, licenses aren't deducted from your organization's available licenses until the invitee accepts. See -[Licenses and invites](/manuals/admin/organization/manage/manage-licenses.md#licenses-and-invites). +[Licenses and invites](/manuals/accounts/organization/manage/manage-licenses.md#licenses-and-invites). ### Invite members via Docker ID or email address @@ -137,7 +138,7 @@ able to invite more members. > Need to manage more than 1,000 team members? > [Upgrade to Docker Business for unlimited user invites](https://www.docker.com/pricing?ref=Docs&refAction=DocsAdminMembers) > and advanced role management. You can also -> [add seats](/manuals/admin/organization/manage/manage-seats.md) to your +> [add seats](/manuals/accounts/organization/manage/manage-seats.md) to your > subscription. ### Resend an invitation diff --git a/content/manuals/admin/organization/setup/_index.md b/content/manuals/accounts/organization/setup/_index.md similarity index 71% rename from content/manuals/admin/organization/setup/_index.md rename to content/manuals/accounts/organization/setup/_index.md index 1a30cc663c26..56ad6c539c61 100644 --- a/content/manuals/admin/organization/setup/_index.md +++ b/content/manuals/accounts/organization/setup/_index.md @@ -2,38 +2,36 @@ title: Set up your organization linkTitle: Setup weight: 10 -description: Learn how to set up your Docker organization, including creating an organization, onboarding, and configuring settings. -keywords: set up organization, create organization, onboard, convert account, organization settings, docker home +description: Learn how to set up your Docker organization, including creating an organization, onboarding, and converting an account. +keywords: set up organization, create organization, onboard, convert account, docker home grid: - title: Create your organization description: Create an organization to group teams and members and assign access. icon: building-storefront - link: /admin/organization/setup/orgs/ + link: /accounts/organization/setup/orgs/ - title: Onboard your organization description: Onboard and secure your Docker Team or Business organization. icon: magnifying-glass-plus - link: /admin/organization/setup/onboard/ - - title: Change information - description: Update your organization's general information and settings. - icon: pencil-square - link: /admin/organization/setup/general-settings/ + link: /accounts/organization/setup/onboard/ - title: Convert account description: Convert an existing Docker user account into an organization. icon: arrows-right-left - link: /admin/organization/setup/convert-account/ + link: /accounts/organization/setup/convert-account/ - title: Manage your organization description: Add members, teams, licenses, and seats after setup. icon: user-group - link: /admin/organization/manage/ + link: /accounts/organization/manage/ - title: Security description: Configure single sign-on, provisioning, and access management. icon: shield-check link: /platform/security/ +aliases: + - /admin/organization/setup/ --- Before you manage members and access, set up your Docker organization. You can -create an organization, onboard and secure it, update its information, or convert -an existing user account into an organization. +create an organization, onboard and secure it, or convert an existing user +account into an organization. ## Setting up your organization @@ -48,7 +46,6 @@ Setting up an organization happens in broad phases: 1. After creating your organization, you must onboard it by inviting members, securing authentication, and enforcing sign-in. These steps build on each other, so follow them in order. -1. You can update your organization's general information whenever it changes. ## Next steps diff --git a/content/manuals/admin/organization/setup/convert-account.md b/content/manuals/accounts/organization/setup/convert-account.md similarity index 95% rename from content/manuals/admin/organization/setup/convert-account.md rename to content/manuals/accounts/organization/setup/convert-account.md index db3ebf6765e7..d86cab3c4bd2 100644 --- a/content/manuals/admin/organization/setup/convert-account.md +++ b/content/manuals/accounts/organization/setup/convert-account.md @@ -5,6 +5,7 @@ title: Convert an account into an organization keywords: docker hub, hub, organization, convert account, migrate account weight: 40 aliases: + - /admin/organization/setup/convert-account/ - /docker-hub/convert-account/ - /admin/organization/convert-account/ --- @@ -15,8 +16,8 @@ Learn how to convert an existing user account into an organization. This is useful if you need multiple users to access your account and the repositories it’s connected to. Converting it to an organization gives you better control over permissions for these users through -[teams](/manuals/admin/organization/manage/manage-a-team.md) and -[roles](/manuals/platform/security/roles-and-permissions.md). +[teams](/manuals/accounts/organization/manage/manage-a-team.md) and +[roles](/manuals/platform/security/roles-and-permissions/_index.md). When you convert a user account to an organization, the account is migrated to a Docker Team subscription by default. diff --git a/content/manuals/admin/organization/setup/onboard.md b/content/manuals/accounts/organization/setup/onboard.md similarity index 94% rename from content/manuals/admin/organization/setup/onboard.md rename to content/manuals/accounts/organization/setup/onboard.md index e77ed85ef52f..ba0aba76b2cd 100644 --- a/content/manuals/admin/organization/setup/onboard.md +++ b/content/manuals/accounts/organization/setup/onboard.md @@ -7,6 +7,7 @@ keywords: business, team, organizations, get started, onboarding, Docker Home, o toc_min: 1 toc_max: 3 aliases: + - /admin/organization/setup/onboard/ - /docker-hub/onboard/ - /docker-hub/onboard-team/ - /docker-hub/onboard-business/ @@ -40,7 +41,7 @@ Before you start onboarding your organization, ensure you: > When purchasing a self-serve subscription, the on-screen instructions > guide you through creating an organization. If you have purchased a > subscription through Docker Sales and you have not yet created an - > organization, see [Create an organization](/manuals/admin/organization/setup/orgs.md). + > organization, see [Create an organization](/manuals/accounts/organization/setup/orgs.md). - Familiarize yourself with Docker concepts and terminology in the [administration overview](../../_index.md). @@ -50,7 +51,7 @@ Before you start onboarding your organization, ensure you: Docker Home has a guided setup to help you onboard your organization. The guided setup's steps consist of basic onboarding tasks. If you want to onboard outside of the guided setup, -see [Recommended onboarding steps](/manuals/admin/organization/setup/onboard.md#recommended-onboarding-steps). +see [Recommended onboarding steps](/manuals/accounts/organization/setup/onboard.md#recommended-onboarding-steps). To onboard using the guided setup, navigate to [Docker Home](https://app.docker.com) and @@ -104,8 +105,8 @@ When you create an organization, you are the only owner. It is optional to add additional owners. To add an owner, invite a user and assign them the owner role. For more -details, see [Invite members](/manuals/admin/organization/manage/members.md) and -[Roles and permissions](/manuals/platform/security/roles-and-permissions.md). +details, see [Invite members](/manuals/accounts/organization/manage/members.md) and +[Roles and permissions](/manuals/platform/security/roles-and-permissions/_index.md). ### Step three: Invite members @@ -115,8 +116,8 @@ receive increased pull limits and other organization wide benefits when they are signed in. To add a member, invite a user and assign them the member role. -For more details, see [Invite members](/manuals/admin/organization/manage/members.md) and -[Roles and permissions](/manuals/platform/security/roles-and-permissions.md). +For more details, see [Invite members](/manuals/accounts/organization/manage/members.md) and +[Roles and permissions](/manuals/platform/security/roles-and-permissions/_index.md). ### Step four: Manage user access with SSO and SCIM diff --git a/content/manuals/admin/organization/setup/orgs.md b/content/manuals/accounts/organization/setup/orgs.md similarity index 94% rename from content/manuals/admin/organization/setup/orgs.md rename to content/manuals/accounts/organization/setup/orgs.md index 5cb67788393d..c2097d18713c 100644 --- a/content/manuals/admin/organization/setup/orgs.md +++ b/content/manuals/accounts/organization/setup/orgs.md @@ -5,6 +5,7 @@ weight: 10 description: Learn how to create an organization. keywords: docker organizations, organization, create organization, docker teams, organization management aliases: + - /admin/organization/setup/orgs/ - /docker-hub/orgs/ - /admin/organization/orgs/ --- @@ -19,9 +20,9 @@ There are multiple ways to create an organization. You can either: ## Prerequisites -- Before you create an organization, you need a [Docker ID](/manuals/accounts/create-account.md). +- Before you create an organization, you need a [Docker ID](/manuals/accounts/individual/create-account.md). - For prerequisites and detailed instructions on converting an existing user account to an organization, see - [Convert an account into an organization](/manuals/admin/organization/setup/convert-account.md). + [Convert an account into an organization](/manuals/accounts/organization/setup/convert-account.md). > [!TIP] > Need a different plan for your team's needs? Review different [Docker subscriptions and features](https://www.docker.com/pricing?ref=Docs&refAction=DocsAdminOrgs) to choose a subscription for your organization. @@ -36,7 +37,7 @@ There are multiple ways to create an organization. You can either: your organization in Docker Hub. - It's not possible to change the name of the organization after you've created it. - Your Docker ID and organization can't share the same name. - - If you want to use your Docker ID as the organization name, then you must first [convert your account into an organization](/manuals/admin/organization/setup/convert-account.md). + - If you want to use your Docker ID as the organization name, then you must first [convert your account into an organization](/manuals/accounts/organization/setup/convert-account.md). 1. Enter your **Company name**. This is the full name of your company. - Docker displays the company name on your organization page and in the details of any public images you publish. diff --git a/content/manuals/admin/organization/_index.md b/content/manuals/admin/organization/_index.md deleted file mode 100644 index aec33fa838bc..000000000000 --- a/content/manuals/admin/organization/_index.md +++ /dev/null @@ -1,76 +0,0 @@ ---- -title: Docker organization overview -linkTitle: Organization -weight: 10 -description: > - Learn how Docker organization accounts relate to individual accounts, and how - to manage teams, members, permissions, and settings. -keywords: organizations, admin, overview, manage teams, roles, members, - permissions, organization settings, organization account, individual account, - Docker ID, account types, owners, teams -grid: - - title: Onboard your organization - description: Learn how to onboard and secure your organization. - icon: magnifying-glass-plus - link: /admin/organization/setup/onboard - - title: Manage members - description: Learn how to manage members. - icon: user-plus - link: /admin/organization/manage/members/ - - title: Activity logs - description: Learn how to audit the activities of your members. - icon: document-text - link: /admin/activity-logs/ - - title: Security - description: - Start here to manage security and access for your organization, including - single sign-on, provisioning, and image and registry access management. - icon: shield-check - link: /platform/security/ ---- - -A Docker organization is a collection of teams and repositories under -centralized management. Organization administrators group members and -assign repository access at scale. - -## Organization structure - -The following diagram shows how organizations relate to teams and members. - -![Diagram showing how teams and members relate within a Docker -organization](/admin/images/org-structure.webp) - -For how organizations fit into the broader company hierarchy, see -[Administration -overview](/manuals/admin/_index.md#company-and-organization-hierarchy). - -## Individual and organization accounts - -Docker has two primary account types: - -- Individual accounts that are identified by a Docker ID. -- Organization accounts that are shared workspaces for teams and - repositories. - -Every organization is created and administered by one or more individual -accounts. You always sign in with your individual account, then work in the -organizations you own or belong to. Organization owners and members are -individual accounts that hold a role in that organization. For individual -accounts, see [Accounts](/manuals/accounts/_index.md). - -## Organization roles - -An organization includes owners, members, and optional teams. Organization -owners have full administrator access to manage members, roles, and teams. A -team is an optional grouping of members that share the same repository -permissions. - -For details about each role and its permissions, see -[Roles and -permissions](/manuals/platform/security/roles-and-permissions/_index.md). - -## Next steps - -Learn how to create and manage your organization in the following sections. - -{{< grid >}} diff --git a/content/manuals/ai/sandboxes/governance/access-controls/organization.md b/content/manuals/ai/sandboxes/governance/access-controls/organization.md index 1b439823a29e..d5da0521626b 100644 --- a/content/manuals/ai/sandboxes/governance/access-controls/organization.md +++ b/content/manuals/ai/sandboxes/governance/access-controls/organization.md @@ -108,7 +108,7 @@ it only to members of the teams you select. ### Before you start Team scoping targets your organization's existing -[teams](/manuals/admin/organization/manage/manage-a-team.md), so a team must +[teams](/manuals/accounts/organization/manage/manage-a-team.md), so a team must exist before you can scope a policy to it. Create teams and manage their members in one of two ways: diff --git a/content/manuals/ai/sandboxes/governance/concepts.md b/content/manuals/ai/sandboxes/governance/concepts.md index d39cd47f128c..ed96c722a219 100644 --- a/content/manuals/ai/sandboxes/governance/concepts.md +++ b/content/manuals/ai/sandboxes/governance/concepts.md @@ -47,7 +47,7 @@ to specific teams: - Team-scoped: with one or more teams assigned, the policy applies only to members of those teams. -Teams are the same [teams](/manuals/admin/organization/manage/manage-a-team.md) +Teams are the same [teams](/manuals/accounts/organization/manage/manage-a-team.md) you manage for your organization; Docker matches a policy's teams against each user's team membership. Because an organization can mix org-wide and team-scoped policies, a single user is often subject to several at once. The policies that diff --git a/content/manuals/billing/3d-secure.md b/content/manuals/billing/3d-secure.md index eca8852ca43c..f6efae7e5e16 100644 --- a/content/manuals/billing/3d-secure.md +++ b/content/manuals/billing/3d-secure.md @@ -30,7 +30,7 @@ actions: - Starting a [paid subscription](../subscription/manage.md) - Changing your [billing cycle](/manuals/billing/details.md#billing-cycle) from monthly to annual - [Upgrading your subscription](../subscription/manage.md#upgrade-plans) -- [Adding seats](../admin/organization/manage/manage-seats.md) to an existing +- [Adding seats](../accounts/organization/manage/manage-seats.md) to an existing subscription If 3DS is required and your payment method supports it, the verification prompt diff --git a/content/manuals/build-cloud/_index.md b/content/manuals/build-cloud/_index.md index 4b04be3a920e..dfd72f30a2bd 100644 --- a/content/manuals/build-cloud/_index.md +++ b/content/manuals/build-cloud/_index.md @@ -52,7 +52,7 @@ data between cloud builders. ## Get Docker Build Cloud To get started with Docker Build Cloud, -[create a Docker account](/accounts/create-account/). There are two options +[create a Docker account](/accounts/individual/create-account/). There are two options to get access to Docker Build Cloud: - Users with a free Personal account can opt-in to a 7-day free trial, with the option diff --git a/content/manuals/desktop/previous-versions/edge-releases-mac.md b/content/manuals/desktop/previous-versions/edge-releases-mac.md index 6ab358c1dcc6..a42c984f0f43 100644 --- a/content/manuals/desktop/previous-versions/edge-releases-mac.md +++ b/content/manuals/desktop/previous-versions/edge-releases-mac.md @@ -1104,7 +1104,7 @@ This release contains a Kubernetes upgrade. Note that your local Kubernetes clus - Add daemon options validation - Diagnose can be cancelled & Improved help information. Fixes [docker/for-mac#1134](https://github.com/docker/for-mac/issues/1134), [docker/for-mac#1474](https://github.com/docker/for-mac/issues/1474) -- Support paging of Docker Cloud [repositories](../../docker-hub/repos/_index.md) and [organizations](../../admin/organization/setup/orgs.md). Fixes [docker/for-mac#1538](https://github.com/docker/for-mac/issues/1538) +- Support paging of Docker Cloud [repositories](../../docker-hub/repos/_index.md) and [organizations](../../accounts/organization/setup/orgs.md). Fixes [docker/for-mac#1538](https://github.com/docker/for-mac/issues/1538) ### Docker Community Edition 17.06.1-ce-mac20, 2017-07-18 diff --git a/content/manuals/desktop/setup/sign-in.md b/content/manuals/desktop/setup/sign-in.md index 9d7c6282483f..0abe991654f5 100644 --- a/content/manuals/desktop/setup/sign-in.md +++ b/content/manuals/desktop/setup/sign-in.md @@ -38,7 +38,7 @@ In large enterprises where admin access is restricted, administrators can [enfor ## Signing in with Docker Desktop for Linux Docker Desktop for Linux relies on [`pass`](https://www.passwordstore.org/) to store credentials in GPG-encrypted files. -Before signing in to Docker Desktop with your [Docker ID](/accounts/create-account/), you must initialize `pass`. +Before signing in to Docker Desktop with your [Docker ID](/accounts/individual/create-account/), you must initialize `pass`. Docker Desktop displays a warning if `pass` is not configured. 1. Generate a GPG key. You can initialize pass by using a gpg key. To generate a gpg key, run: diff --git a/content/manuals/dhi/how-to/use.md b/content/manuals/dhi/how-to/use.md index 5df029daa0d6..52dea6884c68 100644 --- a/content/manuals/dhi/how-to/use.md +++ b/content/manuals/dhi/how-to/use.md @@ -23,7 +23,7 @@ package manager, and may run as a non-root user by default. > pull DHI Community images. You can authenticate using either of the following: > > - **Docker ID and password:** Use your Docker Hub username and password. If -> you don't have a Docker account, [create one](../../accounts/create-account.md) +> you don't have a Docker account, [create one](../../accounts/individual/create-account.md > for free. > - **Access token:** Use a [personal access token > (PAT)](../../platform/security/access-tokens/personal-access-tokens.md) for personal accounts, or an diff --git a/content/manuals/dhi/how-to/verify.md b/content/manuals/dhi/how-to/verify.md index 9021b47bc940..b11ac22e7ff7 100644 --- a/content/manuals/dhi/how-to/verify.md +++ b/content/manuals/dhi/how-to/verify.md @@ -27,7 +27,7 @@ attestation infrastructure. > You must authenticate to the Docker Hardened Images registry (`dhi.io`) to > pull images. Use your Docker ID credentials (the same username and password > you use for Docker Hub) when signing in. If you don't have a Docker account, -> [create one](../../accounts/create-account.md) for free. +> [create one](../../accounts/individual/create-account.md) for free. > > Run `docker login dhi.io` to authenticate. diff --git a/content/manuals/dhi/migration/examples/dotnet.md b/content/manuals/dhi/migration/examples/dotnet.md index 79cdee998e1a..129d2f937788 100644 --- a/content/manuals/dhi/migration/examples/dotnet.md +++ b/content/manuals/dhi/migration/examples/dotnet.md @@ -23,7 +23,7 @@ Hardened Images. Each example includes four variations: > You must authenticate to `dhi.io` before you can pull Docker Hardened Images. > Use your Docker ID credentials (the same username and password you use for > Docker Hub). If you don't have a Docker account, [create -> one](../../../accounts/create-account.md) for free. +> one](../../../accounts/individual/create-account.md) for free. > > Run `docker login dhi.io` to authenticate. diff --git a/content/manuals/dhi/migration/examples/go.md b/content/manuals/dhi/migration/examples/go.md index 3a42bdc50a9d..b79ba0d407a6 100644 --- a/content/manuals/dhi/migration/examples/go.md +++ b/content/manuals/dhi/migration/examples/go.md @@ -24,7 +24,7 @@ Hardened Images. Each example includes five variations: > You must authenticate to `dhi.io` before you can pull Docker Hardened Images. > Use your Docker ID credentials (the same username and password you use for > Docker Hub). If you don't have a Docker account, [create -> one](../../../accounts/create-account.md) for free. +> one](../../../accounts/individual/create-account.md) for free. > > Run `docker login dhi.io` to authenticate. diff --git a/content/manuals/dhi/migration/examples/java.md b/content/manuals/dhi/migration/examples/java.md index bfae595dc48a..2b26fbeb1d74 100644 --- a/content/manuals/dhi/migration/examples/java.md +++ b/content/manuals/dhi/migration/examples/java.md @@ -24,7 +24,7 @@ Hardened Images. Each example includes five variations: > You must authenticate to `dhi.io` before you can pull Docker Hardened Images. > Use your Docker ID credentials (the same username and password you use for > Docker Hub). If you don't have a Docker account, [create -> one](../../../accounts/create-account.md) for free. +> one](../../../accounts/individual/create-account.md) for free. > > Run `docker login dhi.io` to authenticate. diff --git a/content/manuals/dhi/migration/examples/node.md b/content/manuals/dhi/migration/examples/node.md index 3019df3f8d16..23425e726437 100644 --- a/content/manuals/dhi/migration/examples/node.md +++ b/content/manuals/dhi/migration/examples/node.md @@ -24,7 +24,7 @@ Hardened Images. Each example includes five variations: > You must authenticate to `dhi.io` before you can pull Docker Hardened Images. > Use your Docker ID credentials (the same username and password you use for > Docker Hub). If you don't have a Docker account, [create -> one](../../../accounts/create-account.md) for free. +> one](../../../accounts/individual/create-account.md) for free. > > Run `docker login dhi.io` to authenticate. diff --git a/content/manuals/dhi/migration/examples/python.md b/content/manuals/dhi/migration/examples/python.md index 4ee4d327551c..bf11e9bc4bfd 100644 --- a/content/manuals/dhi/migration/examples/python.md +++ b/content/manuals/dhi/migration/examples/python.md @@ -24,7 +24,7 @@ Hardened Images. Each example includes five variations: > You must authenticate to `dhi.io` before you can pull Docker Hardened Images. > Use your Docker ID credentials (the same username and password you use for > Docker Hub). If you don't have a Docker account, [create -> one](../../../accounts/create-account.md) for free. +> one](../../../accounts/individual/create-account.md) for free. > > Run `docker login dhi.io` to authenticate. diff --git a/content/manuals/dhi/migration/migrate-from-doi.md b/content/manuals/dhi/migration/migrate-from-doi.md index 559967e003e2..5908e3a4c2c9 100644 --- a/content/manuals/dhi/migration/migrate-from-doi.md +++ b/content/manuals/dhi/migration/migrate-from-doi.md @@ -48,7 +48,7 @@ replaced by the new hardened image. > You must authenticate to `dhi.io` before you can pull Docker Hardened Images. > Use your Docker ID credentials (the same username and password you use for > Docker Hub). If you don't have a Docker account, [create -> one](../../accounts/create-account.md) for free. +> one](../../accounts/individual/create-account.md) for free. > > Run `docker login dhi.io` to authenticate. diff --git a/content/manuals/dhi/migration/migrate-from-ubuntu.md b/content/manuals/dhi/migration/migrate-from-ubuntu.md index b061e791df46..b28d8cecdc18 100644 --- a/content/manuals/dhi/migration/migrate-from-ubuntu.md +++ b/content/manuals/dhi/migration/migrate-from-ubuntu.md @@ -43,7 +43,7 @@ replaced by the new DHI Debian image. > You must authenticate to `dhi.io` before you can pull Docker Hardened Images. > Use your Docker ID credentials (the same username and password you use for > Docker Hub). If you don't have a Docker account, [create -> one](../../accounts/create-account.md) for free. +> one](../../accounts/individual/create-account.md) for free. > > Run `docker login dhi.io` to authenticate. diff --git a/content/manuals/dhi/migration/migrate-from-wolfi.md b/content/manuals/dhi/migration/migrate-from-wolfi.md index d291653e2b40..59de5e0e3f1f 100644 --- a/content/manuals/dhi/migration/migrate-from-wolfi.md +++ b/content/manuals/dhi/migration/migrate-from-wolfi.md @@ -34,7 +34,7 @@ replaced by the new hardened image. > You must authenticate to `dhi.io` before you can pull Docker Hardened Images. > Use your Docker ID credentials (the same username and password you use for > Docker Hub). If you don't have a Docker account, [create -> one](../../accounts/create-account.md) for free. +> one](../../accounts/individual/create-account.md) for free. > > Run `docker login dhi.io` to authenticate. diff --git a/content/manuals/docker-hub/_index.md b/content/manuals/docker-hub/_index.md index da692cc9dc8d..59b549bbae3b 100644 --- a/content/manuals/docker-hub/_index.md +++ b/content/manuals/docker-hub/_index.md @@ -27,7 +27,7 @@ grid: - title: Organizations description: Learn about organization administration. icon: building-storefront - link: /admin/ + link: /accounts/organization/ - title: Usage and limits description: Explore usage limits and how to better utilize Docker Hub. icon: chart-bar diff --git a/content/manuals/docker-hub/release-notes.md b/content/manuals/docker-hub/release-notes.md index da93573e506f..b39b1e466361 100644 --- a/content/manuals/docker-hub/release-notes.md +++ b/content/manuals/docker-hub/release-notes.md @@ -146,7 +146,7 @@ known issues for each Docker Hub release. ### Bug fixes and enhancements -- You can now [export a CSV file of members](../admin/organization/manage/members.md#export-members-csv-file) from organizations that you own. +- You can now [export a CSV file of members](../accounts/organization/manage/members.md#export-members-csv-file) from organizations that you own. ## 2022-07-22 @@ -239,7 +239,7 @@ Docker introduces the Advanced Image Management dashboard that enables you to vi Docker introduces Audit logs, a new feature that allows team owners to view a list of activities that occur at organization and repository levels. This feature begins tracking the activities from the release date, that is, **from 25 January 2021**. -For more information about this feature and for instructions on how to use it, see [Activity logs](../admin/activity-logs.md). +For more information about this feature and for instructions on how to use it, see [Activity logs](../accounts/organization/activity-logs.md). ## 2020-11-10 diff --git a/content/manuals/docker-hub/repos/manage/access.md b/content/manuals/docker-hub/repos/manage/access.md index 0124d2bc28fc..f684d3aa513c 100644 --- a/content/manuals/docker-hub/repos/manage/access.md +++ b/content/manuals/docker-hub/repos/manage/access.md @@ -105,7 +105,7 @@ access. You must create a team before you are able to configure repository permissions. For more details, see [Create and manage a -team](/manuals/admin/organization/manage/manage-a-team.md). +team](/manuals/accounts/organization/manage/manage-a-team.md). To configure team repository permissions: diff --git a/content/manuals/docker-hub/usage/pulls.md b/content/manuals/docker-hub/usage/pulls.md index 7bc3dbb0165a..880944894c29 100644 --- a/content/manuals/docker-hub/usage/pulls.md +++ b/content/manuals/docker-hub/usage/pulls.md @@ -41,7 +41,7 @@ A pull is defined as the following: ## Pull attribution Pulls from authenticated users can be attributed to either a personal or an -[organization namespace](/manuals/accounts/general-faqs.md#whats-an-organization-name-or-namespace). +[organization namespace](/manuals/faqs/general-faqs.md#whats-an-organization-name-or-namespace). Attribution is based on the following: @@ -55,7 +55,7 @@ Attribution is based on the following: - Single organization membership: - If the owner of the verified domain is a company and the user is part of only one organization within that - [company](../../admin/company/company-faqs.md), + [company](../../faqs/company-faqs.md), the pull is attributed to that specific organization. - If the user is part of only one organization, the pull is attributed to that specific organization. diff --git a/content/manuals/extensions/settings-feedback.md b/content/manuals/extensions/settings-feedback.md index fcc00f304ba1..cc7fb18f4c43 100644 --- a/content/manuals/extensions/settings-feedback.md +++ b/content/manuals/extensions/settings-feedback.md @@ -19,7 +19,7 @@ Docker Extensions is switched off by default. To change your settings: > [!NOTE] > -> If you are an [organization owner](/manuals/admin/organization/manage/manage-a-team.md#what-is-an-organization-owner), you can turn off extensions for your users. Open the `settings-store.json` file, and set `"extensionsEnabled"` to `false`. +> If you are an [organization owner](/manuals/accounts/organization/manage/manage-a-team.md#what-is-an-organization-owner), you can turn off extensions for your users. Open the `settings-store.json` file, and set `"extensionsEnabled"` to `false`. > The `settings-store.json` file is located at: > - `~/Library/Group Containers/group.com.docker/settings-store.json` on Mac > - `C:\Users\[USERNAME]\AppData\Roaming\Docker\settings-store.json` on Windows diff --git a/content/manuals/faqs/_index.md b/content/manuals/faqs/_index.md index 69343b7ce5c7..1726d205ee09 100644 --- a/content/manuals/faqs/_index.md +++ b/content/manuals/faqs/_index.md @@ -1,8 +1,8 @@ --- title: FAQs linkTitle: FAQs -description: Frequently asked questions about Docker security, authentication, provisioning, and containers. -keywords: security FAQs, SSO FAQs, container security, Docker security +description: Frequently asked questions about Docker accounts, organizations, companies, and security. +keywords: FAQ, FAQs, accounts, organizations, companies, Docker ID, Docker Home, security FAQs, SSO FAQs weight: 45 params: sidebar: @@ -10,6 +10,48 @@ params: aliases: - /platform/security/faqs/ - /faq/security/ +grid: + - title: Account FAQs + description: FAQs about Docker IDs, account creation, and organization names. + icon: question-mark-circle + link: /faqs/general-faqs/ + - title: Organization FAQs + description: FAQs about organization members, seats, and authentication. + icon: user-group + link: /faqs/organization-faqs/ + - title: Company FAQs + description: FAQs about companies, seats, and company owners. + icon: building-office-2 + link: /faqs/company-faqs/ + - title: General security FAQs + description: FAQs about Docker security, authentication, and organization management. + icon: lock-closed + link: /faqs/general/ + - title: Container security FAQs + description: FAQs about container security and isolation. + icon: lock-closed + link: /faqs/containers/ + - title: Network and VM FAQs + description: FAQs about Docker Desktop networking and virtualization security. + icon: globe-alt + link: /faqs/networking-and-vms/ + - title: SSO FAQs + description: FAQs about single sign-on, identity providers, and user management. + icon: lock-closed + link: /faqs/sso-faqs/ + - title: SSO domain FAQs + description: FAQs about domain verification and management for SSO. + icon: globe-alt + link: /faqs/domain-faqs/ + - title: SSO enforcement FAQs + description: FAQs about SSO enforcement and its effects on users. + icon: shield-check + link: /faqs/enforcement-faqs/ --- -Find answers to common questions about Docker security, authentication, provisioning, and related topics. +Answers to common questions about Docker accounts, organizations, companies, +security, authentication, and related topics. + +## Next steps + +{{< grid >}} diff --git a/content/manuals/admin/company/company-faqs.md b/content/manuals/faqs/company-faqs.md similarity index 84% rename from content/manuals/admin/company/company-faqs.md rename to content/manuals/faqs/company-faqs.md index c6f4f78d1652..e9d8e54d5eb3 100644 --- a/content/manuals/admin/company/company-faqs.md +++ b/content/manuals/faqs/company-faqs.md @@ -1,27 +1,29 @@ --- title: Company FAQs -linkTitle: FAQs +linkTitle: Companies weight: 30 description: Frequently asked questions about Docker companies, including subscriptions, seats, company owners, and permissions. keywords: Docker, Docker Hub, SSO FAQs, single sign-on, company, administration, company management tags: [FAQ] aliases: + - /admin/company/company-faqs/ - /docker-hub/company-faqs/ - /faq/admin/company-faqs/ - /admin/faqs/company-faqs/ + - /accounts/organization/company/company-faqs/ --- ### Some of my organizations don’t have a Docker Business subscription. Can I still use a parent company? Yes, but you can only add organizations with a Docker Business subscription -to a company. For more details, see [Add more organizations](/manuals/admin/company/manage.md#add-more-organizations). +to a company. For more details, see [Add more organizations](/manuals/accounts/organization/company/manage.md#add-more-organizations). ### What happens if one of my organizations downgrades from Docker Business, but I still need access as a company owner? To access and manage a nested organization, it must have a Docker Business subscription. If an organization downgrades from Docker Business, its owner must manage it outside of the company. For more details, see -[Add more organizations](/manuals/admin/company/manage.md#add-more-organizations). +[Add more organizations](/manuals/accounts/organization/company/manage.md#add-more-organizations). ### Do company owners occupy a subscription seat? @@ -34,7 +36,7 @@ Company owners don't occupy a seat unless one of the following is true: When you first create a company, your account is both a company owner and an organization owner, so it occupies a seat as long as you remain an organization owner. To free up that seat, -[assign another user as the organization owner](/manuals/admin/organization/manage/members.md#update-a-member-role) +[assign another user as the organization owner](/manuals/accounts/organization/manage/members.md#update-a-member-role) and remove yourself from the organization. You keep full administrative access as a company owner without using a subscription seat. diff --git a/content/manuals/accounts/general-faqs.md b/content/manuals/faqs/general-faqs.md similarity index 78% rename from content/manuals/accounts/general-faqs.md rename to content/manuals/faqs/general-faqs.md index 8e00863d7881..452f725fb4fd 100644 --- a/content/manuals/accounts/general-faqs.md +++ b/content/manuals/faqs/general-faqs.md @@ -1,7 +1,7 @@ --- title: Docker account FAQs -linkTitle: FAQs -weight: 40 +linkTitle: Accounts +weight: 10 description: FAQs about Docker IDs, account creation, and organization names keywords: docker ID, docker account FAQ, change docker ID, username taken, trademark, @@ -9,6 +9,8 @@ keywords: deactivate docker ID tags: [FAQ] aliases: + - /accounts/general-faqs/ + - /accounts/individual/general-faqs/ - /docker-hub/general-faqs/ - /docker-hub/onboarding-faqs/ - /faq/admin/general-faqs/ @@ -28,7 +30,7 @@ Your Docker ID must be between 4 and 30 characters long, and can only contain numbers and lowercase letters. You can't use any special characters or spaces. For more information, see -[Create a Docker account](/manuals/accounts/create-account.md). +[Create a Docker account](/manuals/accounts/individual/create-account.md). ## Can I change my Docker ID? @@ -53,10 +55,10 @@ the organization ID, is the unique identifier of a Docker organization. The organization name can't be the same as an existing Docker ID. For more information, see -[Docker organization overview](/manuals/admin/organization/_index.md). +[Organization accounts](/manuals/accounts/organization/_index.md). ## Next steps -- [Create a Docker account](/manuals/accounts/create-account.md) -- [Manage a Docker account](/manuals/accounts/manage-account.md) -- [Docker organization overview](/manuals/admin/organization/_index.md) +- [Create a Docker account](/manuals/accounts/individual/create-account.md) +- [Manage a Docker account](/manuals/accounts/individual/manage-account.md) +- [Organization accounts](/manuals/accounts/organization/_index.md) diff --git a/content/manuals/faqs/general.md b/content/manuals/faqs/general.md index bc4b024f72db..c167161d7c96 100644 --- a/content/manuals/faqs/general.md +++ b/content/manuals/faqs/general.md @@ -43,7 +43,7 @@ Docker activity logs are available for 90 days. You're responsible for exporting ## Can I export a list of users with their roles and privileges? -Yes, use the [Export Members](../admin/organization/manage/members.md#export-members-csv-file) feature to export a CSV file containing your organization's users with role and team information. +Yes, use the [Export Members](/manuals/accounts/organization/manage/members.md#export-members-csv-file) feature to export a CSV file containing your organization's users with role and team information. ## How does Docker Desktop handle authentication information? @@ -57,7 +57,7 @@ Docker Desktop uses the host operating system's secure key management to store a If SCIM isn't turned on, you must manually remove users from the organization. SCIM can automate user removal, but only for users added after SCIM is turned on. Users added before SCIM was turned on must be removed manually. -For more information, see [Manage organization members](/manuals/admin/organization/manage/members.md). +For more information, see [Manage organization members](/manuals/accounts/organization/manage/members.md). ## What metadata does Scout collect from container images? diff --git a/content/manuals/admin/organization/organization-faqs.md b/content/manuals/faqs/organization-faqs.md similarity index 86% rename from content/manuals/admin/organization/organization-faqs.md rename to content/manuals/faqs/organization-faqs.md index 7ea67a06184f..9b646f7bf14b 100644 --- a/content/manuals/admin/organization/organization-faqs.md +++ b/content/manuals/faqs/organization-faqs.md @@ -1,14 +1,16 @@ --- title: Organization FAQs -linkTitle: FAQs -weight: 60 +linkTitle: Organizations +weight: 20 description: Organization FAQs keywords: Docker, Docker Hub, SSO FAQs, single sign-on, organizations, administration, Docker Home, members, organization management, manage orgs tags: [FAQ] aliases: + - /admin/organization/organization-faqs/ - /docker-hub/organization-faqs/ - /faq/admin/organization-faqs/ - /admin/faqs/organization-faqs/ + - /accounts/organization/organization-faqs/ --- ### How can I see how many active users are in my organization? @@ -18,7 +20,7 @@ find out how many users have Docker Desktop installed. If your organization doesn't use this software, you can run an internal survey to find out who is using Docker Desktop. -For more information, see [Identify your Docker users and their Docker accounts](../../admin/organization/setup/onboard.md#step-one-identify-your-docker-users). +For more information, see [Identify your Docker users and their Docker accounts](/manuals/accounts/organization/setup/onboard.md#step-one-identify-your-docker-users). ### Do users need to authenticate with Docker before an owner can add them to an organization? @@ -43,14 +45,14 @@ convert a user account into an organization, it's not possible to revert it to a personal user account. For prerequisites and instructions, see -[Convert an account into an organization](setup/convert-account.md). +[Convert an account into an organization](/manuals/accounts/organization/setup/convert-account.md). ### Do organization invitees take up seats? Yes. A user invited to an organization will take up one of the provisioned seats, even if that user hasn’t accepted their invitation yet. -To manage invites, see [Manage organization members](/manuals/admin/organization/manage/members.md). +To manage invites, see [Manage organization members](/manuals/accounts/organization/manage/members.md). ### Do organization owners take a seat? diff --git a/content/manuals/faqs/sso-faqs.md b/content/manuals/faqs/sso-faqs.md index 030a535d7c69..84a1a668b39b 100644 --- a/content/manuals/faqs/sso-faqs.md +++ b/content/manuals/faqs/sso-faqs.md @@ -115,7 +115,7 @@ For detailed instructions, see [Configure single sign-on](/manuals/platform/secu ## Is Docker SSO fully synced with the IdP? -Docker SSO provides Just-in-Time (JIT) provisioning by default. Users are provisioned when they authenticate with SSO. If users leave the organization, administrators must manually [remove the user](/manuals/admin/organization/manage/members.md#remove-members-from-teams) from the organization. +Docker SSO provides Just-in-Time (JIT) provisioning by default. Users are provisioned when they authenticate with SSO. If users leave the organization, administrators must manually [remove the user](/manuals/accounts/organization/manage/members.md#remove-members-from-teams) from the organization. [SCIM](/manuals/platform/security/provisioning/scim/_index.md) provides full synchronization with users and groups. When using SCIM, the recommended configuration is to turn off JIT so all auto-provisioning is handled by SCIM. diff --git a/content/manuals/offload/configuration.md b/content/manuals/offload/configuration.md index f0275bebbde5..83bf541a121c 100644 --- a/content/manuals/offload/configuration.md +++ b/content/manuals/offload/configuration.md @@ -17,7 +17,7 @@ settings when allowed by their organization. For organization owners, you can manage Docker Offload settings for all users in your organization. For more details, see [Manage Docker -products](../admin/organization/manage/manage-products.md). To view usage for Docker +products](../accounts/organization/manage/manage-products.md). To view usage for Docker Offload, see [Docker Offload usage](/offload/usage/). ## Configure settings in Docker Desktop diff --git a/content/manuals/offload/quickstart.md b/content/manuals/offload/quickstart.md index 27b864a2e132..a35e8b30b2ca 100644 --- a/content/manuals/offload/quickstart.md +++ b/content/manuals/offload/quickstart.md @@ -19,7 +19,7 @@ This quickstart covers the steps developers need to get started with Docker Offl > > If you're an organization owner, to get started you must
contact sales and subscribe your > organization to use Docker Offload. After subscribing, see [Manage Docker -> products](../admin/organization/manage/manage-products.md) to learn how to manage +> products](../accounts/organization/manage/manage-products.md) to learn how to manage > access for the developers in your organization. diff --git a/content/manuals/platform-release-notes.md b/content/manuals/platform-release-notes.md index 68f2eb70c799..bcf9bcb876cd 100644 --- a/content/manuals/platform-release-notes.md +++ b/content/manuals/platform-release-notes.md @@ -86,7 +86,7 @@ This page provides details on new features, enhancements, known issues, and bug ### New -- Administrators can now view [organization Insights](/manuals/admin/insights.md). +- Administrators can now view [organization Insights](/manuals/accounts/organization/insights.md). ## 2024-07-17 diff --git a/content/manuals/platform/security/authentication/single-sign-on/troubleshoot-sso.md b/content/manuals/platform/security/authentication/single-sign-on/troubleshoot-sso.md index 22e091433e09..59e37dc105c4 100644 --- a/content/manuals/platform/security/authentication/single-sign-on/troubleshoot-sso.md +++ b/content/manuals/platform/security/authentication/single-sign-on/troubleshoot-sso.md @@ -105,7 +105,7 @@ to re-enable it: **Manually invite users** When JIT is disabled, users are not automatically added to your organization when they authenticate through SSO. -To manually invite users, see [Invite members](/manuals/admin/organization/manage/members.md#invite-members). +To manually invite users, see [Invite members](/manuals/accounts/organization/manage/members.md#invite-members). **Configure SCIM provisioning** @@ -162,11 +162,11 @@ This error occurs when the organization has no available seats for the user when **Add more seats to the organization** -Purchase additional Docker Business subscription seats. For details, see [Manage subscription seats](/manuals/admin/organization/manage/manage-seats.md). +Purchase additional Docker Business subscription seats. For details, see [Manage subscription seats](/manuals/accounts/organization/manage/manage-seats.md). **Remove users or pending invitations** -Review your organization members and pending invitations. Remove inactive users or pending invitations to free up seats. For more details, see [Manage organization members](/manuals/admin/organization/manage/members.md). +Review your organization members and pending invitations. Remove inactive users or pending invitations to free up seats. For more details, see [Manage organization members](/manuals/accounts/organization/manage/members.md). ## Domain is not verified for SSO connection diff --git a/content/manuals/platform/security/provisioning/auto-provisioning.md b/content/manuals/platform/security/provisioning/auto-provisioning.md index f0de99448de3..22905d6d6fa2 100644 --- a/content/manuals/platform/security/provisioning/auto-provisioning.md +++ b/content/manuals/platform/security/provisioning/auto-provisioning.md @@ -20,7 +20,7 @@ When auto-provisioning is enabled for a verified domain: - Auto-provisioning only adds existing Docker users to your organization, it doesn't create new accounts. - Users experience no changes to their sign-in process. - Company and organization owners receive email notifications when new users are added. -- You may need to [manage seats](/manuals/admin/organization/manage/manage-seats.md) to accommodate new users. +- You may need to [manage seats](/manuals/accounts/organization/manage/manage-seats.md) to accommodate new users. ### Enable auto-provisioning diff --git a/content/manuals/platform/security/provisioning/domain-management.md b/content/manuals/platform/security/provisioning/domain-management.md index 55679bea5ffd..5e0f764fd7fc 100644 --- a/content/manuals/platform/security/provisioning/domain-management.md +++ b/content/manuals/platform/security/provisioning/domain-management.md @@ -112,7 +112,7 @@ The CSV file contains the following columns: You can bulk invite uncaptured users to your organization using the exported CSV file. For more information on bulk inviting users, see -[Manage organization members](/manuals/admin/organization/manage/members.md). +[Manage organization members](/manuals/accounts/organization/manage/members.md). ## Auto-provisioning diff --git a/content/manuals/platform/security/provisioning/scim/_index.md b/content/manuals/platform/security/provisioning/scim/_index.md index 38841d4f8f8f..4cd6f5769986 100644 --- a/content/manuals/platform/security/provisioning/scim/_index.md +++ b/content/manuals/platform/security/provisioning/scim/_index.md @@ -55,7 +55,7 @@ SCIM automates: > > To remove those users, delete them manually from your Docker organization. > For more information, see -> [Manage organization members](/manuals/admin/organization/manage/members.md). +> [Manage organization members](/manuals/accounts/organization/manage/members.md). ## Next steps diff --git a/content/manuals/platform/security/roles-and-permissions/core-roles.md b/content/manuals/platform/security/roles-and-permissions/core-roles.md index a6dabb8ceda9..62125d7e6282 100644 --- a/content/manuals/platform/security/roles-and-permissions/core-roles.md +++ b/content/manuals/platform/security/roles-and-permissions/core-roles.md @@ -35,7 +35,7 @@ Docker organizations have three core roles: A company owner has the same organization-management permissions as an organization owner. Content and registry permissions, such as repository pull and push, don't apply to company owners. For more information, see -[Company overview](/manuals/admin/company/_index.md). +[Company overview](/manuals/accounts/organization/company/_index.md). ## Permissions reference @@ -131,7 +131,7 @@ _\* If not part of a company_ - [Custom roles](/manuals/platform/security/roles-and-permissions/custom-roles/_index.md): Create tailored permission sets on a Docker Business plan -- [Manage organization members](/manuals/admin/organization/manage/members.md): +- [Manage organization members](/manuals/accounts/organization/manage/members.md): Invite users and assign roles -- [Company overview](/manuals/admin/company/_index.md): Understand company +- [Company overview](/manuals/accounts/organization/company/_index.md): Understand company owner permissions versus organization owner permissions diff --git a/content/manuals/platform/security/roles-and-permissions/custom-roles/manage.md b/content/manuals/platform/security/roles-and-permissions/custom-roles/manage.md index 1f1844c259d2..c60fd708792b 100644 --- a/content/manuals/platform/security/roles-and-permissions/custom-roles/manage.md +++ b/content/manuals/platform/security/roles-and-permissions/custom-roles/manage.md @@ -160,5 +160,5 @@ To see which users and teams are assigned to roles: permissions you can grant to a custom role - [Core roles and permissions](/manuals/platform/security/roles-and-permissions/core-roles.md): Compare built-in Member, Editor, and Owner permissions -- [Manage organization members](/manuals/admin/organization/manage/members.md): +- [Manage organization members](/manuals/accounts/organization/manage/members.md): Invite and manage users in your organization diff --git a/content/manuals/subscription/plans/ai-governance.md b/content/manuals/subscription/plans/ai-governance.md index 486e9f12a1be..986b6fc2e2d4 100644 --- a/content/manuals/subscription/plans/ai-governance.md +++ b/content/manuals/subscription/plans/ai-governance.md @@ -22,7 +22,7 @@ aliases: AI Governance lets organization owners enforce [organization policies](/manuals/ai/sandboxes/governance/access-controls/organization.md) for license-holding members. Organization policies override a license-holding member's local policies. -You can [assign AI Governance licenses](/manuals/admin/organization/manage/manage-licenses.md) to any organization member, even if they don't occupy a Docker Team or Docker Business seat. For best practice, review available licenses as you add new members since members without an AI Governance license can still use Docker AI products. +You can [assign AI Governance licenses](/manuals/accounts/organization/manage/manage-licenses.md) to any organization member, even if they don't occupy a Docker Team or Docker Business seat. For best practice, review available licenses as you add new members since members without an AI Governance license can still use Docker AI products. ## Billing cycle diff --git a/content/manuals/subscription/plans/docker.md b/content/manuals/subscription/plans/docker.md index bb72f83445c6..08c6b7bd4dab 100644 --- a/content/manuals/subscription/plans/docker.md +++ b/content/manuals/subscription/plans/docker.md @@ -36,7 +36,7 @@ Docker Personal and Docker Pro are Docker plans for individual account types whi > [!TIP] > If you're upgrading from a Personal plan to a Team plan > and want to keep your username, -> [convert your user account into an organization](/manuals/admin/organization/setup/convert-account.md). +> [convert your user account into an organization](/manuals/accounts/organization/setup/convert-account.md). ## Billing cycle @@ -58,11 +58,11 @@ For Docker Team and Docker Business, you can purchase more seats for new members 1. Verify your billing details, continue to payment, and complete checkout. To learn how to manage seats from Docker Home, see -[Manage seats](/manuals/admin/organization/manage/manage-seats.md). +[Manage seats](/manuals/accounts/organization/manage/manage-seats.md). ### Docker Offload licenses -[Docker Offload](/manuals/offload/_index.md) licenses are available for Docker Team and Docker Business plans. Once assigned to your account, organization owners can [manage license assignments](/manuals/admin/organization/manage/manage-licenses.md) in Docker Home. +[Docker Offload](/manuals/offload/_index.md) licenses are available for Docker Team and Docker Business plans. Once assigned to your account, organization owners can [manage license assignments](/manuals/accounts/organization/manage/manage-licenses.md) in Docker Home. To add Docker Offload licenses, you must contact sales. From 33f6d55908a3d1bcb21c0ccb4baa6d7aa11ae775 Mon Sep 17 00:00:00 2001 From: Alexa Date: Mon, 31 Aug 2026 12:49:25 -0500 Subject: [PATCH 03/19] docs: use /security/ as the live Security URL to match other Platform sections Co-authored-by: Cursor --- content/guides/admin-set-up.md | 16 +++++++------- content/guides/admin-user-management.md | 10 ++++----- content/guides/genai-claude-code-mcp.md | 2 +- content/guides/gha.md | 2 +- content/manuals/_index.md | 2 +- .../accounts/individual/create-account.md | 2 +- .../accounts/individual/manage-account.md | 6 +++--- .../manuals/accounts/organization/_index.md | 2 +- .../accounts/organization/company/_index.md | 4 ++-- .../manuals/accounts/organization/insights.md | 8 +++---- .../accounts/organization/manage/_index.md | 4 ++-- .../organization/manage/deactivate-account.md | 2 +- .../organization/manage/general-settings.md | 6 +++--- .../organization/manage/manage-a-team.md | 4 ++-- .../organization/manage/manage-licenses.md | 6 +++--- .../organization/manage/manage-products.md | 4 ++-- .../accounts/organization/manage/members.md | 8 +++---- .../accounts/organization/setup/_index.md | 4 ++-- .../organization/setup/convert-account.md | 2 +- .../accounts/organization/setup/onboard.md | 20 +++++++++--------- .../access-controls/organization.md | 6 +++--- .../ai/sandboxes/governance/audit/_index.md | 4 ++-- .../sandboxes/governance/audit/configure.md | 4 ++-- .../sign-in-enforcement.md | 2 +- content/manuals/build-cloud/_index.md | 2 +- content/manuals/build-cloud/ci.md | 8 +++---- content/manuals/desktop/release-notes.md | 16 +++++++------- .../desktop/setup/install/mac-install.md | 2 +- .../desktop/setup/install/windows-install.md | 2 +- content/manuals/desktop/setup/sign-in.md | 2 +- content/manuals/dhi/how-to/customize.md | 4 ++-- content/manuals/dhi/how-to/helm.md | 4 ++-- content/manuals/dhi/how-to/mirror.md | 16 +++++++------- content/manuals/dhi/how-to/policies.md | 2 +- content/manuals/dhi/how-to/use.md | 12 +++++------ content/manuals/dhi/how-to/verify.md | 4 ++-- content/manuals/dhi/tools/api.md | 2 +- content/manuals/dhi/tools/mcp.md | 2 +- content/manuals/docker-hub/release-notes.md | 6 +++--- content/manuals/docker-hub/repos/create.md | 2 +- .../manuals/docker-hub/repos/manage/access.md | 6 +++--- .../docker-hub/repos/manage/builds/migrate.md | 4 ++-- .../manuals/docker-hub/repos/manage/export.md | 2 +- .../pkg-install-and-configure.md | 2 +- .../enterprise-deployment/use-intune.md | 2 +- .../enterprise-deployment/use-jamf-pro.md | 2 +- .../hardened-desktop/air-gapped-containers.md | 2 +- .../enable-eci.md | 2 +- .../image-access-management.md | 4 ++-- .../registry-access-management.md | 6 +++--- .../settings-management/_index.md | 6 +++--- .../compliance-reporting.md | 4 ++-- .../configure-admin-console.md | 4 ++-- .../configure-json-file.md | 2 +- .../manuals/extensions/private-marketplace.md | 2 +- content/manuals/faqs/company-faqs.md | 2 +- content/manuals/faqs/enforcement-faqs.md | 8 +++---- content/manuals/faqs/general.md | 2 +- content/manuals/faqs/organization-faqs.md | 2 +- content/manuals/faqs/sso-faqs.md | 14 ++++++------ content/manuals/platform-release-notes.md | 6 +++--- content/manuals/retired.md | 2 +- .../manuals/scout/explore/metrics-exporter.md | 8 +++---- .../scout/integrations/registry/acr.md | 2 +- .../integrations/registry/artifactory.md | 2 +- .../scout/integrations/registry/ecr.md | 2 +- .../manuals/{platform => }/security/_index.md | 5 +++-- .../security/access-tokens/_index.md | 2 ++ .../organization-access-tokens.md | 3 ++- .../access-tokens/personal-access-tokens.md | 5 +++-- .../security/authentication/2fa/_index.md | 1 + .../authentication/2fa/recover-hub-account.md | 1 + .../security/authentication/_index.md | 2 ++ .../authentication/enforce-sign-in/_index.md | 7 +++--- .../authentication/enforce-sign-in/methods.md | 1 + .../authentication/oidc-connections/_index.md | 7 +++--- .../oidc-connections/create-manage.md | 6 ++++-- .../oidc-connections/rulesets-claims.md | 6 ++++-- .../authentication/single-sign-on/_index.md | 5 +++-- .../authentication/single-sign-on/connect.md | 17 ++++++++------- .../single-sign-on/images/SSO.png | Bin .../authentication/single-sign-on/manage.md | 3 ++- .../single-sign-on/troubleshoot-sso.md | 5 +++-- .../security/images/jit-disabled-flow.svg | 0 .../security/images/jit-enabled-flow.svg | 0 .../security/provisioning/_index.md | 1 + .../provisioning/auto-provisioning.md | 6 ++++-- .../provisioning/domain-management.md | 9 ++++---- .../security/provisioning/just-in-time.md | 7 +++--- .../security/provisioning/scim/_index.md | 7 +++--- .../provisioning/scim/group-mapping.md | 5 +++-- .../provisioning/scim/migrate-scim.md | 10 +++++---- .../provisioning/scim/provision-scim.md | 17 ++++++++------- .../provisioning/troubleshoot-provisioning.md | 1 + .../security/roles-and-permissions/_index.md | 7 +++--- .../roles-and-permissions/core-roles.md | 8 ++++--- .../custom-roles/_index.md | 8 ++++--- .../custom-roles/manage.md | 4 +++- .../custom-roles/permissions-reference.md | 4 +++- .../security/security-announcements.md | 5 +++-- .../manuals/unassociated-machines/_index.md | 8 +++---- content/reference/api/hub/latest.yaml | 2 +- data/redirects.yml | 2 +- 103 files changed, 272 insertions(+), 231 deletions(-) rename content/manuals/{platform => }/security/_index.md (95%) rename content/manuals/{platform => }/security/access-tokens/_index.md (86%) rename content/manuals/{platform => }/security/access-tokens/organization-access-tokens.md (98%) rename content/manuals/{platform => }/security/access-tokens/personal-access-tokens.md (94%) rename content/manuals/{platform => }/security/authentication/2fa/_index.md (98%) rename content/manuals/{platform => }/security/authentication/2fa/recover-hub-account.md (96%) rename content/manuals/{platform => }/security/authentication/_index.md (86%) rename content/manuals/{platform => }/security/authentication/enforce-sign-in/_index.md (92%) rename content/manuals/{platform => }/security/authentication/enforce-sign-in/methods.md (99%) rename content/manuals/{platform => }/security/authentication/oidc-connections/_index.md (84%) rename content/manuals/{platform => }/security/authentication/oidc-connections/create-manage.md (91%) rename content/manuals/{platform => }/security/authentication/oidc-connections/rulesets-claims.md (92%) rename content/manuals/{platform => }/security/authentication/single-sign-on/_index.md (88%) rename content/manuals/{platform => }/security/authentication/single-sign-on/connect.md (92%) rename content/manuals/{platform => }/security/authentication/single-sign-on/images/SSO.png (100%) rename content/manuals/{platform => }/security/authentication/single-sign-on/manage.md (98%) rename content/manuals/{platform => }/security/authentication/single-sign-on/troubleshoot-sso.md (97%) rename content/manuals/{platform => }/security/images/jit-disabled-flow.svg (100%) rename content/manuals/{platform => }/security/images/jit-enabled-flow.svg (100%) rename content/manuals/{platform => }/security/provisioning/_index.md (99%) rename content/manuals/{platform => }/security/provisioning/auto-provisioning.md (89%) rename content/manuals/{platform => }/security/provisioning/domain-management.md (92%) rename content/manuals/{platform => }/security/provisioning/just-in-time.md (92%) rename content/manuals/{platform => }/security/provisioning/scim/_index.md (82%) rename content/manuals/{platform => }/security/provisioning/scim/group-mapping.md (97%) rename content/manuals/{platform => }/security/provisioning/scim/migrate-scim.md (93%) rename content/manuals/{platform => }/security/provisioning/scim/provision-scim.md (94%) rename content/manuals/{platform => }/security/provisioning/troubleshoot-provisioning.md (97%) rename content/manuals/{platform => }/security/roles-and-permissions/_index.md (90%) rename content/manuals/{platform => }/security/roles-and-permissions/core-roles.md (95%) rename content/manuals/{platform => }/security/roles-and-permissions/custom-roles/_index.md (85%) rename content/manuals/{platform => }/security/roles-and-permissions/custom-roles/manage.md (96%) rename content/manuals/{platform => }/security/roles-and-permissions/custom-roles/permissions-reference.md (96%) rename content/manuals/{platform => }/security/security-announcements.md (97%) diff --git a/content/guides/admin-set-up.md b/content/guides/admin-set-up.md index 944e69161d3d..80e81ceab2ab 100644 --- a/content/guides/admin-set-up.md +++ b/content/guides/admin-set-up.md @@ -56,11 +56,11 @@ This guide covers the following Docker features: repositories. Your organization was created with your subscription and is managed by one or more owners. Users signed into the organization are assigned seats based on the purchased subscription. -- [Enforce sign-in](/manuals/platform/security/authentication/enforce-sign-in/_index.md): +- [Enforce sign-in](/manuals/security/authentication/enforce-sign-in/_index.md): By default, Docker Desktop doesn't require sign-in. You can configure settings to enforce this and ensure your developers sign in to your Docker organization. -- [SSO](/manuals/platform/security/authentication/single-sign-on/_index.md): Without SSO, +- [SSO](/manuals/security/authentication/single-sign-on/_index.md): Without SSO, user management in a Docker organization is manual. Setting up an SSO connection between your identity provider and Docker ensures compliance with your security policy and automates user provisioning. Adding @@ -154,7 +154,7 @@ configuration: Review these areas together: - Security features and - [enforcing sign-in](/manuals/platform/security/authentication/enforce-sign-in/_index.md) + [enforcing sign-in](/manuals/security/authentication/enforce-sign-in/_index.md) for Docker Desktop users - Additional Docker products included in your subscriptions @@ -176,7 +176,7 @@ security configurations as outlined in the previous section, configure Settings [`admin-settings.json` file](/manuals/enterprise/hardened-desktop/settings-management/configure-json-file.md). Once the file is ready, collaborate with your MDM team to deploy your chosen -settings, along with your chosen method for [enforcing sign-in](/manuals/platform/security/authentication/enforce-sign-in/_index.md). +settings, along with your chosen method for [enforcing sign-in](/manuals/security/authentication/enforce-sign-in/_index.md). > [!IMPORTANT] > @@ -196,9 +196,9 @@ organizations. Single sign-on (SSO) lets developers authenticate using their identity providers (IdPs) to access Docker. SSO is available for a whole company and all associated organizations, or an individual organization that has a Docker Business subscription. For more information, see the -[documentation](/manuals/platform/security/authentication/single-sign-on/_index.md). +[documentation](/manuals/security/authentication/single-sign-on/_index.md). -You can also enable [SCIM](/manuals/platform/security/provisioning/scim/_index.md) +You can also enable [SCIM](/manuals/security/provisioning/scim/_index.md) for further automation of provisioning and deprovisioning of users. #### Set up Docker product entitlements included in the subscription @@ -252,7 +252,7 @@ SSO and SCIM setup. > [!IMPORTANT] > > Some users may need CLI based logins to Docker Hub, and for this they will -> need a [personal access token (PAT)](/manuals/platform/security/access-tokens/personal-access-tokens.md). +> need a [personal access token (PAT)](/manuals/security/access-tokens/personal-access-tokens.md). ### Test Registry Access Management and Image Access Management @@ -312,7 +312,7 @@ that matches your verified domain must sign in using your SSO connection. Make sure the Identity provider groups associated with your SSO connection cover all the developer groups that you want to have access to the Docker subscription. -For instructions on how to enforce SSO, see [Enforce SSO](/manuals/platform/security/authentication/single-sign-on/connect.md). +For instructions on how to enforce SSO, see [Enforce SSO](/manuals/security/authentication/single-sign-on/connect.md). ### Deploy configuration settings and enforce sign-in to users diff --git a/content/guides/admin-user-management.md b/content/guides/admin-user-management.md index 5975cc2becf7..9be9aab1432b 100644 --- a/content/guides/admin-user-management.md +++ b/content/guides/admin-user-management.md @@ -58,7 +58,7 @@ Docker's predefined roles offer flexibility for various organizational needs. As - Editor: Partial administrative access to the organization. Editors can create, edit, and delete repositories. They can also edit an existing team's access permissions. - Owner: Full organization administrative access. Owners can manage organization repositories, teams, members, settings, and billing. -For more information, see [Roles and permissions](/manuals/platform/security/roles-and-permissions.md). +For more information, see [Roles and permissions](/manuals/security/roles-and-permissions.md). #### Enhance with teams @@ -89,7 +89,7 @@ This page guides you through onboarding owners and members, and using tools like When you create a Docker organization, you automatically become its sole owner. While optional, adding additional owners can significantly ease the process of onboarding and managing your organization by distributing administrative responsibilities. It also ensures continuity and prevents blockers if the primary owner is unavailable. -For detailed information on owners, see [Roles and permissions](/manuals/platform/security/roles-and-permissions.md). +For detailed information on owners, see [Roles and permissions](/manuals/security/roles-and-permissions.md). ### Invite members and assign roles @@ -119,11 +119,11 @@ SSO: - Reduces password-related vulnerabilities. - Simplifies onboarding as it works seamlessly with SCIM and group mapping for automated provisioning. -For more information, see the [SSO documentation](/manuals/platform/security/authentication/single-sign-on/_index.md). +For more information, see the [SSO documentation](/manuals/security/authentication/single-sign-on/_index.md). #### Automate onboarding with SCIM and JIT provisioning -Streamline user provisioning and role management with [SCIM](/manuals/platform/security/provisioning/scim/_index.md) and [Just-in-Time (JIT) provisioning](/manuals/platform/security/provisioning/just-in-time.md). +Streamline user provisioning and role management with [SCIM](/manuals/security/provisioning/scim/_index.md) and [Just-in-Time (JIT) provisioning](/manuals/security/provisioning/just-in-time.md). With SCIM you can: @@ -145,7 +145,7 @@ It also: - Ensures consistent access control policies. - Help you scale permissions as teams grow or change. -For more information on how it works, see [Group mapping](/manuals/platform/security/provisioning/scim/group-mapping.md). +For more information on how it works, see [Group mapping](/manuals/security/provisioning/scim/group-mapping.md). ## Monitoring and insights diff --git a/content/guides/genai-claude-code-mcp.md b/content/guides/genai-claude-code-mcp.md index 7eecad93e79f..9e4fcb449737 100644 --- a/content/guides/genai-claude-code-mcp.md +++ b/content/guides/genai-claude-code-mcp.md @@ -71,7 +71,7 @@ Make sure you have: 1. Select the **Docker Hub**MCP server 1. Add the MCP server, then open the **Configuration** tab 1. Enter your Docker Hub username -1. [Create a read-only personal access token](/platform/security/access-tokens/personal-access-tokens/#create-a-personal-access-token) and enter your access token under **Secrets** +1. [Create a read-only personal access token](/security/access-tokens/personal-access-tokens/#create-a-personal-access-token) and enter your access token under **Secrets** 1. Save the configuration ![Docker Hub](images/genai-claude-code-mcp-catalog-docker-hub.avif "Docker Hub") diff --git a/content/guides/gha.md b/content/guides/gha.md index 197730cbe556..085cbf0565bf 100644 --- a/content/guides/gha.md +++ b/content/guides/gha.md @@ -52,7 +52,7 @@ that, you must authenticate with your Docker credentials (username and access token) as part of the GitHub Actions workflow. For instructions on how to create a Docker access token, see -[Create and manage access tokens](/manuals/platform/security/access-tokens/personal-access-tokens.md). +[Create and manage access tokens](/manuals/security/access-tokens/personal-access-tokens.md). Once you have your Docker credentials ready, add the credentials to your GitHub repository so you can use them in GitHub Actions: diff --git a/content/manuals/_index.md b/content/manuals/_index.md index 5e07f5f99230..bcf629528ea4 100644 --- a/content/manuals/_index.md +++ b/content/manuals/_index.md @@ -90,7 +90,7 @@ params: - title: Security description: Security guardrails for both administrators and developers. icon: lock-closed - link: /platform/security/ + link: /security/ - title: FAQs description: Frequently asked questions about Docker accounts, organizations, companies, and security. icon: question-mark-circle diff --git a/content/manuals/accounts/individual/create-account.md b/content/manuals/accounts/individual/create-account.md index 9501ed3e520b..6147e8d9d162 100644 --- a/content/manuals/accounts/individual/create-account.md +++ b/content/manuals/accounts/individual/create-account.md @@ -87,4 +87,4 @@ basis: ## Next steps - [Manage a Docker account](/manuals/accounts/individual/manage-account.md) -- [Enable two-factor authentication](/manuals/platform/security/authentication/2fa/_index.md) +- [Enable two-factor authentication](/manuals/security/authentication/2fa/_index.md) diff --git a/content/manuals/accounts/individual/manage-account.md b/content/manuals/accounts/individual/manage-account.md index 1e8b5c8dbc67..616abe7bfac1 100644 --- a/content/manuals/accounts/individual/manage-account.md +++ b/content/manuals/accounts/individual/manage-account.md @@ -79,7 +79,7 @@ To update your two-factor authentication (2FA) settings: 1. Select **2FA**. For more information, see -[Enable two-factor authentication](/manuals/platform/security/authentication/2fa/_index.md). +[Enable two-factor authentication](/manuals/security/authentication/2fa/_index.md). ## Manage personal access tokens @@ -90,7 +90,7 @@ To manage personal access tokens: 1. Select **Personal access tokens**. For more information, see -[Create and manage access tokens](/manuals/platform/security/access-tokens/personal-access-tokens.md). +[Create and manage access tokens](/manuals/security/access-tokens/personal-access-tokens.md). ## Manage connected accounts @@ -129,4 +129,4 @@ For information on deactivating your account, see - [Docker individual accounts overview](/manuals/accounts/individual/_index.md) - [Create a Docker account](/manuals/accounts/individual/create-account.md) -- [Enable two-factor authentication](/manuals/platform/security/authentication/2fa/_index.md) +- [Enable two-factor authentication](/manuals/security/authentication/2fa/_index.md) diff --git a/content/manuals/accounts/organization/_index.md b/content/manuals/accounts/organization/_index.md index 0b169def8fbd..5749f24aa32b 100644 --- a/content/manuals/accounts/organization/_index.md +++ b/content/manuals/accounts/organization/_index.md @@ -23,7 +23,7 @@ grid: - title: Security description: Explore security features for administrators. icon: shield-check - link: /platform/security/ + link: /security/ aliases: - /admin/ - /docker-hub/admin-overview diff --git a/content/manuals/accounts/organization/company/_index.md b/content/manuals/accounts/organization/company/_index.md index 41e4b7082c8e..3579755f68c8 100644 --- a/content/manuals/accounts/organization/company/_index.md +++ b/content/manuals/accounts/organization/company/_index.md @@ -16,11 +16,11 @@ grid: - title: Configure SSO and SCIM description: Set up single sign-on and SCIM provisioning for your company. icon: key - link: /platform/security/authentication/single-sign-on/ + link: /security/authentication/single-sign-on/ - title: Domain management description: Add and verify your company's domains. icon: check-badge - link: /platform/security/provisioning/domain-management/ + link: /security/provisioning/domain-management/ - title: FAQs description: Explore frequently asked questions about companies. link: /faqs/company-faqs/ diff --git a/content/manuals/accounts/organization/insights.md b/content/manuals/accounts/organization/insights.md index bd42b48d8357..61f3eacf3230 100644 --- a/content/manuals/accounts/organization/insights.md +++ b/content/manuals/accounts/organization/insights.md @@ -30,7 +30,7 @@ Key benefits include: To use Insights, you must meet the following requirements: - [Docker Business subscription](https://www.docker.com/pricing?ref=Docs&refAction=DocsAdminInsights) -- Administrators must [enforce sign-in](/manuals/platform/security/authentication/enforce-sign-in/_index.md) +- Administrators must [enforce sign-in](/manuals/security/authentication/enforce-sign-in/_index.md) for users - Your Account Executive must turn on Insights for your organization @@ -61,7 +61,7 @@ The chart contains the following data: | Data | Description | | :--------------------------- | :---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| Active user | The number of users who have actively used Docker Desktop and either signed in with a Docker account that has a license in your organization or signed in to a Docker account with an email address from a domain associated with your organization.

Users who don’t sign in to an account associated with your organization are not represented in the data. To ensure users sign in with an account associated with your organization, you can [enforce sign-in](/manuals/platform/security/authentication/enforce-sign-in/_index.md). | +| Active user | The number of users who have actively used Docker Desktop and either signed in with a Docker account that has a license in your organization or signed in to a Docker account with an email address from a domain associated with your organization.

Users who don’t sign in to an account associated with your organization are not represented in the data. To ensure users sign in with an account associated with your organization, you can [enforce sign-in](/manuals/security/authentication/enforce-sign-in/_index.md). | | Total organization members | The number of users who have used Docker Desktop, regardless of their Insights activity. | | Users opted out of analytics | The number of users who are members of your organization that have opted out of sending analytics.

When users opt out of sending analytics, you won't see any of their data in Insights. To ensure that the data includes all users, you can use [Settings Management](/manuals/enterprise/hardened-desktop/settings-management/_index.md) to set `analyticsEnabled` for all your users. | | Active users (graph) | The view over time for total active users. | @@ -165,7 +165,7 @@ A Docker Desktop user export file contains the following data points: - Username: User's Docker ID - Email: User's email address associated with their Docker ID - Type: User type -- Role: User [role](/manuals/platform/security/roles-and-permissions.md) +- Role: User [role](/manuals/security/roles-and-permissions.md) - Teams: Team(s) within your organization the user is a member of - Date Joined: The date the user joined your organization @@ -209,4 +209,4 @@ solutions to resolve common problems: Users who don’t sign in to an account associated with your organization are not represented in the data. To ensure users sign in with an account associated with your organization, you can [enforce - sign-in](/manuals/platform/security/authentication/enforce-sign-in/_index.md). + sign-in](/manuals/security/authentication/enforce-sign-in/_index.md). diff --git a/content/manuals/accounts/organization/manage/_index.md b/content/manuals/accounts/organization/manage/_index.md index 86f5fcd499a4..507c5117a293 100644 --- a/content/manuals/accounts/organization/manage/_index.md +++ b/content/manuals/accounts/organization/manage/_index.md @@ -24,7 +24,7 @@ grid: - title: Security description: Configure single sign-on, provisioning, and access management. icon: shield-check - link: /platform/security/ + link: /security/ - title: Billing description: Manage payment methods and view billing history. icon: credit-card @@ -42,7 +42,7 @@ organization information, and deactivate the organization. You manage your organization from [Docker Home](https://app.docker.com) and must be assigned the -[organization owner role](/manuals/platform/security/roles-and-permissions/_index.md). +[organization owner role](/manuals/security/roles-and-permissions/_index.md). ## Seats and licenses diff --git a/content/manuals/accounts/organization/manage/deactivate-account.md b/content/manuals/accounts/organization/manage/deactivate-account.md index be62036d6c21..2ff11a772b8e 100644 --- a/content/manuals/accounts/organization/manage/deactivate-account.md +++ b/content/manuals/accounts/organization/manage/deactivate-account.md @@ -39,7 +39,7 @@ organization: - Unlink your [GitHub and Bitbucket accounts](/manuals/docker-hub/repos/manage/builds/link-source.md#unlink-a-github-user-account). - For Business organizations, [remove your SSO - connection](/manuals/platform/security/authentication/single-sign-on/manage.md#delete-a-connection). + connection](/manuals/security/authentication/single-sign-on/manage.md#delete-a-connection). ## Deactivate diff --git a/content/manuals/accounts/organization/manage/general-settings.md b/content/manuals/accounts/organization/manage/general-settings.md index 88ddd6fd81a1..0ffc3d317e65 100644 --- a/content/manuals/accounts/organization/manage/general-settings.md +++ b/content/manuals/accounts/organization/manage/general-settings.md @@ -35,7 +35,7 @@ To edit this information: After configuring your organization information, you can: -- [Configure single sign-on (SSO)](/manuals/platform/security/authentication/single-sign-on/connect.md) -- [Set up SCIM provisioning](/manuals/platform/security/provisioning/scim/_index.md) -- [Manage domains](/manuals/platform/security/provisioning/domain-management.md) +- [Configure single sign-on (SSO)](/manuals/security/authentication/single-sign-on/connect.md) +- [Set up SCIM provisioning](/manuals/security/provisioning/scim/_index.md) +- [Manage domains](/manuals/security/provisioning/domain-management.md) - [Create a company](/manuals/accounts/organization/company/new-company.md) diff --git a/content/manuals/accounts/organization/manage/manage-a-team.md b/content/manuals/accounts/organization/manage/manage-a-team.md index 24ed758dc6a5..b2ee5b57327d 100644 --- a/content/manuals/accounts/organization/manage/manage-a-team.md +++ b/content/manuals/accounts/organization/manage/manage-a-team.md @@ -35,7 +35,7 @@ An organization owner is an administrator who has the following permissions: organization settings - Specify [permissions](#permissions-reference) for each team in the organization -- Enable [SSO](/manuals/platform/security/authentication/single-sign-on/_index.md) for the +- Enable [SSO](/manuals/security/authentication/single-sign-on/_index.md) for the organization When SSO is enabled for your organization, the organization owner can @@ -47,7 +47,7 @@ Organization owners can add others with the owner role to help them manage users, teams, and repositories in the organization. For more information on roles, see -[Roles and permissions](/manuals/platform/security/roles-and-permissions.md). +[Roles and permissions](/manuals/security/roles-and-permissions.md). ## Create a team diff --git a/content/manuals/accounts/organization/manage/manage-licenses.md b/content/manuals/accounts/organization/manage/manage-licenses.md index c4a99572e96f..b0e6be325671 100644 --- a/content/manuals/accounts/organization/manage/manage-licenses.md +++ b/content/manuals/accounts/organization/manage/manage-licenses.md @@ -52,7 +52,7 @@ a member: 1. Select **Emails or usernames**. 1. Enter the email addresses or Docker IDs of the people you want to invite, then assign their - [role](/manuals/platform/security/roles-and-permissions/_index.md). + [role](/manuals/security/roles-and-permissions/_index.md). 1. Under **Licenses (optional)**, select one or more licenses that are available to your organization. 1. Select **Invite** to send the invite. @@ -90,8 +90,8 @@ set up auto-assignment for Docker Core as well. AI Governance licenses include single sign-on (SSO) and provisioning features regardless of your Docker Core subscription. Automatic license assignment requires -[setting up SSO](/manuals/platform/security/authentication/single-sign-on/connect.md), then -[provisioning](/manuals/platform/security/provisioning/_index.md) with System +[setting up SSO](/manuals/security/authentication/single-sign-on/connect.md), then +[provisioning](/manuals/security/provisioning/_index.md) with System for Cross-domain Identity Management (SCIM) or Just-in-Time (JIT). ## Manage licenses diff --git a/content/manuals/accounts/organization/manage/manage-products.md b/content/manuals/accounts/organization/manage/manage-products.md index 8b73156ae329..c829fd9514c9 100644 --- a/content/manuals/accounts/organization/manage/manage-products.md +++ b/content/manuals/accounts/organization/manage/manage-products.md @@ -26,9 +26,9 @@ use the following procedures to control access for all members. To manage Docker Desktop access: -1. [Enforce sign-in](../../../platform/security/authentication/enforce-sign-in/_index.md). +1. [Enforce sign-in](../../../security/authentication/enforce-sign-in/_index.md). 1. Manage members [manually](./members.md) or use - [provisioning](../../../platform/security/provisioning/_index.md). + [provisioning](../../../security/provisioning/_index.md). With sign-in enforced, only users who are a member of your organization can use Docker Desktop after signing in. diff --git a/content/manuals/accounts/organization/manage/members.md b/content/manuals/accounts/organization/manage/members.md index 2ffc51e5abcc..116865de6764 100644 --- a/content/manuals/accounts/organization/manage/members.md +++ b/content/manuals/accounts/organization/manage/members.md @@ -41,7 +41,7 @@ or email address. 1000 members and separate multiple entries by comma, semicolon, or space. When you invite members, you assign them a role. See -[Roles and permissions](/manuals/platform/security/roles-and-permissions/_index.md) +[Roles and permissions](/manuals/security/roles-and-permissions/_index.md) for details about the access permissions for each role. Pending invitations appear in the table. Invitees can accept or decline the @@ -197,7 +197,7 @@ being added to the team. ### Remove members from teams If your organization uses single sign-on (SSO) with -[SCIM](/manuals/platform/security/provisioning/scim/_index.md) enabled, you +[SCIM](/manuals/security/provisioning/scim/_index.md) enabled, you should remove members from your identity provider (IdP). This automatically removes members from Docker. If SCIM is disabled, follow procedures in this doc to remove members manually in Docker. @@ -216,10 +216,10 @@ from a specific team: ### Update a member role Organization owners can manage -[roles](/manuals/platform/security/roles-and-permissions/_index.md) within +[roles](/manuals/security/roles-and-permissions/_index.md) within an organization. If an organization is part of a company, the company owner can also manage that organization's roles. If you have SSO enabled, you can -use [SCIM for role mapping](/manuals/platform/security/provisioning/scim/_index.md). +use [SCIM for role mapping](/manuals/security/provisioning/scim/_index.md). To update a member role: diff --git a/content/manuals/accounts/organization/setup/_index.md b/content/manuals/accounts/organization/setup/_index.md index 56ad6c539c61..87c233886ddc 100644 --- a/content/manuals/accounts/organization/setup/_index.md +++ b/content/manuals/accounts/organization/setup/_index.md @@ -24,7 +24,7 @@ grid: - title: Security description: Configure single sign-on, provisioning, and access management. icon: shield-check - link: /platform/security/ + link: /security/ aliases: - /admin/organization/setup/ --- @@ -37,7 +37,7 @@ account into an organization. You set up your organization from [Docker Home](https://app.docker.com) and must be assigned the -[organization owner role](/manuals/platform/security/roles-and-permissions/_index.md). +[organization owner role](/manuals/security/roles-and-permissions/_index.md). Setting up an organization happens in broad phases: 1. You can create a new organization, or convert an existing user account diff --git a/content/manuals/accounts/organization/setup/convert-account.md b/content/manuals/accounts/organization/setup/convert-account.md index d86cab3c4bd2..a17ba032cdcd 100644 --- a/content/manuals/accounts/organization/setup/convert-account.md +++ b/content/manuals/accounts/organization/setup/convert-account.md @@ -17,7 +17,7 @@ useful if you need multiple users to access your account and the repositories it’s connected to. Converting it to an organization gives you better control over permissions for these users through [teams](/manuals/accounts/organization/manage/manage-a-team.md) and -[roles](/manuals/platform/security/roles-and-permissions/_index.md). +[roles](/manuals/security/roles-and-permissions/_index.md). When you convert a user account to an organization, the account is migrated to a Docker Team subscription by default. diff --git a/content/manuals/accounts/organization/setup/onboard.md b/content/manuals/accounts/organization/setup/onboard.md index ba0aba76b2cd..a42e27c5e369 100644 --- a/content/manuals/accounts/organization/setup/onboard.md +++ b/content/manuals/accounts/organization/setup/onboard.md @@ -106,7 +106,7 @@ add additional owners. To add an owner, invite a user and assign them the owner role. For more details, see [Invite members](/manuals/accounts/organization/manage/members.md) and -[Roles and permissions](/manuals/platform/security/roles-and-permissions/_index.md). +[Roles and permissions](/manuals/security/roles-and-permissions/_index.md). ### Step three: Invite members @@ -117,7 +117,7 @@ they are signed in. To add a member, invite a user and assign them the member role. For more details, see [Invite members](/manuals/accounts/organization/manage/members.md) and -[Roles and permissions](/manuals/platform/security/roles-and-permissions/_index.md). +[Roles and permissions](/manuals/security/roles-and-permissions/_index.md). ### Step four: Manage user access with SSO and SCIM @@ -128,20 +128,20 @@ subscription, see [Upgrade a plan](/manuals/subscription/manage.md#upgrade-plans Use your identity provider (IdP) to manage members and provision them to Docker automatically via SSO and SCIM. See the following for more details: -- [Configure SSO](/manuals/platform/security/authentication/single-sign-on/connect.md) +- [Configure SSO](/manuals/security/authentication/single-sign-on/connect.md) to authenticate and add members when they sign in to Docker through your identity provider. - Optional. - [Enforce SSO](/manuals/platform/security/authentication/single-sign-on/connect.md) to + [Enforce SSO](/manuals/security/authentication/single-sign-on/connect.md) to ensure that when users sign in to Docker, they must use SSO. > [!NOTE] > > Enforcing single sign-on (SSO) and enforcing Docker Desktop sign in > are different features. For more details, see - > [Enforcing sign-in versus enforcing single sign-on (SSO)](/manuals/platform/security/authentication/enforce-sign-in/_index.md#enforcing-sign-in-versus-enforcing-single-sign-on-sso). + > [Enforcing sign-in versus enforcing single sign-on (SSO)](/manuals/security/authentication/enforce-sign-in/_index.md#enforcing-sign-in-versus-enforcing-single-sign-on-sso). -- [Configure SCIM](/manuals/platform/security/provisioning/scim/_index.md) to +- [Configure SCIM](/manuals/security/provisioning/scim/_index.md) to automatically provision, add, and de-provision members to Docker through your identity provider. @@ -156,9 +156,9 @@ and they can circumvent [Docker’s security features](/manuals/enterprise/harde There are multiple ways you can enforce sign-in, depending on your organization's Docker configuration: -- [Registry key method (Windows only)](/manuals/platform/security/authentication/enforce-sign-in/methods.md#registry-key-method-windows-only) -- [`.plist` method (Mac only)](/manuals/platform/security/authentication/enforce-sign-in/methods.md#plist-method-mac-only) -- [`registry.json` method (All)](/manuals/platform/security/authentication/enforce-sign-in/methods.md#registryjson-method-all) +- [Registry key method (Windows only)](/manuals/security/authentication/enforce-sign-in/methods.md#registry-key-method-windows-only) +- [`.plist` method (Mac only)](/manuals/security/authentication/enforce-sign-in/methods.md#plist-method-mac-only) +- [`registry.json` method (All)](/manuals/security/authentication/enforce-sign-in/methods.md#registryjson-method-all) ### Step six: Manage Docker Desktop security @@ -173,7 +173,7 @@ security posture: - [Manage Docker products](../manage/manage-products.md) to configure access and view usage. - Configure [Hardened Docker Desktop](/manuals/enterprise/hardened-desktop/_index.md) to improve your organization’s security posture for containerized development. -- [Manage your domains](/manuals/platform/security/provisioning/domain-management.md) to ensure that all Docker users in your domain are part of your organization. +- [Manage your domains](/manuals/security/provisioning/domain-management.md) to ensure that all Docker users in your domain are part of your organization. Your Docker subscription provides many more additional features. To learn more, see [Docker subscriptions and features](https://www.docker.com/pricing?ref=Docs&refAction=DocsAdminOnboard). diff --git a/content/manuals/ai/sandboxes/governance/access-controls/organization.md b/content/manuals/ai/sandboxes/governance/access-controls/organization.md index d5da0521626b..1b65fad4edb1 100644 --- a/content/manuals/ai/sandboxes/governance/access-controls/organization.md +++ b/content/manuals/ai/sandboxes/governance/access-controls/organization.md @@ -23,10 +23,10 @@ programmatic management of network and filesystem policies, use the [Governance API](/reference/api/ai-governance/). By default, only organization -[owners](/manuals/platform/security/roles-and-permissions/core-roles.md) can +[owners](/manuals/security/roles-and-permissions/core-roles.md) can view and manage AI Governance policies. To let someone other than an owner manage policies, create a -[custom role](/manuals/platform/security/roles-and-permissions/custom-roles/_index.md) +[custom role](/manuals/security/roles-and-permissions/custom-roles/_index.md) with the **Governance** permissions and assign it to a user or team. > [!NOTE] @@ -114,7 +114,7 @@ in one of two ways: - Manually, in Docker Home. - Automatically, by using - [group mapping](/manuals/platform/security/provisioning/scim/group-mapping.md) + [group mapping](/manuals/security/provisioning/scim/group-mapping.md) to synchronize your identity provider's groups with the teams in your organization. Group mapping creates teams that don't already exist and keeps their membership in step with your IdP groups. diff --git a/content/manuals/ai/sandboxes/governance/audit/_index.md b/content/manuals/ai/sandboxes/governance/audit/_index.md index 3dfca85862c2..360df806f4e3 100644 --- a/content/manuals/ai/sandboxes/governance/audit/_index.md +++ b/content/manuals/ai/sandboxes/governance/audit/_index.md @@ -32,7 +32,7 @@ To use AI Governance Audit Logs, your organization needs: - A Docker [AI Governance plan](/manuals/subscription/plans/ai-governance.md) - An enforced organization governance policy - A Docker organization account -- An organization owner, or a user with a [custom role](/manuals/platform/security/roles-and-permissions/custom-roles/_index.md) that includes AI Governance audit permissions, to configure delivery and view hosted events +- An organization owner, or a user with a [custom role](/manuals/security/roles-and-permissions/custom-roles/_index.md) that includes AI Governance audit permissions, to configure delivery and view hosted events > [!NOTE] > Other Docker subscriptions are not sufficient on their own to use AI Governance @@ -58,7 +58,7 @@ Docker supports two delivery modes for audit records: app.docker.com. Cloud delivery is on by default when AI Governance is enabled. Organization owners can disable it in [audit delivery settings](configure.md). -Organization owners and users with a [custom role](/manuals/platform/security/roles-and-permissions/custom-roles/_index.md) that includes AI Governance audit permissions can configure local disk, Docker Cloud, or both. +Organization owners and users with a [custom role](/manuals/security/roles-and-permissions/custom-roles/_index.md) that includes AI Governance audit permissions can configure local disk, Docker Cloud, or both. The hosted audit log view, CSV export, and SIEM forwarding all require Docker Cloud delivery to be enabled. Local delivery alone does not power these features. diff --git a/content/manuals/ai/sandboxes/governance/audit/configure.md b/content/manuals/ai/sandboxes/governance/audit/configure.md index 314c449479f0..c6db4050a030 100644 --- a/content/manuals/ai/sandboxes/governance/audit/configure.md +++ b/content/manuals/ai/sandboxes/governance/audit/configure.md @@ -6,7 +6,7 @@ description: Configure local and cloud delivery, retention, and history for Dock keywords: docker sandboxes, audit delivery, AI Governance, audit logs, retention, cloud delivery, AI Platform --- -Organization owners and users with a [custom role](/manuals/platform/security/roles-and-permissions/custom-roles/_index.md) that includes AI Governance audit permissions can configure where Docker writes audit events. +Organization owners and users with a [custom role](/manuals/security/roles-and-permissions/custom-roles/_index.md) that includes AI Governance audit permissions can configure where Docker writes audit events. Two delivery destinations are available and can be used independently or together: @@ -21,7 +21,7 @@ Your organization needs: - A Docker [AI Governance plan](/manuals/subscription/plans/ai-governance.md) - An enforced organization governance policy -- Organization owner access, or a [custom role](/manuals/platform/security/roles-and-permissions/custom-roles/_index.md) with AI Governance audit permissions +- Organization owner access, or a [custom role](/manuals/security/roles-and-permissions/custom-roles/_index.md) with AI Governance audit permissions Only users who have an AI Governance license and are governed by the enforced organization policy send Docker Sandboxes audit data. diff --git a/content/manuals/ai/sandboxes/governance/monitor-and-enforce/sign-in-enforcement.md b/content/manuals/ai/sandboxes/governance/monitor-and-enforce/sign-in-enforcement.md index 6794c045a14f..89a4d278a5b0 100644 --- a/content/manuals/ai/sandboxes/governance/monitor-and-enforce/sign-in-enforcement.md +++ b/content/manuals/ai/sandboxes/governance/monitor-and-enforce/sign-in-enforcement.md @@ -269,5 +269,5 @@ For access, contact ACME IT Security: Console - [Governance overview](../_index.md): how local and organization governance fit together -- [Enforce sign-in for Docker Desktop](/manuals/platform/security/authentication/enforce-sign-in/_index.md): +- [Enforce sign-in for Docker Desktop](/manuals/security/authentication/enforce-sign-in/_index.md): the equivalent control for Docker Desktop diff --git a/content/manuals/build-cloud/_index.md b/content/manuals/build-cloud/_index.md index dfd72f30a2bd..54af535bd8d5 100644 --- a/content/manuals/build-cloud/_index.md +++ b/content/manuals/build-cloud/_index.md @@ -64,4 +64,4 @@ Once you've signed up and created a builder, continue by [setting up the builder in your local environment](./setup.md). For information about roles and permissions related to Docker Build Cloud, see -[Roles and Permissions](/manuals/platform/security/roles-and-permissions/core-roles.md#docker-build-cloud). +[Roles and Permissions](/manuals/security/roles-and-permissions/core-roles.md#docker-build-cloud). diff --git a/content/manuals/build-cloud/ci.md b/content/manuals/build-cloud/ci.md index d01d115d6af9..7aa9f176d154 100644 --- a/content/manuals/build-cloud/ci.md +++ b/content/manuals/build-cloud/ci.md @@ -37,8 +37,8 @@ See [Loading build results](./usage/#loading-build-results) for details. To enable your CI/CD system to build and push images using Docker Build Cloud, provide both an access token and a username. The type of token and the username you use depend on your account type and permissions. -- If you are an organization administrator or have permission to create [organization access tokens (OAT)](/manuals/platform/security/access-tokens/organization-access-tokens.md), use an OAT and set `DOCKER_ACCOUNT` to your Docker Hub organization name. -- If you do not have permission to create OATs or are using a personal account, use a [personal access token (PAT)](/platform/security/access-tokens/personal-access-tokens/) and set `DOCKER_ACCOUNT` to your Docker Hub username. +- If you are an organization administrator or have permission to create [organization access tokens (OAT)](/manuals/security/access-tokens/organization-access-tokens.md), use an OAT and set `DOCKER_ACCOUNT` to your Docker Hub organization name. +- If you do not have permission to create OATs or are using a personal account, use a [personal access token (PAT)](/security/access-tokens/personal-access-tokens/) and set `DOCKER_ACCOUNT` to your Docker Hub username. ### Creating access tokens @@ -46,7 +46,7 @@ To enable your CI/CD system to build and push images using Docker Build Cloud, p If you are an organization administrator: -- Create an [organization access token (OAT)](/manuals/platform/security/access-tokens/organization-access-tokens.md). The token must have these permissions: +- Create an [organization access token (OAT)](/manuals/security/access-tokens/organization-access-tokens.md). The token must have these permissions: 1. **cloud-connect** scope 2. **Read public repositories** permission 3. **Repository access** with **Image push** permission for the target repository: @@ -60,7 +60,7 @@ If you are not an organization administrator: #### For personal accounts -- Create a [personal access token (PAT)](/platform/security/access-tokens/personal-access-tokens/) with the following permissions: +- Create a [personal access token (PAT)](/security/access-tokens/personal-access-tokens/) with the following permissions: 1. **Read & write** access. - Note: Building with Docker Build Cloud only requires read access, but you need write access to push images to a Docker Hub repository. diff --git a/content/manuals/desktop/release-notes.md b/content/manuals/desktop/release-notes.md index c6b7954e1292..5e100232c97e 100644 --- a/content/manuals/desktop/release-notes.md +++ b/content/manuals/desktop/release-notes.md @@ -1572,7 +1572,7 @@ For more frequently asked questions, see the [FAQs](/manuals/desktop/troubleshoo ### New - You can now specify PAC files and Embedded PAC scripts with installer flags for [macOS](/manuals/desktop/setup/install/mac-install.md#proxy-configuration) and [Windows](/manuals/desktop/setup/install/windows-install.md#proxy-configuration). -- Administrators can set proxy settings via [macOS configuration profiles](/manuals/platform/security/authentication/enforce-sign-in/methods.md#macos-configuration-profiles-method-recommended). +- Administrators can set proxy settings via [macOS configuration profiles](/manuals/security/authentication/enforce-sign-in/methods.md#macos-configuration-profiles-method-recommended). ### Upgrades @@ -1951,7 +1951,7 @@ We are aware of [CVE-2025-23266](https://nvd.nist.gov/vuln/detail/CVE-2025-23266 - Improved the sign-in enforcement message when more than 10 organizations are enforced. - Changed the way ports are mapped by Docker Desktop to fully support IPv6 ports. - Fixed a bug in the Dashboard container logs screen causing the scrollbar to disappear as the mouse approaches. -- [Enforced sign-in](/manuals/platform/security/authentication/enforce-sign-in/_index.md) fixed for Teams subscription users. +- [Enforced sign-in](/manuals/security/authentication/enforce-sign-in/_index.md) fixed for Teams subscription users. - `llama.cpp` server now supports streaming and tool calling in Model Runner. - Sign-in Enforcement capability is now available to all subscriptions. @@ -2352,7 +2352,7 @@ We are aware of [CVE-2025-23266](https://nvd.nist.gov/vuln/detail/CVE-2025-23266 - Existing Docker Desktop installations using the WSL2 engine on Windows are now automatically migrated to a unified single-distribution architecture for enhanced consistency and performance. - Administrators can now: - - Enforce sign-in with macOS [configuration profiles](/manuals/platform/security/authentication/enforce-sign-in/methods.md#configuration-profiles-method-mac-only) (Early Access). + - Enforce sign-in with macOS [configuration profiles](/manuals/security/authentication/enforce-sign-in/methods.md#configuration-profiles-method-mac-only) (Early Access). - Enforce sign-in for more than one organization at a time (Early Access). - Deploy Docker Desktop for Mac in bulk with the [PKG installer](/manuals/enterprise/enterprise-deployment/pkg-install-and-configure.md) (Early Access). - Use Desktop Settings Management to manage and enforce defaults via admin.docker.com (Early Access). @@ -2470,7 +2470,7 @@ We are aware of [CVE-2025-23266](https://nvd.nist.gov/vuln/detail/CVE-2025-23266 - Image tags added to **Build results** section under the **Info** tab. - Improved efficiency of host-side disk utilization for fresh installations on Mac and Linux. - Fixed a bug that prevented the Sign in enforcement popup to be triggered when token expires. -- Fixed a bug where containers would not be displayed in the GUI immediately after signing in when using [enforced sign-in](/manuals/platform/security/authentication/enforce-sign-in/_index.md). +- Fixed a bug where containers would not be displayed in the GUI immediately after signing in when using [enforced sign-in](/manuals/security/authentication/enforce-sign-in/_index.md). - `settings.json` has been renamed to `settings-store.json` - The host networking feature no longer requires users to be signed-in in order to use it. @@ -2572,7 +2572,7 @@ We are aware of [CVE-2025-23266](https://nvd.nist.gov/vuln/detail/CVE-2025-23266 - If you authenticate via the CLI, you can now authenticate through a browser-based flow, removing the need for manual PAT generation. - Windows now supports automatic reclamation of disk space in Docker Desktop for WSL2 installations [using a managed virtual hard disk](/manuals/desktop/features/wsl/best-practices.md). - Deploying Docker Desktop via the [MSI installer](/manuals/enterprise/enterprise-deployment/msi-install-and-configure.md) is now generally available. -- Two new methods to [enforce sign-in](/manuals/platform/security/authentication/enforce-sign-in/_index.md) (windows registry key and `.plist` file) are now generally available. +- Two new methods to [enforce sign-in](/manuals/security/authentication/enforce-sign-in/_index.md) (windows registry key and `.plist` file) are now generally available. - Fresh installations of Docker Desktop now use the containerd image store by default. - [Compose Bridge](/manuals/compose/bridge/_index.md) (Experimental) is now available from the Compose file viewer. Easily convert and deploy your Compose project to a Kubernetes cluster. @@ -4983,7 +4983,7 @@ Installing Docker Desktop 4.5.0 from scratch has a bug which defaults Docker Des ### New - Easy, Secure sign in with Auth0 and Single Sign-on - - Single Sign-on: Users with a Docker Business subscription can now configure SSO to authenticate using their identity providers (IdPs) to access Docker. For more information, see [Single Sign-on](/manuals/platform/security/authentication/single-sign-on/_index.md). + - Single Sign-on: Users with a Docker Business subscription can now configure SSO to authenticate using their identity providers (IdPs) to access Docker. For more information, see [Single Sign-on](/manuals/security/authentication/single-sign-on/_index.md). - Signing in to Docker Desktop now takes you through the browser so that you get all the benefits of auto-filling from password managers. ### Upgrades @@ -4995,7 +4995,7 @@ Installing Docker Desktop 4.5.0 from scratch has a bug which defaults Docker Des ### Security -- Fixed [CVE-2021-45449](../platform/security/security-announcements.md#cve-2021-45449) that affects users currently on Docker Desktop version 4.3.0 or 4.3.1. +- Fixed [CVE-2021-45449](../security/security-announcements.md#cve-2021-45449) that affects users currently on Docker Desktop version 4.3.0 or 4.3.1. Docker Desktop version 4.3.0 and 4.3.1 has a bug that may log sensitive information (access token or password) on the user's machine during login. This only affects users if they are on Docker Desktop 4.3.0, 4.3.1 and the user has logged in while on 4.3.0, 4.3.1. Gaining access to this data would require having access to the user’s local files. @@ -5035,7 +5035,7 @@ This only affects users if they are on Docker Desktop 4.3.0, 4.3.1 and the user ### Security -- Fixed [CVE-2021-45449](../platform/security/security-announcements.md#cve-2021-45449) that affects users currently on Docker Desktop version 4.3.0 or 4.3.1. +- Fixed [CVE-2021-45449](../security/security-announcements.md#cve-2021-45449) that affects users currently on Docker Desktop version 4.3.0 or 4.3.1. Docker Desktop version 4.3.0 and 4.3.1 has a bug that may log sensitive information (access token or password) on the user's machine during login. This only affects users if they are on Docker Desktop 4.3.0, 4.3.1 and the user has logged in while on 4.3.0, 4.3.1. Gaining access to this data would require having access to the user’s local files. diff --git a/content/manuals/desktop/setup/install/mac-install.md b/content/manuals/desktop/setup/install/mac-install.md index 848ab969da20..30d94c2301a9 100644 --- a/content/manuals/desktop/setup/install/mac-install.md +++ b/content/manuals/desktop/setup/install/mac-install.md @@ -154,7 +154,7 @@ $ sudo /Applications/Docker.app/Contents/MacOS/install --user testuser --proxy-h > [!TIP] > -> As an IT administrator, you can use endpoint management (MDM) software to identify the number of Docker Desktop instances and their versions within your environment. This can provide accurate license reporting, help ensure your machines use the latest version of Docker Desktop, and enable you to [enforce sign-in](/manuals/platform/security/authentication/enforce-sign-in/_index.md). +> As an IT administrator, you can use endpoint management (MDM) software to identify the number of Docker Desktop instances and their versions within your environment. This can provide accurate license reporting, help ensure your machines use the latest version of Docker Desktop, and enable you to [enforce sign-in](/manuals/security/authentication/enforce-sign-in/_index.md). > - [Intune](https://learn.microsoft.com/en-us/mem/intune/apps/app-discovered-apps) > - [Jamf](https://docs.jamf.com/10.25.0/jamf-pro/administrator-guide/Application_Usage.html) > - [Kandji](https://support.kandji.io/support/solutions/articles/72000559793-view-a-device-application-list) diff --git a/content/manuals/desktop/setup/install/windows-install.md b/content/manuals/desktop/setup/install/windows-install.md index f237bdb87fc7..9049b276a6df 100644 --- a/content/manuals/desktop/setup/install/windows-install.md +++ b/content/manuals/desktop/setup/install/windows-install.md @@ -232,7 +232,7 @@ Docker Desktop does not start automatically after installation. To start Docker > [!TIP] > -> As an IT administrator, you can use endpoint management (MDM) software to identify the number of Docker Desktop instances and their versions within your environment. This can provide accurate license reporting, help ensure your machines use the latest version of Docker Desktop, and enable you to [enforce sign-in](/manuals/platform/security/authentication/enforce-sign-in/_index.md). +> As an IT administrator, you can use endpoint management (MDM) software to identify the number of Docker Desktop instances and their versions within your environment. This can provide accurate license reporting, help ensure your machines use the latest version of Docker Desktop, and enable you to [enforce sign-in](/manuals/security/authentication/enforce-sign-in/_index.md). > - [Intune](https://learn.microsoft.com/en-us/mem/intune/apps/app-discovered-apps) > - [Jamf](https://docs.jamf.com/10.25.0/jamf-pro/administrator-guide/Application_Usage.html) > - [Kandji](https://support.kandji.io/support/solutions/articles/72000559793-view-a-device-application-list) diff --git a/content/manuals/desktop/setup/sign-in.md b/content/manuals/desktop/setup/sign-in.md index 0abe991654f5..c5a3dbf666ba 100644 --- a/content/manuals/desktop/setup/sign-in.md +++ b/content/manuals/desktop/setup/sign-in.md @@ -17,7 +17,7 @@ aliases: Docker recommends signing in with the **Sign in** option in the top-right corner of the Docker Dashboard. -In large enterprises where admin access is restricted, administrators can [enforce sign-in](/manuals/platform/security/authentication/enforce-sign-in/_index.md). +In large enterprises where admin access is restricted, administrators can [enforce sign-in](/manuals/security/authentication/enforce-sign-in/_index.md). > [!TIP] > diff --git a/content/manuals/dhi/how-to/customize.md b/content/manuals/dhi/how-to/customize.md index e4129e9cac29..559bc482c9d3 100644 --- a/content/manuals/dhi/how-to/customize.md +++ b/content/manuals/dhi/how-to/customize.md @@ -161,9 +161,9 @@ You can create customizations using either the DHI CLI or the Docker Hub web int {{< tab name="CLI" >}} Authenticate with `docker login` using your Docker credentials or a [personal -access token (PAT)](../../platform/security/access-tokens/personal-access-tokens.md) with **Read & Write** +access token (PAT)](../../security/access-tokens/personal-access-tokens.md) with **Read & Write** permissions, or an [organization access token -(OAT)](../../platform/security/access-tokens/organization-access-tokens.md). When using an OAT, the +(OAT)](../../security/access-tokens/organization-access-tokens.md). When using an OAT, the available operations depend on the token's permission scope: - To list or get customizations, or to view build logs, the OAT must have read diff --git a/content/manuals/dhi/how-to/helm.md b/content/manuals/dhi/how-to/helm.md index cfc3ba372162..ee65e52d596b 100644 --- a/content/manuals/dhi/how-to/helm.md +++ b/content/manuals/dhi/how-to/helm.md @@ -53,8 +53,8 @@ registry, you still need to create this secret if the registry requires authentication. 1. For `dhi.io` or Docker Hub, create a [personal access token - (PAT)](/platform/security/access-tokens/personal-access-tokens/) using your Docker account or an - [organization access token (OAT)](/platform/security/access-tokens/organization-access-tokens/). + (PAT)](/security/access-tokens/personal-access-tokens/) using your Docker account or an + [organization access token (OAT)](/security/access-tokens/organization-access-tokens/). Ensure the token has at least read-only access to the Docker Hardened Image repositories. 2. Create a secret in Kubernetes using the following command. Replace ``, ``, diff --git a/content/manuals/dhi/how-to/mirror.md b/content/manuals/dhi/how-to/mirror.md index 3c89c3b7e375..56b3c4a1bd5e 100644 --- a/content/manuals/dhi/how-to/mirror.md +++ b/content/manuals/dhi/how-to/mirror.md @@ -34,10 +34,10 @@ repositories: ## Mirror a DHI repository to your organization -Organization owners, editors, and members with a [custom role](../../platform/security/roles-and-permissions/custom-roles/_index.md) +Organization owners, editors, and members with a [custom role](../../security/roles-and-permissions/custom-roles/_index.md) that includes the DHI mirroring permission can create, view, and manage mirrors. When using the CLI or Terraform, you can also mirror using an [organization -access token (OAT)](../../platform/security/access-tokens/organization-access-tokens.md) with the +access token (OAT)](../../security/access-tokens/organization-access-tokens.md) with the appropriate permission scopes, without requiring role-based access. When a member with a custom role that includes the DHI mirroring permission @@ -83,9 +83,9 @@ It may take a few minutes for all the tags to finish mirroring. {{< tab name="CLI" >}} Authenticate with `docker login` using your Docker credentials, a [personal -access token (PAT)](../../platform/security/access-tokens/personal-access-tokens.md) with **Read & Write** +access token (PAT)](../../security/access-tokens/personal-access-tokens.md) with **Read & Write** permissions, or an [organization access token -(OAT)](../../platform/security/access-tokens/organization-access-tokens.md). When using an OAT, the +(OAT)](../../security/access-tokens/organization-access-tokens.md). When using an OAT, the available operations depend on the token's permission scope: - To list mirrored repositories, the OAT must have read (pull) access to the @@ -200,9 +200,9 @@ updates. You can still use the last images or charts that were mirrored. {{< tab name="CLI" >}} Authenticate with `docker login` using your Docker credentials, a [personal -access token (PAT)](../../platform/security/access-tokens/personal-access-tokens.md) with **Read & Write** +access token (PAT)](../../security/access-tokens/personal-access-tokens.md) with **Read & Write** permissions, or an [organization access token -(OAT)](../../platform/security/access-tokens/organization-access-tokens.md) with push access to the +(OAT)](../../security/access-tokens/organization-access-tokens.md) with push access to the relevant repository. Use the [`docker dhi mirror`](/reference/cli/docker/dhi/mirror/) command: @@ -303,11 +303,11 @@ same steps to a non-mirrored image by updating the `SRC_ATT_REPO` and In this example, you authenticate as your Docker organization using an [organization access token - (OAT)](../../platform/security/access-tokens/organization-access-tokens.md). The OAT must have at + (OAT)](../../security/access-tokens/organization-access-tokens.md). The OAT must have at least pull access to every DHI repository you want to mirror. Only repositories in the token's scope are accessible. Alternatively, you can authenticate as a Docker Hub user with a [personal access token - (PAT)](../../platform/security/access-tokens/personal-access-tokens.md) that has `read only` access. + (PAT)](../../security/access-tokens/personal-access-tokens.md) that has `read only` access. > [!WARNING] > diff --git a/content/manuals/dhi/how-to/policies.md b/content/manuals/dhi/how-to/policies.md index bbf0caff7059..152aa454dc1b 100644 --- a/content/manuals/dhi/how-to/policies.md +++ b/content/manuals/dhi/how-to/policies.md @@ -215,7 +215,7 @@ jobs: The `docker/login-action` step authenticates with Docker Hub so the runner can pull the DHI base image and the `dhi/policies` bundle. Store your Docker Hub -username and a [personal access token](/manuals/platform/security/access-tokens/personal-access-tokens.md) as the +username and a [personal access token](/manuals/security/access-tokens/personal-access-tokens.md) as the `DOCKER_USER` and `DOCKER_PAT` repository secrets. Set `exit-code: true` to fail the step when any policy isn't met. The diff --git a/content/manuals/dhi/how-to/use.md b/content/manuals/dhi/how-to/use.md index 52dea6884c68..2725d4f07050 100644 --- a/content/manuals/dhi/how-to/use.md +++ b/content/manuals/dhi/how-to/use.md @@ -26,9 +26,9 @@ package manager, and may run as a non-root user by default. > you don't have a Docker account, [create one](../../accounts/individual/create-account.md > for free. > - **Access token:** Use a [personal access token -> (PAT)](../../platform/security/access-tokens/personal-access-tokens.md) for personal accounts, or an +> (PAT)](../../security/access-tokens/personal-access-tokens.md) for personal accounts, or an > [organization access token -> (OAT)](../../platform/security/access-tokens/organization-access-tokens.md) with your organization +> (OAT)](../../security/access-tokens/organization-access-tokens.md) with your organization > name as the username. > > Run `docker login dhi.io` to authenticate. @@ -109,14 +109,14 @@ attached to Docker Hardened Images. This is particularly useful in CI/CD pipelines for supply chain security validation and compliance checks. For automated workflows, authenticate using an [organization access token -(OAT)](../../platform/security/access-tokens/organization-access-tokens.md). OATs are owned by the +(OAT)](../../security/access-tokens/organization-access-tokens.md). OATs are owned by the organization rather than an individual user, making them better suited for CI/CD pipelines. To discover attestations with ORAS: 1. [Generate an organization access - token](../../platform/security/access-tokens/organization-access-tokens.md) with **Read public + token](../../security/access-tokens/organization-access-tokens.md) with **Read public repositories** scope. The following example shows how to discover attestations on DHI community @@ -268,8 +268,8 @@ For the `--docker-server` value: #### Using an access token Create a secret using a [Personal Access Token -(PAT)](../../platform/security/access-tokens/personal-access-tokens.md) or [Organization Access Token -(OAT)](../../platform/security/access-tokens/organization-access-tokens.md). Ensure the token has at +(PAT)](../../security/access-tokens/personal-access-tokens.md) or [Organization Access Token +(OAT)](../../security/access-tokens/organization-access-tokens.md). Ensure the token has at least read-only access to the repositories. ```console diff --git a/content/manuals/dhi/how-to/verify.md b/content/manuals/dhi/how-to/verify.md index b11ac22e7ff7..1095c40176b8 100644 --- a/content/manuals/dhi/how-to/verify.md +++ b/content/manuals/dhi/how-to/verify.md @@ -62,11 +62,11 @@ This command shows all available attestations, including SBOMs, provenance, vuln First, authenticate to both registries. This example authenticates as your Docker organization using an [organization access token -(OAT)](../../platform/security/access-tokens/organization-access-tokens.md). The OAT must have at least +(OAT)](../../security/access-tokens/organization-access-tokens.md). The OAT must have at least pull access to the DHI repositories you want to verify. Only repositories in the token's scope are accessible. Alternatively, you can authenticate as a Docker Hub user with a [personal access token -(PAT)](../../platform/security/access-tokens/personal-access-tokens.md) that has `read only` access. +(PAT)](../../security/access-tokens/personal-access-tokens.md) that has `read only` access. > [!WARNING] > diff --git a/content/manuals/dhi/tools/api.md b/content/manuals/dhi/tools/api.md index 7062770f541f..e52f50e5b5cc 100644 --- a/content/manuals/dhi/tools/api.md +++ b/content/manuals/dhi/tools/api.md @@ -40,7 +40,7 @@ Every query takes a `Context` argument (conventionally named `ctx` in the ## Authentication -An [organization access token](/manuals/platform/security/access-tokens/organization-access-tokens.md) +An [organization access token](/manuals/security/access-tokens/organization-access-tokens.md) (OAT) or personal access token (PAT) isn't used directly as the bearer token. Exchange it first for an access token: diff --git a/content/manuals/dhi/tools/mcp.md b/content/manuals/dhi/tools/mcp.md index ebf014575c99..d894d26e0efd 100644 --- a/content/manuals/dhi/tools/mcp.md +++ b/content/manuals/dhi/tools/mcp.md @@ -148,7 +148,7 @@ based on what you ask: ## Authenticate for mirror tools The mirror tools require a Docker Hub username and [personal access token -(PAT)](/platform/security/access-tokens/personal-access-tokens/) with owner access to the target organization, +(PAT)](/security/access-tokens/personal-access-tokens/) with owner access to the target organization, passed as an HTTP Basic auth header. Generate the value with: ```console diff --git a/content/manuals/docker-hub/release-notes.md b/content/manuals/docker-hub/release-notes.md index b39b1e466361..1ac5c191b5f5 100644 --- a/content/manuals/docker-hub/release-notes.md +++ b/content/manuals/docker-hub/release-notes.md @@ -110,7 +110,7 @@ known issues for each Docker Hub release. ### New -- Organizations can assign the [editor role](/manuals/platform/security/roles-and-permissions/_index.md) to members to grant additional permissions without full administrative access. +- Organizations can assign the [editor role](/manuals/security/roles-and-permissions/_index.md) to members to grant additional permissions without full administrative access. ## 2023-05-09 @@ -140,7 +140,7 @@ known issues for each Docker Hub release. ### Bug fixes and enhancements -- In Docker Hub, you can now download a [registry.json](/manuals/platform/security/authentication/enforce-sign-in/_index.md) file or copy the commands to create a registry.json file to enforce sign-in for your organization. +- In Docker Hub, you can now download a [registry.json](/manuals/security/authentication/enforce-sign-in/_index.md) file or copy the commands to create a registry.json file to enforce sign-in for your organization. ## 2022-09-19 @@ -318,7 +318,7 @@ Docker introduces Hub Vulnerability Scanning which enables you to automatically ### New features -- You can now [create personal access tokens](/platform/security/access-tokens/personal-access-tokens/) in Docker Hub and use them to authenticate from the Docker CLI. Find them in your account settings, under the new **[Security](https://hub.docker.com/settings/security)** section. +- You can now [create personal access tokens](/security/access-tokens/personal-access-tokens/) in Docker Hub and use them to authenticate from the Docker CLI. Find them in your account settings, under the new **[Security](https://hub.docker.com/settings/security)** section. ### Known Issues diff --git a/content/manuals/docker-hub/repos/create.md b/content/manuals/docker-hub/repos/create.md index d21171cd5bf6..b2674644b9fc 100644 --- a/content/manuals/docker-hub/repos/create.md +++ b/content/manuals/docker-hub/repos/create.md @@ -39,7 +39,7 @@ weight: 20 is only accessible to you and collaborators. In addition, if you selected an organization's namespace, then the repository is accessible to those with applicable roles or permissions. For more details, see [Roles and - permissions](/manuals/platform/security/roles-and-permissions.md). + permissions](/manuals/security/roles-and-permissions.md). > [!NOTE] > diff --git a/content/manuals/docker-hub/repos/manage/access.md b/content/manuals/docker-hub/repos/manage/access.md index f684d3aa513c..aa9732a65e20 100644 --- a/content/manuals/docker-hub/repos/manage/access.md +++ b/content/manuals/docker-hub/repos/manage/access.md @@ -94,7 +94,7 @@ repository from that repository's **Settings** page. Organizations can use roles for individuals, giving them different permissions in the organization. For more details, see [Roles and -permissions](/manuals/platform/security/roles-and-permissions.md). +permissions](/manuals/security/roles-and-permissions.md). ## Organization teams @@ -131,7 +131,7 @@ To configure team repository permissions: Organizations can use OATs. OATs let you assign fine-grained repository access permissions to tokens. For more details, see [Organization access -tokens](/manuals/platform/security/access-tokens/organization-access-tokens.md). +tokens](/manuals/security/access-tokens/organization-access-tokens.md). ## Gated distribution @@ -156,7 +156,7 @@ If you are interested in Gated Distribution contact the }} @@ -14,7 +15,7 @@ Organization access tokens (OATs) provide secure, programmatic access to Docker > [!WARNING] > -> Organization access tokens are incompatible with Docker Desktop and Image Access Management. If you use these features, use [personal access tokens](/manuals/platform/security/access-tokens/personal-access-tokens.md) instead. +> Organization access tokens are incompatible with Docker Desktop and Image Access Management. If you use these features, use [personal access tokens](/manuals/security/access-tokens/personal-access-tokens.md) instead. ## Who should use organization access tokens? diff --git a/content/manuals/platform/security/access-tokens/personal-access-tokens.md b/content/manuals/security/access-tokens/personal-access-tokens.md similarity index 94% rename from content/manuals/platform/security/access-tokens/personal-access-tokens.md rename to content/manuals/security/access-tokens/personal-access-tokens.md index e3d35140095d..fe185b6f434a 100644 --- a/content/manuals/platform/security/access-tokens/personal-access-tokens.md +++ b/content/manuals/security/access-tokens/personal-access-tokens.md @@ -9,6 +9,7 @@ aliases: - /security/access-tokens/ - /security/personal-access-tokens/ - /security/for-developers/access-tokens/ + - /platform/security/access-tokens/personal-access-tokens/ --- Personal access tokens (PATs) provide a secure alternative to passwords for Docker CLI authentication. Use PATs to authenticate automated systems, CI/CD pipelines, and development tools without exposing your Docker Hub password. @@ -34,7 +35,7 @@ Use PATs for these common scenarios: > [!NOTE] > -> For organization-wide automation, consider [organization access tokens](/manuals/platform/security/access-tokens/organization-access-tokens.md) which aren't tied to individual user accounts. +> For organization-wide automation, consider [organization access tokens](/manuals/security/access-tokens/organization-access-tokens.md) which aren't tied to individual user accounts. ## Create a personal access token @@ -103,5 +104,5 @@ Best practices for fair use include: - Reuse tokens across similar use cases instead of creating many single-purpose tokens - Delete unused tokens regularly -- Use [organization access tokens](/manuals/platform/security/access-tokens/organization-access-tokens.md) for organization-wide automation +- Use [organization access tokens](/manuals/security/access-tokens/organization-access-tokens.md) for organization-wide automation - Monitor token usage to identify optimization opportunities diff --git a/content/manuals/platform/security/authentication/2fa/_index.md b/content/manuals/security/authentication/2fa/_index.md similarity index 98% rename from content/manuals/platform/security/authentication/2fa/_index.md rename to content/manuals/security/authentication/2fa/_index.md index 1cb2332cc7c1..5dd4af329acb 100644 --- a/content/manuals/platform/security/authentication/2fa/_index.md +++ b/content/manuals/security/authentication/2fa/_index.md @@ -10,6 +10,7 @@ aliases: - /security/for-developers/2fa/ - /security/for-developers/2fa/disable-2fa/ - /security/2fa/ + - /platform/security/authentication/2fa/ --- Two-factor authentication (2FA) adds an essential security layer to your Docker account by requiring a unique security code in addition to your password when signing in. This prevents unauthorized access even if your password is compromised. diff --git a/content/manuals/platform/security/authentication/2fa/recover-hub-account.md b/content/manuals/security/authentication/2fa/recover-hub-account.md similarity index 96% rename from content/manuals/platform/security/authentication/2fa/recover-hub-account.md rename to content/manuals/security/authentication/2fa/recover-hub-account.md index 4535b6b77741..d549a2b4214d 100644 --- a/content/manuals/platform/security/authentication/2fa/recover-hub-account.md +++ b/content/manuals/security/authentication/2fa/recover-hub-account.md @@ -6,6 +6,7 @@ aliases: - /docker-hub/2fa/recover-hub-account/ - /security/for-developers/2fa/recover-hub-account/ - /security/2fa/new-recovery-code/ + - /platform/security/authentication/2fa/recover-hub-account/ weight: 20 --- diff --git a/content/manuals/platform/security/authentication/_index.md b/content/manuals/security/authentication/_index.md similarity index 86% rename from content/manuals/platform/security/authentication/_index.md rename to content/manuals/security/authentication/_index.md index fd683d953cd5..5c6a004c705a 100644 --- a/content/manuals/platform/security/authentication/_index.md +++ b/content/manuals/security/authentication/_index.md @@ -6,4 +6,6 @@ linkTitle: Authentication description: Configure single sign-on, OIDC connections, two-factor authentication, and sign-in enforcement. keywords: authentication, SSO, OIDC, two-factor authentication, 2FA, enforce sign-in, Docker security weight: 20 +aliases: + - /platform/security/authentication/ --- diff --git a/content/manuals/platform/security/authentication/enforce-sign-in/_index.md b/content/manuals/security/authentication/enforce-sign-in/_index.md similarity index 92% rename from content/manuals/platform/security/authentication/enforce-sign-in/_index.md rename to content/manuals/security/authentication/enforce-sign-in/_index.md index 87121af63822..afd38e622a06 100644 --- a/content/manuals/platform/security/authentication/enforce-sign-in/_index.md +++ b/content/manuals/security/authentication/enforce-sign-in/_index.md @@ -9,6 +9,7 @@ aliases: - /security/for-admins/configure-sign-in/ - /security/for-admins/enforce-sign-in/ - /enterprise/security/enforce-sign-in/ + - /platform/security/authentication/enforce-sign-in/ weight: 30 --- @@ -56,7 +57,7 @@ On the next Docker Desktop restart: ## Enforcing sign-in versus enforcing single sign-on (SSO) -Enforcing Docker Desktop sign-in and [enforcing SSO](/manuals/platform/security/authentication/single-sign-on/connect.md#optional-enforce-sso) are different features that serve different purposes: +Enforcing Docker Desktop sign-in and [enforcing SSO](/manuals/security/authentication/single-sign-on/connect.md#optional-enforce-sso) are different features that serve different purposes: | Enforcement | Description | Benefits | @@ -68,5 +69,5 @@ Enforcing Docker Desktop sign-in and [enforcing SSO](/manuals/platform/security/ ## Next steps -- To set up sign-in enforcement, see [Configure sign-in enforcement](/manuals/platform/security/authentication/enforce-sign-in/methods.md). -- To configure SSO enforcement, see [Enforce SSO](/manuals/platform/security/authentication/single-sign-on/connect.md). +- To set up sign-in enforcement, see [Configure sign-in enforcement](/manuals/security/authentication/enforce-sign-in/methods.md). +- To configure SSO enforcement, see [Enforce SSO](/manuals/security/authentication/single-sign-on/connect.md). diff --git a/content/manuals/platform/security/authentication/enforce-sign-in/methods.md b/content/manuals/security/authentication/enforce-sign-in/methods.md similarity index 99% rename from content/manuals/platform/security/authentication/enforce-sign-in/methods.md rename to content/manuals/security/authentication/enforce-sign-in/methods.md index 6c97f2bac7d9..67624a471fe5 100644 --- a/content/manuals/platform/security/authentication/enforce-sign-in/methods.md +++ b/content/manuals/security/authentication/enforce-sign-in/methods.md @@ -7,6 +7,7 @@ tags: [admin] aliases: - /security/for-admins/enforce-sign-in/methods/ - /enterprise/security/enforce-sign-in/methods/ + - /platform/security/authentication/enforce-sign-in/methods/ --- {{< summary-bar feature_name="Enforce sign-in" >}} diff --git a/content/manuals/platform/security/authentication/oidc-connections/_index.md b/content/manuals/security/authentication/oidc-connections/_index.md similarity index 84% rename from content/manuals/platform/security/authentication/oidc-connections/_index.md rename to content/manuals/security/authentication/oidc-connections/_index.md index 9d349e929b3d..bca796dcf123 100644 --- a/content/manuals/platform/security/authentication/oidc-connections/_index.md +++ b/content/manuals/security/authentication/oidc-connections/_index.md @@ -7,6 +7,7 @@ tags: [admin] weight: 35 aliases: - /enterprise/security/oidc-connections/ + - /platform/security/authentication/oidc-connections/ --- {{< summary-bar feature_name="OIDC connections" >}} @@ -36,7 +37,7 @@ and issued on a per-workflow basis. ## OIDC connections and OATs -[Organization access tokens (OATs)](/manuals/platform/security/access-tokens/organization-access-tokens.md) +[Organization access tokens (OATs)](/manuals/security/access-tokens/organization-access-tokens.md) provide programmatic access to your Docker resources at the organization level. Unlike personal access tokens, OATs aren't tied to individual members, so access continues when membership changes. @@ -50,5 +51,5 @@ they request a change to your Docker resources. ## Next steps -- [Create an OIDC connection](/manuals/platform/security/authentication/oidc-connections/create-manage.md) -- [OIDC rulesets and subject claims](/manuals/platform/security/authentication/oidc-connections/rulesets-claims.md) +- [Create an OIDC connection](/manuals/security/authentication/oidc-connections/create-manage.md) +- [OIDC rulesets and subject claims](/manuals/security/authentication/oidc-connections/rulesets-claims.md) diff --git a/content/manuals/platform/security/authentication/oidc-connections/create-manage.md b/content/manuals/security/authentication/oidc-connections/create-manage.md similarity index 91% rename from content/manuals/platform/security/authentication/oidc-connections/create-manage.md rename to content/manuals/security/authentication/oidc-connections/create-manage.md index 581fa014ae39..6961ce607115 100644 --- a/content/manuals/platform/security/authentication/oidc-connections/create-manage.md +++ b/content/manuals/security/authentication/oidc-connections/create-manage.md @@ -5,6 +5,8 @@ description: Create and manage OIDC connections in Docker Home, then authenticat keywords: oidc connections, create oidc connection, github actions, docker/login-action, DOCKERHUB_OIDC_CONNECTIONID, openid connect, docker hub, enterprise security, admin tags: [admin] weight: 10 +aliases: + - /platform/security/authentication/oidc-connections/create-manage/ --- {{< summary-bar feature_name="OIDC connections" >}} @@ -25,7 +27,7 @@ with a short-lived token. 1. Select **Create OIDC connection** and fill in the OIDC connection form. - Provide rulesets and subject claims. Other values are optional. - For rulesets, subject claims, and resources, see - [OIDC connections rulesets and subject claims](/manuals/platform/security/authentication/oidc-connections/rulesets-claims.md). + [OIDC connections rulesets and subject claims](/manuals/security/authentication/oidc-connections/rulesets-claims.md). 1. Select **Create connection**. 1. Copy your OIDC connection ID. @@ -90,4 +92,4 @@ fails at the token-exchange step until you activate the connection. ## Next steps -- [OIDC connections rulesets and subject claims](/manuals/platform/security/authentication/oidc-connections/rulesets-claims.md) +- [OIDC connections rulesets and subject claims](/manuals/security/authentication/oidc-connections/rulesets-claims.md) diff --git a/content/manuals/platform/security/authentication/oidc-connections/rulesets-claims.md b/content/manuals/security/authentication/oidc-connections/rulesets-claims.md similarity index 92% rename from content/manuals/platform/security/authentication/oidc-connections/rulesets-claims.md rename to content/manuals/security/authentication/oidc-connections/rulesets-claims.md index 104d06667da4..a1632d8f9c1d 100644 --- a/content/manuals/platform/security/authentication/oidc-connections/rulesets-claims.md +++ b/content/manuals/security/authentication/oidc-connections/rulesets-claims.md @@ -5,6 +5,8 @@ description: Configure rulesets and subject claims to control OIDC workflow acce keywords: oidc connections, rulesets, subject claims, github actions, jwt claims, access control, wildcards, enterprise security tags: [admin] weight: 20 +aliases: + - /platform/security/authentication/oidc-connections/rulesets-claims/ --- {{< summary-bar feature_name="OIDC connections" >}} @@ -91,5 +93,5 @@ Docker Hub repositories and Docker Build Cloud are supported resources. ## Next steps -- [OIDC connections overview](/manuals/platform/security/authentication/oidc-connections/_index.md) -- [Create or manage OIDC connections](/manuals/platform/security/authentication/oidc-connections/create-manage.md) +- [OIDC connections overview](/manuals/security/authentication/oidc-connections/_index.md) +- [Create or manage OIDC connections](/manuals/security/authentication/oidc-connections/create-manage.md) diff --git a/content/manuals/platform/security/authentication/single-sign-on/_index.md b/content/manuals/security/authentication/single-sign-on/_index.md similarity index 88% rename from content/manuals/platform/security/authentication/single-sign-on/_index.md rename to content/manuals/security/authentication/single-sign-on/_index.md index 8abb723f1ef6..ca93cf43fa9d 100644 --- a/content/manuals/platform/security/authentication/single-sign-on/_index.md +++ b/content/manuals/security/authentication/single-sign-on/_index.md @@ -9,6 +9,7 @@ aliases: - /admin/organization/security-settings/sso-management/ - /security/for-admins/single-sign-on/ - /enterprise/security/single-sign-on/ + - /platform/security/authentication/single-sign-on/ weight: 10 --- @@ -51,10 +52,10 @@ assigned to an organization, and added to a team. > > When SSO is enforced, CLI password-based sign-in is no longer supported. > Use a personal access token (PAT) for CLI access. For more information, see the -> [security announcement](/manuals/platform/security/security-announcements.md#deprecation-of-password-logins-on-cli-when-sso-enforced). +> [security announcement](/manuals/security/security-announcements.md#deprecation-of-password-logins-on-cli-when-sso-enforced). ## Next steps - Start [configuring SSO](connect.md). - Read the [FAQs](/manuals/faqs/sso-faqs.md). -- [Troubleshoot](/manuals/platform/security/authentication/single-sign-on/troubleshoot-sso.md) SSO issues. +- [Troubleshoot](/manuals/security/authentication/single-sign-on/troubleshoot-sso.md) SSO issues. diff --git a/content/manuals/platform/security/authentication/single-sign-on/connect.md b/content/manuals/security/authentication/single-sign-on/connect.md similarity index 92% rename from content/manuals/platform/security/authentication/single-sign-on/connect.md rename to content/manuals/security/authentication/single-sign-on/connect.md index 85eb77d6cc3b..36e3c224d324 100644 --- a/content/manuals/platform/security/authentication/single-sign-on/connect.md +++ b/content/manuals/security/authentication/single-sign-on/connect.md @@ -14,6 +14,7 @@ aliases: - /admin/organization/security-settings/sso-configuration/ - /security/for-admins/single-sign-on/configure/ - /enterprise/security/single-sign-on/connect/ + - /platform/security/authentication/single-sign-on/connect/ --- {{< summary-bar feature_name="SSO" >}} @@ -22,7 +23,7 @@ To set up a single sign-on (SSO), you need to establish a connection between Doc and your identity provider (IdP). While this guide uses Okta and Microsoft Entra ID as a working example, the general process remains the same for other IdPs. -If you're unfamiliar with the SSO process, first review [SSO overview](/manuals/platform/security/authentication/single-sign-on/_index.md) to learn about how SSO works. +If you're unfamiliar with the SSO process, first review [SSO overview](/manuals/security/authentication/single-sign-on/_index.md) to learn about how SSO works. ## Prerequisites @@ -124,7 +125,7 @@ You need [super admin permissions](https://help.okta.com/en-us/content/topics/se - For **Name ID format**, choose `EmailAddress` - For **Application username**, choose `Email` - For **Update application username on**, choose `Create and update` - - Optional. Add [SAML attributes](/manuals/platform/security/provisioning/_index.md#sso-attributes), if required by your org. + - Optional. Add [SAML attributes](/manuals/security/provisioning/_index.md#sso-attributes), if required by your org. 1. For **Feedback**, choose **This is an internal app that we have created** checkbox before finishing. Keep your Okta window open for the next step. @@ -140,7 +141,7 @@ To enable SSO with Microsoft Entra, you need [Cloud Application Administrator](h 1. Select **Edit** on the **Basic SAML configuration** section. From **Basic SAML configuration**, choose **Edit** and paste the values you copied from creating an SSO connection in Docker: - For the **Identifier** value, paste the Docker Entity ID. - For the **Reply URL** value, paste Docker ACS URL. -1. Optional. Add [SAML attributes](/manuals/platform/security/provisioning/_index.md#sso-attributes), if required by your org. +1. Optional. Add [SAML attributes](/manuals/security/provisioning/_index.md#sso-attributes), if required by your org. 1. From the **SAML Signing Certificate** section, download your **Certificate (Base64)**. {{< /tab >}} @@ -233,7 +234,7 @@ Docker supports multiple identity provider (IdP) configurations by letting you a To add multiple IdPs: 1. Use the same domain for each connection. -1. Repeat steps 3-6 from the [Set up an SSO connection](/manuals/platform/security/authentication/single-sign-on/connect.md#set-up-an-sso-connection) procedures on this page. Repeat these steps for each IdP your organization intends to use. +1. Repeat steps 3-6 from the [Set up an SSO connection](/manuals/security/authentication/single-sign-on/connect.md#set-up-an-sso-connection) procedures on this page. Repeat these steps for each IdP your organization intends to use. Because you must use the same domain for each IdP, you won't need to repeat steps to add and verify your domains. @@ -241,7 +242,7 @@ Because you must use the same domain for each IdP, you won't need to repeat step If SSO is not enforced, users can still sign in using Docker usernames and passwords. Enforcing SSO requires users to use SSO when signing into Docker, which centralizes authentication and enforces policies set by the IdP. -Before enforcing SSO, users accessing Docker through the CLI must [create a personal access token (PAT)](/manuals/platform/security/access-tokens/personal-access-tokens.md). The PAT replaces their username and password for authentication. +Before enforcing SSO, users accessing Docker through the CLI must [create a personal access token (PAT)](/manuals/security/access-tokens/personal-access-tokens.md). The PAT replaces their username and password for authentication. 1. Sign in to [Docker Home](https://app.docker.com/) and select your organization or company. @@ -256,7 +257,7 @@ Docker Hub. If you want to use 2FA, you must enable 2FA through your IdP. ## Next steps -- [Provision users](/manuals/platform/security/provisioning/_index.md). +- [Provision users](/manuals/security/provisioning/_index.md). - [Enforce sign-in](../enforce-sign-in/_index.md). -- [Create personal access tokens](/manuals/platform/security/access-tokens/personal-access-tokens.md). -- [Troubleshoot SSO](/manuals/platform/security/authentication/single-sign-on/troubleshoot-sso.md) issues. +- [Create personal access tokens](/manuals/security/access-tokens/personal-access-tokens.md). +- [Troubleshoot SSO](/manuals/security/authentication/single-sign-on/troubleshoot-sso.md) issues. diff --git a/content/manuals/platform/security/authentication/single-sign-on/images/SSO.png b/content/manuals/security/authentication/single-sign-on/images/SSO.png similarity index 100% rename from content/manuals/platform/security/authentication/single-sign-on/images/SSO.png rename to content/manuals/security/authentication/single-sign-on/images/SSO.png diff --git a/content/manuals/platform/security/authentication/single-sign-on/manage.md b/content/manuals/security/authentication/single-sign-on/manage.md similarity index 98% rename from content/manuals/platform/security/authentication/single-sign-on/manage.md rename to content/manuals/security/authentication/single-sign-on/manage.md index 71d34c1c63a9..c931de7b1030 100644 --- a/content/manuals/platform/security/authentication/single-sign-on/manage.md +++ b/content/manuals/security/authentication/single-sign-on/manage.md @@ -9,6 +9,7 @@ aliases: - /single-sign-on/manage/ - /security/for-admins/single-sign-on/manage/ - /enterprise/security/single-sign-on/manage/ +- /platform/security/authentication/single-sign-on/manage/ --- {{< summary-bar feature_name="SSO" >}} @@ -107,7 +108,7 @@ when they sign in via SSO - Group mapping: Sync user groups from your identity provider with teams in your Docker organization - Manual provisioning: Turn off automatic provisioning and manually invite users -For more information on provisioning methods, see [Provision users](/manuals/platform/security/provisioning/_index.md). +For more information on provisioning methods, see [Provision users](/manuals/security/provisioning/_index.md). ### Add guest users diff --git a/content/manuals/platform/security/authentication/single-sign-on/troubleshoot-sso.md b/content/manuals/security/authentication/single-sign-on/troubleshoot-sso.md similarity index 97% rename from content/manuals/platform/security/authentication/single-sign-on/troubleshoot-sso.md rename to content/manuals/security/authentication/single-sign-on/troubleshoot-sso.md index 59e37dc105c4..8bbb0d4a3e14 100644 --- a/content/manuals/platform/security/authentication/single-sign-on/troubleshoot-sso.md +++ b/content/manuals/security/authentication/single-sign-on/troubleshoot-sso.md @@ -10,6 +10,7 @@ aliases: - /security/for-admins/single-sign-on/troubleshoot/ - /security/troubleshoot/troubleshoot-sso/ - /enterprise/troubleshoot/troubleshoot-sso/ + - /platform/security/authentication/single-sign-on/troubleshoot-sso/ --- This page describes common single sign-on (SSO) errors and their solutions. Issues can stem from your identity provider (IdP) configuration or Docker settings. @@ -117,7 +118,7 @@ If you have SCIM enabled, troubleshoot your SCIM connection using the following 1. Navigate back to **Identity & auth**, then **SSO and SCIM**, and verify your SCIM configuration: - Ensure that the SCIM Base URL and API Token in your IdP match those provided in Docker. - Verify that SCIM is enabled in both Docker and your IdP. -1. Ensure that the attributes being synced from your IdP match Docker's [supported attributes](/manuals/platform/security/provisioning/scim/provision-scim.md#supported-attributes) for SCIM. +1. Ensure that the attributes being synced from your IdP match Docker's [supported attributes](/manuals/security/provisioning/scim/provision-scim.md#supported-attributes) for SCIM. 1. Test user provisioning by trying to provision a test user through your IdP and verify if they appear in Docker. ## IdP-initiated sign in is not enabled for connection @@ -192,7 +193,7 @@ Ensure that the IdP SSO connection is returning the correct UPN value in the ass **Add and verify all domains** -Add and verify all domains and subdomains used as UPN by your IdP and associate them with your Docker SSO connection. For details, see [Configure single sign-on](/manuals/platform/security/authentication/single-sign-on/connect.md). +Add and verify all domains and subdomains used as UPN by your IdP and associate them with your Docker SSO connection. For details, see [Configure single sign-on](/manuals/security/authentication/single-sign-on/connect.md). ## Unable to find session diff --git a/content/manuals/platform/security/images/jit-disabled-flow.svg b/content/manuals/security/images/jit-disabled-flow.svg similarity index 100% rename from content/manuals/platform/security/images/jit-disabled-flow.svg rename to content/manuals/security/images/jit-disabled-flow.svg diff --git a/content/manuals/platform/security/images/jit-enabled-flow.svg b/content/manuals/security/images/jit-enabled-flow.svg similarity index 100% rename from content/manuals/platform/security/images/jit-enabled-flow.svg rename to content/manuals/security/images/jit-enabled-flow.svg diff --git a/content/manuals/platform/security/provisioning/_index.md b/content/manuals/security/provisioning/_index.md similarity index 99% rename from content/manuals/platform/security/provisioning/_index.md rename to content/manuals/security/provisioning/_index.md index 62c0fdfbdd28..3604309d8237 100644 --- a/content/manuals/platform/security/provisioning/_index.md +++ b/content/manuals/security/provisioning/_index.md @@ -7,6 +7,7 @@ weight: 30 aliases: - /security/for-admins/provisioning/ - /enterprise/security/provisioning/ + - /platform/security/provisioning/ grid: - title: "Add and manage domains" description: "Add, verify, and manage domains to control user access and enable auto-provisioning." diff --git a/content/manuals/platform/security/provisioning/auto-provisioning.md b/content/manuals/security/provisioning/auto-provisioning.md similarity index 89% rename from content/manuals/platform/security/provisioning/auto-provisioning.md rename to content/manuals/security/provisioning/auto-provisioning.md index 22905d6d6fa2..5775aba77022 100644 --- a/content/manuals/platform/security/provisioning/auto-provisioning.md +++ b/content/manuals/security/provisioning/auto-provisioning.md @@ -4,6 +4,8 @@ linkTitle: Auto-provision description: Auto-provision users by associating members to your organization when email addresses match a verified domain. keywords: user provisioning, just-in-time provisioning, JIT, autoprovision, Docker Admin, admin, security weight: 30 +aliases: + - /platform/security/provisioning/auto-provisioning/ --- Auto-provisioning automatically adds users to your organization when they sign in with email addresses that match your verified domains. You must verify a domain before enabling auto-provisioning. @@ -54,5 +56,5 @@ To disable auto-provisioning for a user: To choose a different method to provision users, you can set up: -- [SCIM provisioning](/manuals/platform/security/provisioning/scim/_index.md) for advanced user management. -- [Group mapping](/manuals/platform/security/provisioning/scim/group-mapping.md) to assign users to teams automatically. +- [SCIM provisioning](/manuals/security/provisioning/scim/_index.md) for advanced user management. +- [Group mapping](/manuals/security/provisioning/scim/group-mapping.md) to assign users to teams automatically. diff --git a/content/manuals/platform/security/provisioning/domain-management.md b/content/manuals/security/provisioning/domain-management.md similarity index 92% rename from content/manuals/platform/security/provisioning/domain-management.md rename to content/manuals/security/provisioning/domain-management.md index 5e0f764fd7fc..0c14bdc0523e 100644 --- a/content/manuals/platform/security/provisioning/domain-management.md +++ b/content/manuals/security/provisioning/domain-management.md @@ -7,6 +7,7 @@ aliases: - /security/for-admins/domain-management/ - /enterprise/security/domain-management/ - /platform/security/domains/domain-management/ + - /platform/security/provisioning/domain-management/ --- {{< summary-bar feature_name="Domain management" >}} @@ -92,7 +93,7 @@ Domain audit can't identify: - Users who authenticate using an account that doesn't have an email address associated with one of your verified domains -To prevent unidentifiable users from accessing Docker Desktop, [enforce sign-in](/manuals/platform/security/authentication/enforce-sign-in/_index.md). +To prevent unidentifiable users from accessing Docker Desktop, [enforce sign-in](/manuals/security/authentication/enforce-sign-in/_index.md). ### Run a domain audit @@ -116,10 +117,10 @@ CSV file. For more information on bulk inviting users, see ## Auto-provisioning -[Auto-provisioning](/manuals/platform/security/provisioning/auto-provisioning.md) uses verified domains to associate organization members with email address that match the verified domains. To override auto-provisioning, you can configure one of the two alternative methods: +[Auto-provisioning](/manuals/security/provisioning/auto-provisioning.md) uses verified domains to associate organization members with email address that match the verified domains. To override auto-provisioning, you can configure one of the two alternative methods: -- [Just-in-Time (JIT)](/manuals/platform/security/provisioning/just-in-time.md) provisioning -- [System for Cross-domain Identity Management (SCIM)](/manuals/platform/security/provisioning/scim/_index.md) +- [Just-in-Time (JIT)](/manuals/security/provisioning/just-in-time.md) provisioning +- [System for Cross-domain Identity Management (SCIM)](/manuals/security/provisioning/scim/_index.md) ## Delete a domain diff --git a/content/manuals/platform/security/provisioning/just-in-time.md b/content/manuals/security/provisioning/just-in-time.md similarity index 92% rename from content/manuals/platform/security/provisioning/just-in-time.md rename to content/manuals/security/provisioning/just-in-time.md index 9faf96896460..c6b3af2d9ae2 100644 --- a/content/manuals/platform/security/provisioning/just-in-time.md +++ b/content/manuals/security/provisioning/just-in-time.md @@ -6,6 +6,7 @@ linkTitle: Just-in-Time weight: 20 aliases: - /security/for-admins/provisioning/just-in-time/ + - /platform/security/provisioning/just-in-time/ --- {{< summary-bar feature_name="SSO" >}} @@ -79,6 +80,6 @@ Users are provisioned with JIT by default. If you enable SCIM, you can disable J ## Next steps -- Configure [SCIM provisioning](/manuals/platform/security/provisioning/scim/_index.md) for advanced user management. -- Set up [group mapping](/manuals/platform/security/provisioning/scim/group-mapping.md) to automatically assign users to teams. -- Review [Troubleshoot provisioning](/manuals/platform/security/provisioning/troubleshoot-provisioning.md). +- Configure [SCIM provisioning](/manuals/security/provisioning/scim/_index.md) for advanced user management. +- Set up [group mapping](/manuals/security/provisioning/scim/group-mapping.md) to automatically assign users to teams. +- Review [Troubleshoot provisioning](/manuals/security/provisioning/troubleshoot-provisioning.md). diff --git a/content/manuals/platform/security/provisioning/scim/_index.md b/content/manuals/security/provisioning/scim/_index.md similarity index 82% rename from content/manuals/platform/security/provisioning/scim/_index.md rename to content/manuals/security/provisioning/scim/_index.md index 4cd6f5769986..68cc5743cd27 100644 --- a/content/manuals/platform/security/provisioning/scim/_index.md +++ b/content/manuals/security/provisioning/scim/_index.md @@ -7,6 +7,7 @@ keywords: SCIM, SSO, user provisioning, de-provisioning, role mapping, assign us aliases: - /security/for-admins/scim/ - /security/for-admins/provisioning/scim/ + - /platform/security/provisioning/scim/ --- {{< summary-bar feature_name="SSO" >}} @@ -59,6 +60,6 @@ SCIM automates: ## Next steps -- [Migrate JIT to SCIM](/manuals/platform/security/provisioning/scim/migrate-scim.md) if users were provisioned with Just-in-Time (JIT) before you enabled SCIM. -- [Group mapping](/manuals/platform/security/provisioning/scim/group-mapping.md) to sync identity provider groups with members. -- [Troubleshoot provisioning](/manuals/platform/security/provisioning/troubleshoot-provisioning.md) for SCIM, JIT, and attribute issues. +- [Migrate JIT to SCIM](/manuals/security/provisioning/scim/migrate-scim.md) if users were provisioned with Just-in-Time (JIT) before you enabled SCIM. +- [Group mapping](/manuals/security/provisioning/scim/group-mapping.md) to sync identity provider groups with members. +- [Troubleshoot provisioning](/manuals/security/provisioning/troubleshoot-provisioning.md) for SCIM, JIT, and attribute issues. diff --git a/content/manuals/platform/security/provisioning/scim/group-mapping.md b/content/manuals/security/provisioning/scim/group-mapping.md similarity index 97% rename from content/manuals/platform/security/provisioning/scim/group-mapping.md rename to content/manuals/security/provisioning/scim/group-mapping.md index 00cce8cbcee7..b30f4e912557 100644 --- a/content/manuals/platform/security/provisioning/scim/group-mapping.md +++ b/content/manuals/security/provisioning/scim/group-mapping.md @@ -8,6 +8,7 @@ aliases: - /security/for-admins/group-mapping/ - /security/for-admins/provisioning/scim/group-mapping/ - /platform/security/provisioning/group-mapping/ +- /platform/security/provisioning/scim/group-mapping/ weight: 20 --- @@ -194,5 +195,5 @@ Once complete, a user who signs in to Docker through SSO is automatically added ## Next steps -- [Assign roles](/manuals/platform/security/roles-and-permissions/core-roles.md) to members of your org. -- [Enforce sign in](/manuals/platform/security/authentication/enforce-sign-in.md), if needed. +- [Assign roles](/manuals/security/roles-and-permissions/core-roles.md) to members of your org. +- [Enforce sign in](/manuals/security/authentication/enforce-sign-in.md), if needed. diff --git a/content/manuals/platform/security/provisioning/scim/migrate-scim.md b/content/manuals/security/provisioning/scim/migrate-scim.md similarity index 93% rename from content/manuals/platform/security/provisioning/scim/migrate-scim.md rename to content/manuals/security/provisioning/scim/migrate-scim.md index fa31fa18a97b..1bc55491f44d 100644 --- a/content/manuals/platform/security/provisioning/scim/migrate-scim.md +++ b/content/manuals/security/provisioning/scim/migrate-scim.md @@ -3,6 +3,8 @@ title: Migrate JIT to SCIM linkTitle: Migrate description: Learn how to migrate from just-in-time (JIT) to SCIM. weight: 30 +aliases: + - /platform/security/provisioning/scim/migrate-scim/ --- If you already have users provisioned through Just-in-Time (JIT) and want to @@ -171,10 +173,10 @@ If a user fails to reappear after removal: 4. Check provisioning logs in your identity provider for errors. For more troubleshooting guidance, see -[Troubleshoot provisioning](/manuals/platform/security/provisioning/troubleshoot-provisioning.md). +[Troubleshoot provisioning](/manuals/security/provisioning/troubleshoot-provisioning.md). ## Next steps -- Set up [Group mapping](/manuals/platform/security/provisioning/scim/group-mapping.md). -- [Assign roles](/manuals/platform/security/roles-and-permissions/core-roles.md) to members of your org. -- [Enforce sign in](/manuals/platform/security/authentication/enforce-sign-in.md), if needed. +- Set up [Group mapping](/manuals/security/provisioning/scim/group-mapping.md). +- [Assign roles](/manuals/security/roles-and-permissions/core-roles.md) to members of your org. +- [Enforce sign in](/manuals/security/authentication/enforce-sign-in.md), if needed. diff --git a/content/manuals/platform/security/provisioning/scim/provision-scim.md b/content/manuals/security/provisioning/scim/provision-scim.md similarity index 94% rename from content/manuals/platform/security/provisioning/scim/provision-scim.md rename to content/manuals/security/provisioning/scim/provision-scim.md index 069bf870c131..9a6220064640 100644 --- a/content/manuals/platform/security/provisioning/scim/provision-scim.md +++ b/content/manuals/security/provisioning/scim/provision-scim.md @@ -5,6 +5,7 @@ description: Learn how System for Cross-domain Identity Management works and how weight: 10 aliases: - /platform/security/provisioning/scim/ + - /platform/security/provisioning/scim/provision-scim/ --- {{< summary-bar feature_name="SSO" >}} @@ -37,7 +38,7 @@ For additional details about supported attributes and SCIM, see > your SCIM values. > > Alternatively, you can disable JIT provisioning to rely solely on SCIM. -> For details, see [Just-in-Time](/manuals/platform/security/provisioning/just-in-time.md). +> For details, see [Just-in-Time](/manuals/security/provisioning/just-in-time.md). ## Enable SCIM in Docker @@ -152,7 +153,7 @@ Next, [set up role mapping](#set-up-role-mapping). ## Set up role mapping -You can assign [Docker roles](/manuals/platform/security/roles-and-permissions/_index.md) to +You can assign [Docker roles](/manuals/security/roles-and-permissions/_index.md) to users by adding optional SCIM attributes in your IdP. These attributes override default role and team values set in your SSO configuration. @@ -166,7 +167,7 @@ The following table lists the supported optional user-level attributes: | Attribute | Possible values | Notes | | ------------ | ---------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| `dockerRole` | `member`, `editor`, or `owner` | If not set, the user defaults to the `member` role. Setting this attribute overrides the default.

For role definitions, see [Roles and permissions](/manuals/platform/security/roles-and-permissions/_index.md). | +| `dockerRole` | `member`, `editor`, or `owner` | If not set, the user defaults to the `member` role. Setting this attribute overrides the default.

For role definitions, see [Roles and permissions](/manuals/security/roles-and-permissions/_index.md). | | `dockerOrg` | Docker `organizationName` (e.g., `moby`) | Overrides the default organization configured in your SSO connection.

If unset, the user is provisioned to the default organization. If `dockerOrg` and `dockerTeam` are both set, the user is provisioned to the team within the specified organization. | | `dockerTeam` | Docker `teamName` (e.g., `developers`) | Provisions the user to the specified team in the default or specified organization. If the team doesn't exist, it is automatically created.

You can still use [group mapping](group-mapping.md) to assign users to multiple teams across organizations. | @@ -178,7 +179,7 @@ This value is required in your identity provider when creating custom SCIM attri ### Step one: Set up role mapping in Okta -1. Setup [SSO](/manuals/platform/security/authentication/single-sign-on/connect.md) and SCIM first. +1. Setup [SSO](/manuals/security/authentication/single-sign-on/connect.md) and SCIM first. 1. In the Okta admin portal, go to **Directory**, select **Profile Editor**, and then **User (Default)**. 1. Select **Add Attribute** and configure the values for the role, organization, @@ -221,7 +222,7 @@ group will inherit these attributes upon provisioning. ### Step one: Configure attribute mappings -1. Complete the [SCIM provisioning setup](/manuals/platform/security/provisioning/scim/provision-scim.md#enable-scim-in-docker). +1. Complete the [SCIM provisioning setup](/manuals/security/provisioning/scim/provision-scim.md#enable-scim-in-docker). 1. In the Azure Portal, open **Microsoft Entra ID** > **Enterprise Applications**, and select your SCIM application. 1. Go to **Provisioning** > **Mappings** > @@ -230,7 +231,7 @@ group will inherit these attributes upon provisioning. - `userPrincipalName` -> `userName` - `mail` -> `emails.value` - Optional. Map `dockerRole`, `dockerOrg`, or `dockerTeam` using one of the - [mapping methods](/manuals/platform/security/provisioning/scim/provision-scim.md#set-up-role-mapping). + [mapping methods](/manuals/security/provisioning/scim/provision-scim.md#set-up-role-mapping). 1. Remove any unsupported attributes to prevent sync errors. 1. Optional. Go to **Mappings** > **Provision Azure Active Directory Groups**: - If group provisioning causes errors, set **Enabled** to **No**. @@ -370,5 +371,5 @@ To disable SCIM: ## Next steps -- Set up [Group mapping](/manuals/platform/security/provisioning/scim/group-mapping.md). -- [Troubleshoot provisioning](/manuals/platform/security/provisioning/troubleshoot-provisioning.md). +- Set up [Group mapping](/manuals/security/provisioning/scim/group-mapping.md). +- [Troubleshoot provisioning](/manuals/security/provisioning/troubleshoot-provisioning.md). diff --git a/content/manuals/platform/security/provisioning/troubleshoot-provisioning.md b/content/manuals/security/provisioning/troubleshoot-provisioning.md similarity index 97% rename from content/manuals/platform/security/provisioning/troubleshoot-provisioning.md rename to content/manuals/security/provisioning/troubleshoot-provisioning.md index d682ac63cecf..b61089a19d7b 100644 --- a/content/manuals/platform/security/provisioning/troubleshoot-provisioning.md +++ b/content/manuals/security/provisioning/troubleshoot-provisioning.md @@ -7,6 +7,7 @@ tags: [Troubleshooting] toc_max: 2 aliases: - /enterprise/troubleshoot/troubleshoot-provisioning/ + - /platform/security/provisioning/troubleshoot-provisioning/ --- This page helps troubleshoot common user provisioning issues including user roles, attributes, and unexpected account behavior with SCIM and Just-in-Time (JIT) provisioning. diff --git a/content/manuals/platform/security/roles-and-permissions/_index.md b/content/manuals/security/roles-and-permissions/_index.md similarity index 90% rename from content/manuals/platform/security/roles-and-permissions/_index.md rename to content/manuals/security/roles-and-permissions/_index.md index abd3689982ab..170e91789d06 100644 --- a/content/manuals/platform/security/roles-and-permissions/_index.md +++ b/content/manuals/security/roles-and-permissions/_index.md @@ -14,22 +14,23 @@ aliases: - /security/for-admins/roles-and-permissions/ - /docker-hub/roles-and-permissions/ - /enterprise/security/roles-and-permissions/ + - /platform/security/roles-and-permissions/ grid: - title: Core roles description: >- Compare permissions for the built-in Member, Editor, and Owner roles. icon: shield-check - link: /platform/security/roles-and-permissions/core-roles/ + link: /security/roles-and-permissions/core-roles/ - title: Custom roles description: >- Build permission sets that match your organization's access control needs. icon: adjustments-horizontal - link: /platform/security/roles-and-permissions/custom-roles/ + link: /security/roles-and-permissions/custom-roles/ - title: Custom roles permissions description: >- Review every permission you can assign to a custom role. icon: list-bullet - link: /platform/security/roles-and-permissions/custom-roles/permissions-reference/ + link: /security/roles-and-permissions/custom-roles/permissions-reference/ --- {{< summary-bar feature_name="General admin" >}} diff --git a/content/manuals/platform/security/roles-and-permissions/core-roles.md b/content/manuals/security/roles-and-permissions/core-roles.md similarity index 95% rename from content/manuals/platform/security/roles-and-permissions/core-roles.md rename to content/manuals/security/roles-and-permissions/core-roles.md index 62125d7e6282..1054582dd501 100644 --- a/content/manuals/platform/security/roles-and-permissions/core-roles.md +++ b/content/manuals/security/roles-and-permissions/core-roles.md @@ -8,6 +8,8 @@ keywords: >- permissions, company owner, Docker Hub, Docker Scout, Docker Build Cloud, OIDC, teams, access control, Docker Business, custom roles weight: 10 +aliases: + - /platform/security/roles-and-permissions/core-roles/ --- {{< summary-bar feature_name="General admin" >}} @@ -15,7 +17,7 @@ weight: 10 Docker organizations use built-in Member, Editor, and Owner roles with predefined permissions. This reference compares their permissions across Docker products. To assign a different combination of permissions, use -[custom roles](/manuals/platform/security/roles-and-permissions/custom-roles/_index.md) +[custom roles](/manuals/security/roles-and-permissions/custom-roles/_index.md) instead. ## Core roles @@ -103,7 +105,7 @@ Use team permissions for that. > > For more granular access control, > [upgrade to a Docker Business plan](https://www.docker.com/pricing?ref=Docs&refAction=DocsEnterpriseCoreRoles) -> to use [custom roles](/manuals/platform/security/roles-and-permissions/custom-roles/_index.md). +> to use [custom roles](/manuals/security/roles-and-permissions/custom-roles/_index.md). _\* If not part of a company_ @@ -129,7 +131,7 @@ _\* If not part of a company_ ## Next steps -- [Custom roles](/manuals/platform/security/roles-and-permissions/custom-roles/_index.md): +- [Custom roles](/manuals/security/roles-and-permissions/custom-roles/_index.md): Create tailored permission sets on a Docker Business plan - [Manage organization members](/manuals/accounts/organization/manage/members.md): Invite users and assign roles diff --git a/content/manuals/platform/security/roles-and-permissions/custom-roles/_index.md b/content/manuals/security/roles-and-permissions/custom-roles/_index.md similarity index 85% rename from content/manuals/platform/security/roles-and-permissions/custom-roles/_index.md rename to content/manuals/security/roles-and-permissions/custom-roles/_index.md index fd5fa2c469ca..8ba69af1b31a 100644 --- a/content/manuals/platform/security/roles-and-permissions/custom-roles/_index.md +++ b/content/manuals/security/roles-and-permissions/custom-roles/_index.md @@ -14,11 +14,13 @@ grid: - title: Manage custom roles description: Create, edit, assign, and delete custom roles for users and teams. icon: adjustments-horizontal - link: /platform/security/roles-and-permissions/custom-roles/manage/ + link: /security/roles-and-permissions/custom-roles/manage/ - title: Permissions reference description: Review every permission you can assign when building a custom role. icon: list-bullet - link: /platform/security/roles-and-permissions/custom-roles/permissions-reference/ + link: /security/roles-and-permissions/custom-roles/permissions-reference/ +aliases: + - /platform/security/roles-and-permissions/custom-roles/ --- {{< summary-bar feature_name="Custom roles" >}} @@ -32,7 +34,7 @@ Custom roles are permission sets that you choose to grant access to users or tea If Docker's predefined permission sets meet your needs, use -[core roles](/manuals/platform/security/roles-and-permissions/core-roles.md) +[core roles](/manuals/security/roles-and-permissions/core-roles.md) instead. ## Prerequisites diff --git a/content/manuals/platform/security/roles-and-permissions/custom-roles/manage.md b/content/manuals/security/roles-and-permissions/custom-roles/manage.md similarity index 96% rename from content/manuals/platform/security/roles-and-permissions/custom-roles/manage.md rename to content/manuals/security/roles-and-permissions/custom-roles/manage.md index c60fd708792b..97a57a024831 100644 --- a/content/manuals/platform/security/roles-and-permissions/custom-roles/manage.md +++ b/content/manuals/security/roles-and-permissions/custom-roles/manage.md @@ -8,6 +8,8 @@ keywords: >- custom roles, manage custom roles, role assignments, access control, Docker Home, Docker Business, organization roles, permissions, teams weight: 10 +aliases: + - /platform/security/roles-and-permissions/custom-roles/manage/ --- {{< summary-bar feature_name="Custom roles" >}} @@ -158,7 +160,7 @@ To see which users and teams are assigned to roles: - [Custom roles permissions reference](permissions-reference.md): Review permissions you can grant to a custom role -- [Core roles and permissions](/manuals/platform/security/roles-and-permissions/core-roles.md): +- [Core roles and permissions](/manuals/security/roles-and-permissions/core-roles.md): Compare built-in Member, Editor, and Owner permissions - [Manage organization members](/manuals/accounts/organization/manage/members.md): Invite and manage users in your organization diff --git a/content/manuals/platform/security/roles-and-permissions/custom-roles/permissions-reference.md b/content/manuals/security/roles-and-permissions/custom-roles/permissions-reference.md similarity index 96% rename from content/manuals/platform/security/roles-and-permissions/custom-roles/permissions-reference.md rename to content/manuals/security/roles-and-permissions/custom-roles/permissions-reference.md index 0871da550e96..a697ecdb0b7f 100644 --- a/content/manuals/platform/security/roles-and-permissions/custom-roles/permissions-reference.md +++ b/content/manuals/security/roles-and-permissions/custom-roles/permissions-reference.md @@ -10,6 +10,8 @@ keywords: >- management, billing, AI Governance, access tokens, SSO, SCIM, OIDC, DHI, Docker Offload, security weight: 20 +aliases: + - /platform/security/roles-and-permissions/custom-roles/permissions-reference/ --- {{< summary-bar feature_name="Custom roles" >}} @@ -81,5 +83,5 @@ the following tables to [create or edit a custom role](manage.md). - [Manage custom roles](manage.md): Create, assign, and delete custom roles -- [Core roles and permissions](/manuals/platform/security/roles-and-permissions/core-roles.md): +- [Core roles and permissions](/manuals/security/roles-and-permissions/core-roles.md): Compare built-in Member, Editor, and Owner permissions diff --git a/content/manuals/platform/security/security-announcements.md b/content/manuals/security/security-announcements.md similarity index 97% rename from content/manuals/platform/security/security-announcements.md rename to content/manuals/security/security-announcements.md index 58ba226274c1..70a24868413d 100644 --- a/content/manuals/platform/security/security-announcements.md +++ b/content/manuals/security/security-announcements.md @@ -12,9 +12,10 @@ aliases: - /security/security-announcements/ - /platform/security/resources/security-announcements/ - /security-announcements/ + - /platform/security/security-announcements/ --- -[Subscribe to security RSS feed](/platform/security/security-announcements/index.xml) +[Subscribe to security RSS feed](/security/security-announcements/index.xml) ## Docker Desktop 4.86.0 security update: CVE-2026-17106 @@ -121,7 +122,7 @@ We strongly encourage you to update to Docker Desktop [4.34.2](/manuals/desktop/ _Last updated July, 2024_ -When [SSO enforcement](/manuals/platform/security/authentication/single-sign-on/connect.md) was first introduced, Docker provided a grace period to continue to let passwords be used on the Docker CLI when authenticating to Docker Hub. This was allowed so organizations could more easily use SSO enforcement. It is recommended that administrators configuring SSO encourage users using the CLI [to switch over to Personal Access Tokens](/manuals/platform/security/authentication/single-sign-on/_index.md#prerequisites) in anticipation of this grace period ending. +When [SSO enforcement](/manuals/security/authentication/single-sign-on/connect.md) was first introduced, Docker provided a grace period to continue to let passwords be used on the Docker CLI when authenticating to Docker Hub. This was allowed so organizations could more easily use SSO enforcement. It is recommended that administrators configuring SSO encourage users using the CLI [to switch over to Personal Access Tokens](/manuals/security/authentication/single-sign-on/_index.md#prerequisites) in anticipation of this grace period ending. On September 16, 2024, the grace period ended and passwords can no longer authenticate to Docker Hub via the Docker CLI when SSO is enforced. Affected users are required to switch over to using PATs to continue signing in. diff --git a/content/manuals/unassociated-machines/_index.md b/content/manuals/unassociated-machines/_index.md index cc8a9e0ea8fa..035b0f54f786 100644 --- a/content/manuals/unassociated-machines/_index.md +++ b/content/manuals/unassociated-machines/_index.md @@ -72,12 +72,12 @@ You can: > [!NOTE] > > Sign-in enforcement for unassociated machines is different from -> the [organization-level sign-in enforcement](/platform/security/authentication/enforce-sign-in/) +> the [organization-level sign-in enforcement](/security/authentication/enforce-sign-in/) > available through `registry.json` and configuration profiles. This sign-in > enforcement only requires users to sign in so admins can identify who is > using the machine, meaning users can sign in with any email address. For more > stringent security controls that limit sign-ins to users who are already part -> of your organization, see [Enforce sign-in](/platform/security/authentication/enforce-sign-in/). +> of your organization, see [Enforce sign-in](/security/authentication/enforce-sign-in/). Sign-in enforcement helps you identify who is using unassociated machines in your organization. When you enable enforcement, users on these machines will @@ -160,9 +160,9 @@ organization in two ways: - Auto-provisioning: If you have verified domains with auto-provisioning enabled, users who sign in with a matching email domain will automatically be added to your organization. For more information on verifying domains and - auto-provisioning, see [Domain management](/platform/security/provisioning/domain-management). + auto-provisioning, see [Domain management](/security/provisioning/domain-management). - SSO user provisioning: If you have SSO configured with - [Just-in-Time provisioning](/manuals/platform/security/provisioning/just-in-time.md), + [Just-in-Time provisioning](/manuals/security/provisioning/just-in-time.md), users who sign in through your SSO connection will automatically be added to your organization. - Manual addition: If you don't have auto-provisioning or SSO set up, or if a diff --git a/content/reference/api/hub/latest.yaml b/content/reference/api/hub/latest.yaml index f5ffdf3e5175..e1df4223f091 100644 --- a/content/reference/api/hub/latest.yaml +++ b/content/reference/api/hub/latest.yaml @@ -101,7 +101,7 @@ tags: - name: access-tokens x-displayName: Personal Access Tokens description: | - The Personal Access Token endpoints lets you manage personal access tokens. For more information, see [Access Tokens](https://docs.docker.com/platform/security/access-tokens/personal-access-tokens/). + The Personal Access Token endpoints lets you manage personal access tokens. For more information, see [Access Tokens](https://docs.docker.com/security/access-tokens/personal-access-tokens/). You can use a personal access token instead of a password in the [Docker CLI](https://docs.docker.com/engine/reference/commandline/cli/) or in the [Create an authentication token](#operation/PostUsersLogin) route to obtain a bearer token. diff --git a/data/redirects.yml b/data/redirects.yml index 5612772e4af0..285e4800cd6b 100644 --- a/data/redirects.yml +++ b/data/redirects.yml @@ -10,7 +10,7 @@ # in its help output, which can be redirected to elsewhere in the documentation. "/learn/": - /learn -"/platform/security/access-tokens/personal-access-tokens/": +"/security/access-tokens/personal-access-tokens/": - /go/access-tokens/ "/agentic-platform/": - /go/dap/ From 94c913d5cafeb7a6866ffc4486a5cb5b7b9c7108 Mon Sep 17 00:00:00 2001 From: Alexa Date: Mon, 31 Aug 2026 13:12:09 -0500 Subject: [PATCH 04/19] docs: fix Security self-aliases and leftover enterprise/security refs Co-authored-by: Cursor --- content/manuals/accounts/individual/_index.md | 2 +- content/manuals/accounts/organization/_index.md | 2 +- content/manuals/security/_index.md | 1 - content/manuals/security/security-announcements.md | 1 - 4 files changed, 2 insertions(+), 4 deletions(-) diff --git a/content/manuals/accounts/individual/_index.md b/content/manuals/accounts/individual/_index.md index 33e5a40a46b1..3137914f56bf 100644 --- a/content/manuals/accounts/individual/_index.md +++ b/content/manuals/accounts/individual/_index.md @@ -54,7 +54,7 @@ Docker also ties a verified email to the account. - Email: How Docker contacts you for notifications and security-related communications. - Sign-in method: Email and password, - [single sign-on (SSO)](/manuals/enterprise/security/single-sign-on/_index.md), + [single sign-on (SSO)](/manuals/security/authentication/single-sign-on/_index.md), Google, or GitHub. ## Next steps diff --git a/content/manuals/accounts/organization/_index.md b/content/manuals/accounts/organization/_index.md index 5749f24aa32b..e84bc743be6e 100644 --- a/content/manuals/accounts/organization/_index.md +++ b/content/manuals/accounts/organization/_index.md @@ -76,7 +76,7 @@ permissions. For details about each role and its permissions, see [Roles and -permissions](/manuals/enterprise/security/roles-and-permissions/_index.md). +permissions](/manuals/security/roles-and-permissions/_index.md). ## Company and organization hierarchy diff --git a/content/manuals/security/_index.md b/content/manuals/security/_index.md index dbe521593342..0d1e1afe3d47 100644 --- a/content/manuals/security/_index.md +++ b/content/manuals/security/_index.md @@ -5,7 +5,6 @@ description: Learn about developer-level security features like 2FA and access t keywords: docker, docker hub, docker desktop, security, developer security, 2FA, access tokens weight: 40 aliases: - - /security/ - /security/for-developers/ - /platform/security/ params: diff --git a/content/manuals/security/security-announcements.md b/content/manuals/security/security-announcements.md index 70a24868413d..141e55ddbf30 100644 --- a/content/manuals/security/security-announcements.md +++ b/content/manuals/security/security-announcements.md @@ -9,7 +9,6 @@ weight: 1 toc_min: 1 toc_max: 2 aliases: - - /security/security-announcements/ - /platform/security/resources/security-announcements/ - /security-announcements/ - /platform/security/security-announcements/ From d0f45e092af05a512e304f61c67749de341c8f83 Mon Sep 17 00:00:00 2001 From: Alexa Date: Mon, 31 Aug 2026 13:14:47 -0500 Subject: [PATCH 05/19] docs: squash-merge subscription/billing IA into platform-enterprise-IA Co-authored-by: Cursor --- .github/CODEOWNERS | 4 +-- .github/labeler.yml | 4 +-- content/manuals/_index.md | 10 ++---- .../individual/deactivate-user-account.md | 2 +- .../accounts/organization/manage/_index.md | 2 +- .../organization/manage/deactivate-account.md | 2 +- .../organization/manage/manage-licenses.md | 6 ++-- .../organization/manage/manage-products.md | 2 +- .../accounts/organization/setup/onboard.md | 2 +- .../accounts/organization/setup/orgs.md | 2 +- content/manuals/agentic-platform/_index.md | 2 +- content/manuals/agentic-platform/faq.md | 2 +- content/manuals/agentic-platform/sandboxes.md | 2 +- .../ai/sandboxes/governance/audit/_index.md | 2 +- .../sandboxes/governance/audit/configure.md | 2 +- .../manuals/build-cloud/builder-settings.md | 2 +- content/manuals/desktop/release-notes.md | 2 +- .../manuals/dhi/how-to/select-enterprise.md | 2 +- content/manuals/docker-hub/release-notes.md | 10 +++--- content/manuals/docker-hub/troubleshoot.md | 2 +- content/manuals/scout/_index.md | 2 +- .../manuals/subscription-billing/_index.md | 16 ++++++++++ .../billing/3d-secure.md | 10 +++--- .../billing/_index.md | 21 +++++------- .../billing/details.md | 5 +-- .../billing/history.md | 3 +- .../billing/payment-method.md | 3 +- .../billing/tax-certificate.md | 4 ++- .../desktop-license.md | 3 +- .../subscription-billing/faqs/_index.md | 9 ++++++ .../faqs/billing.md} | 14 ++++---- .../faqs/subscription.md} | 12 ++++--- .../subscription/_index.md | 32 ++++++++----------- .../subscription/manage.md | 17 +++++----- .../subscription/plans/_index.md | 13 ++++---- .../subscription/plans/ai-governance.md | 1 + .../subscription/plans/dhi.md | 1 + .../plans/docker-agentic-platform.md | 8 +++-- .../plans/docker-verified-publisher.md | 2 ++ .../subscription/plans/docker.md | 1 + .../subscription/plans/gordon.md | 3 +- data/redirects.yml | 2 +- data/whats-new.json | 2 +- 43 files changed, 139 insertions(+), 109 deletions(-) create mode 100644 content/manuals/subscription-billing/_index.md rename content/manuals/{ => subscription-billing}/billing/3d-secure.md (79%) rename content/manuals/{ => subscription-billing}/billing/_index.md (83%) rename content/manuals/{ => subscription-billing}/billing/details.md (89%) rename content/manuals/{ => subscription-billing}/billing/history.md (97%) rename content/manuals/{ => subscription-billing}/billing/payment-method.md (98%) rename content/manuals/{ => subscription-billing}/billing/tax-certificate.md (96%) rename content/manuals/{subscription => subscription-billing}/desktop-license.md (97%) create mode 100644 content/manuals/subscription-billing/faqs/_index.md rename content/manuals/{billing/faqs.md => subscription-billing/faqs/billing.md} (82%) rename content/manuals/{subscription/faq.md => subscription-billing/faqs/subscription.md} (77%) rename content/manuals/{ => subscription-billing}/subscription/_index.md (68%) rename content/manuals/{ => subscription-billing}/subscription/manage.md (84%) rename content/manuals/{ => subscription-billing}/subscription/plans/_index.md (80%) rename content/manuals/{ => subscription-billing}/subscription/plans/ai-governance.md (97%) rename content/manuals/{ => subscription-billing}/subscription/plans/dhi.md (99%) rename content/manuals/{ => subscription-billing}/subscription/plans/docker-agentic-platform.md (91%) rename content/manuals/{ => subscription-billing}/subscription/plans/docker-verified-publisher.md (98%) rename content/manuals/{ => subscription-billing}/subscription/plans/docker.md (99%) rename content/manuals/{ => subscription-billing}/subscription/plans/gordon.md (97%) diff --git a/.github/CODEOWNERS b/.github/CODEOWNERS index 9d959ab3647a..0431b1c2305e 100644 --- a/.github/CODEOWNERS +++ b/.github/CODEOWNERS @@ -25,14 +25,12 @@ /content/reference/cli/ @dvdksn -/content/manuals/subscription/ @sarahsanders-docker +/content/manuals/subscription-billing/ @sarahsanders-docker /content/manuals/security/ @aevesdocker @sarahsanders-docker /content/manuals/admin/ @sarahsanders-docker -/content/manuals/billing/ @sarahsanders-docker - /content/manuals/accounts/ @sarahsanders-docker /content/manuals/ai/ @dvdksn diff --git a/.github/labeler.yml b/.github/labeler.yml index 32796e097775..fbb9eeffe71c 100644 --- a/.github/labeler.yml +++ b/.github/labeler.yml @@ -143,12 +143,12 @@ area/scout: area/billing: - changed-files: - any-glob-to-any-file: - - content/manuals/billing/** + - content/manuals/subscription-billing/** area/subscription: - changed-files: - any-glob-to-any-file: - - content/manuals/subscription/** + - content/manuals/subscription-billing/** area/admin: - changed-files: diff --git a/content/manuals/_index.md b/content/manuals/_index.md index bcf629528ea4..42d38b20d021 100644 --- a/content/manuals/_index.md +++ b/content/manuals/_index.md @@ -83,10 +83,10 @@ params: description: Manage Docker individual and organization accounts. icon: user-circle link: /accounts/ - - title: Billing - description: Manage billing and payment methods. + - title: Subscription and billing + description: Manage Docker subscriptions, plans, billing, and payments. icon: credit-card - link: /billing/ + link: /subscription-billing/ - title: Security description: Security guardrails for both administrators and developers. icon: lock-closed @@ -95,10 +95,6 @@ params: description: Frequently asked questions about Docker accounts, organizations, companies, and security. icon: question-mark-circle link: /faqs/ - - title: Subscription - description: Commercial use licenses for Docker products. - icon: credit-card - link: /subscription/ enterprise: - title: Deploy Docker Desktop description: Deploy Docker Desktop at scale within your company diff --git a/content/manuals/accounts/individual/deactivate-user-account.md b/content/manuals/accounts/individual/deactivate-user-account.md index 31c80a2bd908..84e6201bbf80 100644 --- a/content/manuals/accounts/individual/deactivate-user-account.md +++ b/content/manuals/accounts/individual/deactivate-user-account.md @@ -40,7 +40,7 @@ requirements: and then remove yourself, or deactivate the company. - If you have an active Docker subscription, [downgrade it to a Docker Personal - subscription](/manuals/subscription/plans/docker.md#cancel-a-docker-plan). + subscription](/manuals/subscription-billing/subscription/plans/docker.md#cancel-a-docker-plan). - Download any images and tags you want to keep. Use `docker pull -a ` to pull all tags, or `docker pull :` to pull a specific tag. diff --git a/content/manuals/accounts/organization/manage/_index.md b/content/manuals/accounts/organization/manage/_index.md index 507c5117a293..e9297fad83b1 100644 --- a/content/manuals/accounts/organization/manage/_index.md +++ b/content/manuals/accounts/organization/manage/_index.md @@ -28,7 +28,7 @@ grid: - title: Billing description: Manage payment methods and view billing history. icon: credit-card - link: /billing/ + link: /subscription-billing/billing/ aliases: - /admin/organization/manage/ --- diff --git a/content/manuals/accounts/organization/manage/deactivate-account.md b/content/manuals/accounts/organization/manage/deactivate-account.md index 2ff11a772b8e..1dfc7d089d7b 100644 --- a/content/manuals/accounts/organization/manage/deactivate-account.md +++ b/content/manuals/accounts/organization/manage/deactivate-account.md @@ -34,7 +34,7 @@ organization: to pull all tags, or `docker pull :` to pull a specific tag. - If you have an active Docker subscription, [downgrade it to a basic organization - account](/manuals/subscription/plans/docker.md#cancel-a-docker-plan). + account](/manuals/subscription-billing/subscription/plans/docker.md#cancel-a-docker-plan). - Remove all other members within the organization. - Unlink your [GitHub and Bitbucket accounts](/manuals/docker-hub/repos/manage/builds/link-source.md#unlink-a-github-user-account). diff --git a/content/manuals/accounts/organization/manage/manage-licenses.md b/content/manuals/accounts/organization/manage/manage-licenses.md index b0e6be325671..96ab939bf173 100644 --- a/content/manuals/accounts/organization/manage/manage-licenses.md +++ b/content/manuals/accounts/organization/manage/manage-licenses.md @@ -15,7 +15,7 @@ products. > [!TIP] > To learn more about product licenses, Docker Core seats, and other Docker -> add-ons, see [Docker plans](/manuals/subscription/plans/_index.md), +> add-ons, see [Docker plans](/manuals/subscription-billing/subscription/plans/_index.md), > or >
contact sales > to purchase licenses. @@ -116,11 +116,11 @@ To manage licenses for your organization: Explore Docker Core add-ons and products that need licenses: -- [Docker plans](/manuals/subscription/plans/_index.md) to learn about different +- [Docker plans](/manuals/subscription-billing/subscription/plans/_index.md) to learn about different add-ons - [Manage seats](/manuals/accounts/organization/manage/manage-seats.md) to add more seats to your Docker Core subscription -- [AI Governance plan](/manuals/subscription/plans/ai-governance.md) to learn +- [AI Governance plan](/manuals/subscription-billing/subscription/plans/ai-governance.md) to learn about AI Governance license usage and billing - [Docker Offload](/manuals/offload/about.md) to let your developers offload building and running containers to the cloud diff --git a/content/manuals/accounts/organization/manage/manage-products.md b/content/manuals/accounts/organization/manage/manage-products.md index c829fd9514c9..aa19d8e3fe36 100644 --- a/content/manuals/accounts/organization/manage/manage-products.md +++ b/content/manuals/accounts/organization/manage/manage-products.md @@ -141,7 +141,7 @@ following table to learn where you can monitor organization usage: | Docker Offload | From [Docker Home](https://app.docker.com/), select **Offload**, then **Offload activity**. See [Docker Offload usage and billing](../../../offload/usage.md) for more details. | If your usage or seat count exceeds your subscription amount, you can -[add seats](./manage-seats.md) or [view available Docker plans](../../../subscription/plans/_index.md) to meet your needs. +[add seats](./manage-seats.md) or [view available Docker plans](../../../subscription-billing/subscription/plans/_index.md) to meet your needs. ## Next steps diff --git a/content/manuals/accounts/organization/setup/onboard.md b/content/manuals/accounts/organization/setup/onboard.md index a42e27c5e369..33de537f5032 100644 --- a/content/manuals/accounts/organization/setup/onboard.md +++ b/content/manuals/accounts/organization/setup/onboard.md @@ -123,7 +123,7 @@ For more details, see [Invite members](/manuals/accounts/organization/manage/mem Configuring SSO and SCIM is optional and only available to Docker Business subscribers. To upgrade a Docker Team subscription to a Docker Business -subscription, see [Upgrade a plan](/manuals/subscription/manage.md#upgrade-plans). +subscription, see [Upgrade a plan](/manuals/subscription-billing/subscription/manage.md#upgrade-plans). Use your identity provider (IdP) to manage members and provision them to Docker automatically via SSO and SCIM. See the following for more details: diff --git a/content/manuals/accounts/organization/setup/orgs.md b/content/manuals/accounts/organization/setup/orgs.md index c2097d18713c..b2900112398f 100644 --- a/content/manuals/accounts/organization/setup/orgs.md +++ b/content/manuals/accounts/organization/setup/orgs.md @@ -72,7 +72,7 @@ the following steps: 1. Based on the number of seats from the secondary organization, [purchase additional seats](../manage/manage-seats.md) for the primary organization account that you want to keep. 1. Manually add users to the primary organization and remove existing users from the secondary organization. 1. Manually move over your data, including all repositories. -1. Once you're done moving all of your users and data, [downgrade](../../../subscription/plans/docker.md#cancel-a-docker-plan) the secondary account to a free subscription. Note that Docker does not offer refunds for downgrading organizations mid-billing cycle. +1. Once you're done moving all of your users and data, [downgrade](../../../subscription-billing/subscription/plans/docker.md#cancel-a-docker-plan) the secondary account to a free subscription. Note that Docker does not offer refunds for downgrading organizations mid-billing cycle. If your organization has a Docker Business subscription with a purchase order, contact Support or your Account Manager at Docker. diff --git a/content/manuals/agentic-platform/_index.md b/content/manuals/agentic-platform/_index.md index 179c8e790c77..a029ae5fb65a 100644 --- a/content/manuals/agentic-platform/_index.md +++ b/content/manuals/agentic-platform/_index.md @@ -65,6 +65,6 @@ Account-level configuration can be reused across sandboxes: To begin, open [Docker Agentic Platform](https://agentic-platform.docker.com/) and sign in with your Docker account. Docker meters sandbox compute per second. -For account and payment information, see [Docker Billing](/billing/). +For account and payment information, see [Docker Billing](/subscription-billing/billing/). {{< grid >}} diff --git a/content/manuals/agentic-platform/faq.md b/content/manuals/agentic-platform/faq.md index e40da49e8205..3f56f823eb32 100644 --- a/content/manuals/agentic-platform/faq.md +++ b/content/manuals/agentic-platform/faq.md @@ -49,7 +49,7 @@ also shows the equivalent hourly rate. Model inference is billed separately. The sandbox uses your credential for an external model provider, which meters and bills inference under that provider -account. See [Docker Billing](/billing/) for account, usage, and payment +account. See [Docker Billing](/subscription-billing/billing/) for account, usage, and payment information. ## How long are logs, telemetry, and snapshots retained? diff --git a/content/manuals/agentic-platform/sandboxes.md b/content/manuals/agentic-platform/sandboxes.md index b9ecf3b49035..595339a5422a 100644 --- a/content/manuals/agentic-platform/sandboxes.md +++ b/content/manuals/agentic-platform/sandboxes.md @@ -62,7 +62,7 @@ when the sandbox is created and cannot be changed while it runs. Docker bills sandbox compute per second while the sandbox runs. Model inference uses your external provider credential and is metered by that provider. For -account, usage, and payment information, see [Docker Billing](/billing/). +account, usage, and payment information, see [Docker Billing](/subscription-billing/billing/). ## Check sandbox configuration diff --git a/content/manuals/ai/sandboxes/governance/audit/_index.md b/content/manuals/ai/sandboxes/governance/audit/_index.md index 360df806f4e3..391319b7546e 100644 --- a/content/manuals/ai/sandboxes/governance/audit/_index.md +++ b/content/manuals/ai/sandboxes/governance/audit/_index.md @@ -29,7 +29,7 @@ don't send audit data to audit logs. To use AI Governance Audit Logs, your organization needs: -- A Docker [AI Governance plan](/manuals/subscription/plans/ai-governance.md) +- A Docker [AI Governance plan](/manuals/subscription-billing/subscription/plans/ai-governance.md) - An enforced organization governance policy - A Docker organization account - An organization owner, or a user with a [custom role](/manuals/security/roles-and-permissions/custom-roles/_index.md) that includes AI Governance audit permissions, to configure delivery and view hosted events diff --git a/content/manuals/ai/sandboxes/governance/audit/configure.md b/content/manuals/ai/sandboxes/governance/audit/configure.md index c6db4050a030..8d4ff784edbe 100644 --- a/content/manuals/ai/sandboxes/governance/audit/configure.md +++ b/content/manuals/ai/sandboxes/governance/audit/configure.md @@ -19,7 +19,7 @@ together: Your organization needs: -- A Docker [AI Governance plan](/manuals/subscription/plans/ai-governance.md) +- A Docker [AI Governance plan](/manuals/subscription-billing/subscription/plans/ai-governance.md) - An enforced organization governance policy - Organization owner access, or a [custom role](/manuals/security/roles-and-permissions/custom-roles/_index.md) with AI Governance audit permissions diff --git a/content/manuals/build-cloud/builder-settings.md b/content/manuals/build-cloud/builder-settings.md index 665fa99b05dc..9ba815218279 100644 --- a/content/manuals/build-cloud/builder-settings.md +++ b/content/manuals/build-cloud/builder-settings.md @@ -47,7 +47,7 @@ two builders: ### Get more build cache space -To get more Build cache space, [upgrade your subscription](/manuals/subscription/manage.md#upgrade-plans). +To get more Build cache space, [upgrade your subscription](/manuals/subscription-billing/subscription/manage.md#upgrade-plans). > [!TIP] > diff --git a/content/manuals/desktop/release-notes.md b/content/manuals/desktop/release-notes.md index 5e100232c97e..0d9319d03913 100644 --- a/content/manuals/desktop/release-notes.md +++ b/content/manuals/desktop/release-notes.md @@ -5262,7 +5262,7 @@ The updated [Docker Subscription Service Agreement](https://www.docker.com/legal - **No changes** to Docker Engine or any other upstream **open source** Docker or Moby project. To understand how these changes affect you, read the [FAQs](https://www.docker.com/pricing/faq). -For more information, see [Docker subscription overview](../subscription/_index.md). +For more information, see [Docker subscription overview](../subscription-billing/subscription/_index.md). ### Upgrades diff --git a/content/manuals/dhi/how-to/select-enterprise.md b/content/manuals/dhi/how-to/select-enterprise.md index e108079f0254..8dadcda264fb 100644 --- a/content/manuals/dhi/how-to/select-enterprise.md +++ b/content/manuals/dhi/how-to/select-enterprise.md @@ -20,7 +20,7 @@ To use this workflow, you need: - One of the following: - A DHI Select or Enterprise subscription. [Contact Docker sales](https://www.docker.com/products/hardened-images/#compare) to purchase DHI Enterprise - or [learn more about DHI plans](../../subscription/plans/dhi.md). + or [learn more about DHI plans](../../subscription-billing/subscription/plans/dhi.md). - An active DHI trial. [Start a free DHI trial](https://hub.docker.com/hardened-images/start-free-trial). - [Docker Desktop](../../desktop/release-notes.md) 4.65 or later to use the diff --git a/content/manuals/docker-hub/release-notes.md b/content/manuals/docker-hub/release-notes.md index 1ac5c191b5f5..adcdee0fe313 100644 --- a/content/manuals/docker-hub/release-notes.md +++ b/content/manuals/docker-hub/release-notes.md @@ -182,7 +182,7 @@ known issues for each Docker Hub release. ### New -- You can now purchase or upgrade to a Docker Business subscription using a credit card. To learn more, see [Upgrade your subscription](../subscription/plans/docker.md). +- You can now purchase or upgrade to a Docker Business subscription using a credit card. To learn more, see [Upgrade your subscription](../subscription-billing/subscription/plans/docker.md). ## 2021-08-31 @@ -199,7 +199,7 @@ The updated [Docker Subscription Service Agreement](https://www.docker.com/legal - The existing Docker Free subscription has been renamed **Docker Personal**. - **No changes** to Docker Engine or any other upstream **open source** Docker or Moby project. - To understand how these changes affect you, read the [FAQs](https://www.docker.com/pricing/faq). For more information, see [Docker subscription overview](../subscription/_index.md). + To understand how these changes affect you, read the [FAQs](https://www.docker.com/pricing/faq). For more information, see [Docker subscription overview](../subscription-billing/subscription/_index.md). ## 2021-05-05 @@ -223,7 +223,7 @@ You can now specify any email address to receive billing-related emails for your To change the email address receiving billing-related emails, log into Docker Hub and navigate to the **Billing** tab of your organization. Select **Payment Methods** > **Billing Information**. Enter the new email address that you'd like to use in the **Email** field. Click **Update** for the changes to take effect. -For details on how to update your billing information, see [Update billing information](../billing/_index.md). +For details on how to update your billing information, see [Update billing information](../subscription-billing/billing/_index.md). ## 2021-03-22 @@ -257,7 +257,7 @@ Docker introduces Hub Vulnerability Scanning which enables you to automatically ### New features -- Docker has announced a new, per-seat pricing model to accelerate developer workflows for cloud-native development. The previous private repository/concurrent autobuild-based plans have been replaced with new **Pro** and **Team** plans that include unlimited private repositories. For more information, see [Docker subscription](../subscription/_index.md). +- Docker has announced a new, per-seat pricing model to accelerate developer workflows for cloud-native development. The previous private repository/concurrent autobuild-based plans have been replaced with new **Pro** and **Team** plans that include unlimited private repositories. For more information, see [Docker subscription](../subscription-billing/subscription/_index.md). - Docker has enabled download rate limits for downloads and pull requests on Docker Hub. This caps the number of objects that users can download within a specified timeframe. For more information, see [Usage and limits](/manuals/docker-hub/usage/_index.md). @@ -328,7 +328,7 @@ Docker introduces Hub Vulnerability Scanning which enables you to automatically ### Enhancements -- The [billing page](../subscription/plans/docker.md) for personal accounts has been updated. You can access the page at its new URL: [https://hub.docker.com/billing/plan](https://hub.docker.com/billing/plan). +- The [billing page](../subscription-billing/subscription/plans/docker.md) for personal accounts has been updated. You can access the page at its new URL: [https://hub.docker.com/billing/plan](https://hub.docker.com/billing/plan). ### Known Issues diff --git a/content/manuals/docker-hub/troubleshoot.md b/content/manuals/docker-hub/troubleshoot.md index ddf772eba73c..72916695bf3e 100644 --- a/content/manuals/docker-hub/troubleshoot.md +++ b/content/manuals/docker-hub/troubleshoot.md @@ -33,7 +33,7 @@ You have reached your pull rate limit. You may increase the limit by authenticat You can use one of the following solutions: - [Authenticate](./usage/pulls.md#authentication) or - [upgrade](../subscription/manage.md#upgrade-plans) your Docker + [upgrade](../subscription-billing/subscription/manage.md#upgrade-plans) your Docker account. - [View your pull rate limit](./usage/pulls.md#view-hourly-pull-rate-and-limit), wait until your pull rate limit decreases, and then try again. diff --git a/content/manuals/scout/_index.md b/content/manuals/scout/_index.md index 2de739f7f90a..e1e323fe60d4 100644 --- a/content/manuals/scout/_index.md +++ b/content/manuals/scout/_index.md @@ -38,7 +38,7 @@ grid: Ensure that your artifacts align with supply chain best practices. icon: shield-check - title: Upgrade - link: /subscription/change/ + link: /subscription-billing/subscription/manage/ description: | A Personal subscription includes up to 1 repository. Upgrade for more. icon: arrow-up-circle diff --git a/content/manuals/subscription-billing/_index.md b/content/manuals/subscription-billing/_index.md new file mode 100644 index 000000000000..33924b1d7770 --- /dev/null +++ b/content/manuals/subscription-billing/_index.md @@ -0,0 +1,16 @@ +--- +title: Subscription and billing +linkTitle: Subscription and billing +description: Manage Docker subscriptions, plans, billing, and payments. +keywords: subscription, billing, docker plans, payments, invoices, pricing +weight: 20 +params: + sidebar: + group: Platform +aliases: + - /subscription/ + - /billing/ + - /docker-hub/billing/ + - /docker-hub/billing/faq/ + - /billing/docker-hub-pricing/ +--- diff --git a/content/manuals/billing/3d-secure.md b/content/manuals/subscription-billing/billing/3d-secure.md similarity index 79% rename from content/manuals/billing/3d-secure.md rename to content/manuals/subscription-billing/billing/3d-secure.md index f6efae7e5e16..f65d7a1e444c 100644 --- a/content/manuals/billing/3d-secure.md +++ b/content/manuals/subscription-billing/billing/3d-secure.md @@ -4,6 +4,8 @@ linkTitle: 3D Secure description: Learn how 3D Secure authentication works for Docker subscription payments and how to troubleshoot verification issues. keywords: billing, payments, subscriptions, 3D Secure, 3DS, credit card verification, payment authentication weight: 30 +aliases: + - /billing/3d-secure/ --- Docker supports 3D Secure (3DS), an extra layer of authentication required @@ -27,10 +29,10 @@ requirements. You may be asked to verify your identity when performing any of the following actions: -- Starting a [paid subscription](../subscription/manage.md) -- Changing your [billing cycle](/manuals/billing/details.md#billing-cycle) from monthly to annual -- [Upgrading your subscription](../subscription/manage.md#upgrade-plans) -- [Adding seats](../accounts/organization/manage/manage-seats.md) to an existing +- Starting a [paid subscription](/manuals/subscription-billing/subscription/manage.md) +- Changing your [billing cycle](/manuals/subscription-billing/billing/details.md#billing-cycle) from monthly to annual +- [Upgrading your subscription](/manuals/subscription-billing/subscription/manage.md#upgrade-plans) +- [Adding seats](/manuals/accounts/organization/manage/manage-seats.md) to an existing subscription If 3DS is required and your payment method supports it, the verification prompt diff --git a/content/manuals/billing/_index.md b/content/manuals/subscription-billing/billing/_index.md similarity index 83% rename from content/manuals/billing/_index.md rename to content/manuals/subscription-billing/billing/_index.md index 4f94c88bdec0..7f4fdaa582e4 100644 --- a/content/manuals/billing/_index.md +++ b/content/manuals/subscription-billing/billing/_index.md @@ -8,33 +8,28 @@ keywords: billing, invoice, payment, subscription, Docker billing, update payment method, billing history, invoices, payment verification, tax exemption, usage, costs, credits, metered billing -weight: 30 -params: - sidebar: - group: Platform +weight: 20 grid_core: - title: Add or update a payment method description: Learn how to add or update a payment method for your personal account or organization. - link: /billing/payment-method/ + link: /subscription-billing/billing/payment-method/ icon: credit-card - title: Update billing information description: Learn how to update billing information for your personal account or organization. - link: /billing/details/ + link: /subscription-billing/billing/details/ icon: pencil-square - title: View billing history description: Learn how to view billing history and download past invoices. - link: /billing/history/ + link: /subscription-billing/billing/history/ icon: credit-card - title: 3D Secure authentication description: Learn how 3DS works and how to troubleshoot verification issues. - link: /billing/3d-secure/ + link: /subscription-billing/billing/3d-secure/ icon: wallet - title: Taxes description: Learn how to submit a US tax exemption certificate or add a VAT number. - link: /billing/tax-certificate/ + link: /subscription-billing/billing/tax-certificate/ icon: document-text -aliases: - - /billing/docker-hub-pricing/ --- You can use the billing portal to manage your Docker subscriptions, such @@ -72,8 +67,8 @@ from this page. Your invoice history is a reference to the Docker plans you subscribe to. For information about your billing cycle and renewal dates, see -[Billing cycle](/manuals/billing/details.md#billing-cycle). To upgrade or add -a new plan, see [Subscription](/manuals/subscription/_index.md). +[Billing cycle](/manuals/subscription-billing/billing/details.md#billing-cycle). To upgrade or add +a new plan, see [Subscription](/manuals/subscription-billing/subscription/_index.md). ## Next steps diff --git a/content/manuals/billing/details.md b/content/manuals/subscription-billing/billing/details.md similarity index 89% rename from content/manuals/billing/details.md rename to content/manuals/subscription-billing/billing/details.md index 817272f845df..4e0e341cb7dd 100644 --- a/content/manuals/billing/details.md +++ b/content/manuals/subscription-billing/billing/details.md @@ -5,6 +5,7 @@ weight: 40 description: Learn how to update billing details, like contact information, addresses, and notification email for Docker subscriptions. keywords: payments, billing, subscription, invoices, update billing email, change billing address, Docker billing account aliases: + - /billing/details/ - /billing/cycle/ --- @@ -22,7 +23,7 @@ To update your billing information from **Settings** in Docker Home: 1. Select **Edit** to make your changes. 1. Verify your information, then select **Save as default**. -For more information on changing your default payment method, see [Change default payment method](/manuals/billing/payment-method.md#change-default-payment-method). +For more information on changing your default payment method, see [Change default payment method](/manuals/subscription-billing/billing/payment-method.md#change-default-payment-method). ## Billing notifications @@ -37,4 +38,4 @@ to the billing account's email address. These communications include: Billing cycles are defined on a per-plan basis. Depending on the product you subscribe to, your cycle can be monthly, annual, or another cadence. For -plan-specific billing cycle details, see [Plans](/manuals/subscription/plans/_index.md). +plan-specific billing cycle details, see [Plans](/manuals/subscription-billing/subscription/plans/_index.md). diff --git a/content/manuals/billing/history.md b/content/manuals/subscription-billing/billing/history.md similarity index 97% rename from content/manuals/billing/history.md rename to content/manuals/subscription-billing/billing/history.md index c56089369f3b..e7a209ada81a 100644 --- a/content/manuals/billing/history.md +++ b/content/manuals/subscription-billing/billing/history.md @@ -5,6 +5,7 @@ weight: 60 description: Learn how to view your Docker billing history, understand what's on an invoice, and pay by invoice. keywords: payments, billing, subscription, invoices, renewals, billing history, pay by invoice aliases: + - /billing/history/ - /billing/core-billing/history/ --- @@ -58,7 +59,7 @@ Docker finalizes your invoice. For more information, see [Update billing informa ## View renewal date -Renewal dates are set on a per-plan basis, so check each plan individually if you subscribe to more than one. Depending on the product, your billing cycle can be monthly, annual, or another cadence. For plan-specific renewal and billing cycle details, see [Plans](/manuals/subscription/plans/_index.md). +Renewal dates are set on a per-plan basis, so check each plan individually if you subscribe to more than one. Depending on the product, your billing cycle can be monthly, annual, or another cadence. For plan-specific renewal and billing cycle details, see [Plans](/manuals/subscription-billing/subscription/plans/_index.md). ## Pay by invoice diff --git a/content/manuals/billing/payment-method.md b/content/manuals/subscription-billing/billing/payment-method.md similarity index 98% rename from content/manuals/billing/payment-method.md rename to content/manuals/subscription-billing/billing/payment-method.md index 6c6a64e274d7..16176448d4e8 100644 --- a/content/manuals/billing/payment-method.md +++ b/content/manuals/subscription-billing/billing/payment-method.md @@ -5,6 +5,7 @@ weight: 20 description: Learn how to manage cards, US bank accounts, Stripe Link, and pay by invoice for Docker subscriptions. keywords: payments, billing, subscription, payment methods, credit card, ACH, US bank account, Stripe Link, pay by invoice, failed payments aliases: + - /billing/payment-method/ - /billing/core-billing/payment-method/ --- @@ -72,7 +73,7 @@ You can only remove secondary payment methods. To remove a secondary payment met 1. Select the **Actions** menu next to the payment method you want to remove, then select **Remove**. 1. Verify your billing details, then select **Save as default**. -To remove your default payment method, first set a different payment method as default, or [downgrade to a free subscription](/manuals/subscription/plans/docker.md#cancel-a-docker-plan). +To remove your default payment method, first set a different payment method as default, or [downgrade to a free subscription](/manuals/subscription-billing/subscription/plans/docker.md#cancel-a-docker-plan). ## Enable and disable pay by invoice diff --git a/content/manuals/billing/tax-certificate.md b/content/manuals/subscription-billing/billing/tax-certificate.md similarity index 96% rename from content/manuals/billing/tax-certificate.md rename to content/manuals/subscription-billing/billing/tax-certificate.md index 6b6a83b58ab1..118dd1f29526 100644 --- a/content/manuals/billing/tax-certificate.md +++ b/content/manuals/subscription-billing/billing/tax-certificate.md @@ -8,6 +8,8 @@ keywords: billing, sales tax, VAT, tax exemption certificate, tax ID, VAT number, United States tax exemption, Docker Support, billing portal weight: 70 +aliases: + - /billing/tax-certificate/ --- Depending on your location, Docker may collect sales tax or VAT on your @@ -88,4 +90,4 @@ Your VAT number must include your country prefix. For example, enter > existing payment method or billing details in billing settings. Add a VAT number or tax ID when you -[set up a new plan](/manuals/subscription/manage.md#set-up-a-new-plan). \ No newline at end of file +[set up a new plan](/manuals/subscription-billing/subscription/manage.md#set-up-a-new-plan). \ No newline at end of file diff --git a/content/manuals/subscription/desktop-license.md b/content/manuals/subscription-billing/desktop-license.md similarity index 97% rename from content/manuals/subscription/desktop-license.md rename to content/manuals/subscription-billing/desktop-license.md index 4b23bbf19ed2..6b83533c8e01 100644 --- a/content/manuals/subscription/desktop-license.md +++ b/content/manuals/subscription-billing/desktop-license.md @@ -2,8 +2,9 @@ title: Docker Desktop license agreement description: Information about Docker Desktop's license agreement and commercial use requirements keywords: docker desktop license, subscription service agreement, commercial use, licensing terms -weight: 40 +weight: 30 aliases: + - /subscription/desktop-license/ - /subscription/products/desktop-license/ - /subscription/plans/desktop-license/ --- diff --git a/content/manuals/subscription-billing/faqs/_index.md b/content/manuals/subscription-billing/faqs/_index.md new file mode 100644 index 000000000000..cb24091059ef --- /dev/null +++ b/content/manuals/subscription-billing/faqs/_index.md @@ -0,0 +1,9 @@ +--- +build: + render: never +title: FAQs +linkTitle: FAQs +description: Frequently asked questions about Docker subscriptions and billing +keywords: subscription faq, billing faq, docker plans +weight: 40 +--- diff --git a/content/manuals/billing/faqs.md b/content/manuals/subscription-billing/faqs/billing.md similarity index 82% rename from content/manuals/billing/faqs.md rename to content/manuals/subscription-billing/faqs/billing.md index 2f7a9a838b9f..1604d20317b6 100644 --- a/content/manuals/billing/faqs.md +++ b/content/manuals/subscription-billing/faqs/billing.md @@ -1,10 +1,12 @@ --- title: Billing FAQs -linkTitle: FAQs +linkTitle: Billing FAQ description: Find answers to common questions about Docker billing, failed payments, taxes, and pay by invoice. keywords: billing, renewal, failed payments, sales tax, VAT, academic pricing, pay by invoice tags: [FAQ] -weight: 80 +weight: 20 +aliases: + - /billing/faqs/ --- ## What happens if my subscription payment fails? @@ -32,7 +34,7 @@ Stripe. Before retrying, verify that your default payment method is up to date. For instructions, see -[Manage a payment method](/manuals/billing/payment-method.md#manage-payment-method). +[Manage a payment method](/manuals/subscription-billing/billing/payment-method.md#manage-payment-method). ## Does Docker collect sales tax and VAT? @@ -44,9 +46,9 @@ Docker collects sales tax or VAT from the following customers: - For United Kingdom customers, Docker began collecting VAT on May 1, 2025. To help ensure correct tax assessments, keep your -[billing information](/manuals/billing/details.md) up to date. For details on +[billing information](/manuals/subscription-billing/billing/details.md) up to date. For details on adding a VAT number or submitting a US tax exemption certificate, see -[Taxes](/manuals/billing/tax-certificate.md). +[Taxes](/manuals/subscription-billing/billing/tax-certificate.md). ## Does Docker offer academic pricing? @@ -60,4 +62,4 @@ purchasing upgrades or additional seats. You must use card payment or US bank accounts for these changes. For a list of supported payment methods, see -[Add or update a payment method](/manuals/billing/payment-method.md). +[Add or update a payment method](/manuals/subscription-billing/billing/payment-method.md). diff --git a/content/manuals/subscription/faq.md b/content/manuals/subscription-billing/faqs/subscription.md similarity index 77% rename from content/manuals/subscription/faq.md rename to content/manuals/subscription-billing/faqs/subscription.md index 8e009b0a99a7..4f957f61b65b 100644 --- a/content/manuals/subscription/faq.md +++ b/content/manuals/subscription-billing/faqs/subscription.md @@ -1,13 +1,15 @@ --- title: Plan FAQs -linkTitle: FAQs +linkTitle: Subscription FAQ description: Frequently asked questions about Docker subscriptions and billing keywords: subscription faqs, docker billing, subscription transfer, academic pricing, docker programs tags: [FAQ] -weight: 30 +weight: 10 +aliases: + - /subscription/faq/ --- -For more information on Docker subscriptions, see [Docker subscription overview](_index.md). +For more information on Docker subscriptions, see [Docker subscription overview](/manuals/subscription-billing/subscription/_index.md). ## Can I transfer my subscription from one user or organization account to another? @@ -25,8 +27,8 @@ Contact the [Docker Sales Team](https://www.docker.com/company/contact) for info Docker offers two content contribution programs: -- [Docker-Sponsored Open Source Program (DSOS)](../docker-hub/repos/manage/trusted-content/dsos-program.md) for open source projects -- [Docker Verified Publisher (DVP)](../docker-hub/repos/manage/trusted-content/dvp-program.md) for commercial publishers +- [Docker-Sponsored Open Source Program (DSOS)](/manuals/docker-hub/repos/manage/trusted-content/dsos-program.md) for open source projects +- [Docker Verified Publisher (DVP)](/manuals/docker-hub/repos/manage/trusted-content/dvp-program.md) for commercial publishers You can also join the [Developer Preview Program](https://www.docker.com/community/get-involved/developer-preview/) or sign up for early access programs to participate in research and try new features. diff --git a/content/manuals/subscription/_index.md b/content/manuals/subscription-billing/subscription/_index.md similarity index 68% rename from content/manuals/subscription/_index.md rename to content/manuals/subscription-billing/subscription/_index.md index 58e84d922711..0474a445459b 100644 --- a/content/manuals/subscription/_index.md +++ b/content/manuals/subscription-billing/subscription/_index.md @@ -6,10 +6,7 @@ keywords: docker subscription, pricing, billing, subscription types, subscription plans, docker hardened images, gordon, cloud sandboxes, subscription management -weight: 20 -params: - sidebar: - group: Platform +weight: 10 grid_subscriptions: - title: Compare Docker plans description: Visit the pricing page to see what's included in different Docker plans. @@ -17,23 +14,20 @@ grid_subscriptions: icon: magnifying-glass - title: Manage plans description: Add a new plan, upgrade an active plan, or cancel auto-renewal. - link: /subscription/manage/ + link: /subscription-billing/subscription/manage/ icon: shopping-cart - title: Explore plans description: Browse available Docker plans and add-ons for individuals, teams, and organizations. - link: /subscription/plans/ + link: /subscription-billing/subscription/plans/ icon: chart-bar - title: Docker Desktop license agreement description: Review the terms of the Docker Subscription Service Agreement. - link: /subscription/desktop-license/ + link: /subscription-billing/desktop-license/ icon: document-text - title: Plan FAQs description: Find the answers you need and explore common questions. - link: /subscription/faq/ + link: /subscription-billing/faqs/subscription/ icon: question-mark-circle -aliases: - - /docker-hub/billing/ - - /docker-hub/billing/faq/ --- You can subscribe to several Docker plans that range from free to paid plans. When you upgrade a plan, you expand your usage entitlements and feature sets for Docker products. You can also top up some plans, extending usage to more users without changing your plan type. @@ -44,14 +38,14 @@ You can subscribe to plans for individual or organization accounts, or plans for | Plans | Billing model | Types | | ---------------------------------------------------------------------- | --------------------------------------------------------- | --------------------------------------------------------- | -| [Docker](/manuals/subscription/plans/docker.md) | Flat-rate plans for personal and organization accounts | Docker Personal, Docker Pro, Docker Team, Docker Business | -| [Docker Agentic Platform](/manuals/subscription/plans/docker-agentic-platform.md) | Pay-as-you-go (PayGo) for cloud sandbox usage | Docker Agentic Platform | -| [Docker Hardened Images (DHI)](/manuals/subscription/plans/dhi.md) | Graduated security features for hardened container images | DHI Community, DHI Select, DHI Enterprise | -| [Gordon](/manuals/subscription/plans/gordon.md) | Prepaid usage for the Gordon AI agent | Gordon Plus, Gordon Max, Gordon Ultra | -| [AI Governance](/manuals/subscription/plans/ai-governance.md) | Purchase set amount of licenses | AI Governance | -| [Docker Verified Publisher (DVP)](/manuals/subscription/plans/docker-verified-publisher.md) | Annual plans based on consuming domains | DVP Starter, DVP Growth | +| [Docker](/manuals/subscription-billing/subscription/plans/docker.md) | Flat-rate plans for personal and organization accounts | Docker Personal, Docker Pro, Docker Team, Docker Business | +| [Docker Agentic Platform](/manuals/subscription-billing/subscription/plans/docker-agentic-platform.md) | Pay-as-you-go (PayGo) for cloud sandbox usage | Docker Agentic Platform | +| [Docker Hardened Images (DHI)](/manuals/subscription-billing/subscription/plans/dhi.md) | Graduated security features for hardened container images | DHI Community, DHI Select, DHI Enterprise | +| [Gordon](/manuals/subscription-billing/subscription/plans/gordon.md) | Prepaid usage for the Gordon AI agent | Gordon Plus, Gordon Max, Gordon Ultra | +| [AI Governance](/manuals/subscription-billing/subscription/plans/ai-governance.md) | Purchase set amount of licenses | AI Governance | +| [Docker Verified Publisher (DVP)](/manuals/subscription-billing/subscription/plans/docker-verified-publisher.md) | Annual plans based on consuming domains | DVP Starter, DVP Growth | -Docker plans that upgrade your account (Docker Pro or Docker Team and Business) can provide a foundation for most use cases. Some product plans may require an upgraded Docker account while other product plans let you subscribe without an upgraded account. To learn more, see [Docker plans](/manuals/subscription/plans/_index.md). +Docker plans that upgrade your account (Docker Pro or Docker Team and Business) can provide a foundation for most use cases. Some product plans may require an upgraded Docker account while other product plans let you subscribe without an upgraded account. To learn more, see [Docker plans](/manuals/subscription-billing/subscription/plans/_index.md). ## Top up your plan @@ -69,7 +63,7 @@ Plans come with usage entitlements that can be extended without upgrading to a d To subscribe to a new plan, you can self-serve through **Billing** in [Docker Home](https://app.docker.com), or by contacting sales. -To learn more about adding a new plan or upgrading an active plan, see [Manage plans](/manuals/subscription/manage.md). +To learn more about adding a new plan or upgrading an active plan, see [Manage plans](/manuals/subscription-billing/subscription/manage.md). ## Next steps diff --git a/content/manuals/subscription/manage.md b/content/manuals/subscription-billing/subscription/manage.md similarity index 84% rename from content/manuals/subscription/manage.md rename to content/manuals/subscription-billing/subscription/manage.md index 33d8d961e25c..7509eadf9133 100644 --- a/content/manuals/subscription/manage.md +++ b/content/manuals/subscription-billing/subscription/manage.md @@ -9,6 +9,7 @@ keywords: products, upgrade subscription, downgrade subscription, docker billing, cancel auto-renewal, cancel, top up, manage weight: 20 aliases: + - /subscription/manage/ - /subscription/change/ - /subscription/setup/ - /docker-hub/upgrade/ @@ -57,17 +58,17 @@ You can upgrade active plans from the billing Overview page. > [!TIP] > Billing cycle details vary from plan to plan. Learn more about usage, downgrading, or canceling plans > from the relevant -> [product page](/manuals/subscription/plans/_index.md). +> [product page](/manuals/subscription-billing/subscription/plans/_index.md). ## View your credits Docker displays available account credits in the billing portal. Credits offset eligible usage automatically before Docker charges your payment method. To review credit balance and applied credits, see -[Credits](/manuals/billing/_index.md#credits). +[Credits](/manuals/subscription-billing/billing/_index.md#credits). Credits apply to -[Docker Agentic Platform](/manuals/subscription/plans/docker-agentic-platform.md). +[Docker Agentic Platform](/manuals/subscription-billing/subscription/plans/docker-agentic-platform.md). When you sign up for Docker Agentic Platform, Docker adds a one-time promotional credit to your account. This credit is non-recurring, doesn't expire, and applies to cloud compute usage only. It doesn't @@ -80,9 +81,9 @@ Some products are sales-led. You must ## Next steps -- [Learn about available plans](/manuals/subscription/plans/_index.md) -- [Set up payment information](/manuals/billing/payment-method.md) -- [View invoices](/manuals/billing/history.md) -- To learn more about managing your billing details, see [Billing](/manuals/billing/_index.md). +- [Learn about available plans](/manuals/subscription-billing/subscription/plans/_index.md) +- [Set up payment information](/manuals/subscription-billing/billing/payment-method.md) +- [View invoices](/manuals/subscription-billing/billing/history.md) +- To learn more about managing your billing details, see [Billing](/manuals/subscription-billing/billing/_index.md). - To learn about sales tax and VAT, see - [Taxes](/manuals/billing/tax-certificate.md). + [Taxes](/manuals/subscription-billing/billing/tax-certificate.md). diff --git a/content/manuals/subscription/plans/_index.md b/content/manuals/subscription-billing/subscription/plans/_index.md similarity index 80% rename from content/manuals/subscription/plans/_index.md rename to content/manuals/subscription-billing/subscription/plans/_index.md index dacd056981eb..994fe190f92c 100644 --- a/content/manuals/subscription/plans/_index.md +++ b/content/manuals/subscription-billing/subscription/plans/_index.md @@ -9,6 +9,7 @@ keywords: docker build cloud, gordon plans, docker agentic platform, product catalog weight: 10 aliases: + - /subscription/plans/ - /subscription/products/ - /subscription/scale/ - /subscription/details/ @@ -18,23 +19,23 @@ aliases: grid: - title: Docker description: Personal and organization plans, including build and runtime minutes. - link: /subscription/plans/docker/ + link: /subscription-billing/subscription/plans/docker/ icon: credit-card - title: Gordon plans description: Usage plans that increase your Gordon allowance. - link: /subscription/plans/gordon/ + link: /subscription-billing/subscription/plans/gordon/ icon: /icons/gordon.svg - title: Docker Hardened Images (DHI) description: Hardened image repositories for organization accounts. - link: /subscription/plans/dhi/ + link: /subscription-billing/subscription/plans/dhi/ icon: /icons/dhi.svg - title: AI Governance description: Licenses for organization-wide AI policy enforcement. - link: /subscription/plans/ai-governance/ + link: /subscription-billing/subscription/plans/ai-governance/ icon: shield-check - title: Docker Verified Publisher (DVP) description: Publisher analytics and reporting plans for organization accounts. - link: /subscription/plans/docker-verified-publisher/ + link: /subscription-billing/subscription/plans/docker-verified-publisher/ icon: check-badge --- @@ -46,7 +47,7 @@ You can subscribe to plans on a self-serve basis when you go to the Docker produ This section covers usage entitlements, billing cycle, and plan management options for each available plan. -To manage your plans by adding a new plan or upgrading an active plan, see [Manage plans](/manuals/subscription/manage.md). +To manage your plans by adding a new plan or upgrading an active plan, see [Manage plans](/manuals/subscription-billing/subscription/manage.md). ## Product catalog diff --git a/content/manuals/subscription/plans/ai-governance.md b/content/manuals/subscription-billing/subscription/plans/ai-governance.md similarity index 97% rename from content/manuals/subscription/plans/ai-governance.md rename to content/manuals/subscription-billing/subscription/plans/ai-governance.md index 986b6fc2e2d4..1f483ef27034 100644 --- a/content/manuals/subscription/plans/ai-governance.md +++ b/content/manuals/subscription-billing/subscription/plans/ai-governance.md @@ -9,6 +9,7 @@ keywords: subscription management weight: 50 aliases: + - /subscription/plans/ai-governance/ - /subscription/products/ai-governance/ - /subscription/ai-governance/ --- diff --git a/content/manuals/subscription/plans/dhi.md b/content/manuals/subscription-billing/subscription/plans/dhi.md similarity index 99% rename from content/manuals/subscription/plans/dhi.md rename to content/manuals/subscription-billing/subscription/plans/dhi.md index 443ea3ea023d..2538a3f8b951 100644 --- a/content/manuals/subscription/plans/dhi.md +++ b/content/manuals/subscription-billing/subscription/plans/dhi.md @@ -9,6 +9,7 @@ keywords: dhi select, dhi enterprise, docker hardened images, hardened images, repositories, organization subscription, secure images weight: 40 aliases: + - /subscription/plans/dhi/ - /subscription/products/dhi-select/ - /subscription/dhi-select/ - /subscription/plans/dhi-select/ diff --git a/content/manuals/subscription/plans/docker-agentic-platform.md b/content/manuals/subscription-billing/subscription/plans/docker-agentic-platform.md similarity index 91% rename from content/manuals/subscription/plans/docker-agentic-platform.md rename to content/manuals/subscription-billing/subscription/plans/docker-agentic-platform.md index e0ad92e9a802..c7df17faeeab 100644 --- a/content/manuals/subscription/plans/docker-agentic-platform.md +++ b/content/manuals/subscription-billing/subscription/plans/docker-agentic-platform.md @@ -11,12 +11,14 @@ keywords: compute, usage and billing weight: 20 sitemap: false +aliases: + - /subscription/plans/docker-agentic-platform/ --- > [!TIP] > Docker Agentic Platform signups receive a one-time promotional > credit toward cloud compute usage. To review your balance, see -> [Credits](/manuals/billing/_index.md#credits). +> [Credits](/manuals/subscription-billing/billing/_index.md#credits). [Docker Agentic Platform](https://agentic-platform.docker.com/) is a pay-as-you-go plan for running agent and tool workloads in isolated @@ -77,6 +79,6 @@ the plan period. ## Next steps - To add or cancel a plan, see - [Manage plans](/manuals/subscription/manage.md) + [Manage plans](/manuals/subscription-billing/subscription/manage.md) - To track usage across plans, see - [Usage](/manuals/billing/_index.md#usage) + [Usage](/manuals/subscription-billing/billing/_index.md#usage) diff --git a/content/manuals/subscription/plans/docker-verified-publisher.md b/content/manuals/subscription-billing/subscription/plans/docker-verified-publisher.md similarity index 98% rename from content/manuals/subscription/plans/docker-verified-publisher.md rename to content/manuals/subscription-billing/subscription/plans/docker-verified-publisher.md index f72ce0140475..f71b5aa76b94 100644 --- a/content/manuals/subscription/plans/docker-verified-publisher.md +++ b/content/manuals/subscription-billing/subscription/plans/docker-verified-publisher.md @@ -9,6 +9,8 @@ keywords: domains, publisher analytics, organization subscription, apply for dvp, auto-renewal, billing portal, docker hub weight: 60 +aliases: + - /subscription/plans/docker-verified-publisher/ --- [Docker Verified Publisher (DVP)](/manuals/docker-hub/repos/manage/trusted-content/dvp-program.md) diff --git a/content/manuals/subscription/plans/docker.md b/content/manuals/subscription-billing/subscription/plans/docker.md similarity index 99% rename from content/manuals/subscription/plans/docker.md rename to content/manuals/subscription-billing/subscription/plans/docker.md index 08c6b7bd4dab..8b75359a68ae 100644 --- a/content/manuals/subscription/plans/docker.md +++ b/content/manuals/subscription-billing/subscription/plans/docker.md @@ -10,6 +10,7 @@ keywords: pricing, subscription changes, build cloud minutes, testcontainers minutes weight: 10 aliases: + - /subscription/plans/docker/ - /subscription/plans/core/ - /subscription/products/core/ - /subscription/core/ diff --git a/content/manuals/subscription/plans/gordon.md b/content/manuals/subscription-billing/subscription/plans/gordon.md similarity index 97% rename from content/manuals/subscription/plans/gordon.md rename to content/manuals/subscription-billing/subscription/plans/gordon.md index 321ae886bf34..4e97db03ff0c 100644 --- a/content/manuals/subscription/plans/gordon.md +++ b/content/manuals/subscription-billing/subscription/plans/gordon.md @@ -9,6 +9,7 @@ keywords: personal subscription, ai assistant, usage allowance weight: 30 aliases: + - /subscription/plans/gordon/ - /subscription/products/gordon/ - /subscription/gordon/ --- @@ -20,7 +21,7 @@ aliases: - Gordon Max is for power users who rely on Gordon throughout their workflow. It offers a significantly higher usage allowance than Plus. - Gordon Ultra is for developers with the highest usage needs. It provides the maximum monthly allowance available on a self-serve plan. -To upgrade to a Gordon paid plan, see [Manage plans](/manuals/subscription/manage.md). +To upgrade to a Gordon paid plan, see [Manage plans](/manuals/subscription-billing/subscription/manage.md). ## Usage diff --git a/data/redirects.yml b/data/redirects.yml index 285e4800cd6b..1e74226c659e 100644 --- a/data/redirects.yml +++ b/data/redirects.yml @@ -321,7 +321,7 @@ - /go/settings-management/ # Billing - cancellation -"/subscription/desktop-license/": +"/subscription-billing/desktop-license/": - /go/desktop-license/ "/docker-hub/usage/pulls/": - /go/hub-pull-limits/ diff --git a/data/whats-new.json b/data/whats-new.json index f70ab9553ee9..9821101f53a3 100644 --- a/data/whats-new.json +++ b/data/whats-new.json @@ -6,7 +6,7 @@ "product": "Docker Verified Publisher", "title": "Join Docker Verified Publisher through self-service plans", "description": "Apply for DVP Starter or Growth, complete checkout after approval, and manage publisher analytics, tracked companies, and billing.", - "url": "/subscription/plans/docker-verified-publisher/", + "url": "/subscription-billing/subscription/plans/docker-verified-publisher/", "published": "2026-08-20", "source_prs": [25891, 25903], "featured": true From 0591e262df2311d03241a3c5d834154f929833ea Mon Sep 17 00:00:00 2001 From: Alexa Date: Mon, 31 Aug 2026 13:36:42 -0500 Subject: [PATCH 06/19] docs: flatten subscription-billing; nest billing under Manage Drop the Subscription and Billing subcategory wrappers, merge those landings onto the parent, and move billing docs under Manage. Keep shipped main aliases; do not alias branch-only nested URLs. Co-authored-by: Cursor --- .../individual/deactivate-user-account.md | 2 +- .../accounts/organization/manage/_index.md | 2 +- .../organization/manage/deactivate-account.md | 2 +- .../organization/manage/manage-licenses.md | 6 +- .../organization/manage/manage-products.md | 2 +- .../accounts/organization/setup/onboard.md | 2 +- .../accounts/organization/setup/orgs.md | 2 +- content/manuals/agentic-platform/_index.md | 2 +- content/manuals/agentic-platform/faq.md | 2 +- content/manuals/agentic-platform/sandboxes.md | 2 +- .../ai/sandboxes/governance/audit/_index.md | 2 +- .../sandboxes/governance/audit/configure.md | 2 +- .../manuals/build-cloud/builder-settings.md | 2 +- content/manuals/desktop/release-notes.md | 2 +- .../manuals/dhi/how-to/select-enterprise.md | 2 +- content/manuals/docker-hub/release-notes.md | 10 +- content/manuals/docker-hub/troubleshoot.md | 2 +- content/manuals/scout/_index.md | 2 +- .../manuals/subscription-billing/_index.md | 121 ++++++++++++++++++ .../subscription-billing/billing/_index.md | 75 ----------- .../subscription-billing/faqs/billing.md | 8 +- .../subscription-billing/faqs/subscription.md | 2 +- .../{billing => manage}/3d-secure.md | 6 +- .../subscription-billing/manage/_index.md | 9 ++ .../{billing => manage}/details.md | 4 +- .../{billing => manage}/history.md | 2 +- .../{billing => manage}/payment-method.md | 2 +- .../manage.md => manage/plans.md} | 20 +-- .../{billing => manage}/tax-certificate.md | 2 +- .../{subscription => }/plans/_index.md | 12 +- .../{subscription => }/plans/ai-governance.md | 0 .../{subscription => }/plans/dhi.md | 0 .../plans/docker-agentic-platform.md | 6 +- .../plans/docker-verified-publisher.md | 0 .../{subscription => }/plans/docker.md | 0 .../{subscription => }/plans/gordon.md | 2 +- .../subscription/_index.md | 70 ---------- data/whats-new.json | 2 +- 38 files changed, 188 insertions(+), 203 deletions(-) delete mode 100644 content/manuals/subscription-billing/billing/_index.md rename content/manuals/subscription-billing/{billing => manage}/3d-secure.md (85%) create mode 100644 content/manuals/subscription-billing/manage/_index.md rename content/manuals/subscription-billing/{billing => manage}/details.md (94%) rename content/manuals/subscription-billing/{billing => manage}/history.md (98%) rename content/manuals/subscription-billing/{billing => manage}/payment-method.md (98%) rename content/manuals/subscription-billing/{subscription/manage.md => manage/plans.md} (84%) rename content/manuals/subscription-billing/{billing => manage}/tax-certificate.md (97%) rename content/manuals/subscription-billing/{subscription => }/plans/_index.md (81%) rename content/manuals/subscription-billing/{subscription => }/plans/ai-governance.md (100%) rename content/manuals/subscription-billing/{subscription => }/plans/dhi.md (100%) rename content/manuals/subscription-billing/{subscription => }/plans/docker-agentic-platform.md (93%) rename content/manuals/subscription-billing/{subscription => }/plans/docker-verified-publisher.md (100%) rename content/manuals/subscription-billing/{subscription => }/plans/docker.md (100%) rename content/manuals/subscription-billing/{subscription => }/plans/gordon.md (98%) delete mode 100644 content/manuals/subscription-billing/subscription/_index.md diff --git a/content/manuals/accounts/individual/deactivate-user-account.md b/content/manuals/accounts/individual/deactivate-user-account.md index 84e6201bbf80..273ba89a0955 100644 --- a/content/manuals/accounts/individual/deactivate-user-account.md +++ b/content/manuals/accounts/individual/deactivate-user-account.md @@ -40,7 +40,7 @@ requirements: and then remove yourself, or deactivate the company. - If you have an active Docker subscription, [downgrade it to a Docker Personal - subscription](/manuals/subscription-billing/subscription/plans/docker.md#cancel-a-docker-plan). + subscription](/manuals/subscription-billing/plans/docker.md#cancel-a-docker-plan). - Download any images and tags you want to keep. Use `docker pull -a ` to pull all tags, or `docker pull :` to pull a specific tag. diff --git a/content/manuals/accounts/organization/manage/_index.md b/content/manuals/accounts/organization/manage/_index.md index e9297fad83b1..7427a0300a1f 100644 --- a/content/manuals/accounts/organization/manage/_index.md +++ b/content/manuals/accounts/organization/manage/_index.md @@ -28,7 +28,7 @@ grid: - title: Billing description: Manage payment methods and view billing history. icon: credit-card - link: /subscription-billing/billing/ + link: /subscription-billing/ aliases: - /admin/organization/manage/ --- diff --git a/content/manuals/accounts/organization/manage/deactivate-account.md b/content/manuals/accounts/organization/manage/deactivate-account.md index 1dfc7d089d7b..13b9374e88d3 100644 --- a/content/manuals/accounts/organization/manage/deactivate-account.md +++ b/content/manuals/accounts/organization/manage/deactivate-account.md @@ -34,7 +34,7 @@ organization: to pull all tags, or `docker pull :` to pull a specific tag. - If you have an active Docker subscription, [downgrade it to a basic organization - account](/manuals/subscription-billing/subscription/plans/docker.md#cancel-a-docker-plan). + account](/manuals/subscription-billing/plans/docker.md#cancel-a-docker-plan). - Remove all other members within the organization. - Unlink your [GitHub and Bitbucket accounts](/manuals/docker-hub/repos/manage/builds/link-source.md#unlink-a-github-user-account). diff --git a/content/manuals/accounts/organization/manage/manage-licenses.md b/content/manuals/accounts/organization/manage/manage-licenses.md index 96ab939bf173..dae594e409f3 100644 --- a/content/manuals/accounts/organization/manage/manage-licenses.md +++ b/content/manuals/accounts/organization/manage/manage-licenses.md @@ -15,7 +15,7 @@ products. > [!TIP] > To learn more about product licenses, Docker Core seats, and other Docker -> add-ons, see [Docker plans](/manuals/subscription-billing/subscription/plans/_index.md), +> add-ons, see [Docker plans](/manuals/subscription-billing/plans/_index.md), > or > contact sales > to purchase licenses. @@ -116,11 +116,11 @@ To manage licenses for your organization: Explore Docker Core add-ons and products that need licenses: -- [Docker plans](/manuals/subscription-billing/subscription/plans/_index.md) to learn about different +- [Docker plans](/manuals/subscription-billing/plans/_index.md) to learn about different add-ons - [Manage seats](/manuals/accounts/organization/manage/manage-seats.md) to add more seats to your Docker Core subscription -- [AI Governance plan](/manuals/subscription-billing/subscription/plans/ai-governance.md) to learn +- [AI Governance plan](/manuals/subscription-billing/plans/ai-governance.md) to learn about AI Governance license usage and billing - [Docker Offload](/manuals/offload/about.md) to let your developers offload building and running containers to the cloud diff --git a/content/manuals/accounts/organization/manage/manage-products.md b/content/manuals/accounts/organization/manage/manage-products.md index aa19d8e3fe36..5a2afb5b4bc5 100644 --- a/content/manuals/accounts/organization/manage/manage-products.md +++ b/content/manuals/accounts/organization/manage/manage-products.md @@ -141,7 +141,7 @@ following table to learn where you can monitor organization usage: | Docker Offload | From [Docker Home](https://app.docker.com/), select **Offload**, then **Offload activity**. See [Docker Offload usage and billing](../../../offload/usage.md) for more details. | If your usage or seat count exceeds your subscription amount, you can -[add seats](./manage-seats.md) or [view available Docker plans](../../../subscription-billing/subscription/plans/_index.md) to meet your needs. +[add seats](./manage-seats.md) or [view available Docker plans](../../../subscription-billing/plans/_index.md) to meet your needs. ## Next steps diff --git a/content/manuals/accounts/organization/setup/onboard.md b/content/manuals/accounts/organization/setup/onboard.md index 33de537f5032..6bc1de453e4e 100644 --- a/content/manuals/accounts/organization/setup/onboard.md +++ b/content/manuals/accounts/organization/setup/onboard.md @@ -123,7 +123,7 @@ For more details, see [Invite members](/manuals/accounts/organization/manage/mem Configuring SSO and SCIM is optional and only available to Docker Business subscribers. To upgrade a Docker Team subscription to a Docker Business -subscription, see [Upgrade a plan](/manuals/subscription-billing/subscription/manage.md#upgrade-plans). +subscription, see [Upgrade a plan](/manuals/subscription-billing/manage/plans.md#upgrade-plans). Use your identity provider (IdP) to manage members and provision them to Docker automatically via SSO and SCIM. See the following for more details: diff --git a/content/manuals/accounts/organization/setup/orgs.md b/content/manuals/accounts/organization/setup/orgs.md index b2900112398f..fb30f23cf465 100644 --- a/content/manuals/accounts/organization/setup/orgs.md +++ b/content/manuals/accounts/organization/setup/orgs.md @@ -72,7 +72,7 @@ the following steps: 1. Based on the number of seats from the secondary organization, [purchase additional seats](../manage/manage-seats.md) for the primary organization account that you want to keep. 1. Manually add users to the primary organization and remove existing users from the secondary organization. 1. Manually move over your data, including all repositories. -1. Once you're done moving all of your users and data, [downgrade](../../../subscription-billing/subscription/plans/docker.md#cancel-a-docker-plan) the secondary account to a free subscription. Note that Docker does not offer refunds for downgrading organizations mid-billing cycle. +1. Once you're done moving all of your users and data, [downgrade](../../../subscription-billing/plans/docker.md#cancel-a-docker-plan) the secondary account to a free subscription. Note that Docker does not offer refunds for downgrading organizations mid-billing cycle. If your organization has a Docker Business subscription with a purchase order, contact Support or your Account Manager at Docker. diff --git a/content/manuals/agentic-platform/_index.md b/content/manuals/agentic-platform/_index.md index a029ae5fb65a..38baaac6ca35 100644 --- a/content/manuals/agentic-platform/_index.md +++ b/content/manuals/agentic-platform/_index.md @@ -65,6 +65,6 @@ Account-level configuration can be reused across sandboxes: To begin, open [Docker Agentic Platform](https://agentic-platform.docker.com/) and sign in with your Docker account. Docker meters sandbox compute per second. -For account and payment information, see [Docker Billing](/subscription-billing/billing/). +For account and payment information, see [Docker Billing](/subscription-billing/). {{< grid >}} diff --git a/content/manuals/agentic-platform/faq.md b/content/manuals/agentic-platform/faq.md index 3f56f823eb32..ee4edceeaeda 100644 --- a/content/manuals/agentic-platform/faq.md +++ b/content/manuals/agentic-platform/faq.md @@ -49,7 +49,7 @@ also shows the equivalent hourly rate. Model inference is billed separately. The sandbox uses your credential for an external model provider, which meters and bills inference under that provider -account. See [Docker Billing](/subscription-billing/billing/) for account, usage, and payment +account. See [Docker Billing](/subscription-billing/) for account, usage, and payment information. ## How long are logs, telemetry, and snapshots retained? diff --git a/content/manuals/agentic-platform/sandboxes.md b/content/manuals/agentic-platform/sandboxes.md index 595339a5422a..607b3219a6b0 100644 --- a/content/manuals/agentic-platform/sandboxes.md +++ b/content/manuals/agentic-platform/sandboxes.md @@ -62,7 +62,7 @@ when the sandbox is created and cannot be changed while it runs. Docker bills sandbox compute per second while the sandbox runs. Model inference uses your external provider credential and is metered by that provider. For -account, usage, and payment information, see [Docker Billing](/subscription-billing/billing/). +account, usage, and payment information, see [Docker Billing](/subscription-billing/). ## Check sandbox configuration diff --git a/content/manuals/ai/sandboxes/governance/audit/_index.md b/content/manuals/ai/sandboxes/governance/audit/_index.md index 391319b7546e..844758e94453 100644 --- a/content/manuals/ai/sandboxes/governance/audit/_index.md +++ b/content/manuals/ai/sandboxes/governance/audit/_index.md @@ -29,7 +29,7 @@ don't send audit data to audit logs. To use AI Governance Audit Logs, your organization needs: -- A Docker [AI Governance plan](/manuals/subscription-billing/subscription/plans/ai-governance.md) +- A Docker [AI Governance plan](/manuals/subscription-billing/plans/ai-governance.md) - An enforced organization governance policy - A Docker organization account - An organization owner, or a user with a [custom role](/manuals/security/roles-and-permissions/custom-roles/_index.md) that includes AI Governance audit permissions, to configure delivery and view hosted events diff --git a/content/manuals/ai/sandboxes/governance/audit/configure.md b/content/manuals/ai/sandboxes/governance/audit/configure.md index 8d4ff784edbe..5afa22949ab6 100644 --- a/content/manuals/ai/sandboxes/governance/audit/configure.md +++ b/content/manuals/ai/sandboxes/governance/audit/configure.md @@ -19,7 +19,7 @@ together: Your organization needs: -- A Docker [AI Governance plan](/manuals/subscription-billing/subscription/plans/ai-governance.md) +- A Docker [AI Governance plan](/manuals/subscription-billing/plans/ai-governance.md) - An enforced organization governance policy - Organization owner access, or a [custom role](/manuals/security/roles-and-permissions/custom-roles/_index.md) with AI Governance audit permissions diff --git a/content/manuals/build-cloud/builder-settings.md b/content/manuals/build-cloud/builder-settings.md index 9ba815218279..2b6f41a59aa3 100644 --- a/content/manuals/build-cloud/builder-settings.md +++ b/content/manuals/build-cloud/builder-settings.md @@ -47,7 +47,7 @@ two builders: ### Get more build cache space -To get more Build cache space, [upgrade your subscription](/manuals/subscription-billing/subscription/manage.md#upgrade-plans). +To get more Build cache space, [upgrade your subscription](/manuals/subscription-billing/manage/plans.md#upgrade-plans). > [!TIP] > diff --git a/content/manuals/desktop/release-notes.md b/content/manuals/desktop/release-notes.md index 0d9319d03913..de1d86169fdb 100644 --- a/content/manuals/desktop/release-notes.md +++ b/content/manuals/desktop/release-notes.md @@ -5262,7 +5262,7 @@ The updated [Docker Subscription Service Agreement](https://www.docker.com/legal - **No changes** to Docker Engine or any other upstream **open source** Docker or Moby project. To understand how these changes affect you, read the [FAQs](https://www.docker.com/pricing/faq). -For more information, see [Docker subscription overview](../subscription-billing/subscription/_index.md). +For more information, see [Docker subscription overview](../subscription-billing/_index.md). ### Upgrades diff --git a/content/manuals/dhi/how-to/select-enterprise.md b/content/manuals/dhi/how-to/select-enterprise.md index 8dadcda264fb..2e9c6bda3877 100644 --- a/content/manuals/dhi/how-to/select-enterprise.md +++ b/content/manuals/dhi/how-to/select-enterprise.md @@ -20,7 +20,7 @@ To use this workflow, you need: - One of the following: - A DHI Select or Enterprise subscription. [Contact Docker sales](https://www.docker.com/products/hardened-images/#compare) to purchase DHI Enterprise - or [learn more about DHI plans](../../subscription-billing/subscription/plans/dhi.md). + or [learn more about DHI plans](../../subscription-billing/plans/dhi.md). - An active DHI trial. [Start a free DHI trial](https://hub.docker.com/hardened-images/start-free-trial). - [Docker Desktop](../../desktop/release-notes.md) 4.65 or later to use the diff --git a/content/manuals/docker-hub/release-notes.md b/content/manuals/docker-hub/release-notes.md index adcdee0fe313..26c64ac0c574 100644 --- a/content/manuals/docker-hub/release-notes.md +++ b/content/manuals/docker-hub/release-notes.md @@ -182,7 +182,7 @@ known issues for each Docker Hub release. ### New -- You can now purchase or upgrade to a Docker Business subscription using a credit card. To learn more, see [Upgrade your subscription](../subscription-billing/subscription/plans/docker.md). +- You can now purchase or upgrade to a Docker Business subscription using a credit card. To learn more, see [Upgrade your subscription](../subscription-billing/plans/docker.md). ## 2021-08-31 @@ -199,7 +199,7 @@ The updated [Docker Subscription Service Agreement](https://www.docker.com/legal - The existing Docker Free subscription has been renamed **Docker Personal**. - **No changes** to Docker Engine or any other upstream **open source** Docker or Moby project. - To understand how these changes affect you, read the [FAQs](https://www.docker.com/pricing/faq). For more information, see [Docker subscription overview](../subscription-billing/subscription/_index.md). + To understand how these changes affect you, read the [FAQs](https://www.docker.com/pricing/faq). For more information, see [Docker subscription overview](../subscription-billing/_index.md). ## 2021-05-05 @@ -223,7 +223,7 @@ You can now specify any email address to receive billing-related emails for your To change the email address receiving billing-related emails, log into Docker Hub and navigate to the **Billing** tab of your organization. Select **Payment Methods** > **Billing Information**. Enter the new email address that you'd like to use in the **Email** field. Click **Update** for the changes to take effect. -For details on how to update your billing information, see [Update billing information](../subscription-billing/billing/_index.md). +For details on how to update your billing information, see [Update billing information](../subscription-billing/_index.md). ## 2021-03-22 @@ -257,7 +257,7 @@ Docker introduces Hub Vulnerability Scanning which enables you to automatically ### New features -- Docker has announced a new, per-seat pricing model to accelerate developer workflows for cloud-native development. The previous private repository/concurrent autobuild-based plans have been replaced with new **Pro** and **Team** plans that include unlimited private repositories. For more information, see [Docker subscription](../subscription-billing/subscription/_index.md). +- Docker has announced a new, per-seat pricing model to accelerate developer workflows for cloud-native development. The previous private repository/concurrent autobuild-based plans have been replaced with new **Pro** and **Team** plans that include unlimited private repositories. For more information, see [Docker subscription](../subscription-billing/_index.md). - Docker has enabled download rate limits for downloads and pull requests on Docker Hub. This caps the number of objects that users can download within a specified timeframe. For more information, see [Usage and limits](/manuals/docker-hub/usage/_index.md). @@ -328,7 +328,7 @@ Docker introduces Hub Vulnerability Scanning which enables you to automatically ### Enhancements -- The [billing page](../subscription-billing/subscription/plans/docker.md) for personal accounts has been updated. You can access the page at its new URL: [https://hub.docker.com/billing/plan](https://hub.docker.com/billing/plan). +- The [billing page](../subscription-billing/plans/docker.md) for personal accounts has been updated. You can access the page at its new URL: [https://hub.docker.com/billing/plan](https://hub.docker.com/billing/plan). ### Known Issues diff --git a/content/manuals/docker-hub/troubleshoot.md b/content/manuals/docker-hub/troubleshoot.md index 72916695bf3e..9cc1a60db0b5 100644 --- a/content/manuals/docker-hub/troubleshoot.md +++ b/content/manuals/docker-hub/troubleshoot.md @@ -33,7 +33,7 @@ You have reached your pull rate limit. You may increase the limit by authenticat You can use one of the following solutions: - [Authenticate](./usage/pulls.md#authentication) or - [upgrade](../subscription-billing/subscription/manage.md#upgrade-plans) your Docker + [upgrade](../subscription-billing/manage/plans.md#upgrade-plans) your Docker account. - [View your pull rate limit](./usage/pulls.md#view-hourly-pull-rate-and-limit), wait until your pull rate limit decreases, and then try again. diff --git a/content/manuals/scout/_index.md b/content/manuals/scout/_index.md index e1e323fe60d4..7f5046903622 100644 --- a/content/manuals/scout/_index.md +++ b/content/manuals/scout/_index.md @@ -38,7 +38,7 @@ grid: Ensure that your artifacts align with supply chain best practices. icon: shield-check - title: Upgrade - link: /subscription-billing/subscription/manage/ + link: /subscription-billing/manage/plans/ description: | A Personal subscription includes up to 1 repository. Upgrade for more. icon: arrow-up-circle diff --git a/content/manuals/subscription-billing/_index.md b/content/manuals/subscription-billing/_index.md index 33924b1d7770..ac22d1c0bd37 100644 --- a/content/manuals/subscription-billing/_index.md +++ b/content/manuals/subscription-billing/_index.md @@ -13,4 +13,125 @@ aliases: - /docker-hub/billing/ - /docker-hub/billing/faq/ - /billing/docker-hub-pricing/ +grid_subscriptions: + - title: Compare Docker plans + description: Visit the pricing page to see what's included in different Docker plans. + link: "https://www.docker.com/pricing?ref=Docs&refAction=DocsSubscription" + icon: magnifying-glass + - title: Manage plans + description: Add a new plan, upgrade an active plan, or cancel auto-renewal. + link: /subscription-billing/manage/plans/ + icon: shopping-cart + - title: Explore plans + description: Browse available Docker plans and add-ons for individuals, teams, and organizations. + link: /subscription-billing/plans/ + icon: chart-bar + - title: Docker Desktop license agreement + description: Review the terms of the Docker Subscription Service Agreement. + link: /subscription-billing/desktop-license/ + icon: document-text + - title: Plan FAQs + description: Find the answers you need and explore common questions. + link: /subscription-billing/faqs/subscription/ + icon: question-mark-circle +grid_core: + - title: Add or update a payment method + description: Learn how to add or update a payment method for your personal account or organization. + link: /subscription-billing/manage/payment-method/ + icon: credit-card + - title: Update billing information + description: Learn how to update billing information for your personal account or organization. + link: /subscription-billing/manage/details/ + icon: pencil-square + - title: View billing history + description: Learn how to view billing history and download past invoices. + link: /subscription-billing/manage/history/ + icon: credit-card + - title: 3D Secure authentication + description: Learn how 3DS works and how to troubleshoot verification issues. + link: /subscription-billing/manage/3d-secure/ + icon: wallet + - title: Taxes + description: Learn how to submit a US tax exemption certificate or add a VAT number. + link: /subscription-billing/manage/tax-certificate/ + icon: document-text --- + +You can subscribe to several Docker plans that range from free to paid plans. When you upgrade a plan, you expand your usage entitlements and feature sets for Docker products. You can also top up some plans, extending usage to more users without changing your plan type. + +## Docker plans + +You can subscribe to plans for individual or organization accounts, or plans for specific products. The following table summarizes the available plans. + +| Plans | Billing model | Types | +| ---------------------------------------------------------------------- | --------------------------------------------------------- | --------------------------------------------------------- | +| [Docker](/manuals/subscription-billing/plans/docker.md) | Flat-rate plans for personal and organization accounts | Docker Personal, Docker Pro, Docker Team, Docker Business | +| [Docker Agentic Platform](/manuals/subscription-billing/plans/docker-agentic-platform.md) | Pay-as-you-go (PayGo) for cloud sandbox usage | Docker Agentic Platform | +| [Docker Hardened Images (DHI)](/manuals/subscription-billing/plans/dhi.md) | Graduated security features for hardened container images | DHI Community, DHI Select, DHI Enterprise | +| [Gordon](/manuals/subscription-billing/plans/gordon.md) | Prepaid usage for the Gordon AI agent | Gordon Plus, Gordon Max, Gordon Ultra | +| [AI Governance](/manuals/subscription-billing/plans/ai-governance.md) | Purchase set amount of licenses | AI Governance | +| [Docker Verified Publisher (DVP)](/manuals/subscription-billing/plans/docker-verified-publisher.md) | Annual plans based on consuming domains | DVP Starter, DVP Growth | + +Docker plans that upgrade your account (Docker Pro or Docker Team and Business) can provide a foundation for most use cases. Some product plans may require an upgraded Docker account while other product plans let you subscribe without an upgraded account. To learn more, see [Docker plans](/manuals/subscription-billing/plans/_index.md). + +## Top up your plan + +Plans come with usage entitlements that can be extended without upgrading to a different plan. + +| Unit | Description | Examples | +| ----------------- | ------------------------------------------------------------------------------------- | ----------------------------- | +| Seats | Each seat extends entitlements to one more member. | Docker Team, Docker Business | +| Licenses | Access to specific products or features. | AI Governance, Docker Offload | +| Minutes | Cloud build capacity, sold in blocks and consumed within the billing period. | Docker Build Cloud | +| Repositories | Additional container repositories covered by security scanning and analysis features. | DHI | +| Consuming domains | Additional consuming domains tracked in publisher analytics, sold in blocks of 25. | DVP Starter, DVP Growth | + +## Manage your plans + +To subscribe to a new plan, you can self-serve through **Billing** in [Docker Home](https://app.docker.com), or by contacting sales. + +To learn more about adding a new plan or upgrading an active plan, see [Manage plans](/manuals/subscription-billing/manage/plans.md). + +You can use the billing portal to manage your Docker subscriptions, such +as updating payment methods, reviewing billing details, and tracking +invoice history. + +## Billing + +You can manage your Docker plans from the billing portal: + +1. Sign in to [Docker Home](https://app.docker.com/), then choose your + account. +1. Go to **Billing** to view the **Overview** page. +1. Select the page you want to explore. + +### Usage + +The billing **Usage** page helps you compare usage-based charges across +billing periods. You can track usage by changing the period, product, +and how the product is metered. + +### Costs + +The billing **Costs** page aggregates all costs by billing period. It +breaks down charges by resource (the product accruing a charge), the +status of your billing period, and costs to date. + +### Credits + +The billing **Credits** page shows credits applied to your costs. If you +received a promotional credit, you can see how it applies to your bill +from this page. + +## Docker plans and billing cycle + +Your invoice history is a reference to the Docker plans you subscribe +to. For information about your billing cycle and renewal dates, see +[Billing cycle](/manuals/subscription-billing/manage/details.md#billing-cycle). To upgrade or add +a new plan, see [Subscription](/manuals/subscription-billing/_index.md). + +## Next steps + +{{< grid items="grid_subscriptions" >}} + +{{< grid items="grid_core" >}} diff --git a/content/manuals/subscription-billing/billing/_index.md b/content/manuals/subscription-billing/billing/_index.md deleted file mode 100644 index 7f4fdaa582e4..000000000000 --- a/content/manuals/subscription-billing/billing/_index.md +++ /dev/null @@ -1,75 +0,0 @@ ---- -title: Manage billing and payments -linkTitle: Billing -description: > - Manage Docker billing and payments, including usage, costs, credits, - invoices, payment methods, and tax details. -keywords: - billing, invoice, payment, subscription, Docker billing, update payment - method, billing history, invoices, payment verification, tax exemption, - usage, costs, credits, metered billing -weight: 20 -grid_core: - - title: Add or update a payment method - description: Learn how to add or update a payment method for your personal account or organization. - link: /subscription-billing/billing/payment-method/ - icon: credit-card - - title: Update billing information - description: Learn how to update billing information for your personal account or organization. - link: /subscription-billing/billing/details/ - icon: pencil-square - - title: View billing history - description: Learn how to view billing history and download past invoices. - link: /subscription-billing/billing/history/ - icon: credit-card - - title: 3D Secure authentication - description: Learn how 3DS works and how to troubleshoot verification issues. - link: /subscription-billing/billing/3d-secure/ - icon: wallet - - title: Taxes - description: Learn how to submit a US tax exemption certificate or add a VAT number. - link: /subscription-billing/billing/tax-certificate/ - icon: document-text ---- - -You can use the billing portal to manage your Docker subscriptions, such -as updating payment methods, reviewing billing details, and tracking -invoice history. - -## Billing - -You can manage your Docker plans from the billing portal: - -1. Sign in to [Docker Home](https://app.docker.com/), then choose your - account. -1. Go to **Billing** to view the **Overview** page. -1. Select the page you want to explore. - -### Usage - -The billing **Usage** page helps you compare usage-based charges across -billing periods. You can track usage by changing the period, product, -and how the product is metered. - -### Costs - -The billing **Costs** page aggregates all costs by billing period. It -breaks down charges by resource (the product accruing a charge), the -status of your billing period, and costs to date. - -### Credits - -The billing **Credits** page shows credits applied to your costs. If you -received a promotional credit, you can see how it applies to your bill -from this page. - -## Docker plans and billing cycle - -Your invoice history is a reference to the Docker plans you subscribe -to. For information about your billing cycle and renewal dates, see -[Billing cycle](/manuals/subscription-billing/billing/details.md#billing-cycle). To upgrade or add -a new plan, see [Subscription](/manuals/subscription-billing/subscription/_index.md). - -## Next steps - -{{< grid items="grid_core" >}} diff --git a/content/manuals/subscription-billing/faqs/billing.md b/content/manuals/subscription-billing/faqs/billing.md index 1604d20317b6..813bf1bee653 100644 --- a/content/manuals/subscription-billing/faqs/billing.md +++ b/content/manuals/subscription-billing/faqs/billing.md @@ -34,7 +34,7 @@ Stripe. Before retrying, verify that your default payment method is up to date. For instructions, see -[Manage a payment method](/manuals/subscription-billing/billing/payment-method.md#manage-payment-method). +[Manage a payment method](/manuals/subscription-billing/manage/payment-method.md#manage-payment-method). ## Does Docker collect sales tax and VAT? @@ -46,9 +46,9 @@ Docker collects sales tax or VAT from the following customers: - For United Kingdom customers, Docker began collecting VAT on May 1, 2025. To help ensure correct tax assessments, keep your -[billing information](/manuals/subscription-billing/billing/details.md) up to date. For details on +[billing information](/manuals/subscription-billing/manage/details.md) up to date. For details on adding a VAT number or submitting a US tax exemption certificate, see -[Taxes](/manuals/subscription-billing/billing/tax-certificate.md). +[Taxes](/manuals/subscription-billing/manage/tax-certificate.md). ## Does Docker offer academic pricing? @@ -62,4 +62,4 @@ purchasing upgrades or additional seats. You must use card payment or US bank accounts for these changes. For a list of supported payment methods, see -[Add or update a payment method](/manuals/subscription-billing/billing/payment-method.md). +[Add or update a payment method](/manuals/subscription-billing/manage/payment-method.md). diff --git a/content/manuals/subscription-billing/faqs/subscription.md b/content/manuals/subscription-billing/faqs/subscription.md index 4f957f61b65b..949bcf7b4000 100644 --- a/content/manuals/subscription-billing/faqs/subscription.md +++ b/content/manuals/subscription-billing/faqs/subscription.md @@ -9,7 +9,7 @@ aliases: - /subscription/faq/ --- -For more information on Docker subscriptions, see [Docker subscription overview](/manuals/subscription-billing/subscription/_index.md). +For more information on Docker subscriptions, see [Docker subscription overview](/manuals/subscription-billing/_index.md). ## Can I transfer my subscription from one user or organization account to another? diff --git a/content/manuals/subscription-billing/billing/3d-secure.md b/content/manuals/subscription-billing/manage/3d-secure.md similarity index 85% rename from content/manuals/subscription-billing/billing/3d-secure.md rename to content/manuals/subscription-billing/manage/3d-secure.md index f65d7a1e444c..7b17cacc7373 100644 --- a/content/manuals/subscription-billing/billing/3d-secure.md +++ b/content/manuals/subscription-billing/manage/3d-secure.md @@ -29,9 +29,9 @@ requirements. You may be asked to verify your identity when performing any of the following actions: -- Starting a [paid subscription](/manuals/subscription-billing/subscription/manage.md) -- Changing your [billing cycle](/manuals/subscription-billing/billing/details.md#billing-cycle) from monthly to annual -- [Upgrading your subscription](/manuals/subscription-billing/subscription/manage.md#upgrade-plans) +- Starting a [paid subscription](/manuals/subscription-billing/manage/plans.md) +- Changing your [billing cycle](/manuals/subscription-billing/manage/details.md#billing-cycle) from monthly to annual +- [Upgrading your subscription](/manuals/subscription-billing/manage/plans.md#upgrade-plans) - [Adding seats](/manuals/accounts/organization/manage/manage-seats.md) to an existing subscription diff --git a/content/manuals/subscription-billing/manage/_index.md b/content/manuals/subscription-billing/manage/_index.md new file mode 100644 index 000000000000..544dc81a316c --- /dev/null +++ b/content/manuals/subscription-billing/manage/_index.md @@ -0,0 +1,9 @@ +--- +build: + render: never +title: Manage +linkTitle: Manage +description: Manage Docker plans, payment methods, billing details, invoices, and taxes. +keywords: manage plans, billing, payment methods, invoices, taxes, docker subscription +weight: 20 +--- diff --git a/content/manuals/subscription-billing/billing/details.md b/content/manuals/subscription-billing/manage/details.md similarity index 94% rename from content/manuals/subscription-billing/billing/details.md rename to content/manuals/subscription-billing/manage/details.md index 4e0e341cb7dd..d3f060b215ec 100644 --- a/content/manuals/subscription-billing/billing/details.md +++ b/content/manuals/subscription-billing/manage/details.md @@ -23,7 +23,7 @@ To update your billing information from **Settings** in Docker Home: 1. Select **Edit** to make your changes. 1. Verify your information, then select **Save as default**. -For more information on changing your default payment method, see [Change default payment method](/manuals/subscription-billing/billing/payment-method.md#change-default-payment-method). +For more information on changing your default payment method, see [Change default payment method](/manuals/subscription-billing/manage/payment-method.md#change-default-payment-method). ## Billing notifications @@ -38,4 +38,4 @@ to the billing account's email address. These communications include: Billing cycles are defined on a per-plan basis. Depending on the product you subscribe to, your cycle can be monthly, annual, or another cadence. For -plan-specific billing cycle details, see [Plans](/manuals/subscription-billing/subscription/plans/_index.md). +plan-specific billing cycle details, see [Plans](/manuals/subscription-billing/plans/_index.md). diff --git a/content/manuals/subscription-billing/billing/history.md b/content/manuals/subscription-billing/manage/history.md similarity index 98% rename from content/manuals/subscription-billing/billing/history.md rename to content/manuals/subscription-billing/manage/history.md index e7a209ada81a..36f3afbf3708 100644 --- a/content/manuals/subscription-billing/billing/history.md +++ b/content/manuals/subscription-billing/manage/history.md @@ -59,7 +59,7 @@ Docker finalizes your invoice. For more information, see [Update billing informa ## View renewal date -Renewal dates are set on a per-plan basis, so check each plan individually if you subscribe to more than one. Depending on the product, your billing cycle can be monthly, annual, or another cadence. For plan-specific renewal and billing cycle details, see [Plans](/manuals/subscription-billing/subscription/plans/_index.md). +Renewal dates are set on a per-plan basis, so check each plan individually if you subscribe to more than one. Depending on the product, your billing cycle can be monthly, annual, or another cadence. For plan-specific renewal and billing cycle details, see [Plans](/manuals/subscription-billing/plans/_index.md). ## Pay by invoice diff --git a/content/manuals/subscription-billing/billing/payment-method.md b/content/manuals/subscription-billing/manage/payment-method.md similarity index 98% rename from content/manuals/subscription-billing/billing/payment-method.md rename to content/manuals/subscription-billing/manage/payment-method.md index 16176448d4e8..3797c7d269f6 100644 --- a/content/manuals/subscription-billing/billing/payment-method.md +++ b/content/manuals/subscription-billing/manage/payment-method.md @@ -73,7 +73,7 @@ You can only remove secondary payment methods. To remove a secondary payment met 1. Select the **Actions** menu next to the payment method you want to remove, then select **Remove**. 1. Verify your billing details, then select **Save as default**. -To remove your default payment method, first set a different payment method as default, or [downgrade to a free subscription](/manuals/subscription-billing/subscription/plans/docker.md#cancel-a-docker-plan). +To remove your default payment method, first set a different payment method as default, or [downgrade to a free subscription](/manuals/subscription-billing/plans/docker.md#cancel-a-docker-plan). ## Enable and disable pay by invoice diff --git a/content/manuals/subscription-billing/subscription/manage.md b/content/manuals/subscription-billing/manage/plans.md similarity index 84% rename from content/manuals/subscription-billing/subscription/manage.md rename to content/manuals/subscription-billing/manage/plans.md index 7509eadf9133..6e81c3f18eb5 100644 --- a/content/manuals/subscription-billing/subscription/manage.md +++ b/content/manuals/subscription-billing/manage/plans.md @@ -1,13 +1,13 @@ --- title: Manage plans -linkTitle: Manage +linkTitle: Plans description: > Learn how to set up, upgrade, downgrade, or cancel plans, and how to manage auto-renewal and credits. keywords: purchase subscription, buy docker subscription, product catalog, browse products, upgrade subscription, downgrade subscription, docker billing, cancel auto-renewal, cancel, top up, manage -weight: 20 +weight: 10 aliases: - /subscription/manage/ - /subscription/change/ @@ -58,17 +58,17 @@ You can upgrade active plans from the billing Overview page. > [!TIP] > Billing cycle details vary from plan to plan. Learn more about usage, downgrading, or canceling plans > from the relevant -> [product page](/manuals/subscription-billing/subscription/plans/_index.md). +> [product page](/manuals/subscription-billing/plans/_index.md). ## View your credits Docker displays available account credits in the billing portal. Credits offset eligible usage automatically before Docker charges your payment method. To review credit balance and applied credits, see -[Credits](/manuals/subscription-billing/billing/_index.md#credits). +[Credits](/manuals/subscription-billing/_index.md#credits). Credits apply to -[Docker Agentic Platform](/manuals/subscription-billing/subscription/plans/docker-agentic-platform.md). +[Docker Agentic Platform](/manuals/subscription-billing/plans/docker-agentic-platform.md). When you sign up for Docker Agentic Platform, Docker adds a one-time promotional credit to your account. This credit is non-recurring, doesn't expire, and applies to cloud compute usage only. It doesn't @@ -81,9 +81,9 @@ Some products are sales-led. You must ## Next steps -- [Learn about available plans](/manuals/subscription-billing/subscription/plans/_index.md) -- [Set up payment information](/manuals/subscription-billing/billing/payment-method.md) -- [View invoices](/manuals/subscription-billing/billing/history.md) -- To learn more about managing your billing details, see [Billing](/manuals/subscription-billing/billing/_index.md). +- [Learn about available plans](/manuals/subscription-billing/plans/_index.md) +- [Set up payment information](/manuals/subscription-billing/manage/payment-method.md) +- [View invoices](/manuals/subscription-billing/manage/history.md) +- To learn more about managing your billing details, see [Billing](/manuals/subscription-billing/_index.md). - To learn about sales tax and VAT, see - [Taxes](/manuals/subscription-billing/billing/tax-certificate.md). + [Taxes](/manuals/subscription-billing/manage/tax-certificate.md). diff --git a/content/manuals/subscription-billing/billing/tax-certificate.md b/content/manuals/subscription-billing/manage/tax-certificate.md similarity index 97% rename from content/manuals/subscription-billing/billing/tax-certificate.md rename to content/manuals/subscription-billing/manage/tax-certificate.md index 118dd1f29526..4261c1af901d 100644 --- a/content/manuals/subscription-billing/billing/tax-certificate.md +++ b/content/manuals/subscription-billing/manage/tax-certificate.md @@ -90,4 +90,4 @@ Your VAT number must include your country prefix. For example, enter > existing payment method or billing details in billing settings. Add a VAT number or tax ID when you -[set up a new plan](/manuals/subscription-billing/subscription/manage.md#set-up-a-new-plan). \ No newline at end of file +[set up a new plan](/manuals/subscription-billing/manage/plans.md#set-up-a-new-plan). \ No newline at end of file diff --git a/content/manuals/subscription-billing/subscription/plans/_index.md b/content/manuals/subscription-billing/plans/_index.md similarity index 81% rename from content/manuals/subscription-billing/subscription/plans/_index.md rename to content/manuals/subscription-billing/plans/_index.md index 994fe190f92c..debe5fbd95da 100644 --- a/content/manuals/subscription-billing/subscription/plans/_index.md +++ b/content/manuals/subscription-billing/plans/_index.md @@ -19,23 +19,23 @@ aliases: grid: - title: Docker description: Personal and organization plans, including build and runtime minutes. - link: /subscription-billing/subscription/plans/docker/ + link: /subscription-billing/plans/docker/ icon: credit-card - title: Gordon plans description: Usage plans that increase your Gordon allowance. - link: /subscription-billing/subscription/plans/gordon/ + link: /subscription-billing/plans/gordon/ icon: /icons/gordon.svg - title: Docker Hardened Images (DHI) description: Hardened image repositories for organization accounts. - link: /subscription-billing/subscription/plans/dhi/ + link: /subscription-billing/plans/dhi/ icon: /icons/dhi.svg - title: AI Governance description: Licenses for organization-wide AI policy enforcement. - link: /subscription-billing/subscription/plans/ai-governance/ + link: /subscription-billing/plans/ai-governance/ icon: shield-check - title: Docker Verified Publisher (DVP) description: Publisher analytics and reporting plans for organization accounts. - link: /subscription-billing/subscription/plans/docker-verified-publisher/ + link: /subscription-billing/plans/docker-verified-publisher/ icon: check-badge --- @@ -47,7 +47,7 @@ You can subscribe to plans on a self-serve basis when you go to the Docker produ This section covers usage entitlements, billing cycle, and plan management options for each available plan. -To manage your plans by adding a new plan or upgrading an active plan, see [Manage plans](/manuals/subscription-billing/subscription/manage.md). +To manage your plans by adding a new plan or upgrading an active plan, see [Manage plans](/manuals/subscription-billing/manage/plans.md). ## Product catalog diff --git a/content/manuals/subscription-billing/subscription/plans/ai-governance.md b/content/manuals/subscription-billing/plans/ai-governance.md similarity index 100% rename from content/manuals/subscription-billing/subscription/plans/ai-governance.md rename to content/manuals/subscription-billing/plans/ai-governance.md diff --git a/content/manuals/subscription-billing/subscription/plans/dhi.md b/content/manuals/subscription-billing/plans/dhi.md similarity index 100% rename from content/manuals/subscription-billing/subscription/plans/dhi.md rename to content/manuals/subscription-billing/plans/dhi.md diff --git a/content/manuals/subscription-billing/subscription/plans/docker-agentic-platform.md b/content/manuals/subscription-billing/plans/docker-agentic-platform.md similarity index 93% rename from content/manuals/subscription-billing/subscription/plans/docker-agentic-platform.md rename to content/manuals/subscription-billing/plans/docker-agentic-platform.md index c7df17faeeab..5391463183b2 100644 --- a/content/manuals/subscription-billing/subscription/plans/docker-agentic-platform.md +++ b/content/manuals/subscription-billing/plans/docker-agentic-platform.md @@ -18,7 +18,7 @@ aliases: > [!TIP] > Docker Agentic Platform signups receive a one-time promotional > credit toward cloud compute usage. To review your balance, see -> [Credits](/manuals/subscription-billing/billing/_index.md#credits). +> [Credits](/manuals/subscription-billing/_index.md#credits). [Docker Agentic Platform](https://agentic-platform.docker.com/) is a pay-as-you-go plan for running agent and tool workloads in isolated @@ -79,6 +79,6 @@ the plan period. ## Next steps - To add or cancel a plan, see - [Manage plans](/manuals/subscription-billing/subscription/manage.md) + [Manage plans](/manuals/subscription-billing/manage/plans.md) - To track usage across plans, see - [Usage](/manuals/subscription-billing/billing/_index.md#usage) + [Usage](/manuals/subscription-billing/_index.md#usage) diff --git a/content/manuals/subscription-billing/subscription/plans/docker-verified-publisher.md b/content/manuals/subscription-billing/plans/docker-verified-publisher.md similarity index 100% rename from content/manuals/subscription-billing/subscription/plans/docker-verified-publisher.md rename to content/manuals/subscription-billing/plans/docker-verified-publisher.md diff --git a/content/manuals/subscription-billing/subscription/plans/docker.md b/content/manuals/subscription-billing/plans/docker.md similarity index 100% rename from content/manuals/subscription-billing/subscription/plans/docker.md rename to content/manuals/subscription-billing/plans/docker.md diff --git a/content/manuals/subscription-billing/subscription/plans/gordon.md b/content/manuals/subscription-billing/plans/gordon.md similarity index 98% rename from content/manuals/subscription-billing/subscription/plans/gordon.md rename to content/manuals/subscription-billing/plans/gordon.md index 4e97db03ff0c..b8dabd5f7d34 100644 --- a/content/manuals/subscription-billing/subscription/plans/gordon.md +++ b/content/manuals/subscription-billing/plans/gordon.md @@ -21,7 +21,7 @@ aliases: - Gordon Max is for power users who rely on Gordon throughout their workflow. It offers a significantly higher usage allowance than Plus. - Gordon Ultra is for developers with the highest usage needs. It provides the maximum monthly allowance available on a self-serve plan. -To upgrade to a Gordon paid plan, see [Manage plans](/manuals/subscription-billing/subscription/manage.md). +To upgrade to a Gordon paid plan, see [Manage plans](/manuals/subscription-billing/manage/plans.md). ## Usage diff --git a/content/manuals/subscription-billing/subscription/_index.md b/content/manuals/subscription-billing/subscription/_index.md deleted file mode 100644 index 0474a445459b..000000000000 --- a/content/manuals/subscription-billing/subscription/_index.md +++ /dev/null @@ -1,70 +0,0 @@ ---- -title: Overview -linkTitle: Subscription -description: Learn about Docker plans, like how to subscribe to product-based plans and how they apply to personal and organization accounts. -keywords: - docker subscription, pricing, billing, subscription types, subscription - plans, docker hardened images, gordon, cloud sandboxes, subscription - management -weight: 10 -grid_subscriptions: - - title: Compare Docker plans - description: Visit the pricing page to see what's included in different Docker plans. - link: "https://www.docker.com/pricing?ref=Docs&refAction=DocsSubscription" - icon: magnifying-glass - - title: Manage plans - description: Add a new plan, upgrade an active plan, or cancel auto-renewal. - link: /subscription-billing/subscription/manage/ - icon: shopping-cart - - title: Explore plans - description: Browse available Docker plans and add-ons for individuals, teams, and organizations. - link: /subscription-billing/subscription/plans/ - icon: chart-bar - - title: Docker Desktop license agreement - description: Review the terms of the Docker Subscription Service Agreement. - link: /subscription-billing/desktop-license/ - icon: document-text - - title: Plan FAQs - description: Find the answers you need and explore common questions. - link: /subscription-billing/faqs/subscription/ - icon: question-mark-circle ---- - -You can subscribe to several Docker plans that range from free to paid plans. When you upgrade a plan, you expand your usage entitlements and feature sets for Docker products. You can also top up some plans, extending usage to more users without changing your plan type. - -## Docker plans - -You can subscribe to plans for individual or organization accounts, or plans for specific products. The following table summarizes the available plans. - -| Plans | Billing model | Types | -| ---------------------------------------------------------------------- | --------------------------------------------------------- | --------------------------------------------------------- | -| [Docker](/manuals/subscription-billing/subscription/plans/docker.md) | Flat-rate plans for personal and organization accounts | Docker Personal, Docker Pro, Docker Team, Docker Business | -| [Docker Agentic Platform](/manuals/subscription-billing/subscription/plans/docker-agentic-platform.md) | Pay-as-you-go (PayGo) for cloud sandbox usage | Docker Agentic Platform | -| [Docker Hardened Images (DHI)](/manuals/subscription-billing/subscription/plans/dhi.md) | Graduated security features for hardened container images | DHI Community, DHI Select, DHI Enterprise | -| [Gordon](/manuals/subscription-billing/subscription/plans/gordon.md) | Prepaid usage for the Gordon AI agent | Gordon Plus, Gordon Max, Gordon Ultra | -| [AI Governance](/manuals/subscription-billing/subscription/plans/ai-governance.md) | Purchase set amount of licenses | AI Governance | -| [Docker Verified Publisher (DVP)](/manuals/subscription-billing/subscription/plans/docker-verified-publisher.md) | Annual plans based on consuming domains | DVP Starter, DVP Growth | - -Docker plans that upgrade your account (Docker Pro or Docker Team and Business) can provide a foundation for most use cases. Some product plans may require an upgraded Docker account while other product plans let you subscribe without an upgraded account. To learn more, see [Docker plans](/manuals/subscription-billing/subscription/plans/_index.md). - -## Top up your plan - -Plans come with usage entitlements that can be extended without upgrading to a different plan. - -| Unit | Description | Examples | -| ----------------- | ------------------------------------------------------------------------------------- | ----------------------------- | -| Seats | Each seat extends entitlements to one more member. | Docker Team, Docker Business | -| Licenses | Access to specific products or features. | AI Governance, Docker Offload | -| Minutes | Cloud build capacity, sold in blocks and consumed within the billing period. | Docker Build Cloud | -| Repositories | Additional container repositories covered by security scanning and analysis features. | DHI | -| Consuming domains | Additional consuming domains tracked in publisher analytics, sold in blocks of 25. | DVP Starter, DVP Growth | - -## Manage your plans - -To subscribe to a new plan, you can self-serve through **Billing** in [Docker Home](https://app.docker.com), or by contacting sales. - -To learn more about adding a new plan or upgrading an active plan, see [Manage plans](/manuals/subscription-billing/subscription/manage.md). - -## Next steps - -{{< grid items="grid_subscriptions" >}} diff --git a/data/whats-new.json b/data/whats-new.json index 9821101f53a3..a819220b6b45 100644 --- a/data/whats-new.json +++ b/data/whats-new.json @@ -6,7 +6,7 @@ "product": "Docker Verified Publisher", "title": "Join Docker Verified Publisher through self-service plans", "description": "Apply for DVP Starter or Growth, complete checkout after approval, and manage publisher analytics, tracked companies, and billing.", - "url": "/subscription-billing/subscription/plans/docker-verified-publisher/", + "url": "/subscription-billing/plans/docker-verified-publisher/", "published": "2026-08-20", "source_prs": [25891, 25903], "featured": true From 042d9a959f4e7e8f76d534002af30284cc1ab21f Mon Sep 17 00:00:00 2001 From: Alexa Date: Mon, 31 Aug 2026 14:14:03 -0500 Subject: [PATCH 07/19] docs: restore HDD and security FAQ URLs to match main Undo the HDD promotion to /enterprise/hardened-desktop/ and the lift of Container, Network and VM, and General security FAQs into /faqs/. Shipped URLs again match main: HDD under /enterprise/security/hardened-desktop/, FAQs under /security/faqs/. Co-authored-by: Cursor --- content/guides/admin-set-up.md | 12 ++--- content/guides/admin-user-management.md | 2 +- content/guides/zscaler.md | 2 +- content/manuals/_index.md | 2 +- .../manuals/accounts/organization/insights.md | 6 +-- .../organization/manage/manage-products.md | 10 ++-- .../accounts/organization/setup/onboard.md | 10 ++-- content/manuals/ai/gordon/_index.md | 2 +- .../ai/gordon/concepts/data-privacy.md | 4 +- .../ai/gordon/how-to/configure-tools.md | 2 +- .../manuals/ai/gordon/how-to/permissions.md | 2 +- .../features/networking/networking-how-tos.md | 2 +- .../manuals/desktop/features/wsl/_index.md | 2 +- content/manuals/desktop/release-notes.md | 52 +++++++++---------- .../settings-and-maintenance/settings.md | 12 ++--- .../desktop/setup/install/mac-install.md | 2 +- .../install/mac-permission-requirements.md | 2 +- .../desktop/setup/install/windows-install.md | 2 +- .../windows-permission-requirements.md | 2 +- content/manuals/desktop/setup/sign-in.md | 2 +- .../manuals/desktop/use-desktop/kubernetes.md | 8 +-- content/manuals/docker-hub/release-notes.md | 2 +- .../msi-install-and-configure.md | 2 +- content/manuals/enterprise/security/_index.md | 22 ++++++++ .../{ => security}/hardened-desktop/_index.md | 18 +++---- .../hardened-desktop/air-gapped-containers.md | 11 ++-- .../enhanced-container-isolation/_index.md | 5 +- .../enhanced-container-isolation/config.md | 9 ++-- .../enable-eci.md | 12 ++--- .../enhanced-container-isolation/faq.md | 9 ++-- .../limitations.md | 1 - .../image-access-management.md | 3 +- .../hardened-desktop/namespace-access.md | 2 - .../registry-access-management.md | 3 +- .../settings-management/_index.md | 9 ++-- .../compliance-reporting.md | 1 - .../configure-admin-console.md | 1 - .../configure-json-file.md | 1 - .../settings-management/settings-reference.md | 5 +- .../manuals/extensions/private-marketplace.md | 12 ++--- .../manuals/extensions/settings-feedback.md | 2 +- content/manuals/faqs/_index.md | 12 ----- content/manuals/faqs/organization-faqs.md | 2 +- content/manuals/platform-release-notes.md | 10 ++-- content/manuals/security/_index.md | 4 ++ content/manuals/security/faqs/_index.md | 6 +++ .../manuals/{ => security}/faqs/containers.md | 3 -- .../manuals/{ => security}/faqs/general.md | 5 +- .../{ => security}/faqs/networking-and-vms.md | 5 +- .../security/security-announcements.md | 8 +-- data/redirects.yml | 2 +- 51 files changed, 158 insertions(+), 169 deletions(-) create mode 100644 content/manuals/enterprise/security/_index.md rename content/manuals/enterprise/{ => security}/hardened-desktop/_index.md (87%) rename content/manuals/enterprise/{ => security}/hardened-desktop/air-gapped-containers.md (90%) rename content/manuals/enterprise/{ => security}/hardened-desktop/enhanced-container-isolation/_index.md (97%) rename content/manuals/enterprise/{ => security}/hardened-desktop/enhanced-container-isolation/config.md (94%) rename content/manuals/enterprise/{ => security}/hardened-desktop/enhanced-container-isolation/enable-eci.md (88%) rename content/manuals/enterprise/{ => security}/hardened-desktop/enhanced-container-isolation/faq.md (89%) rename content/manuals/enterprise/{ => security}/hardened-desktop/enhanced-container-isolation/limitations.md (98%) rename content/manuals/enterprise/{ => security}/hardened-desktop/image-access-management.md (97%) rename content/manuals/enterprise/{ => security}/hardened-desktop/namespace-access.md (97%) rename content/manuals/enterprise/{ => security}/hardened-desktop/registry-access-management.md (97%) rename content/manuals/enterprise/{ => security}/hardened-desktop/settings-management/_index.md (89%) rename content/manuals/enterprise/{ => security}/hardened-desktop/settings-management/compliance-reporting.md (98%) rename content/manuals/enterprise/{ => security}/hardened-desktop/settings-management/configure-admin-console.md (98%) rename content/manuals/enterprise/{ => security}/hardened-desktop/settings-management/configure-json-file.md (99%) rename content/manuals/enterprise/{ => security}/hardened-desktop/settings-management/settings-reference.md (98%) create mode 100644 content/manuals/security/faqs/_index.md rename content/manuals/{ => security}/faqs/containers.md (94%) rename content/manuals/{ => security}/faqs/general.md (91%) rename content/manuals/{ => security}/faqs/networking-and-vms.md (87%) diff --git a/content/guides/admin-set-up.md b/content/guides/admin-set-up.md index 80e81ceab2ab..1ded3e02af4b 100644 --- a/content/guides/admin-set-up.md +++ b/content/guides/admin-set-up.md @@ -142,7 +142,7 @@ If you suspect your company has multiple Docker organizations: ### Gather requirements -[Settings Management](/manuals/enterprise/hardened-desktop/settings-management/_index.md) lets you preset numerous configuration parameters for Docker Desktop. +[Settings Management](/manuals/enterprise/security/hardened-desktop/settings-management/_index.md) lets you preset numerous configuration parameters for Docker Desktop. Work with the following stakeholders to establish your company's baseline configuration: @@ -158,7 +158,7 @@ Review these areas together: for Docker Desktop users - Additional Docker products included in your subscriptions -To view the parameters that can be preset, see [Configure Settings Management](/manuals/enterprise/hardened-desktop/settings-management/configure-json-file.md#step-two-configure-the-settings-you-want-to-lock-in). +To view the parameters that can be preset, see [Configure Settings Management](/manuals/enterprise/security/hardened-desktop/settings-management/configure-json-file.md#step-two-configure-the-settings-you-want-to-lock-in). ### Optional: Meet with the Docker Implementation team @@ -172,8 +172,8 @@ To schedule a meeting, email successteam@docker.com. ### Send finalized settings files to the MDM team After reaching an agreement with the relevant teams about your baseline and -security configurations as outlined in the previous section, configure Settings Management either via [Docker Home](/manuals/enterprise/hardened-desktop/settings-management/configure-admin-console.md) or with an -[`admin-settings.json` file](/manuals/enterprise/hardened-desktop/settings-management/configure-json-file.md). +security configurations as outlined in the previous section, configure Settings Management either via [Docker Home](/manuals/enterprise/security/hardened-desktop/settings-management/configure-admin-console.md) or with an +[`admin-settings.json` file](/manuals/enterprise/security/hardened-desktop/settings-management/configure-json-file.md). Once the file is ready, collaborate with your MDM team to deploy your chosen settings, along with your chosen method for [enforcing sign-in](/manuals/security/authentication/enforce-sign-in/_index.md). @@ -261,7 +261,7 @@ SSO and SCIM setup. > Communicate with your users before proceeding, as this step will impact all > existing users signing into your Docker organization. -If you plan to use [Registry Access Management (RAM)](/manuals/enterprise/hardened-desktop/registry-access-management.md) and/or [Image Access Management (IAM)](/manuals/enterprise/hardened-desktop/image-access-management.md): +If you plan to use [Registry Access Management (RAM)](/manuals/enterprise/security/hardened-desktop/registry-access-management.md) and/or [Image Access Management (IAM)](/manuals/enterprise/security/hardened-desktop/image-access-management.md): 1. Ensure your test developer signs in to Docker Desktop using their organization credentials @@ -327,4 +327,4 @@ To continue optimizing your Docker environment: - Review your [organization's usage data](/manuals/accounts/organization/insights.md) to track adoption - Monitor [Docker Scout findings](/manuals/scout/explore/analysis.md) for security insights -- Explore [additional security features](/manuals/enterprise/hardened-desktop/_index.md) to enhance your configuration +- Explore [additional security features](/manuals/enterprise/security/hardened-desktop/_index.md) to enhance your configuration diff --git a/content/guides/admin-user-management.md b/content/guides/admin-user-management.md index 9be9aab1432b..0ec2938bde7c 100644 --- a/content/guides/admin-user-management.md +++ b/content/guides/admin-user-management.md @@ -194,5 +194,5 @@ Now that you've mastered user and access management in Docker, you can: - Review your [activity logs](/manuals/accounts/organization/activity-logs.md) regularly to maintain security awareness - Check your [Insights dashboard](/manuals/accounts/organization/insights.md) to identify opportunities for optimization -- Explore [advanced security features](/manuals/enterprise/hardened-desktop/_index.md) to further enhance your Docker environment +- Explore [advanced security features](/manuals/enterprise/security/hardened-desktop/_index.md) to further enhance your Docker environment - Share best practices with your team to ensure consistent adoption of security policies diff --git a/content/guides/zscaler.md b/content/guides/zscaler.md index 80a8a0640b4a..c705e34e526a 100644 --- a/content/guides/zscaler.md +++ b/content/guides/zscaler.md @@ -47,7 +47,7 @@ necessary. If you are not using Zscaler as a system-level proxy, manually configure proxy settings in Docker Desktop. Set up proxy settings for all clients in the -organization using [Settings Management](/manuals/enterprise/hardened-desktop/settings-management/_index.md), +organization using [Settings Management](/manuals/enterprise/security/hardened-desktop/settings-management/_index.md), or edit proxy configuration in the Docker Desktop GUI under [**Settings > Resources > Proxies**](/manuals/desktop/settings-and-maintenance/settings.md#proxies). ## Install root certificates in Docker images diff --git a/content/manuals/_index.md b/content/manuals/_index.md index 42d38b20d021..ad846c8c6bc8 100644 --- a/content/manuals/_index.md +++ b/content/manuals/_index.md @@ -103,7 +103,7 @@ params: - title: Hardened Docker Desktop description: Security features that strengthen developer environments. icon: shield-check - link: /enterprise/hardened-desktop/ + link: /enterprise/security/hardened-desktop/ --- This section contains user guides on how to install, set up, configure, and use diff --git a/content/manuals/accounts/organization/insights.md b/content/manuals/accounts/organization/insights.md index 61f3eacf3230..96e37764e08a 100644 --- a/content/manuals/accounts/organization/insights.md +++ b/content/manuals/accounts/organization/insights.md @@ -63,7 +63,7 @@ The chart contains the following data: | :--------------------------- | :---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | Active user | The number of users who have actively used Docker Desktop and either signed in with a Docker account that has a license in your organization or signed in to a Docker account with an email address from a domain associated with your organization.

Users who don’t sign in to an account associated with your organization are not represented in the data. To ensure users sign in with an account associated with your organization, you can [enforce sign-in](/manuals/security/authentication/enforce-sign-in/_index.md). | | Total organization members | The number of users who have used Docker Desktop, regardless of their Insights activity. | -| Users opted out of analytics | The number of users who are members of your organization that have opted out of sending analytics.

When users opt out of sending analytics, you won't see any of their data in Insights. To ensure that the data includes all users, you can use [Settings Management](/manuals/enterprise/hardened-desktop/settings-management/_index.md) to set `analyticsEnabled` for all your users. | +| Users opted out of analytics | The number of users who are members of your organization that have opted out of sending analytics.

When users opt out of sending analytics, you won't see any of their data in Insights. To ensure that the data includes all users, you can use [Settings Management](/manuals/enterprise/security/hardened-desktop/settings-management/_index.md) to set `analyticsEnabled` for all your users. | | Active users (graph) | The view over time for total active users. | ### Builds @@ -175,7 +175,7 @@ A Docker Desktop user export file contains the following data points: installed - Last Seen Date: The last date the user used the Docker Desktop application - Opted Out Analytics: Whether the user has opted out of the - [Send usage statistics](/manuals/enterprise/hardened-desktop/settings-management/settings-reference.md#send-usage-statistics) setting in Docker Desktop + [Send usage statistics](/manuals/enterprise/security/hardened-desktop/settings-management/settings-reference.md#send-usage-statistics) setting in Docker Desktop ## Troubleshoot Insights @@ -193,7 +193,7 @@ solutions to resolve common problems: If users have opted out of sending usage statistics for Docker Desktop, then their usage data will not be a part of Insights. To manage the setting at scale for all your users, you can use [Settings - Management](/manuals/enterprise/hardened-desktop/settings-management/_index.md) and turn on the + Management](/manuals/enterprise/security/hardened-desktop/settings-management/_index.md) and turn on the `analyticsEnabled` setting. - Ensure users use Docker Desktop and aren't using the standalone diff --git a/content/manuals/accounts/organization/manage/manage-products.md b/content/manuals/accounts/organization/manage/manage-products.md index 5a2afb5b4bc5..6f117acac01f 100644 --- a/content/manuals/accounts/organization/manage/manage-products.md +++ b/content/manuals/accounts/organization/manage/manage-products.md @@ -40,9 +40,9 @@ To manage Docker Hub access: 1. Sign in to [Docker Home](https://app.docker.com/) and select your organization, then select **Docker Desktop**. 1. Select **Registry Access** to configure - [Registry Access Management](../../../enterprise/hardened-desktop/registry-access-management.md). + [Registry Access Management](../../../enterprise/security/hardened-desktop/registry-access-management.md). 1. Select **Image Access** to control - [Image Access Management](../../../enterprise/hardened-desktop/image-access-management.md). + [Image Access Management](../../../enterprise/security/hardened-desktop/image-access-management.md). ### Docker Build Cloud access @@ -73,7 +73,7 @@ To manage Docker Scout access: [repository settings](../../../scout/explore/dashboard.md#repository-settings). 1. To manage access to Docker Scout for use on local images with Docker Desktop, use - [Settings Management](../../../enterprise/hardened-desktop/settings-management/_index.md) + [Settings Management](../../../enterprise/security/hardened-desktop/settings-management/_index.md) and set `sbomIndexing` to `false` to disable, or to `true` to enable. ### Testcontainers Cloud access @@ -99,7 +99,7 @@ To manage access to Testcontainers Cloud: > subscribe. To manage Docker Offload access for your organization, use [Settings -Management](../../../enterprise/hardened-desktop/settings-management/_index.md): +Management](../../../enterprise/security/hardened-desktop/settings-management/_index.md): 1. Sign in to [Docker Home](https://app.docker.com/), then select **Docker Desktop**. @@ -124,7 +124,7 @@ Management](../../../enterprise/hardened-desktop/settings-management/_index.md): 1. Select **Save**. For more details on Settings Management, see the [Settings -reference](../../../enterprise/hardened-desktop/settings-management/settings-reference.md#enable-docker-offload). +reference](../../../enterprise/security/hardened-desktop/settings-management/settings-reference.md#enable-docker-offload). ## Monitor product usage for your organization diff --git a/content/manuals/accounts/organization/setup/onboard.md b/content/manuals/accounts/organization/setup/onboard.md index 6bc1de453e4e..716d6f58c4d1 100644 --- a/content/manuals/accounts/organization/setup/onboard.md +++ b/content/manuals/accounts/organization/setup/onboard.md @@ -151,7 +151,7 @@ By default, members of your organization can use Docker Desktop without signing in. When users don’t sign in as a member of your organization, they don’t receive the [benefits of your organization’s subscription](https://www.docker.com/pricing?ref=Docs&refAction=DocsAdminOnboard) -and they can circumvent [Docker’s security features](/manuals/enterprise/hardened-desktop/_index.md). +and they can circumvent [Docker’s security features](/manuals/enterprise/security/hardened-desktop/_index.md). There are multiple ways you can enforce sign-in, depending on your organization's Docker configuration: @@ -165,14 +165,14 @@ Docker configuration: Docker offers the following security features to manage your organization's security posture: -- [Image Access Management](/manuals/enterprise/hardened-desktop/image-access-management.md): Control which types of images your developers can pull from Docker Hub. -- [Registry Access Management](/manuals/enterprise/hardened-desktop/registry-access-management.md): Define which registries your developers can access. -- [Settings management](/manuals/enterprise/hardened-desktop/settings-management.md): Set and control Docker Desktop settings for your users. +- [Image Access Management](/manuals/enterprise/security/hardened-desktop/image-access-management.md): Control which types of images your developers can pull from Docker Hub. +- [Registry Access Management](/manuals/enterprise/security/hardened-desktop/registry-access-management.md): Define which registries your developers can access. +- [Settings management](/manuals/enterprise/security/hardened-desktop/settings-management.md): Set and control Docker Desktop settings for your users. ## Next steps - [Manage Docker products](../manage/manage-products.md) to configure access and view usage. -- Configure [Hardened Docker Desktop](/manuals/enterprise/hardened-desktop/_index.md) to improve your organization’s security posture for containerized development. +- Configure [Hardened Docker Desktop](/manuals/enterprise/security/hardened-desktop/_index.md) to improve your organization’s security posture for containerized development. - [Manage your domains](/manuals/security/provisioning/domain-management.md) to ensure that all Docker users in your domain are part of your organization. Your Docker subscription provides many more additional features. To learn more, diff --git a/content/manuals/ai/gordon/_index.md b/content/manuals/ai/gordon/_index.md index c4809547468a..6b586e91c999 100644 --- a/content/manuals/ai/gordon/_index.md +++ b/content/manuals/ai/gordon/_index.md @@ -67,7 +67,7 @@ Before you begin: > 1. Contact Docker Support to activate Gordon for your organization. Docker > will confirm when activation is complete. > 2. Once confirmed, an organization administrator must turn on Gordon via -> [Settings Management](/manuals/enterprise/hardened-desktop/settings-management/_index.md). +> [Settings Management](/manuals/enterprise/security/hardened-desktop/settings-management/_index.md). > Set **Enable Gordon** to **Enabled** or **Always enabled**. Ensure all > Settings Management prerequisites are met for the setting to take effect > on Docker Desktop clients. diff --git a/content/manuals/ai/gordon/concepts/data-privacy.md b/content/manuals/ai/gordon/concepts/data-privacy.md index c85dbcffc827..38f5a5b49acb 100644 --- a/content/manuals/ai/gordon/concepts/data-privacy.md +++ b/content/manuals/ai/gordon/concepts/data-privacy.md @@ -95,7 +95,7 @@ For Business subscriptions, administrators can enable or disable Gordon for their organization using Settings Management. Review your organization's data handling requirements before enabling Gordon. -See [Settings Management](/enterprise/hardened-desktop/settings-management/) +See [Settings Management](/enterprise/security/hardened-desktop/settings-management/) for configuration details. ## Disabling Gordon @@ -112,7 +112,7 @@ Individual users: Business organizations: Administrators can disable Gordon for the entire organization using Settings -Management. See [Settings Management](/enterprise/hardened-desktop/settings-management/) +Management. See [Settings Management](/enterprise/security/hardened-desktop/settings-management/) for details. ## Questions about privacy diff --git a/content/manuals/ai/gordon/how-to/configure-tools.md b/content/manuals/ai/gordon/how-to/configure-tools.md index e016b41e6538..90c3b6ae11f7 100644 --- a/content/manuals/ai/gordon/how-to/configure-tools.md +++ b/content/manuals/ai/gordon/how-to/configure-tools.md @@ -77,5 +77,5 @@ Administrators can: - Lock tool configuration to prevent users from changing it - Set organization-wide tool policies -See [Settings Management](/enterprise/hardened-desktop/settings-management/) +See [Settings Management](/enterprise/security/hardened-desktop/settings-management/) for details. diff --git a/content/manuals/ai/gordon/how-to/permissions.md b/content/manuals/ai/gordon/how-to/permissions.md index 0fda05508464..3e08cfb3c58a 100644 --- a/content/manuals/ai/gordon/how-to/permissions.md +++ b/content/manuals/ai/gordon/how-to/permissions.md @@ -121,5 +121,5 @@ Available controls: For Business subscriptions, Gordon must be enabled by an administrator before users can access it. -See [Settings Management](/enterprise/hardened-desktop/settings-management/) +See [Settings Management](/enterprise/security/hardened-desktop/settings-management/) for details. diff --git a/content/manuals/desktop/features/networking/networking-how-tos.md b/content/manuals/desktop/features/networking/networking-how-tos.md index cc8db7d6b76a..6591a3abb671 100644 --- a/content/manuals/desktop/features/networking/networking-how-tos.md +++ b/content/manuals/desktop/features/networking/networking-how-tos.md @@ -97,7 +97,7 @@ For more details on proxies and proxy configurations, see the [Proxy settings do You can control how Docker handles container networking and DNS resolution to better support a range of environments — from IPv4-only to dual-stack and IPv6-only systems. These settings help prevent timeouts and connectivity issues caused by incompatible or misconfigured host networks. -You can set the following settings on the **Network** tab in the Docker Desktop Dashboard settings, or if you're an admin, with Settings Management via the [`admin-settings.json` file](/manuals/enterprise/hardened-desktop/settings-management/configure-json-file.md#networking), or [Docker Home](/manuals/enterprise/hardened-desktop/settings-management/configure-admin-console.md) +You can set the following settings on the **Network** tab in the Docker Desktop Dashboard settings, or if you're an admin, with Settings Management via the [`admin-settings.json` file](/manuals/enterprise/security/hardened-desktop/settings-management/configure-json-file.md#networking), or [Docker Home](/manuals/enterprise/security/hardened-desktop/settings-management/configure-admin-console.md) > [!NOTE] > diff --git a/content/manuals/desktop/features/wsl/_index.md b/content/manuals/desktop/features/wsl/_index.md index 2d6692fc6cd1..080e9d1bac09 100644 --- a/content/manuals/desktop/features/wsl/_index.md +++ b/content/manuals/desktop/features/wsl/_index.md @@ -97,7 +97,7 @@ WSL is designed to aid interoperability between Windows and Linux environments. For environments that require stricter isolation: - Run Docker Desktop in Hyper-V mode instead of WSL 2 to avoid the shared-kernel model entirely. -- Enable [Enhanced Container Isolation](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/_index.md) to add an additional layer of protection around container workloads regardless of backend. +- Enable [Enhanced Container Isolation](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/_index.md) to add an additional layer of protection around container workloads regardless of backend. ## Additional resources diff --git a/content/manuals/desktop/release-notes.md b/content/manuals/desktop/release-notes.md index de1d86169fdb..dce3c9fa6f8a 100644 --- a/content/manuals/desktop/release-notes.md +++ b/content/manuals/desktop/release-notes.md @@ -1446,7 +1446,7 @@ For more frequently asked questions, see the [FAQs](/manuals/desktop/troubleshoo ### Security -- Added security patches to address CVEs [2025-52565](https://github.com/opencontainers/runc/security/advisories/GHSA-9493-h29p-rfm2), [2025-52881](https://github.com/opencontainers/runc/security/advisories/GHSA-cgrx-mc8f-2prm), and [2025-31133](https://github.com/opencontainers/runc/security/advisories/GHSA-qw9x-cqr3-wc7r) when using [Enhanced Container Isolation](https://docs.docker.com/enterprise/hardened-desktop/enhanced-container-isolation). +- Added security patches to address CVEs [2025-52565](https://github.com/opencontainers/runc/security/advisories/GHSA-9493-h29p-rfm2), [2025-52881](https://github.com/opencontainers/runc/security/advisories/GHSA-cgrx-mc8f-2prm), and [2025-31133](https://github.com/opencontainers/runc/security/advisories/GHSA-qw9x-cqr3-wc7r) when using [Enhanced Container Isolation](https://docs.docker.com/enterprise/security/hardened-desktop/enhanced-container-isolation). ## 4.52.0 @@ -1604,7 +1604,7 @@ For more frequently asked questions, see the [FAQs](/manuals/desktop/troubleshoo ### Security -- Fixed [CVE-2025-10657](https://www.cve.org/CVERecord?id=CVE-2025-10657) where the Enhanced Container Isolation [Docker Socket command restrictions](../enterprise/hardened-desktop/enhanced-container-isolation/config.md#command-restrictions) feature was not working properly in Docker Desktop 4.46.0 only (the configuration for it was being ignored). +- Fixed [CVE-2025-10657](https://www.cve.org/CVERecord?id=CVE-2025-10657) where the Enhanced Container Isolation [Docker Socket command restrictions](../enterprise/security/hardened-desktop/enhanced-container-isolation/config.md#command-restrictions) feature was not working properly in Docker Desktop 4.46.0 only (the configuration for it was being ignored). ### New @@ -1649,7 +1649,7 @@ For more frequently asked questions, see the [FAQs](/manuals/desktop/troubleshoo ### New - Added a new Learning center walkthrough for Docker MCP Toolkit and other onboarding improvements. -- Administrators can now control [PAC configurations with Settings Management](/manuals/enterprise/hardened-desktop/settings-management/configure-json-file.md#proxy-settings). +- Administrators can now control [PAC configurations with Settings Management](/manuals/enterprise/security/hardened-desktop/settings-management/configure-json-file.md#proxy-settings). - The update experience has been redesigned to make it easier to understand and manage updates for Docker Desktop and its components. ### Upgrades @@ -1785,9 +1785,9 @@ We are aware of [CVE-2025-23266](https://nvd.nist.gov/vuln/detail/CVE-2025-23266 - Fixed an issue pulling images with zstd differential layers when the containerd image store is enabled. - Fixed a bug causing containers launching with the `--restart` flag to not restart properly when using Enhanced Container Isolation. -- Improved interaction between [Kubernetes custom registry images](/manuals/desktop/use-desktop/kubernetes.md#configuring-a-custom-image-registry-for-kubernetes-control-plane-images) and Enhanced Container Isolation (ECI), so the [ECI Docker Socket image list](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/config.md) no longer needs to be manually updated when using a custom registry for Kubernetes control plane images. +- Improved interaction between [Kubernetes custom registry images](/manuals/desktop/use-desktop/kubernetes.md#configuring-a-custom-image-registry-for-kubernetes-control-plane-images) and Enhanced Container Isolation (ECI), so the [ECI Docker Socket image list](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/config.md) no longer needs to be manually updated when using a custom registry for Kubernetes control plane images. - Fixed a bug where a Docker Desktop Kubernetes cluster in kind mode fails to start after restarting Docker Desktop if the user is required to be signed in but is currently signed out. -- Fixed a bug that prevented the mounting of MCP secrets into containers when [Enhanced Container Isolation](/enterprise/hardened-desktop/enhanced-container-isolation/) is enabled. +- Fixed a bug that prevented the mounting of MCP secrets into containers when [Enhanced Container Isolation](/enterprise/security/hardened-desktop/enhanced-container-isolation/) is enabled. - Fixed a bug preventing the use of `--publish-all` when `--publish` was already specified. - Fixed a bug causing the **Images** view to scroll infinitely. Fixes [docker/for-mac#7725](https://github.com/docker/for-mac/issues/7725). - Fixed a bug which caused the **Volumes** tab to be blank while in Resource Saver mode. @@ -2046,7 +2046,7 @@ We are aware of [CVE-2025-23266](https://nvd.nist.gov/vuln/detail/CVE-2025-23266 - Improved error messages when downloading Registry Access Management configuration. - If Docker can't bind an ICMPv4 socket, it now logs an error and continues rather than quits. - Enabled the memory protection keys mechanism in the Docker Desktop Linux VM, allowing containers like Oracle database images to run correctly. -- Fixed a problem with containers accessing `/proc/sys/kernel/shm*` sysctls when [Enhanced Container Isolation](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/_index.md) is enabled on Mac, Windows Hyper-V, or Linux. +- Fixed a problem with containers accessing `/proc/sys/kernel/shm*` sysctls when [Enhanced Container Isolation](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/_index.md) is enabled on Mac, Windows Hyper-V, or Linux. - Added kernel module `nft_fib_inet`, required for running firewalld in a Linux container. - MacOS QEMU Virtualization option is being deprecated on July 14, 2025. @@ -2203,7 +2203,7 @@ We are aware of [CVE-2025-23266](https://nvd.nist.gov/vuln/detail/CVE-2025-23266 #### For all platforms - Fixed a bug where access tokens generated by the `docker login` web flow could not be refreshed by Docker Desktop. -- Fixed a bug where container creation via the Docker API using `curl` failed when [Enhanced Container Isolation](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/_index.md) was enabled. +- Fixed a bug where container creation via the Docker API using `curl` failed when [Enhanced Container Isolation](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/_index.md) was enabled. - Fixed a bug where the RAM policy was not refreshed after the refresh period had elapsed. - Fixed a bug in Enhanced Container Isolation when mounting the Docker socket into a container, and then creating Docker containers with bind-mounts from within that container. - Fixed an issue that caused a discrepancy between the GUI and the CLI, the former forcing the `0.0.0.0` HostIP in port-mappings. This caused default binding IPs configured through Engine's `ip` flag, or through the bridge option `com.docker.network.bridge.host_binding_ipv4`, to not be used. @@ -2262,7 +2262,7 @@ We are aware of [CVE-2025-23266](https://nvd.nist.gov/vuln/detail/CVE-2025-23266 #### For all platforms - Fixed an issue that caused the AI Catalog in Docker Hub to be unavailable in Docker Desktop. -- Fixed an issue that caused Docker Desktop to panic with `index out of range [0] with length 0` when using [Enhanced Container Isolation](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/_index.md). +- Fixed an issue that caused Docker Desktop to panic with `index out of range [0] with length 0` when using [Enhanced Container Isolation](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/_index.md). ### Known issues @@ -2357,8 +2357,8 @@ We are aware of [CVE-2025-23266](https://nvd.nist.gov/vuln/detail/CVE-2025-23266 - Deploy Docker Desktop for Mac in bulk with the [PKG installer](/manuals/enterprise/enterprise-deployment/pkg-install-and-configure.md) (Early Access). - Use Desktop Settings Management to manage and enforce defaults via admin.docker.com (Early Access). - Enhance Container Isolation (ECI) has been improved to: - - Allow admins to [turn off Docker socket mount restrictions](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/config.md#allowing-all-containers-to-mount-the-docker-socket). - - Support wildcard tags when using the [`allowedDerivedImages` setting](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/config.md#docker-socket-mount-permissions-for-derived-images). + - Allow admins to [turn off Docker socket mount restrictions](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/config.md#allowing-all-containers-to-mount-the-docker-socket). + - Support wildcard tags when using the [`allowedDerivedImages` setting](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/config.md#docker-socket-mount-permissions-for-derived-images). ### Upgrades @@ -2462,7 +2462,7 @@ We are aware of [CVE-2025-23266](https://nvd.nist.gov/vuln/detail/CVE-2025-23266 - Fixed a bug where the **Push to Docker Hub** action in the **Images** view would result in an `invalid tag format` error. Fixes [docker/for-win#14258](https://github.com/docker/for-win/issues/14258). - Fixed an issue where Docker Desktop startup failed when ICMPv6 setup was not successful. - Added drivers that allow USB/IP to work. -- Fixed a bug in Enhanced Container Isolation (ECI) [Docker socket mount permissions for derived images](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/config.md) where it was incorrectly denying Docker socket mounts for some images when Docker Desktop uses the containerd image store. +- Fixed a bug in Enhanced Container Isolation (ECI) [Docker socket mount permissions for derived images](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/config.md) where it was incorrectly denying Docker socket mounts for some images when Docker Desktop uses the containerd image store. - Enable `NFT_NUMGEN`, `NFT_FIB_IPV4` and `NFT_FIB_IPV6` kernel modules. - Build UI: - Highlight build check warnings in the **Completed builds** list. @@ -2619,8 +2619,8 @@ We are aware of [CVE-2025-23266](https://nvd.nist.gov/vuln/detail/CVE-2025-23266 > [!NOTE] > Using `docker login` with an address that includes URL path segments is not a documented use case and is considered unsupported. The recommended usage is to specify only a registry hostname, and optionally a port, as the address for `docker login`. - When running `docker compose up` and Docker Desktop is in the Resource Saver mode, the command is unresponsive. As a workaround, manually exit the Resource Saving mode and Docker Compose becomes responsive again. -- When [Enhanced Container Isolation (ECI)](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/_index.md) is enabled, Docker Desktop may not enter Resource Saver mode. This will be fixed in a future Docker Desktop release. -- The new [ECI Docker socket mount permissions for derived images](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/config.md#docker-socket-mount-permissions-for-derived-images) feature does not yet work when Docker Desktop is configured with the **Use containerd for pulling and storing images**. This will be fixed in the next Docker Desktop release. +- When [Enhanced Container Isolation (ECI)](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/_index.md) is enabled, Docker Desktop may not enter Resource Saver mode. This will be fixed in a future Docker Desktop release. +- The new [ECI Docker socket mount permissions for derived images](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/config.md#docker-socket-mount-permissions-for-derived-images) feature does not yet work when Docker Desktop is configured with the **Use containerd for pulling and storing images**. This will be fixed in the next Docker Desktop release. ## 4.33.2 @@ -2766,7 +2766,7 @@ For more information, see [microsoft/WSL#11794](https://github.com/microsoft/WSL - Improved instructions for `watch` in the Compose File Viewer - Added support for Golang projects that don't have dependencies in Docker Init. Addresses [docker/roadmap#611](https://github.com/docker/roadmap/issues/611) -- [Settings Management](/manuals/enterprise/hardened-desktop/settings-management/_index.md) now lets admins set the default value to `ProxyEnableKerberosNTLM`. +- [Settings Management](/manuals/enterprise/security/hardened-desktop/settings-management/_index.md) now lets admins set the default value to `ProxyEnableKerberosNTLM`. - Removed a temporary compatibility fix for older versions of Visual Studio Code. - Builds view: - Changed icon for imported build record to a "files" icon. @@ -2821,7 +2821,7 @@ For more information, see [microsoft/WSL#11794](https://github.com/microsoft/WSL ### New -- [Air-Gapped Containers](/manuals/enterprise/hardened-desktop/air-gapped-containers.md) is now generally available. +- [Air-Gapped Containers](/manuals/enterprise/security/hardened-desktop/air-gapped-containers.md) is now generally available. - Docker Compose File Viewer shows your Compose YAML with syntax highlighting and contextual links to relevant docs (Beta, progressive rollout). - New Sidebar user experience. @@ -2845,7 +2845,7 @@ For more information, see [microsoft/WSL#11794](https://github.com/microsoft/WSL - Added `proxyEnableKerberosNTLM` config to `settings.json` to enable fallback to basic proxy authentication if Kerberos/NTLM environment is not properly set up. - Fixed a bug where Docker Debug was not working properly with Enhanced Container Isolation enabled. - Fixed a bug where UDP responses were not truncated properly. -- Fixed a bug where the **Update** screen was hidden when using [Settings Management](/manuals/enterprise/hardened-desktop/settings-management/_index.md). +- Fixed a bug where the **Update** screen was hidden when using [Settings Management](/manuals/enterprise/security/hardened-desktop/settings-management/_index.md). - Fixed a bug where proxy settings defined in `admin-settings.json` were not applied correctly on startup. - Fixed a bug where the **Manage Synchronized file shares with Compose** toggle did not correctly reflect the value with the feature. - Fixed a bug where a bind mounted file modified on host is not updated after the container restarts, when gRPC FUSE file sharing is used on macOS and on Windows with Hyper-V. Fixes [docker/for-mac#7274](https://github.com/docker/for-mac/issues/7274), [docker/for-win#14060](https://github.com/docker/for-win/issues/14060). @@ -2908,7 +2908,7 @@ For more information, see [microsoft/WSL#11794](https://github.com/microsoft/WSL #### For all platforms - Docker Desktop now supports [SOCKS5 proxies](/manuals/desktop/features/networking.md#socks5-proxy-support). Requires a Business subscription. -- Added a new setting to manage the onboarding survey in [Settings Management](/manuals/enterprise/hardened-desktop/settings-management/_index.md). +- Added a new setting to manage the onboarding survey in [Settings Management](/manuals/enterprise/security/hardened-desktop/settings-management/_index.md). #### For Windows @@ -2985,14 +2985,14 @@ This can be resolved by adding the user to the **docker-users** group. Before st ### New -- You can now enforce Rosetta usage via [Settings Management](/manuals/enterprise/hardened-desktop/settings-management/_index.md). -- [Docker socket mount restrictions](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/config.md) with ECI is now generally available. +- You can now enforce Rosetta usage via [Settings Management](/manuals/enterprise/security/hardened-desktop/settings-management/_index.md). +- [Docker socket mount restrictions](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/config.md) with ECI is now generally available. - Docker Engine and CLI updated to [Moby 26.0](https://github.com/moby/moby/releases/tag/v26.0.0). This includes Buildkit 0.13, sub volumes mounts, networking updates, and improvements to the containerd multi-platform image store UX. - New and improved Docker Desktop error screens: swift troubleshooting, easy diagnostics uploads, and actionable remediation. - Compose supports [Synchronized file shares (experimental)](/manuals/desktop/features/synchronized-file-sharing.md). - New [interactive Compose CLI (experimental)](/manuals/compose/how-tos/environment-variables/envvars.md#compose_menu). - Beta release of: - - Air-Gapped Containers with [Settings Management](/manuals/enterprise/hardened-desktop/air-gapped-containers.md). + - Air-Gapped Containers with [Settings Management](/manuals/enterprise/security/hardened-desktop/air-gapped-containers.md). - [Host networking](/manuals/engine/network/drivers/host.md#docker-desktop) in Docker Desktop. - [Docker Debug](use-desktop/container.md#integrated-terminal) for running containers. - [Volumes Backup & Share extension](use-desktop/volumes.md) functionality available in the **Volumes** tab. @@ -3063,7 +3063,7 @@ This can be resolved by adding the user to the **docker-users** group. Before st ### New -- [Settings Management](/manuals/enterprise/hardened-desktop/settings-management/_index.md) now allows admins to set the default file-sharing implementation and specify which paths developer can add file shares to. +- [Settings Management](/manuals/enterprise/security/hardened-desktop/settings-management/_index.md) now allows admins to set the default file-sharing implementation and specify which paths developer can add file shares to. - Added support for `socks5://` HTTP and HTTPS proxy URLs when the [`SOCKS` proxy support beta feature](/manuals/desktop/features/networking.md) is enabled. - Users can now filter volumes to see which ones are in use in the **Volumes** tab. @@ -3182,7 +3182,7 @@ This can be resolved by adding the user to the **docker-users** group. Before st - Docker init now supports Java and is generally available to all users. - [Synchronized File Shares](/manuals/desktop/features/synchronized-file-sharing.md) provides fast and flexible host-to-VM file sharing within Docker Desktop. Utilizing the technology behind [Docker’s acquisition of Mutagen](https://www.docker.com/blog/mutagen-acquisition/), this feature provides an alternative to virtual bind mounts that uses synchronized filesystem caches, improving performance for developers working with large codebases. -- Organization admins can now [configure Docker socket mount permissions](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/config.md) when ECI is enabled. +- Organization admins can now [configure Docker socket mount permissions](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/config.md) when ECI is enabled. - [Containerd Image Store](/manuals/desktop/features/containerd.md) support is now generally available to all users. - Get a debug shell into any container or image with the new [`docker debug` command](/reference/cli/docker/debug/) (Beta). - Organization admins, with a Docker Business subscription, can now configure a custom list of extensions with [Private Extensions Marketplace](/manuals/extensions/private-marketplace.md) enabled (Beta) @@ -3283,7 +3283,7 @@ This can be resolved by adding the user to the **docker-users** group. Before st ### New -- Administrators can now control access to beta and experimental features in the **Features in development** tab with [Settings Management](/manuals/enterprise/hardened-desktop/settings-management/_index.md). +- Administrators can now control access to beta and experimental features in the **Features in development** tab with [Settings Management](/manuals/enterprise/security/hardened-desktop/settings-management/_index.md). - Introduced four new version update states in the footer. - `docker init` (Beta) now supports PHP with Apache + Composer. - The [**Builds** view](use-desktop/builds.md) is now GA. You can now inspect builds, troubleshoot errors, and optimize build speed. @@ -3393,7 +3393,7 @@ This can be resolved by adding the user to the **docker-users** group. Before st - Rosetta is now Generally Available for all users on macOS 13 or later. It provides faster emulation of Intel-based images on Apple Silicon. To use Rosetta, see [Settings](/manuals/desktop/settings-and-maintenance/settings.md). Rosetta is enabled by default on macOS 14.1 and later. - Docker Desktop now detects if a WSL version is out of date. If an out dated version of WSL is detected, you can allow Docker Desktop to automatically update the installation or you can manually update WSL outside of Docker Desktop. - New installations of Docker Desktop for Windows now require a Windows version of 19044 or later. -- Administrators now have the ability to control Docker Scout image analysis in [Settings Management](/manuals/enterprise/hardened-desktop/settings-management/_index.md). +- Administrators now have the ability to control Docker Scout image analysis in [Settings Management](/manuals/enterprise/security/hardened-desktop/settings-management/_index.md). ### Upgrades @@ -3654,7 +3654,7 @@ This can be resolved by adding the user to the **docker-users** group. Before st #### For all platforms -- [Settings Management](/manuals/enterprise/hardened-desktop/settings-management/_index.md) now lets you turn off Docker Extensions for your organisation. +- [Settings Management](/manuals/enterprise/security/hardened-desktop/settings-management/_index.md) now lets you turn off Docker Extensions for your organisation. - Fixed a bug where turning on Kubernetes from the UI failed when the system was paused. - Fixed a bug where turning on Wasm from the UI failed when the system was paused. - Bind mounts are now shown when you [inspect a container](use-desktop/container.md). @@ -4286,7 +4286,7 @@ This can be resolved by adding the user to the **docker-users** group. Before st ### New -- Two new security features have been introduced for Docker Business users, Settings Management and Enhanced Container Isolation. Read more about Docker Desktop’s new [Hardened Docker Desktop security model](/manuals/enterprise/hardened-desktop/_index.md). +- Two new security features have been introduced for Docker Business users, Settings Management and Enhanced Container Isolation. Read more about Docker Desktop’s new [Hardened Docker Desktop security model](/manuals/enterprise/security/hardened-desktop/_index.md). - Added the new Dev Environments CLI `docker dev`, so you can create, list, and run Dev Envs via command line. Now it's easier to integrate Dev Envs into custom scripts. - Docker Desktop can now be installed to any drive and folder using the `--installation-dir`. Partially addresses [docker/roadmap#94](https://github.com/docker/roadmap/issues/94). diff --git a/content/manuals/desktop/settings-and-maintenance/settings.md b/content/manuals/desktop/settings-and-maintenance/settings.md index 8882f02dff7b..32f91f922ed2 100644 --- a/content/manuals/desktop/settings-and-maintenance/settings.md +++ b/content/manuals/desktop/settings-and-maintenance/settings.md @@ -24,7 +24,7 @@ You can also locate the `settings-store.json` file at: - Windows: `C:\Users\[USERNAME]\AppData\Roaming\Docker\settings-store.json` - Linux: `~/.docker/desktop/settings-store.json` -For information on enforcing settings at an organization level, see [Settings Management](/manuals/enterprise/hardened-desktop/settings-management/settings-reference.md). +For information on enforcing settings at an organization level, see [Settings Management](/manuals/enterprise/security/hardened-desktop/settings-management/settings-reference.md). ## General @@ -48,7 +48,7 @@ Configure startup behavior, UI appearance, terminal preferences, and feature def | **Choose file sharing implementation for your containers** | Choose whether you want to share files using **VirtioFS**, or **gRPC FUSE** | **VirtioFS** | Mac | Use VirtioFS for speedy file sharing. VirtioFS has reduced the time taken to complete filesystem operations by [up to 98%](https://github.com/docker/roadmap/issues/7#issuecomment-1044452206). It is the only file sharing implementation supported by Docker VMM. | |**Use Rosetta for x86_64/amd64 emulation on Apple Silicon** | Accelerate x86/AMD64 binary emulation on Apple Silicon. This option is only available if you have selected **Apple Virtualization framework** as the Virtual Machine Manager. | Disabled | Mac | | | **Send usage statistics** | Send diagnostics, crash reports, and usage data to Docker to improve and troubleshoot the application. Docker may periodically prompt you for more information. | Enabled | All | | -| **Use Enhanced Container Isolation** | Prevent containers from breaching the Linux VM. For more information, see [Enhanced Container Isolation](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/_index.md). | Disabled | All | Must be signed in and have a Docker Business subscription. | +| **Use Enhanced Container Isolation** | Prevent containers from breaching the Linux VM. For more information, see [Enhanced Container Isolation](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/_index.md). | Disabled | All | Must be signed in and have a Docker Business subscription. | | **Show CLI hints** | Display helpful CLI suggestions in terminal. | Enabled | All | Improves discoverability | | **Enable Docker Scout image analysis** | Show a **Start analysis** button when inspecting an image, which analyzes the image with Docker Scout. | Enabled | All | | | **Enable background SBOM indexing** | Automatically analyze images that you build or pull. | Disabled | All | | @@ -119,7 +119,7 @@ For more information, see [Volume mounting requires file sharing for any project Docker Desktop supports HTTP/HTTPS and SOCKS5 proxies. SOCKS5 requires a Business subscription. To prevent developers from accidentally changing the proxy settings, see -[Settings Management](/manuals/enterprise/hardened-desktop/settings-management/_index.md#what-features-can-i-configure-with-settings-management). +[Settings Management](/manuals/enterprise/security/hardened-desktop/settings-management/_index.md#what-features-can-i-configure-with-settings-management). #### Docker Desktop proxy @@ -133,7 +133,7 @@ Used for Docker Desktop host-level traffic: signing in to Docker, the Desktop ap > [!NOTE] > -> If you use a PAC file hosted on a web server, add the MIME type `application/x-ns-proxy-autoconfig` for the `.pac` extension. Without this, the PAC file may not parse correctly. See [Hardened Docker Desktop](/manuals/enterprise/hardened-desktop/air-gapped-containers.md#proxy-auto-configuration-files). +> If you use a PAC file hosted on a web server, add the MIME type `application/x-ns-proxy-autoconfig` for the `.pac` extension. Without this, the PAC file may not parse correctly. See [Hardened Docker Desktop](/manuals/enterprise/security/hardened-desktop/air-gapped-containers.md#proxy-auto-configuration-files). #### Containers proxy @@ -155,10 +155,10 @@ Used for `docker image pull` (always enforced - all `docker pull` and Compose pu When you run Windows containers, enable **Use proxy for Windows Docker daemon** to let the Windows Docker daemon connect to Docker Desktop's internal proxy. This allows Windows containers to use the configured Docker Desktop proxy, and -it is required if you want [Registry Access Management](/manuals/enterprise/hardened-desktop/registry-access-management.md) +it is required if you want [Registry Access Management](/manuals/enterprise/security/hardened-desktop/registry-access-management.md) restrictions to apply to Windows image operations. Administrators can manage the same behavior with -[**Override Windows "dockerd" port**](/manuals/enterprise/hardened-desktop/settings-management/settings-reference.md#override-windows-dockerd-port). +[**Override Windows "dockerd" port**](/manuals/enterprise/security/hardened-desktop/settings-management/settings-reference.md#override-windows-dockerd-port). #### Proxy authentication diff --git a/content/manuals/desktop/setup/install/mac-install.md b/content/manuals/desktop/setup/install/mac-install.md index 30d94c2301a9..6ed8776d56fb 100644 --- a/content/manuals/desktop/setup/install/mac-install.md +++ b/content/manuals/desktop/setup/install/mac-install.md @@ -127,7 +127,7 @@ The `install` command accepts the following flags: - `--allowed-org=`: Requires the user to sign in and be part of the specified Docker Hub organization when running the application - `--user=`: Performs the privileged configurations once during installation. This removes the need for the user to grant root privileges on first run. For more information, see [Privileged helper permission requirements](/manuals/desktop/setup/install/mac-permission-requirements.md#permission-requirements). To find the username, enter `ls /Users` in the CLI. -- `--admin-settings`: Automatically creates an `admin-settings.json` file which is used by administrators to control certain Docker Desktop settings on client machines within their organization. For more information, see [Settings Management](/manuals/enterprise/hardened-desktop/settings-management/_index.md). +- `--admin-settings`: Automatically creates an `admin-settings.json` file which is used by administrators to control certain Docker Desktop settings on client machines within their organization. For more information, see [Settings Management](/manuals/enterprise/security/hardened-desktop/settings-management/_index.md). - It must be used together with the `--allowed-org=` flag. - For example: `--allowed-org= --admin-settings="{'configurationFileVersion': 2, 'enhancedContainerIsolation': {'value': true, 'locked': false}}"` diff --git a/content/manuals/desktop/setup/install/mac-permission-requirements.md b/content/manuals/desktop/setup/install/mac-permission-requirements.md index a8fff2bc84b3..34bc7d7e2ff8 100644 --- a/content/manuals/desktop/setup/install/mac-permission-requirements.md +++ b/content/manuals/desktop/setup/install/mac-permission-requirements.md @@ -113,7 +113,7 @@ retain their original permissions. ## Enhanced Container Isolation In addition, Docker Desktop supports [Enhanced Container Isolation -mode](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/_index.md) (ECI), +mode](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/_index.md) (ECI), available to Business customers only, which further secures containers without impacting developer workflows. diff --git a/content/manuals/desktop/setup/install/windows-install.md b/content/manuals/desktop/setup/install/windows-install.md index 9049b276a6df..1465d1ba3def 100644 --- a/content/manuals/desktop/setup/install/windows-install.md +++ b/content/manuals/desktop/setup/install/windows-install.md @@ -294,7 +294,7 @@ If Microsoft Store access is blocked due to security policies: #### Security and access control - `--allowed-org=`: Requires the user to sign in and be part of the specified Docker Hub organization when running the application -- `--admin-settings`: Automatically creates an `admin-settings.json` file which is used by admins to control certain Docker Desktop settings on client machines within their organization. For more information, see [Settings Management](/manuals/enterprise/hardened-desktop/settings-management/_index.md). +- `--admin-settings`: Automatically creates an `admin-settings.json` file which is used by admins to control certain Docker Desktop settings on client machines within their organization. For more information, see [Settings Management](/manuals/enterprise/security/hardened-desktop/settings-management/_index.md). - It must be used together with the `--allowed-org=` flag. - For example:`--allowed-org= --admin-settings="{'configurationFileVersion': 2, 'enhancedContainerIsolation': {'value': true, 'locked': false}}"` - `--no-windows-containers`: Disables the Windows containers integration. This can improve security. For more information, see [Windows containers](/manuals/desktop/setup/install/windows-permission-requirements.md#windows-containers). diff --git a/content/manuals/desktop/setup/install/windows-permission-requirements.md b/content/manuals/desktop/setup/install/windows-permission-requirements.md index e0b0c05aff20..c4b06f1be930 100644 --- a/content/manuals/desktop/setup/install/windows-permission-requirements.md +++ b/content/manuals/desktop/setup/install/windows-permission-requirements.md @@ -93,7 +93,7 @@ into Docker containers still retain their original permissions. Containers don' ## Enhanced Container Isolation In addition, Docker Desktop supports [Enhanced Container Isolation -mode](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/_index.md) (ECI), +mode](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/_index.md) (ECI), available to Business customers only, which further secures containers without impacting developer workflows. diff --git a/content/manuals/desktop/setup/sign-in.md b/content/manuals/desktop/setup/sign-in.md index c5a3dbf666ba..4f78136b94f9 100644 --- a/content/manuals/desktop/setup/sign-in.md +++ b/content/manuals/desktop/setup/sign-in.md @@ -29,7 +29,7 @@ In large enterprises where admin access is restricted, administrators can [enfor - Increase your pull rate limit compared to anonymous users. See [Usage and limits](/manuals/docker-hub/usage/_index.md). -- Enhance your organization’s security posture for containerized development with [Hardened Desktop](/manuals/enterprise/hardened-desktop/_index.md). +- Enhance your organization’s security posture for containerized development with [Hardened Desktop](/manuals/enterprise/security/hardened-desktop/_index.md). > [!NOTE] > diff --git a/content/manuals/desktop/use-desktop/kubernetes.md b/content/manuals/desktop/use-desktop/kubernetes.md index 38e74e8f23a7..c5429aebc88d 100644 --- a/content/manuals/desktop/use-desktop/kubernetes.md +++ b/content/manuals/desktop/use-desktop/kubernetes.md @@ -53,7 +53,7 @@ Docker Desktop Kubernetes can be provisioned with either the `kubeadm` or `kind` provisioners. `kubeadm` is the older provisioner. It supports a single-node cluster, you can't select the kubernetes -version, it's slower to provision than `kind`, and it's not supported by [Enhanced Container Isolation](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/index.md) (ECI), +version, it's slower to provision than `kind`, and it's not supported by [Enhanced Container Isolation](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/index.md) (ECI), meaning that if ECI is enabled the cluster works but it's not protected by ECI. `kind` is the newer provisioner. It supports multi-node clusters (for @@ -156,7 +156,7 @@ factors, including the version of Kubernetes being used. The tags vary for each To accommodate scenarios where access to Docker Hub is not allowed, admins can configure Docker Desktop to pull the above listed images from a different registry (e.g., a mirror) -using the [KubernetesImagesRepository](/manuals/enterprise/hardened-desktop/settings-management/configure-json-file.md#kubernetes) setting as follows. +using the [KubernetesImagesRepository](/manuals/enterprise/security/hardened-desktop/settings-management/configure-json-file.md#kubernetes) setting as follows. An image name can be broken into `[registry[:port]/][namespace/]repository[:tag]` components. The `KubernetesImagesRepository` setting allows users to override the `[registry[:port]/][namespace]` @@ -195,8 +195,8 @@ The recommended approach to set this up is the following: > [!NOTE] > -> In Docker Desktop versions 4.43 or earlier, when using `KubernetesImagesRepository` and [Enhanced Container Isolation (ECI)](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/_index.md) -> is enabled, add the following images to the [ECI Docker socket mount image list](/manuals/enterprise/hardened-desktop/settings-management/configure-json-file.md#enhanced-container-isolation): +> In Docker Desktop versions 4.43 or earlier, when using `KubernetesImagesRepository` and [Enhanced Container Isolation (ECI)](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/_index.md) +> is enabled, add the following images to the [ECI Docker socket mount image list](/manuals/enterprise/security/hardened-desktop/settings-management/configure-json-file.md#enhanced-container-isolation): > > `[imagesRepository]/desktop-cloud-provider-kind:` > `[imagesRepository]/desktop-containerd-registry-mirror:` diff --git a/content/manuals/docker-hub/release-notes.md b/content/manuals/docker-hub/release-notes.md index 26c64ac0c574..a2b749d9ad6f 100644 --- a/content/manuals/docker-hub/release-notes.md +++ b/content/manuals/docker-hub/release-notes.md @@ -170,7 +170,7 @@ known issues for each Docker Hub release. ### New -- [Registry Access Management](/manuals/enterprise/hardened-desktop/registry-access-management.md) is now available for all Docker Business subscriptions. When enabled, your users can access specific registries in Docker Hub. +- [Registry Access Management](/manuals/enterprise/security/hardened-desktop/registry-access-management.md) is now available for all Docker Business subscriptions. When enabled, your users can access specific registries in Docker Hub. ## 2022-05-03 diff --git a/content/manuals/enterprise/enterprise-deployment/msi-install-and-configure.md b/content/manuals/enterprise/enterprise-deployment/msi-install-and-configure.md index d9084ec238c2..a6d404629050 100644 --- a/content/manuals/enterprise/enterprise-deployment/msi-install-and-configure.md +++ b/content/manuals/enterprise/enterprise-deployment/msi-install-and-configure.md @@ -200,7 +200,7 @@ In addition to the following custom properties, the Docker Desktop MSI installer | :--------------------------------- | :-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | :---------------------- | | `ENABLEDESKTOPSHORTCUT` | Creates a desktop shortcut. | 1 | | `INSTALLFOLDER` | Specifies a custom location where Docker Desktop will be installed. | C:\Program Files\Docker | -| `ADMINSETTINGS` | Automatically creates an `admin-settings.json` file which is used to [control certain Docker Desktop settings](/manuals/enterprise/hardened-desktop/settings-management/_index.md) on client machines within organizations. It must be used together with the `ALLOWEDORG` property. | None | +| `ADMINSETTINGS` | Automatically creates an `admin-settings.json` file which is used to [control certain Docker Desktop settings](/manuals/enterprise/security/hardened-desktop/settings-management/_index.md) on client machines within organizations. It must be used together with the `ALLOWEDORG` property. | None | | `ALLOWEDORG` | Requires the user to sign in and be part of the specified Docker Hub organization when running the application. This creates a registry key called `allowedOrgs` in `HKLM\Software\Policies\Docker\Docker Desktop`. | None | | `ALWAYSRUNSERVICE` | Lets users switch to Windows containers without needing admin rights | 0 | | `DISABLEWINDOWSCONTAINERS` | Disables the Windows containers integration | 0 | diff --git a/content/manuals/enterprise/security/_index.md b/content/manuals/enterprise/security/_index.md new file mode 100644 index 000000000000..88044f9dd300 --- /dev/null +++ b/content/manuals/enterprise/security/_index.md @@ -0,0 +1,22 @@ +--- +linkTitle: Security +title: Security for enterprises +description: Learn about enterprise level security features Docker has to offer and explore best practices +keywords: docker, docker hub, docker desktop, security, enterprises, scale +weight: 10 +params: + sidebar: + group: Enterprise +grid: + - title: Hardened Docker Desktop + description: Security features that strengthen developer environments. + icon: shield-check + link: /enterprise/security/hardened-desktop/ +--- + +[Hardened Docker Desktop](/manuals/enterprise/security/hardened-desktop/_index.md) +provides security features that help organizations secure developer +environments, including Settings Management, Enhanced Container Isolation, +Registry Access Management, and related controls. + +{{< grid >}} diff --git a/content/manuals/enterprise/hardened-desktop/_index.md b/content/manuals/enterprise/security/hardened-desktop/_index.md similarity index 87% rename from content/manuals/enterprise/hardened-desktop/_index.md rename to content/manuals/enterprise/security/hardened-desktop/_index.md index 38e76abc9783..972660a77fdf 100644 --- a/content/manuals/enterprise/hardened-desktop/_index.md +++ b/content/manuals/enterprise/security/hardened-desktop/_index.md @@ -4,39 +4,33 @@ linkTitle: Hardened Docker Desktop description: Security features that help organizations secure developer environments without impacting productivity keywords: security, hardened desktop, enhanced container isolation, registry access management, settings management, admins, docker desktop, image access management, air-gapped containers tags: [admin] -weight: 30 -params: - sidebar: - group: Enterprise aliases: - /security/for-admins/hardened-desktop/ - - /enterprise/security/hardened-desktop/ - - /enterprise/security/ grid: - title: "Settings Management" description: Learn how Settings Management can secure your developers' workflows. icon: shield-check - link: /enterprise/hardened-desktop/settings-management/ + link: /enterprise/security/hardened-desktop/settings-management/ - title: "Enhanced Container Isolation" description: Understand how Enhanced Container Isolation can prevent container attacks. icon: shield-check - link: /enterprise/hardened-desktop/enhanced-container-isolation/ + link: /enterprise/security/hardened-desktop/enhanced-container-isolation/ - title: "Registry Access Management" description: Control the registries developers can access while using Docker Desktop. icon: server - link: /enterprise/hardened-desktop/registry-access-management/ + link: /enterprise/security/hardened-desktop/registry-access-management/ - title: "Image Access Management" description: Control the images developers can pull from Docker Hub. icon: photo - link: /enterprise/hardened-desktop/image-access-management/ + link: /enterprise/security/hardened-desktop/image-access-management/ - title: "Air-Gapped Containers" description: Restrict containers from accessing unwanted network resources. icon: lock-closed - link: /enterprise/hardened-desktop/air-gapped-containers/ + link: /enterprise/security/hardened-desktop/air-gapped-containers/ - title: "Namespace access" description: Control whether organization members can push content to their personal namespaces. icon: folder-open - link: /enterprise/hardened-desktop/namespace-access/ + link: /enterprise/security/hardened-desktop/namespace-access/ --- {{< summary-bar feature_name="Hardened Docker Desktop" >}} diff --git a/content/manuals/enterprise/hardened-desktop/air-gapped-containers.md b/content/manuals/enterprise/security/hardened-desktop/air-gapped-containers.md similarity index 90% rename from content/manuals/enterprise/hardened-desktop/air-gapped-containers.md rename to content/manuals/enterprise/security/hardened-desktop/air-gapped-containers.md index 882422eb573e..48c797adb096 100644 --- a/content/manuals/enterprise/hardened-desktop/air-gapped-containers.md +++ b/content/manuals/enterprise/security/hardened-desktop/air-gapped-containers.md @@ -4,7 +4,6 @@ description: Restrict outbound container traffic using proxy rules, PAC files, a keywords: air gapped containers, network security, proxy configuration, container isolation, docker desktop, PAC file, network isolation aliases: - /security/for-admins/hardened-desktop/air-gapped-containers/ - - /enterprise/security/hardened-desktop/air-gapped-containers/ weight: 30 --- @@ -44,11 +43,11 @@ Before configuring air-gapped containers, you must have: - [Enforce sign-in](/manuals/security/authentication/enforce-sign-in/_index.md) enabled to ensure users authenticate with your organization - A Docker Business subscription -- Configured [Settings Management](/manuals/enterprise/hardened-desktop/settings-management/_index.md) with the `admin-settings.json` file to manage organization policies +- Configured [Settings Management](/manuals/enterprise/security/hardened-desktop/settings-management/_index.md) with the `admin-settings.json` file to manage organization policies ## Configure air-gapped containers -Add the container proxy to your [`admin-settings.json` file](/manuals/enterprise/hardened-desktop/settings-management/configure-json-file.md). For example: +Add the container proxy to your [`admin-settings.json` file](/manuals/enterprise/security/hardened-desktop/settings-management/configure-json-file.md). For example: ```json { @@ -141,11 +140,11 @@ function FindProxyForURL(url, host) { ### General considerations - `FindProxyForURL` function URL parameter format is `http://host_or_ip:port` or `https://host_or_ip:port` - - If you have an internal container trying to access `https://docs.docker.com/enterprise/hardened-desktop/air-gapped-containers` the Docker proxy service will submit docs.docker.com for the host value and https://docs.docker.com:443 for the URL value to `FindProxyForURL`, if you are using `shExpMatch` function in your PAC file as follows: + - If you have an internal container trying to access `https://docs.docker.com/enterprise/security/hardened-desktop/air-gapped-containers` the Docker proxy service will submit docs.docker.com for the host value and https://docs.docker.com:443 for the URL value to `FindProxyForURL`, if you are using `shExpMatch` function in your PAC file as follows: ```console - if(shExpMatch(url, "https://docs.docker.com:443/enterprise/hardened-desktop/*")) return "DIRECT"; + if(shExpMatch(url, "https://docs.docker.com:443/enterprise/security/hardened-desktop/*")) return "DIRECT"; ``` `shExpMatch` function will fail, instead use: @@ -230,5 +229,5 @@ $ docker run --rm alpine wget -O- https://docker.io ## Next steps -- [Explore Enhanced Container Isolation](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/_index.md) to further restrict what containers can do at runtime +- [Explore Enhanced Container Isolation](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/_index.md) to further restrict what containers can do at runtime - [Understand how Docker Desktop handles host and container networking](/manuals/desktop/features/networking/_index.md) \ No newline at end of file diff --git a/content/manuals/enterprise/hardened-desktop/enhanced-container-isolation/_index.md b/content/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/_index.md similarity index 97% rename from content/manuals/enterprise/hardened-desktop/enhanced-container-isolation/_index.md rename to content/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/_index.md index d2b4487fb835..6651dcd4f208 100644 --- a/content/manuals/enterprise/hardened-desktop/enhanced-container-isolation/_index.md +++ b/content/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/_index.md @@ -6,7 +6,6 @@ keywords: enhanced container isolation, container security, sysbox runtime, linu aliases: - /desktop/hardened-desktop/enhanced-container-isolation/ - /security/for-admins/hardened-desktop/enhanced-container-isolation/ - - /enterprise/security/hardened-desktop/enhanced-container-isolation/ weight: 10 --- @@ -14,7 +13,7 @@ weight: 10 Enhanced Container Isolation (ECI) prevents malicious containers from compromising Docker Desktop or the host system. It applies advanced security techniques automatically while maintaining full developer productivity and workflow compatibility. -- ECI strengthens container isolation and locks in security configurations created by administrators, such as [Registry Access Management policies](/manuals/enterprise/hardened-desktop/registry-access-management.md) and [Settings Management](../settings-management/_index.md) controls. +- ECI strengthens container isolation and locks in security configurations created by administrators, such as [Registry Access Management policies](/manuals/enterprise/security/hardened-desktop/registry-access-management.md) and [Settings Management](../settings-management/_index.md) controls. - ECI works alongside other Docker security features like reduced Linux capabilities, seccomp, and AppArmor. If you are using WSL2 backend, ensure you’re running WSL version 2.6 or later. This is required because ECI depends on a Linux kernel version of at least 6.3.0, and WSL 2.6+ includes kernel version 6.6. @@ -213,4 +212,4 @@ Enhanced Container Isolation maintains optimized performance and full compatibil > [!IMPORTANT] > -> ECI protection varies by Docker Desktop version and doesn't yet protect extension containers. Docker builds and Kubernetes in Docker Desktop have varying protection levels depending on the version. For details, see [Enhanced Container Isolation limitations](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/limitations.md). +> ECI protection varies by Docker Desktop version and doesn't yet protect extension containers. Docker builds and Kubernetes in Docker Desktop have varying protection levels depending on the version. For details, see [Enhanced Container Isolation limitations](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/limitations.md). diff --git a/content/manuals/enterprise/hardened-desktop/enhanced-container-isolation/config.md b/content/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/config.md similarity index 94% rename from content/manuals/enterprise/hardened-desktop/enhanced-container-isolation/config.md rename to content/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/config.md index 3b21936bf31d..2ce32c791dd2 100644 --- a/content/manuals/enterprise/hardened-desktop/enhanced-container-isolation/config.md +++ b/content/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/config.md @@ -5,7 +5,6 @@ description: Configure Docker socket exceptions and advanced settings for Enhanc keywords: enhanced container isolation, docker socket, configuration, testcontainers, admin settings aliases: - /security/for-admins/hardened-desktop/enhanced-container-isolation/config/ - - /enterprise/security/hardened-desktop/enhanced-container-isolation/config/ weight: 20 --- @@ -33,7 +32,7 @@ Configure Docker socket exceptions using Settings Management: 1. Sign in to [Docker Home](https://app.docker.com) and select your organization from the top-left account drop-down. 1. Select **Docker Desktop**, then **Settings Management**. -1. [Create or edit a setting policy](/manuals/enterprise/hardened-desktop/settings-management/configure-admin-console.md). +1. [Create or edit a setting policy](/manuals/enterprise/security/hardened-desktop/settings-management/configure-admin-console.md). 1. Find **Enhanced Container Isolation** settings. 1. Configure **Docker socket access control** with your trusted images and command restrictions. @@ -41,7 +40,7 @@ command restrictions. {{< /tab >}} {{< tab name="JSON file" >}} -Create an [`admin-settings.json` file](/manuals/enterprise/hardened-desktop/settings-management/configure-json-file.md) and add: +Create an [`admin-settings.json` file](/manuals/enterprise/security/hardened-desktop/settings-management/configure-json-file.md) and add: ```json { @@ -279,5 +278,5 @@ This resolves digest mismatches when upstream images are updated. ## Next steps -- Review [Enhanced Container Isolation limitations](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/limitations.md). -- Review [Enhanced Container Isolation FAQs](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/faq.md). +- Review [Enhanced Container Isolation limitations](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/limitations.md). +- Review [Enhanced Container Isolation FAQs](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/faq.md). diff --git a/content/manuals/enterprise/hardened-desktop/enhanced-container-isolation/enable-eci.md b/content/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/enable-eci.md similarity index 88% rename from content/manuals/enterprise/hardened-desktop/enhanced-container-isolation/enable-eci.md rename to content/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/enable-eci.md index 413d474e4647..93478fbf86be 100644 --- a/content/manuals/enterprise/hardened-desktop/enhanced-container-isolation/enable-eci.md +++ b/content/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/enable-eci.md @@ -4,8 +4,6 @@ linkTitle: Enable ECI description: Enable Enhanced Container Isolation to secure containers in Docker Desktop keywords: enhanced container isolation, enable eci, container security, docker desktop setup weight: 15 -aliases: - - /enterprise/security/hardened-desktop/enhanced-container-isolation/enable-eci/ --- {{< summary-bar feature_name="Hardened Docker Desktop" >}} @@ -53,13 +51,13 @@ Configure Enhanced Container Isolation organization-wide using Settings Manageme 1. Sign in to [Docker Home](https://app.docker.com) and select your organization from the top-left account drop-down. 1. Select **Docker Desktop**, then **Settings Management**. -1. [Create or edit a setting policy](/manuals/enterprise/hardened-desktop/settings-management/configure-admin-console.md). +1. [Create or edit a setting policy](/manuals/enterprise/security/hardened-desktop/settings-management/configure-admin-console.md). 1. Set **Enhanced Container Isolation** to **Always enabled**. {{< /tab >}} {{< tab name="JSON file" >}} -1. Create an [`admin-settings.json` file](/manuals/enterprise/hardened-desktop/settings-management/configure-json-file.md) and add: +1. Create an [`admin-settings.json` file](/manuals/enterprise/security/hardened-desktop/settings-management/configure-json-file.md) and add: ```json { @@ -90,7 +88,7 @@ For ECI settings to take effect: > > Restarting from the Docker Desktop menu isn't sufficient. Users must completely quit and reopen Docker Desktop. -You can also configure [Docker socket mount permissions](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/config.md) for trusted images that need Docker API access. +You can also configure [Docker socket mount permissions](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/config.md) for trusted images that need Docker API access. ## Verify Enhanced Container Isolation is active @@ -166,5 +164,5 @@ Docker Desktop settings. ## Next steps -- Review [Configure Docker socket exceptions and advanced settings](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/config.md). -- Review [Enhanced Container Isolation limitations](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/limitations.md). +- Review [Configure Docker socket exceptions and advanced settings](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/config.md). +- Review [Enhanced Container Isolation limitations](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/limitations.md). diff --git a/content/manuals/enterprise/hardened-desktop/enhanced-container-isolation/faq.md b/content/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/faq.md similarity index 89% rename from content/manuals/enterprise/hardened-desktop/enhanced-container-isolation/faq.md rename to content/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/faq.md index d1af00951bea..3dee031d634c 100644 --- a/content/manuals/enterprise/hardened-desktop/enhanced-container-isolation/faq.md +++ b/content/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/faq.md @@ -6,7 +6,6 @@ keywords: enhanced container isolation, faq, troubleshooting, docker desktop toc_max: 2 aliases: - /security/for-admins/hardened-desktop/enhanced-container-isolation/faq/ - - /enterprise/security/hardened-desktop/enhanced-container-isolation/faq/ weight: 40 --- @@ -20,7 +19,7 @@ No. ECI works automatically in the background by creating more secure containers ## Do all container workloads work well with ECI? -Most container workloads run without issues when ECI is turned on. However, some advanced workloads that require specific kernel-level access may not work. For details about which workloads are affected, see [ECI limitations](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/limitations.md). +Most container workloads run without issues when ECI is turned on. However, some advanced workloads that require specific kernel-level access may not work. For details about which workloads are affected, see [ECI limitations](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/limitations.md). ## Why not just restrict usage of the `--privileged` flag? @@ -51,7 +50,7 @@ $ docker stop $(docker ps -q) $ docker rm $(docker ps -aq) ``` -For more details, see [Enable Enhanced Container Isolation](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/enable-eci.md). +For more details, see [Enable Enhanced Container Isolation](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/enable-eci.md). ## Which containers does ECI protect? @@ -73,13 +72,13 @@ ECI protection varies by container type and Docker Desktop version: - Docker Debug containers - Kubernetes with Kubeadm provisioner -For complete details, see [ECI limitations](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/limitations.md). +For complete details, see [ECI limitations](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/limitations.md). ## Can I mount the Docker socket with ECI turned on? By default, no. ECI blocks Docker socket bind mounts for security. However, you can configure exceptions for trusted images like Testcontainers. -For configuration details, see [Configure Docker socket exceptions](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/config.md). +For configuration details, see [Configure Docker socket exceptions](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/config.md). ## What bind mounts does ECI restrict? diff --git a/content/manuals/enterprise/hardened-desktop/enhanced-container-isolation/limitations.md b/content/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/limitations.md similarity index 98% rename from content/manuals/enterprise/hardened-desktop/enhanced-container-isolation/limitations.md rename to content/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/limitations.md index 119c7ce3b403..e7a2f63736b4 100644 --- a/content/manuals/enterprise/hardened-desktop/enhanced-container-isolation/limitations.md +++ b/content/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/limitations.md @@ -7,7 +7,6 @@ toc_max: 3 weight: 30 aliases: - /security/for-admins/hardened-desktop/enhanced-container-isolation/limitations/ - - /enterprise/security/hardened-desktop/enhanced-container-isolation/limitations/ --- {{< summary-bar feature_name="Hardened Docker Desktop" >}} diff --git a/content/manuals/enterprise/hardened-desktop/image-access-management.md b/content/manuals/enterprise/security/hardened-desktop/image-access-management.md similarity index 97% rename from content/manuals/enterprise/hardened-desktop/image-access-management.md rename to content/manuals/enterprise/security/hardened-desktop/image-access-management.md index b929afefc4f4..e1248813b10e 100644 --- a/content/manuals/enterprise/hardened-desktop/image-access-management.md +++ b/content/manuals/enterprise/security/hardened-desktop/image-access-management.md @@ -7,7 +7,6 @@ aliases: - /admin/organization/image-access/ - /security/for-admins/image-access-management/ - /security/for-admins/hardened-desktop/image-access-management/ - - /enterprise/security/hardened-desktop/image-access-management/ weight: 50 --- @@ -110,7 +109,7 @@ Image access restrictions apply to all Docker Hub operations including pulls, bu ## Scope and bypass considerations -- Image Access Management only controls access to Docker Hub images. Images from other registries aren't affected by these policies. Use [Registry Access Management](/manuals/enterprise/hardened-desktop/registry-access-management.md) to control access to other registries. +- Image Access Management only controls access to Docker Hub images. Images from other registries aren't affected by these policies. Use [Registry Access Management](/manuals/enterprise/security/hardened-desktop/registry-access-management.md) to control access to other registries. - Users can potentially bypass Image Access Management by signing out of Docker Desktop (unless sign-in is enforced), using images from other registries that aren't restricted, or using registry mirrors or proxies. Enforce sign-in and combine with Registry Access Management for comprehensive control. - Image restrictions apply to Dockerfile `FROM` instructions, Docker Compose services using restricted images will fail, multi-stage builds may be affected if intermediate images are restricted, and CI/CD pipelines using diverse image types may be impacted. diff --git a/content/manuals/enterprise/hardened-desktop/namespace-access.md b/content/manuals/enterprise/security/hardened-desktop/namespace-access.md similarity index 97% rename from content/manuals/enterprise/hardened-desktop/namespace-access.md rename to content/manuals/enterprise/security/hardened-desktop/namespace-access.md index 9d502100fda8..14c81e03fe51 100644 --- a/content/manuals/enterprise/hardened-desktop/namespace-access.md +++ b/content/manuals/enterprise/security/hardened-desktop/namespace-access.md @@ -5,8 +5,6 @@ description: Control whether organization members can push content to their pers keywords: namespace access, docker hub, personal namespace, organization security, docker business tags: [admin] weight: 60 -aliases: - - /enterprise/security/hardened-desktop/namespace-access/ --- {{< summary-bar feature_name="Namespace access" >}} diff --git a/content/manuals/enterprise/hardened-desktop/registry-access-management.md b/content/manuals/enterprise/security/hardened-desktop/registry-access-management.md similarity index 97% rename from content/manuals/enterprise/hardened-desktop/registry-access-management.md rename to content/manuals/enterprise/security/hardened-desktop/registry-access-management.md index aafa8418da2c..55665b4a2335 100644 --- a/content/manuals/enterprise/hardened-desktop/registry-access-management.md +++ b/content/manuals/enterprise/security/hardened-desktop/registry-access-management.md @@ -12,7 +12,6 @@ aliases: - /security/for-admins/registry-access-management/ - /security/for-admins/hardened-desktop/registry-access-management/ - /docker-hub/registry-access-management/ - - /enterprise/security/hardened-desktop/registry-access-management/ weight: 40 --- @@ -165,5 +164,5 @@ To maximize security effectiveness: - Confirm all necessary redirect domains are included - Ensure development workflows aren't disrupted - Combine with - [Enhanced Container Isolation](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/_index.md) + [Enhanced Container Isolation](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/_index.md) for broader Desktop security \ No newline at end of file diff --git a/content/manuals/enterprise/hardened-desktop/settings-management/_index.md b/content/manuals/enterprise/security/hardened-desktop/settings-management/_index.md similarity index 89% rename from content/manuals/enterprise/hardened-desktop/settings-management/_index.md rename to content/manuals/enterprise/security/hardened-desktop/settings-management/_index.md index f9f3d7a49ad9..4fab86163dce 100644 --- a/content/manuals/enterprise/hardened-desktop/settings-management/_index.md +++ b/content/manuals/enterprise/security/hardened-desktop/settings-management/_index.md @@ -6,7 +6,6 @@ title: Settings Management linkTitle: Settings Management aliases: - /security/for-admins/hardened-desktop/settings-management/ - - /enterprise/security/hardened-desktop/settings-management/ weight: 10 --- @@ -26,9 +25,9 @@ Settings Management is designed for organizations that: Administrators can define settings using one of these methods: -- [Docker Home](/manuals/enterprise/hardened-desktop/settings-management/configure-admin-console.md): Create and assign settings policies via Docker Home. This provides a web-based interface for managing settings +- [Docker Home](/manuals/enterprise/security/hardened-desktop/settings-management/configure-admin-console.md): Create and assign settings policies via Docker Home. This provides a web-based interface for managing settings across your organization. -- [`admin-settings.json` file](/manuals/enterprise/hardened-desktop/settings-management/configure-json-file.md): Place a configuration file on the +- [`admin-settings.json` file](/manuals/enterprise/security/hardened-desktop/settings-management/configure-json-file.md): Place a configuration file on the user's machine to enforce settings. This method works well for automated deployments and scripted installations. @@ -46,7 +45,7 @@ Settings Management supports a wide range of Docker Desktop features, including: - Security policies - Cloud policies -For a complete list of settings you can enforce, see the [Settings reference](/manuals/enterprise/hardened-desktop/settings-management/settings-reference.md). +For a complete list of settings you can enforce, see the [Settings reference](/manuals/enterprise/security/hardened-desktop/settings-management/settings-reference.md). ## Policy precedence @@ -66,7 +65,7 @@ You can create settings management policies at any time, but your organization n ensure all developers authenticate with your organization. 3. Choose a configuration method: - Use the `--admin-settings` installer flag on [macOS](/manuals/desktop/setup/install/mac-install.md#install-from-the-command-line) or [Windows](/manuals/desktop/setup/install/windows-install.md#install-from-the-command-line) to automatically create the `admin-settings.json`. - - Manually create and configure the [`admin-settings.json` file](/manuals/enterprise/hardened-desktop/settings-management/configure-json-file.md). + - Manually create and configure the [`admin-settings.json` file](/manuals/enterprise/security/hardened-desktop/settings-management/configure-json-file.md). - Create a settings policy in the [Docker Home](configure-admin-console.md). After configuration, developers receive the enforced settings when they: diff --git a/content/manuals/enterprise/hardened-desktop/settings-management/compliance-reporting.md b/content/manuals/enterprise/security/hardened-desktop/settings-management/compliance-reporting.md similarity index 98% rename from content/manuals/enterprise/hardened-desktop/settings-management/compliance-reporting.md rename to content/manuals/enterprise/security/hardened-desktop/settings-management/compliance-reporting.md index 64a525bdd382..6b55e67fadde 100644 --- a/content/manuals/enterprise/hardened-desktop/settings-management/compliance-reporting.md +++ b/content/manuals/enterprise/security/hardened-desktop/settings-management/compliance-reporting.md @@ -6,7 +6,6 @@ keywords: settings management, compliance reporting, docker home, policy enforce weight: 30 aliases: - /security/for-admins/hardened-desktop/settings-management/compliance-reporting/ - - /enterprise/security/hardened-desktop/settings-management/compliance-reporting/ --- {{< summary-bar feature_name="Compliance reporting" >}} diff --git a/content/manuals/enterprise/hardened-desktop/settings-management/configure-admin-console.md b/content/manuals/enterprise/security/hardened-desktop/settings-management/configure-admin-console.md similarity index 98% rename from content/manuals/enterprise/hardened-desktop/settings-management/configure-admin-console.md rename to content/manuals/enterprise/security/hardened-desktop/settings-management/configure-admin-console.md index e8c7df8e74bc..4be0aa7fc418 100644 --- a/content/manuals/enterprise/hardened-desktop/settings-management/configure-admin-console.md +++ b/content/manuals/enterprise/security/hardened-desktop/settings-management/configure-admin-console.md @@ -6,7 +6,6 @@ keywords: docker home, settings management, policy configuration, enterprise con weight: 20 aliases: - /security/for-admins/hardened-desktop/settings-management/configure-admin-console/ - - /enterprise/security/hardened-desktop/settings-management/configure-admin-console/ --- {{< summary-bar feature_name="Admin Console" >}} diff --git a/content/manuals/enterprise/hardened-desktop/settings-management/configure-json-file.md b/content/manuals/enterprise/security/hardened-desktop/settings-management/configure-json-file.md similarity index 99% rename from content/manuals/enterprise/hardened-desktop/settings-management/configure-json-file.md rename to content/manuals/enterprise/security/hardened-desktop/settings-management/configure-json-file.md index 8b1a3f77519b..30f3a400c22f 100644 --- a/content/manuals/enterprise/hardened-desktop/settings-management/configure-json-file.md +++ b/content/manuals/enterprise/security/hardened-desktop/settings-management/configure-json-file.md @@ -7,7 +7,6 @@ weight: 10 aliases: - /security/for-admins/hardened-desktop/settings-management/configure/ - /security/for-admins/hardened-desktop/settings-management/configure-json-file/ - - /enterprise/security/hardened-desktop/settings-management/configure-json-file/ --- {{< summary-bar feature_name="Hardened Docker Desktop" >}} diff --git a/content/manuals/enterprise/hardened-desktop/settings-management/settings-reference.md b/content/manuals/enterprise/security/hardened-desktop/settings-management/settings-reference.md similarity index 98% rename from content/manuals/enterprise/hardened-desktop/settings-management/settings-reference.md rename to content/manuals/enterprise/security/hardened-desktop/settings-management/settings-reference.md index 1462378fdad6..80b254341fcc 100644 --- a/content/manuals/enterprise/hardened-desktop/settings-management/settings-reference.md +++ b/content/manuals/enterprise/security/hardened-desktop/settings-management/settings-reference.md @@ -6,10 +6,9 @@ keywords: docker desktop settings, configuration reference, admin controls, sett toc_max: 2 aliases: - /security/for-admins/hardened-desktop/settings-management/settings-reference/ - - /enterprise/security/hardened-desktop/settings-management/settings-reference/ --- -This reference documents Docker Desktop settings that administrators can configure using [Settings Management](/manuals/enterprise/hardened-desktop/settings-management/_index.md). Use this page to understand which settings are available, their accepted values, platform compatibility, and which configuration methods apply. +This reference documents Docker Desktop settings that administrators can configure using [Settings Management](/manuals/enterprise/security/hardened-desktop/settings-management/_index.md). Use this page to understand which settings are available, their accepted values, platform compatibility, and which configuration methods apply. > [!NOTE] > @@ -432,7 +431,7 @@ The [`proxy`](#proxy) setting governs Docker Desktop host-level traffic: the Des } ``` -For more information, see [Air-gapped containers](/manuals/enterprise/hardened-desktop/air-gapped-containers.md). +For more information, see [Air-gapped containers](/manuals/enterprise/security/hardened-desktop/air-gapped-containers.md). ## LinuxVM diff --git a/content/manuals/extensions/private-marketplace.md b/content/manuals/extensions/private-marketplace.md index 849d3f7f0556..d41de893890f 100644 --- a/content/manuals/extensions/private-marketplace.md +++ b/content/manuals/extensions/private-marketplace.md @@ -11,7 +11,7 @@ weight: 30 Learn how to configure and set up a private marketplace with a curated list of extensions for your Docker Desktop users. -Docker Extensions' private marketplace is designed specifically for organizations who don’t give developers root access to their machines. It makes use of [Settings Management](/manuals/enterprise/hardened-desktop/settings-management/_index.md) so administrators have complete control over the private marketplace. +Docker Extensions' private marketplace is designed specifically for organizations who don’t give developers root access to their machines. It makes use of [Settings Management](/manuals/enterprise/security/hardened-desktop/settings-management/_index.md) so administrators have complete control over the private marketplace. ## Prerequisites @@ -65,7 +65,7 @@ This creates 2 files: > [!IMPORTANT] > -> If your org is using [Settings Management](/manuals/enterprise/hardened-desktop/settings-management/_index.md) via [Docker Home](manuals/enterprise/hardened-desktop/settings-management/configure-admin-console/_index.md), you will not need the `admin-settings.json` file. Delete the generated file and keep only the `extensions.txt` file. +> If your org is using [Settings Management](/manuals/enterprise/security/hardened-desktop/settings-management/_index.md) via [Docker Home](manuals/enterprise/security/hardened-desktop/settings-management/configure-admin-console/_index.md), you will not need the `admin-settings.json` file. Delete the generated file and keep only the `extensions.txt` file. ## Step two: Set the behaviour @@ -73,7 +73,7 @@ The generated `admin-settings.json` file includes various settings you can modif > [!IMPORTANT] > -> If your org is managing settings via [Docker Home](manuals/enterprise/hardened-desktop/settings-management/configure-admin-console/_index.md), you will define the same settings in Docker Home instead of the `admin-settings.json` file. +> If your org is managing settings via [Docker Home](manuals/enterprise/security/hardened-desktop/settings-management/configure-admin-console/_index.md), you will define the same settings in Docker Home instead of the `admin-settings.json` file. Each setting has a `value` that you can set, including a `locked` field that lets you lock the setting and make it unchangeable by your developers. @@ -89,7 +89,7 @@ Each setting has a `value` that you can set, including a `locked` field that let } ``` -To find out more information about the `admin-settings.json` file, see [Settings Management](/manuals/enterprise/hardened-desktop/settings-management/_index.md). +To find out more information about the `admin-settings.json` file, see [Settings Management](/manuals/enterprise/security/hardened-desktop/settings-management/_index.md). ## Step three: List allowed extensions @@ -194,7 +194,7 @@ It's recommended that you try the private marketplace on your Docker Desktop ins > [!IMPORTANT] > -> > If your org is managing settings via [Docker Home](manuals/enterprise/hardened-desktop/settings-management/configure-admin-console/_index.md), in Docker Desktop 4.59 and earlier, you must manually delete the `admin-settings.json` file created in the target folder by the `apply` command before step 2. In Docker Desktop 4.60 and later, this step is no longer necessary. +> > If your org is managing settings via [Docker Home](manuals/enterprise/security/hardened-desktop/settings-management/configure-admin-console/_index.md), in Docker Desktop 4.59 and earlier, you must manually delete the `admin-settings.json` file created in the target folder by the `apply` command before step 2. In Docker Desktop 4.60 and later, this step is no longer necessary. When you select the **Extensions** tab, you should see the private marketplace listing only the extensions you have allowed in `extensions.txt`. @@ -205,7 +205,7 @@ When you select the **Extensions** tab, you should see the private marketplace l Once you’ve confirmed that the private marketplace configuration works, the final step is to distribute the files to the developers’ machines with the MDM software your organization uses. For example, [Jamf](https://www.jamf.com/). The files to distribute are: -* `admin-settings.json` (except if your org is managing settings via [Docker Home](manuals/enterprise/hardened-desktop/settings-management/configure-admin-console/_index.md)) +* `admin-settings.json` (except if your org is managing settings via [Docker Home](manuals/enterprise/security/hardened-desktop/settings-management/configure-admin-console/_index.md)) * the entire `extension-marketplace` folder and its subfolders These files must be placed on developer's machines. Depending on your operating system, the target location is (as mentioned above): diff --git a/content/manuals/extensions/settings-feedback.md b/content/manuals/extensions/settings-feedback.md index cc7fb18f4c43..0b6e5e3ceb96 100644 --- a/content/manuals/extensions/settings-feedback.md +++ b/content/manuals/extensions/settings-feedback.md @@ -24,7 +24,7 @@ Docker Extensions is switched off by default. To change your settings: > - `~/Library/Group Containers/group.com.docker/settings-store.json` on Mac > - `C:\Users\[USERNAME]\AppData\Roaming\Docker\settings-store.json` on Windows > -> This can also be done with [Hardened Docker Desktop](/manuals/enterprise/hardened-desktop/_index.md) +> This can also be done with [Hardened Docker Desktop](/manuals/enterprise/security/hardened-desktop/_index.md) ### Turn on or turn off extensions not available in the Marketplace diff --git a/content/manuals/faqs/_index.md b/content/manuals/faqs/_index.md index 1726d205ee09..13b290e22170 100644 --- a/content/manuals/faqs/_index.md +++ b/content/manuals/faqs/_index.md @@ -23,18 +23,6 @@ grid: description: FAQs about companies, seats, and company owners. icon: building-office-2 link: /faqs/company-faqs/ - - title: General security FAQs - description: FAQs about Docker security, authentication, and organization management. - icon: lock-closed - link: /faqs/general/ - - title: Container security FAQs - description: FAQs about container security and isolation. - icon: lock-closed - link: /faqs/containers/ - - title: Network and VM FAQs - description: FAQs about Docker Desktop networking and virtualization security. - icon: globe-alt - link: /faqs/networking-and-vms/ - title: SSO FAQs description: FAQs about single sign-on, identity providers, and user management. icon: lock-closed diff --git a/content/manuals/faqs/organization-faqs.md b/content/manuals/faqs/organization-faqs.md index d6067e3b946d..9003ad164bc0 100644 --- a/content/manuals/faqs/organization-faqs.md +++ b/content/manuals/faqs/organization-faqs.md @@ -35,7 +35,7 @@ Yes. You can Some benefits of enforcing sign-in are: - Ensures users receive the benefits of your subscription. -- Ensures security features like [Image Access Management](/manuals/enterprise/hardened-desktop/image-access-management.md) and [Registry Access Management](/manuals/enterprise/hardened-desktop/registry-access-management.md) are applied. +- Ensures security features like [Image Access Management](/manuals/enterprise/security/hardened-desktop/image-access-management.md) and [Registry Access Management](/manuals/enterprise/security/hardened-desktop/registry-access-management.md) are applied. - Ensures you gain insights into users' activity. ### Can I convert my personal Docker ID to an organization account? diff --git a/content/manuals/platform-release-notes.md b/content/manuals/platform-release-notes.md index cde03012efcc..311eddd8442c 100644 --- a/content/manuals/platform-release-notes.md +++ b/content/manuals/platform-release-notes.md @@ -18,7 +18,7 @@ This page provides details on new features, enhancements, known issues, and bug - Administrators can now control whether organization members can push content to their personal namespaces on Docker Hub with [namespace access - control](/manuals/enterprise/hardened-desktop/namespace-access.md). + control](/manuals/enterprise/security/hardened-desktop/namespace-access.md). - Administrators can now prevent creating public repositories within organization namespaces using the [Disable public repositories](/manuals/docker-hub/settings.md#disable-creation-of-public-repos) setting. @@ -28,7 +28,7 @@ This page provides details on new features, enhancements, known issues, and bug ### New - Administrators can now use an allow list with [Image Access - Management](/manuals/enterprise/hardened-desktop/image-access-management.md) + Management](/manuals/enterprise/security/hardened-desktop/image-access-management.md) to approve specific repositories that bypass image access controls. ## 2025-01-30 @@ -55,13 +55,13 @@ This page provides details on new features, enhancements, known issues, and bug - Enforce sign-in with [configuration profiles](/manuals/security/authentication/enforce-sign-in/methods.md#configuration-profiles-method-mac-only) (Early Access). - Enforce sign-in for more than one organization at a time (Early Access). - Deploy Docker Desktop for Mac in bulk with the [PKG installer](/manuals/enterprise/enterprise-deployment/pkg-install-and-configure.md) (Early Access). - - [Use Desktop Settings Management via the Docker Admin Console](/manuals/enterprise/hardened-desktop/settings-management/configure-admin-console.md) (Early Access). + - [Use Desktop Settings Management via the Docker Admin Console](/manuals/enterprise/security/hardened-desktop/settings-management/configure-admin-console.md) (Early Access). ### Bug fixes and enhancements - Enhance Container Isolation (ECI) has been improved to: - - Permit admins to [turn off Docker socket mount restrictions](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/config.md#allowing-all-containers-to-mount-the-docker-socket). - - Support wildcard tags when using the [`allowedDerivedImages` setting](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/config.md#docker-socket-mount-permissions-for-derived-images). + - Permit admins to [turn off Docker socket mount restrictions](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/config.md#allowing-all-containers-to-mount-the-docker-socket). + - Support wildcard tags when using the [`allowedDerivedImages` setting](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/config.md#docker-socket-mount-permissions-for-derived-images). ## 2024-11-11 diff --git a/content/manuals/security/_index.md b/content/manuals/security/_index.md index 0d1e1afe3d47..58fa86f66d18 100644 --- a/content/manuals/security/_index.md +++ b/content/manuals/security/_index.md @@ -32,6 +32,10 @@ grid_developers: icon: shield-exclamation link: /compose/how-tos/use-secrets/ grid_resources: +- title: Security FAQs + description: Explore common security FAQs. + icon: question-mark-circle + link: /faq/security/general/ - title: Security best practices description: Understand the steps you can take to improve the security of your container. icon: squares-2x2 diff --git a/content/manuals/security/faqs/_index.md b/content/manuals/security/faqs/_index.md new file mode 100644 index 000000000000..4aebbca68bbb --- /dev/null +++ b/content/manuals/security/faqs/_index.md @@ -0,0 +1,6 @@ +--- +build: + render: never +title: FAQs +weight: 70 +--- diff --git a/content/manuals/faqs/containers.md b/content/manuals/security/faqs/containers.md similarity index 94% rename from content/manuals/faqs/containers.md rename to content/manuals/security/faqs/containers.md index cdc3035b6a60..5c3496f338eb 100644 --- a/content/manuals/faqs/containers.md +++ b/content/manuals/security/faqs/containers.md @@ -7,9 +7,6 @@ weight: 20 tags: [FAQ] aliases: - /faq/security/containers/ -- /security/faqs/containers/ -- /platform/security/resources/faqs/containers/ -- /platform/security/faqs/containers/ --- ## How are containers isolated from the host in Docker Desktop? diff --git a/content/manuals/faqs/general.md b/content/manuals/security/faqs/general.md similarity index 91% rename from content/manuals/faqs/general.md rename to content/manuals/security/faqs/general.md index 9728c0221c01..04c69d11f98b 100644 --- a/content/manuals/faqs/general.md +++ b/content/manuals/security/faqs/general.md @@ -7,9 +7,6 @@ weight: 10 tags: [FAQ] aliases: - /faq/security/general/ -- /security/faqs/general/ -- /platform/security/resources/faqs/general/ -- /platform/security/faqs/general/ --- ## How do I report a vulnerability? @@ -69,4 +66,4 @@ Security vetting for extensions isn't implemented. Extensions aren't covered as ## Can I prevent users from pushing images to Docker Hub private repositories? -No direct setting exists to disable private repositories. However, [Registry Access Management](/manuals/enterprise/hardened-desktop/registry-access-management.md) lets administrators control which registries developers can access through Docker Desktop via Docker Home. +No direct setting exists to disable private repositories. However, [Registry Access Management](/manuals/enterprise/security/hardened-desktop/registry-access-management.md) lets administrators control which registries developers can access through Docker Desktop via Docker Home. diff --git a/content/manuals/faqs/networking-and-vms.md b/content/manuals/security/faqs/networking-and-vms.md similarity index 87% rename from content/manuals/faqs/networking-and-vms.md rename to content/manuals/security/faqs/networking-and-vms.md index dd2e912451b3..668697d482a5 100644 --- a/content/manuals/faqs/networking-and-vms.md +++ b/content/manuals/security/faqs/networking-and-vms.md @@ -7,16 +7,13 @@ weight: 30 tags: [FAQ] aliases: - /faq/security/networking-and-vms/ -- /security/faqs/networking-and-vms/ -- /platform/security/resources/faqs/networking-and-vms/ -- /platform/security/faqs/networking-and-vms/ --- ## How can I limit container internet access? Docker Desktop doesn't have a built-in mechanism for this, but you can use process-level firewalls on the host. Apply rules to the `com.docker.vpnkit` user-space process to control where it can connect (DNS allowlists, packet filters) and which ports/protocols it can use. -For enterprise environments, consider [Air-gapped containers](/manuals/enterprise/hardened-desktop/air-gapped-containers.md) which provide network access controls for containers. +For enterprise environments, consider [Air-gapped containers](/manuals/enterprise/security/hardened-desktop/air-gapped-containers.md) which provide network access controls for containers. ## Can I apply firewall rules to container network traffic? diff --git a/content/manuals/security/security-announcements.md b/content/manuals/security/security-announcements.md index 141e55ddbf30..6b30907277a8 100644 --- a/content/manuals/security/security-announcements.md +++ b/content/manuals/security/security-announcements.md @@ -68,7 +68,7 @@ A vulnerability in Docker Desktop for Windows was fixed on October 23 in the [4. A vulnerability in Docker Desktop was fixed on September 25 in the [4.47.0](/manuals/desktop/release-notes.md#4470) release: -- Fixed [CVE-2025-10657](https://www.cve.org/CVERecord?id=CVE-2025-10657) where the Enhanced Container Isolation [Docker Socket command restrictions](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/config.md#command-restrictions) feature was not working properly in Docker Desktop 4.46.0 only (the configuration for it was being ignored). +- Fixed [CVE-2025-10657](https://www.cve.org/CVERecord?id=CVE-2025-10657) where the Enhanced Container Isolation [Docker Socket command restrictions](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/config.md#command-restrictions) feature was not working properly in Docker Desktop 4.46.0 only (the configuration for it was being ignored). ## Docker Desktop 4.44.3 security update: CVE-2025-9074 @@ -167,9 +167,9 @@ If you are unable to update to an unaffected version promptly, follow these best - Only use trusted Docker images (such as [Docker Official Images](/manuals/docker-hub/image-library/trusted-content.md#docker-official-images)). - Don't build Docker images from untrusted sources or untrusted Dockerfiles. -- If you are a Docker Business customer using Docker Desktop and unable to update to v4.27.1, make sure to enable [Hardened Docker Desktop](/manuals/enterprise/hardened-desktop/_index.md) features such as: - - [Enhanced Container Isolation](/manuals/enterprise/hardened-desktop/enhanced-container-isolation/_index.md), which mitigates the impact of CVE-2024-21626 in the case of running containers from malicious images. - - [Image Access Management](/manuals/enterprise/hardened-desktop/image-access-management.md), and [Registry Access Management](/manuals/enterprise/hardened-desktop/registry-access-management.md), which give organizations control over which images and repositories their users can access. +- If you are a Docker Business customer using Docker Desktop and unable to update to v4.27.1, make sure to enable [Hardened Docker Desktop](/manuals/enterprise/security/hardened-desktop/_index.md) features such as: + - [Enhanced Container Isolation](/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/_index.md), which mitigates the impact of CVE-2024-21626 in the case of running containers from malicious images. + - [Image Access Management](/manuals/enterprise/security/hardened-desktop/image-access-management.md), and [Registry Access Management](/manuals/enterprise/security/hardened-desktop/registry-access-management.md), which give organizations control over which images and repositories their users can access. - For CVE-2024-23650, CVE-2024-23651, CVE-2024-23652, and CVE-2024-23653, avoid using BuildKit frontend from an untrusted source. A frontend image is usually specified as the #syntax line on your Dockerfile, or with `--frontend` flag when using the `buildctl build` command. - To mitigate CVE-2024-24557, make sure to either use BuildKit or disable caching when building images. From the CLI this can be done via the `DOCKER_BUILDKIT=1` environment variable (default for Moby >= v23.0 if the buildx plugin is installed) or the `--no-cache flag`. If you are using the HTTP API directly or through a client, the same can be done by setting `nocache` to `true` or `version` to `2` for the [/build API endpoint](https://docs.docker.com/reference/api/engine/version/v1.44/#tag/Image/operation/ImageBuild). diff --git a/data/redirects.yml b/data/redirects.yml index 1e74226c659e..5b474780f948 100644 --- a/data/redirects.yml +++ b/data/redirects.yml @@ -317,7 +317,7 @@ "/admin/organization/insights/#extensions": - /go/insights-extensions/ -"/enterprise/hardened-desktop/settings-management/": +"/enterprise/security/hardened-desktop/settings-management/": - /go/settings-management/ # Billing - cancellation From e9771a2658e5ef6f00dd290add3c1eae5f3c6830 Mon Sep 17 00:00:00 2001 From: Alexa Date: Mon, 31 Aug 2026 14:35:28 -0500 Subject: [PATCH 08/19] docs: restore enforce-sign-in and SSO enforcement FAQ URLs to match main Co-authored-by: Cursor --- content/guides/admin-set-up.md | 6 +++--- content/manuals/accounts/organization/insights.md | 6 +++--- .../accounts/organization/manage/manage-products.md | 2 +- content/manuals/accounts/organization/setup/onboard.md | 8 ++++---- .../monitor-and-enforce/sign-in-enforcement.md | 2 +- content/manuals/desktop/release-notes.md | 10 +++++----- content/manuals/desktop/setup/install/mac-install.md | 2 +- .../manuals/desktop/setup/install/windows-install.md | 2 +- content/manuals/desktop/setup/sign-in.md | 2 +- content/manuals/docker-hub/release-notes.md | 2 +- .../enterprise-deployment/pkg-install-and-configure.md | 2 +- .../enterprise/enterprise-deployment/use-intune.md | 2 +- .../enterprise/enterprise-deployment/use-jamf-pro.md | 2 +- content/manuals/enterprise/security/_index.md | 4 ++++ .../security}/enforce-sign-in/_index.md | 4 +--- .../security}/enforce-sign-in/methods.md | 2 -- .../security/hardened-desktop/air-gapped-containers.md | 2 +- .../enhanced-container-isolation/enable-eci.md | 2 +- .../hardened-desktop/image-access-management.md | 2 +- .../hardened-desktop/registry-access-management.md | 4 ++-- .../hardened-desktop/settings-management/_index.md | 4 ++-- .../settings-management/compliance-reporting.md | 2 +- .../settings-management/configure-admin-console.md | 2 +- .../settings-management/configure-json-file.md | 2 +- .../enterprise/security/single-sign-on/FAQs/_index.md | 8 ++++++++ .../security/single-sign-on/FAQs}/enforcement-faqs.md | 4 +--- .../enterprise/security/single-sign-on/_index.md | 9 +++++++++ content/manuals/extensions/private-marketplace.md | 2 +- content/manuals/faqs/_index.md | 4 ---- content/manuals/faqs/organization-faqs.md | 2 +- content/manuals/platform-release-notes.md | 4 ++-- content/manuals/security/authentication/_index.md | 4 ++-- .../security/authentication/single-sign-on/_index.md | 3 +-- .../security/authentication/single-sign-on/connect.md | 2 +- .../manuals/security/provisioning/domain-management.md | 2 +- .../security/provisioning/scim/group-mapping.md | 2 +- .../manuals/security/provisioning/scim/migrate-scim.md | 2 +- content/manuals/unassociated-machines/_index.md | 4 ++-- 38 files changed, 70 insertions(+), 60 deletions(-) rename content/manuals/{security/authentication => enterprise/security}/enforce-sign-in/_index.md (96%) rename content/manuals/{security/authentication => enterprise/security}/enforce-sign-in/methods.md (99%) create mode 100644 content/manuals/enterprise/security/single-sign-on/FAQs/_index.md rename content/manuals/{faqs => enterprise/security/single-sign-on/FAQs}/enforcement-faqs.md (89%) create mode 100644 content/manuals/enterprise/security/single-sign-on/_index.md diff --git a/content/guides/admin-set-up.md b/content/guides/admin-set-up.md index 1ded3e02af4b..d1676f550dc7 100644 --- a/content/guides/admin-set-up.md +++ b/content/guides/admin-set-up.md @@ -56,7 +56,7 @@ This guide covers the following Docker features: repositories. Your organization was created with your subscription and is managed by one or more owners. Users signed into the organization are assigned seats based on the purchased subscription. -- [Enforce sign-in](/manuals/security/authentication/enforce-sign-in/_index.md): +- [Enforce sign-in](/manuals/enterprise/security/enforce-sign-in/_index.md): By default, Docker Desktop doesn't require sign-in. You can configure settings to enforce this and ensure your developers sign in to your Docker organization. @@ -154,7 +154,7 @@ configuration: Review these areas together: - Security features and - [enforcing sign-in](/manuals/security/authentication/enforce-sign-in/_index.md) + [enforcing sign-in](/manuals/enterprise/security/enforce-sign-in/_index.md) for Docker Desktop users - Additional Docker products included in your subscriptions @@ -176,7 +176,7 @@ security configurations as outlined in the previous section, configure Settings [`admin-settings.json` file](/manuals/enterprise/security/hardened-desktop/settings-management/configure-json-file.md). Once the file is ready, collaborate with your MDM team to deploy your chosen -settings, along with your chosen method for [enforcing sign-in](/manuals/security/authentication/enforce-sign-in/_index.md). +settings, along with your chosen method for [enforcing sign-in](/manuals/enterprise/security/enforce-sign-in/_index.md). > [!IMPORTANT] > diff --git a/content/manuals/accounts/organization/insights.md b/content/manuals/accounts/organization/insights.md index 96e37764e08a..ffb05dbbc858 100644 --- a/content/manuals/accounts/organization/insights.md +++ b/content/manuals/accounts/organization/insights.md @@ -30,7 +30,7 @@ Key benefits include: To use Insights, you must meet the following requirements: - [Docker Business subscription](https://www.docker.com/pricing?ref=Docs&refAction=DocsAdminInsights) -- Administrators must [enforce sign-in](/manuals/security/authentication/enforce-sign-in/_index.md) +- Administrators must [enforce sign-in](/manuals/enterprise/security/enforce-sign-in/_index.md) for users - Your Account Executive must turn on Insights for your organization @@ -61,7 +61,7 @@ The chart contains the following data: | Data | Description | | :--------------------------- | :---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| Active user | The number of users who have actively used Docker Desktop and either signed in with a Docker account that has a license in your organization or signed in to a Docker account with an email address from a domain associated with your organization.

Users who don’t sign in to an account associated with your organization are not represented in the data. To ensure users sign in with an account associated with your organization, you can [enforce sign-in](/manuals/security/authentication/enforce-sign-in/_index.md). | +| Active user | The number of users who have actively used Docker Desktop and either signed in with a Docker account that has a license in your organization or signed in to a Docker account with an email address from a domain associated with your organization.

Users who don’t sign in to an account associated with your organization are not represented in the data. To ensure users sign in with an account associated with your organization, you can [enforce sign-in](/manuals/enterprise/security/enforce-sign-in/_index.md). | | Total organization members | The number of users who have used Docker Desktop, regardless of their Insights activity. | | Users opted out of analytics | The number of users who are members of your organization that have opted out of sending analytics.

When users opt out of sending analytics, you won't see any of their data in Insights. To ensure that the data includes all users, you can use [Settings Management](/manuals/enterprise/security/hardened-desktop/settings-management/_index.md) to set `analyticsEnabled` for all your users. | | Active users (graph) | The view over time for total active users. | @@ -209,4 +209,4 @@ solutions to resolve common problems: Users who don’t sign in to an account associated with your organization are not represented in the data. To ensure users sign in with an account associated with your organization, you can [enforce - sign-in](/manuals/security/authentication/enforce-sign-in/_index.md). + sign-in](/manuals/enterprise/security/enforce-sign-in/_index.md). diff --git a/content/manuals/accounts/organization/manage/manage-products.md b/content/manuals/accounts/organization/manage/manage-products.md index 6f117acac01f..cce9d67281b2 100644 --- a/content/manuals/accounts/organization/manage/manage-products.md +++ b/content/manuals/accounts/organization/manage/manage-products.md @@ -26,7 +26,7 @@ use the following procedures to control access for all members. To manage Docker Desktop access: -1. [Enforce sign-in](../../../security/authentication/enforce-sign-in/_index.md). +1. [Enforce sign-in](../../../enterprise/security/enforce-sign-in/_index.md). 1. Manage members [manually](./members.md) or use [provisioning](../../../security/provisioning/_index.md). diff --git a/content/manuals/accounts/organization/setup/onboard.md b/content/manuals/accounts/organization/setup/onboard.md index 716d6f58c4d1..d652041b9c18 100644 --- a/content/manuals/accounts/organization/setup/onboard.md +++ b/content/manuals/accounts/organization/setup/onboard.md @@ -139,7 +139,7 @@ automatically via SSO and SCIM. See the following for more details: > > Enforcing single sign-on (SSO) and enforcing Docker Desktop sign in > are different features. For more details, see - > [Enforcing sign-in versus enforcing single sign-on (SSO)](/manuals/security/authentication/enforce-sign-in/_index.md#enforcing-sign-in-versus-enforcing-single-sign-on-sso). + > [Enforcing sign-in versus enforcing single sign-on (SSO)](/manuals/enterprise/security/enforce-sign-in/_index.md#enforcing-sign-in-versus-enforcing-single-sign-on-sso). - [Configure SCIM](/manuals/security/provisioning/scim/_index.md) to automatically provision, add, and de-provision members to Docker through @@ -156,9 +156,9 @@ and they can circumvent [Docker’s security features](/manuals/enterprise/secur There are multiple ways you can enforce sign-in, depending on your organization's Docker configuration: -- [Registry key method (Windows only)](/manuals/security/authentication/enforce-sign-in/methods.md#registry-key-method-windows-only) -- [`.plist` method (Mac only)](/manuals/security/authentication/enforce-sign-in/methods.md#plist-method-mac-only) -- [`registry.json` method (All)](/manuals/security/authentication/enforce-sign-in/methods.md#registryjson-method-all) +- [Registry key method (Windows only)](/manuals/enterprise/security/enforce-sign-in/methods.md#registry-key-method-windows-only) +- [`.plist` method (Mac only)](/manuals/enterprise/security/enforce-sign-in/methods.md#plist-method-mac-only) +- [`registry.json` method (All)](/manuals/enterprise/security/enforce-sign-in/methods.md#registryjson-method-all) ### Step six: Manage Docker Desktop security diff --git a/content/manuals/ai/sandboxes/governance/monitor-and-enforce/sign-in-enforcement.md b/content/manuals/ai/sandboxes/governance/monitor-and-enforce/sign-in-enforcement.md index 89a4d278a5b0..ba30413d3453 100644 --- a/content/manuals/ai/sandboxes/governance/monitor-and-enforce/sign-in-enforcement.md +++ b/content/manuals/ai/sandboxes/governance/monitor-and-enforce/sign-in-enforcement.md @@ -269,5 +269,5 @@ For access, contact ACME IT Security: Console - [Governance overview](../_index.md): how local and organization governance fit together -- [Enforce sign-in for Docker Desktop](/manuals/security/authentication/enforce-sign-in/_index.md): +- [Enforce sign-in for Docker Desktop](/manuals/enterprise/security/enforce-sign-in/_index.md): the equivalent control for Docker Desktop diff --git a/content/manuals/desktop/release-notes.md b/content/manuals/desktop/release-notes.md index dce3c9fa6f8a..920c4e70cef5 100644 --- a/content/manuals/desktop/release-notes.md +++ b/content/manuals/desktop/release-notes.md @@ -1572,7 +1572,7 @@ For more frequently asked questions, see the [FAQs](/manuals/desktop/troubleshoo ### New - You can now specify PAC files and Embedded PAC scripts with installer flags for [macOS](/manuals/desktop/setup/install/mac-install.md#proxy-configuration) and [Windows](/manuals/desktop/setup/install/windows-install.md#proxy-configuration). -- Administrators can set proxy settings via [macOS configuration profiles](/manuals/security/authentication/enforce-sign-in/methods.md#macos-configuration-profiles-method-recommended). +- Administrators can set proxy settings via [macOS configuration profiles](/manuals/enterprise/security/enforce-sign-in/methods.md#macos-configuration-profiles-method-recommended). ### Upgrades @@ -1951,7 +1951,7 @@ We are aware of [CVE-2025-23266](https://nvd.nist.gov/vuln/detail/CVE-2025-23266 - Improved the sign-in enforcement message when more than 10 organizations are enforced. - Changed the way ports are mapped by Docker Desktop to fully support IPv6 ports. - Fixed a bug in the Dashboard container logs screen causing the scrollbar to disappear as the mouse approaches. -- [Enforced sign-in](/manuals/security/authentication/enforce-sign-in/_index.md) fixed for Teams subscription users. +- [Enforced sign-in](/manuals/enterprise/security/enforce-sign-in/_index.md) fixed for Teams subscription users. - `llama.cpp` server now supports streaming and tool calling in Model Runner. - Sign-in Enforcement capability is now available to all subscriptions. @@ -2352,7 +2352,7 @@ We are aware of [CVE-2025-23266](https://nvd.nist.gov/vuln/detail/CVE-2025-23266 - Existing Docker Desktop installations using the WSL2 engine on Windows are now automatically migrated to a unified single-distribution architecture for enhanced consistency and performance. - Administrators can now: - - Enforce sign-in with macOS [configuration profiles](/manuals/security/authentication/enforce-sign-in/methods.md#configuration-profiles-method-mac-only) (Early Access). + - Enforce sign-in with macOS [configuration profiles](/manuals/enterprise/security/enforce-sign-in/methods.md#configuration-profiles-method-mac-only) (Early Access). - Enforce sign-in for more than one organization at a time (Early Access). - Deploy Docker Desktop for Mac in bulk with the [PKG installer](/manuals/enterprise/enterprise-deployment/pkg-install-and-configure.md) (Early Access). - Use Desktop Settings Management to manage and enforce defaults via admin.docker.com (Early Access). @@ -2470,7 +2470,7 @@ We are aware of [CVE-2025-23266](https://nvd.nist.gov/vuln/detail/CVE-2025-23266 - Image tags added to **Build results** section under the **Info** tab. - Improved efficiency of host-side disk utilization for fresh installations on Mac and Linux. - Fixed a bug that prevented the Sign in enforcement popup to be triggered when token expires. -- Fixed a bug where containers would not be displayed in the GUI immediately after signing in when using [enforced sign-in](/manuals/security/authentication/enforce-sign-in/_index.md). +- Fixed a bug where containers would not be displayed in the GUI immediately after signing in when using [enforced sign-in](/manuals/enterprise/security/enforce-sign-in/_index.md). - `settings.json` has been renamed to `settings-store.json` - The host networking feature no longer requires users to be signed-in in order to use it. @@ -2572,7 +2572,7 @@ We are aware of [CVE-2025-23266](https://nvd.nist.gov/vuln/detail/CVE-2025-23266 - If you authenticate via the CLI, you can now authenticate through a browser-based flow, removing the need for manual PAT generation. - Windows now supports automatic reclamation of disk space in Docker Desktop for WSL2 installations [using a managed virtual hard disk](/manuals/desktop/features/wsl/best-practices.md). - Deploying Docker Desktop via the [MSI installer](/manuals/enterprise/enterprise-deployment/msi-install-and-configure.md) is now generally available. -- Two new methods to [enforce sign-in](/manuals/security/authentication/enforce-sign-in/_index.md) (windows registry key and `.plist` file) are now generally available. +- Two new methods to [enforce sign-in](/manuals/enterprise/security/enforce-sign-in/_index.md) (windows registry key and `.plist` file) are now generally available. - Fresh installations of Docker Desktop now use the containerd image store by default. - [Compose Bridge](/manuals/compose/bridge/_index.md) (Experimental) is now available from the Compose file viewer. Easily convert and deploy your Compose project to a Kubernetes cluster. diff --git a/content/manuals/desktop/setup/install/mac-install.md b/content/manuals/desktop/setup/install/mac-install.md index 6ed8776d56fb..3c065841aa15 100644 --- a/content/manuals/desktop/setup/install/mac-install.md +++ b/content/manuals/desktop/setup/install/mac-install.md @@ -154,7 +154,7 @@ $ sudo /Applications/Docker.app/Contents/MacOS/install --user testuser --proxy-h > [!TIP] > -> As an IT administrator, you can use endpoint management (MDM) software to identify the number of Docker Desktop instances and their versions within your environment. This can provide accurate license reporting, help ensure your machines use the latest version of Docker Desktop, and enable you to [enforce sign-in](/manuals/security/authentication/enforce-sign-in/_index.md). +> As an IT administrator, you can use endpoint management (MDM) software to identify the number of Docker Desktop instances and their versions within your environment. This can provide accurate license reporting, help ensure your machines use the latest version of Docker Desktop, and enable you to [enforce sign-in](/manuals/enterprise/security/enforce-sign-in/_index.md). > - [Intune](https://learn.microsoft.com/en-us/mem/intune/apps/app-discovered-apps) > - [Jamf](https://docs.jamf.com/10.25.0/jamf-pro/administrator-guide/Application_Usage.html) > - [Kandji](https://support.kandji.io/support/solutions/articles/72000559793-view-a-device-application-list) diff --git a/content/manuals/desktop/setup/install/windows-install.md b/content/manuals/desktop/setup/install/windows-install.md index 1465d1ba3def..af06573c64ba 100644 --- a/content/manuals/desktop/setup/install/windows-install.md +++ b/content/manuals/desktop/setup/install/windows-install.md @@ -232,7 +232,7 @@ Docker Desktop does not start automatically after installation. To start Docker > [!TIP] > -> As an IT administrator, you can use endpoint management (MDM) software to identify the number of Docker Desktop instances and their versions within your environment. This can provide accurate license reporting, help ensure your machines use the latest version of Docker Desktop, and enable you to [enforce sign-in](/manuals/security/authentication/enforce-sign-in/_index.md). +> As an IT administrator, you can use endpoint management (MDM) software to identify the number of Docker Desktop instances and their versions within your environment. This can provide accurate license reporting, help ensure your machines use the latest version of Docker Desktop, and enable you to [enforce sign-in](/manuals/enterprise/security/enforce-sign-in/_index.md). > - [Intune](https://learn.microsoft.com/en-us/mem/intune/apps/app-discovered-apps) > - [Jamf](https://docs.jamf.com/10.25.0/jamf-pro/administrator-guide/Application_Usage.html) > - [Kandji](https://support.kandji.io/support/solutions/articles/72000559793-view-a-device-application-list) diff --git a/content/manuals/desktop/setup/sign-in.md b/content/manuals/desktop/setup/sign-in.md index 4f78136b94f9..d8dd1ea49d59 100644 --- a/content/manuals/desktop/setup/sign-in.md +++ b/content/manuals/desktop/setup/sign-in.md @@ -17,7 +17,7 @@ aliases: Docker recommends signing in with the **Sign in** option in the top-right corner of the Docker Dashboard. -In large enterprises where admin access is restricted, administrators can [enforce sign-in](/manuals/security/authentication/enforce-sign-in/_index.md). +In large enterprises where admin access is restricted, administrators can [enforce sign-in](/manuals/enterprise/security/enforce-sign-in/_index.md). > [!TIP] > diff --git a/content/manuals/docker-hub/release-notes.md b/content/manuals/docker-hub/release-notes.md index a2b749d9ad6f..35f79f9b92cd 100644 --- a/content/manuals/docker-hub/release-notes.md +++ b/content/manuals/docker-hub/release-notes.md @@ -140,7 +140,7 @@ known issues for each Docker Hub release. ### Bug fixes and enhancements -- In Docker Hub, you can now download a [registry.json](/manuals/security/authentication/enforce-sign-in/_index.md) file or copy the commands to create a registry.json file to enforce sign-in for your organization. +- In Docker Hub, you can now download a [registry.json](/manuals/enterprise/security/enforce-sign-in/_index.md) file or copy the commands to create a registry.json file to enforce sign-in for your organization. ## 2022-09-19 diff --git a/content/manuals/enterprise/enterprise-deployment/pkg-install-and-configure.md b/content/manuals/enterprise/enterprise-deployment/pkg-install-and-configure.md index 2e816f37d12d..cd9b6cc618f4 100644 --- a/content/manuals/enterprise/enterprise-deployment/pkg-install-and-configure.md +++ b/content/manuals/enterprise/enterprise-deployment/pkg-install-and-configure.md @@ -46,4 +46,4 @@ The PKG package supports various MDM (Mobile Device Management) solutions, makin ## Additional resources - See how you can deploy Docker Desktop for Mac using [Intune](use-intune.md) or [Jamf Pro](use-jamf-pro.md) -- Explore how to [Enforce sign-in](/manuals/security/authentication/enforce-sign-in/methods.md#plist-method-mac-only) for your users. \ No newline at end of file +- Explore how to [Enforce sign-in](/manuals/enterprise/security/enforce-sign-in/methods.md#plist-method-mac-only) for your users. \ No newline at end of file diff --git a/content/manuals/enterprise/enterprise-deployment/use-intune.md b/content/manuals/enterprise/enterprise-deployment/use-intune.md index 30b48f08c310..25fb74f7b7f4 100644 --- a/content/manuals/enterprise/enterprise-deployment/use-intune.md +++ b/content/manuals/enterprise/enterprise-deployment/use-intune.md @@ -52,4 +52,4 @@ Next, assign the app: ## Additional resources - [Explore the FAQs](faq.md). -- Learn how to [enforce sign-in](/manuals/security/authentication/enforce-sign-in/_index.md) for your users. \ No newline at end of file +- Learn how to [enforce sign-in](/manuals/enterprise/security/enforce-sign-in/_index.md) for your users. \ No newline at end of file diff --git a/content/manuals/enterprise/enterprise-deployment/use-jamf-pro.md b/content/manuals/enterprise/enterprise-deployment/use-jamf-pro.md index 4f52b9c56f37..d2e4104f43b2 100644 --- a/content/manuals/enterprise/enterprise-deployment/use-jamf-pro.md +++ b/content/manuals/enterprise/enterprise-deployment/use-jamf-pro.md @@ -29,4 +29,4 @@ For more information, see [Jamf Pro's official documentation](https://learn.jamf ## Additional resources -- Learn how to [enforce sign-in](/manuals/security/authentication/enforce-sign-in/_index.md) for your users. \ No newline at end of file +- Learn how to [enforce sign-in](/manuals/enterprise/security/enforce-sign-in/_index.md) for your users. \ No newline at end of file diff --git a/content/manuals/enterprise/security/_index.md b/content/manuals/enterprise/security/_index.md index 88044f9dd300..4ebdc93483b6 100644 --- a/content/manuals/enterprise/security/_index.md +++ b/content/manuals/enterprise/security/_index.md @@ -12,6 +12,10 @@ grid: description: Security features that strengthen developer environments. icon: shield-check link: /enterprise/security/hardened-desktop/ + - title: Enforce sign-in + description: Configure sign-in for members of your teams and organizations. + icon: finger-print + link: /enterprise/security/enforce-sign-in/ --- [Hardened Docker Desktop](/manuals/enterprise/security/hardened-desktop/_index.md) diff --git a/content/manuals/security/authentication/enforce-sign-in/_index.md b/content/manuals/enterprise/security/enforce-sign-in/_index.md similarity index 96% rename from content/manuals/security/authentication/enforce-sign-in/_index.md rename to content/manuals/enterprise/security/enforce-sign-in/_index.md index afd38e622a06..772893441bce 100644 --- a/content/manuals/security/authentication/enforce-sign-in/_index.md +++ b/content/manuals/enterprise/security/enforce-sign-in/_index.md @@ -8,8 +8,6 @@ tags: [admin] aliases: - /security/for-admins/configure-sign-in/ - /security/for-admins/enforce-sign-in/ - - /enterprise/security/enforce-sign-in/ - - /platform/security/authentication/enforce-sign-in/ weight: 30 --- @@ -69,5 +67,5 @@ Enforcing Docker Desktop sign-in and [enforcing SSO](/manuals/security/authentic ## Next steps -- To set up sign-in enforcement, see [Configure sign-in enforcement](/manuals/security/authentication/enforce-sign-in/methods.md). +- To set up sign-in enforcement, see [Configure sign-in enforcement](/manuals/enterprise/security/enforce-sign-in/methods.md). - To configure SSO enforcement, see [Enforce SSO](/manuals/security/authentication/single-sign-on/connect.md). diff --git a/content/manuals/security/authentication/enforce-sign-in/methods.md b/content/manuals/enterprise/security/enforce-sign-in/methods.md similarity index 99% rename from content/manuals/security/authentication/enforce-sign-in/methods.md rename to content/manuals/enterprise/security/enforce-sign-in/methods.md index 67624a471fe5..09648085c141 100644 --- a/content/manuals/security/authentication/enforce-sign-in/methods.md +++ b/content/manuals/enterprise/security/enforce-sign-in/methods.md @@ -6,8 +6,6 @@ keywords: authentication, registry.json, configure, enforce sign-in, docker desk tags: [admin] aliases: - /security/for-admins/enforce-sign-in/methods/ - - /enterprise/security/enforce-sign-in/methods/ - - /platform/security/authentication/enforce-sign-in/methods/ --- {{< summary-bar feature_name="Enforce sign-in" >}} diff --git a/content/manuals/enterprise/security/hardened-desktop/air-gapped-containers.md b/content/manuals/enterprise/security/hardened-desktop/air-gapped-containers.md index 48c797adb096..4170bf8bbcf5 100644 --- a/content/manuals/enterprise/security/hardened-desktop/air-gapped-containers.md +++ b/content/manuals/enterprise/security/hardened-desktop/air-gapped-containers.md @@ -41,7 +41,7 @@ Other considerations: Before configuring air-gapped containers, you must have: -- [Enforce sign-in](/manuals/security/authentication/enforce-sign-in/_index.md) enabled to ensure users authenticate with your organization +- [Enforce sign-in](/manuals/enterprise/security/enforce-sign-in/_index.md) enabled to ensure users authenticate with your organization - A Docker Business subscription - Configured [Settings Management](/manuals/enterprise/security/hardened-desktop/settings-management/_index.md) with the `admin-settings.json` file to manage organization policies diff --git a/content/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/enable-eci.md b/content/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/enable-eci.md index 93478fbf86be..6b554f4b28a2 100644 --- a/content/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/enable-eci.md +++ b/content/manuals/enterprise/security/hardened-desktop/enhanced-container-isolation/enable-eci.md @@ -17,7 +17,7 @@ This page shows you how to turn on Enhanced Container Isolation (ECI) and verify Before you begin, you must have: - A Docker Business subscription -- [Enforced sign-in](/manuals/security/authentication/enforce-sign-in/_index.md) (for administrators managing organization-wide settings only) +- [Enforced sign-in](/manuals/enterprise/security/enforce-sign-in/_index.md) (for administrators managing organization-wide settings only) ## Enable Enhanced Container Isolation diff --git a/content/manuals/enterprise/security/hardened-desktop/image-access-management.md b/content/manuals/enterprise/security/hardened-desktop/image-access-management.md index e1248813b10e..fa532cb335e4 100644 --- a/content/manuals/enterprise/security/hardened-desktop/image-access-management.md +++ b/content/manuals/enterprise/security/hardened-desktop/image-access-management.md @@ -44,7 +44,7 @@ Use the repository allowlist when you need to: Before configuring Image Access Management, you must: -- [Enforce sign-in](/manuals/security/authentication/enforce-sign-in/_index.md). Image Access Management only takes effect when users are signed in to Docker Desktop with organization credentials. +- [Enforce sign-in](/manuals/enterprise/security/enforce-sign-in/_index.md). Image Access Management only takes effect when users are signed in to Docker Desktop with organization credentials. - Use [personal access tokens (PATs)](/manuals/security/access-tokens/personal-access-tokens.md) for authentication (Organization access tokens aren't supported) - Have a Docker Business subscription diff --git a/content/manuals/enterprise/security/hardened-desktop/registry-access-management.md b/content/manuals/enterprise/security/hardened-desktop/registry-access-management.md index 55665b4a2335..34be43580036 100644 --- a/content/manuals/enterprise/security/hardened-desktop/registry-access-management.md +++ b/content/manuals/enterprise/security/hardened-desktop/registry-access-management.md @@ -41,7 +41,7 @@ Registry Access Management works with any container registry, including: Before configuring Registry Access Management, you must: -- [Enforce sign-in](/manuals/security/authentication/enforce-sign-in/_index.md). +- [Enforce sign-in](/manuals/enterprise/security/enforce-sign-in/_index.md). Registry Access Management only takes effect when users are signed in to Docker Desktop with organization credentials. - Use @@ -138,7 +138,7 @@ Users can potentially bypass Registry Access Management through: To maximize security effectiveness: -- [Enforce sign-in](/manuals/security/authentication/enforce-sign-in/_index.md) to +- [Enforce sign-in](/manuals/enterprise/security/enforce-sign-in/_index.md) to prevent bypass through sign-out - Implement additional network-level controls for complete protection - Use Registry Access Management as part of a broader security strategy diff --git a/content/manuals/enterprise/security/hardened-desktop/settings-management/_index.md b/content/manuals/enterprise/security/hardened-desktop/settings-management/_index.md index 4fab86163dce..63b09e8615ea 100644 --- a/content/manuals/enterprise/security/hardened-desktop/settings-management/_index.md +++ b/content/manuals/enterprise/security/hardened-desktop/settings-management/_index.md @@ -54,14 +54,14 @@ When multiple policies exist, Docker Desktop applies them in this order: 1. User-specific policies: Highest priority 1. Organization default policy: Applied when no user-specific policy exists 1. Local `admin-settings.json` file: Lowest priority, overridden by Docker Home policies -1. [Configuration profiles](/manuals/security/authentication/enforce-sign-in/methods.md#configuration-profiles-method-mac-only) when used to control proxy settings +1. [Configuration profiles](/manuals/enterprise/security/enforce-sign-in/methods.md#configuration-profiles-method-mac-only) when used to control proxy settings ## Set up Settings Management You can create settings management policies at any time, but your organization needs to verify a domain before the policies take effect. 1. Check that you have [added and verified](/manuals/security/provisioning/domain-management.md#add-and-verify-a-domain) your organization's domain. -2. [Enforce sign-in](/manuals/security/authentication/enforce-sign-in/_index.md) to +2. [Enforce sign-in](/manuals/enterprise/security/enforce-sign-in/_index.md) to ensure all developers authenticate with your organization. 3. Choose a configuration method: - Use the `--admin-settings` installer flag on [macOS](/manuals/desktop/setup/install/mac-install.md#install-from-the-command-line) or [Windows](/manuals/desktop/setup/install/windows-install.md#install-from-the-command-line) to automatically create the `admin-settings.json`. diff --git a/content/manuals/enterprise/security/hardened-desktop/settings-management/compliance-reporting.md b/content/manuals/enterprise/security/hardened-desktop/settings-management/compliance-reporting.md index 6b55e67fadde..742bc0e17c3d 100644 --- a/content/manuals/enterprise/security/hardened-desktop/settings-management/compliance-reporting.md +++ b/content/manuals/enterprise/security/hardened-desktop/settings-management/compliance-reporting.md @@ -18,7 +18,7 @@ Before you can use Docker Desktop settings reporting, make sure you have: - [Docker Desktop](/manuals/desktop/release-notes.md) installed across your organization - [A verified domain](/manuals/security/authentication/single-sign-on/connect.md) -- [Enforced sign-in](/manuals/security/authentication/enforce-sign-in/_index.md) for your organization +- [Enforced sign-in](/manuals/enterprise/security/enforce-sign-in/_index.md) for your organization - A Docker Business subscription - At least one settings policy configured diff --git a/content/manuals/enterprise/security/hardened-desktop/settings-management/configure-admin-console.md b/content/manuals/enterprise/security/hardened-desktop/settings-management/configure-admin-console.md index 4be0aa7fc418..2406727df7bc 100644 --- a/content/manuals/enterprise/security/hardened-desktop/settings-management/configure-admin-console.md +++ b/content/manuals/enterprise/security/hardened-desktop/settings-management/configure-admin-console.md @@ -18,7 +18,7 @@ Before you begin, make sure you have: - [Docker Desktop](/manuals/desktop/release-notes.md) installed - [A verified domain](/security/authentication/single-sign-on/connect/#step-1-add-a-domain) -- [Enforced sign-in](/manuals/security/authentication/enforce-sign-in/_index.md) for your organization +- [Enforced sign-in](/manuals/enterprise/security/enforce-sign-in/_index.md) for your organization - A Docker Business subscription > [!IMPORTANT] diff --git a/content/manuals/enterprise/security/hardened-desktop/settings-management/configure-json-file.md b/content/manuals/enterprise/security/hardened-desktop/settings-management/configure-json-file.md index 30f3a400c22f..8426e587b7ee 100644 --- a/content/manuals/enterprise/security/hardened-desktop/settings-management/configure-json-file.md +++ b/content/manuals/enterprise/security/hardened-desktop/settings-management/configure-json-file.md @@ -17,7 +17,7 @@ Settings Management lets you configure and enforce Docker Desktop settings acros Before you begin, make sure you have: -- [Enforce sign-in](/manuals/security/authentication/enforce-sign-in/_index.md) for +- [Enforce sign-in](/manuals/enterprise/security/enforce-sign-in/_index.md) for your organization - A Docker Business subscription diff --git a/content/manuals/enterprise/security/single-sign-on/FAQs/_index.md b/content/manuals/enterprise/security/single-sign-on/FAQs/_index.md new file mode 100644 index 000000000000..ca4e6173d530 --- /dev/null +++ b/content/manuals/enterprise/security/single-sign-on/FAQs/_index.md @@ -0,0 +1,8 @@ +--- +build: + render: never +title: FAQs +description: Frequently asked questions about Docker single sign-on. +keywords: FAQ, SSO, single sign-on +weight: 50 +--- diff --git a/content/manuals/faqs/enforcement-faqs.md b/content/manuals/enterprise/security/single-sign-on/FAQs/enforcement-faqs.md similarity index 89% rename from content/manuals/faqs/enforcement-faqs.md rename to content/manuals/enterprise/security/single-sign-on/FAQs/enforcement-faqs.md index 0bdb200ba2b0..d153fd06bf5c 100644 --- a/content/manuals/faqs/enforcement-faqs.md +++ b/content/manuals/enterprise/security/single-sign-on/FAQs/enforcement-faqs.md @@ -9,8 +9,6 @@ aliases: - /single-sign-on/enforcement-faqs/ - /faq/security/single-sign-on/enforcement-faqs/ - /security/faqs/single-sign-on/enforcement-faqs/ - - /platform/security/authentication/single-sign-on/FAQs/enforcement-faqs/ - - /platform/security/faqs/enforcement-faqs/ --- ## Does Docker SSO support authenticating through the command line? @@ -42,4 +40,4 @@ These are separate features you can use independently or together: - Enforcing SSO ensures users sign in using SSO credentials instead of their Docker ID, enabling better credential management. - Enforcing sign-in to Docker Desktop ensures users always sign in to accounts that are members of your organization, so security settings and subscription benefits are always applied. -For more details, see [Enforce sign-in for Desktop](/manuals/security/authentication/enforce-sign-in/_index.md#enforcing-sign-in-versus-enforcing-single-sign-on-sso). +For more details, see [Enforce sign-in for Desktop](/manuals/enterprise/security/enforce-sign-in/_index.md#enforcing-sign-in-versus-enforcing-single-sign-on-sso). diff --git a/content/manuals/enterprise/security/single-sign-on/_index.md b/content/manuals/enterprise/security/single-sign-on/_index.md new file mode 100644 index 000000000000..cb2f0611da75 --- /dev/null +++ b/content/manuals/enterprise/security/single-sign-on/_index.md @@ -0,0 +1,9 @@ +--- +build: + render: never +title: Single sign-on overview +linkTitle: Single sign-on +description: Configure single sign-on for your organization. +keywords: SSO, single sign-on, enterprise, security +weight: 10 +--- diff --git a/content/manuals/extensions/private-marketplace.md b/content/manuals/extensions/private-marketplace.md index d41de893890f..593546e67d40 100644 --- a/content/manuals/extensions/private-marketplace.md +++ b/content/manuals/extensions/private-marketplace.md @@ -214,7 +214,7 @@ These files must be placed on developer's machines. Depending on your operating - Windows: `C:\ProgramData\DockerDesktop` - Linux: `/usr/share/docker-desktop` -Make sure your developers are signed in to Docker Desktop in order for the private marketplace configuration to take effect. As an administrator, you should [enforce sign-in](/manuals/security/authentication/enforce-sign-in/_index.md). +Make sure your developers are signed in to Docker Desktop in order for the private marketplace configuration to take effect. As an administrator, you should [enforce sign-in](/manuals/enterprise/security/enforce-sign-in/_index.md). ## Feedback diff --git a/content/manuals/faqs/_index.md b/content/manuals/faqs/_index.md index 13b290e22170..c68e0cfc2aae 100644 --- a/content/manuals/faqs/_index.md +++ b/content/manuals/faqs/_index.md @@ -31,10 +31,6 @@ grid: description: FAQs about domain verification and management for SSO. icon: globe-alt link: /faqs/domain-faqs/ - - title: SSO enforcement FAQs - description: FAQs about SSO enforcement and its effects on users. - icon: shield-check - link: /faqs/enforcement-faqs/ --- Answers to common questions about Docker accounts, organizations, companies, diff --git a/content/manuals/faqs/organization-faqs.md b/content/manuals/faqs/organization-faqs.md index 9003ad164bc0..845ecde913a7 100644 --- a/content/manuals/faqs/organization-faqs.md +++ b/content/manuals/faqs/organization-faqs.md @@ -30,7 +30,7 @@ assign them to a team during the invite process. ### Can I force my organization's members to authenticate before using Docker Desktop and are there any benefits? Yes. You can -[enforce sign-in](/manuals/security/authentication/enforce-sign-in/_index.md). +[enforce sign-in](/manuals/enterprise/security/enforce-sign-in/_index.md). Some benefits of enforcing sign-in are: diff --git a/content/manuals/platform-release-notes.md b/content/manuals/platform-release-notes.md index 311eddd8442c..5c649dcadcad 100644 --- a/content/manuals/platform-release-notes.md +++ b/content/manuals/platform-release-notes.md @@ -52,7 +52,7 @@ This page provides details on new features, enhancements, known issues, and bug ### New - Administrators can now: - - Enforce sign-in with [configuration profiles](/manuals/security/authentication/enforce-sign-in/methods.md#configuration-profiles-method-mac-only) (Early Access). + - Enforce sign-in with [configuration profiles](/manuals/enterprise/security/enforce-sign-in/methods.md#configuration-profiles-method-mac-only) (Early Access). - Enforce sign-in for more than one organization at a time (Early Access). - Deploy Docker Desktop for Mac in bulk with the [PKG installer](/manuals/enterprise/enterprise-deployment/pkg-install-and-configure.md) (Early Access). - [Use Desktop Settings Management via the Docker Admin Console](/manuals/enterprise/security/hardened-desktop/settings-management/configure-admin-console.md) (Early Access). @@ -80,7 +80,7 @@ This page provides details on new features, enhancements, known issues, and bug ### New - Deploying Docker Desktop via the [MSI installer](/manuals/enterprise/enterprise-deployment/msi-install-and-configure.md) is now generally available. -- Two new methods to [enforce sign-in](/manuals/security/authentication/enforce-sign-in/_index.md) (Windows registry key and `.plist` file) are now generally available. +- Two new methods to [enforce sign-in](/manuals/enterprise/security/enforce-sign-in/_index.md) (Windows registry key and `.plist` file) are now generally available. ## 2024-08-24 diff --git a/content/manuals/security/authentication/_index.md b/content/manuals/security/authentication/_index.md index 5c6a004c705a..f9fdf00c4217 100644 --- a/content/manuals/security/authentication/_index.md +++ b/content/manuals/security/authentication/_index.md @@ -3,8 +3,8 @@ build: render: never title: Authentication linkTitle: Authentication -description: Configure single sign-on, OIDC connections, two-factor authentication, and sign-in enforcement. -keywords: authentication, SSO, OIDC, two-factor authentication, 2FA, enforce sign-in, Docker security +description: Configure single sign-on, OIDC connections, and two-factor authentication. +keywords: authentication, SSO, OIDC, two-factor authentication, 2FA, Docker security weight: 20 aliases: - /platform/security/authentication/ diff --git a/content/manuals/security/authentication/single-sign-on/_index.md b/content/manuals/security/authentication/single-sign-on/_index.md index ca93cf43fa9d..c954d30e5257 100644 --- a/content/manuals/security/authentication/single-sign-on/_index.md +++ b/content/manuals/security/authentication/single-sign-on/_index.md @@ -8,7 +8,6 @@ aliases: - /admin/company/settings/sso/ - /admin/organization/security-settings/sso-management/ - /security/for-admins/single-sign-on/ - - /enterprise/security/single-sign-on/ - /platform/security/authentication/single-sign-on/ weight: 10 --- @@ -41,7 +40,7 @@ To configure SSO in Docker, follow these steps: 1. Link Docker to your identity provider. 1. Test your SSO connection. 1. Provision users in Docker. -1. Optional. [Enforce sign-in](../enforce-sign-in/_index.md). +1. Optional. [Enforce sign-in](/manuals/enterprise/security/enforce-sign-in/_index.md). 1. [Manage your SSO configuration](manage.md). Once configuration is complete, users can sign in to Docker services using diff --git a/content/manuals/security/authentication/single-sign-on/connect.md b/content/manuals/security/authentication/single-sign-on/connect.md index 36e3c224d324..2817d48695d2 100644 --- a/content/manuals/security/authentication/single-sign-on/connect.md +++ b/content/manuals/security/authentication/single-sign-on/connect.md @@ -258,6 +258,6 @@ Docker Hub. If you want to use 2FA, you must enable 2FA through your IdP. ## Next steps - [Provision users](/manuals/security/provisioning/_index.md). -- [Enforce sign-in](../enforce-sign-in/_index.md). +- [Enforce sign-in](/manuals/enterprise/security/enforce-sign-in/_index.md). - [Create personal access tokens](/manuals/security/access-tokens/personal-access-tokens.md). - [Troubleshoot SSO](/manuals/security/authentication/single-sign-on/troubleshoot-sso.md) issues. diff --git a/content/manuals/security/provisioning/domain-management.md b/content/manuals/security/provisioning/domain-management.md index 0c14bdc0523e..f21a26a218cd 100644 --- a/content/manuals/security/provisioning/domain-management.md +++ b/content/manuals/security/provisioning/domain-management.md @@ -93,7 +93,7 @@ Domain audit can't identify: - Users who authenticate using an account that doesn't have an email address associated with one of your verified domains -To prevent unidentifiable users from accessing Docker Desktop, [enforce sign-in](/manuals/security/authentication/enforce-sign-in/_index.md). +To prevent unidentifiable users from accessing Docker Desktop, [enforce sign-in](/manuals/enterprise/security/enforce-sign-in/_index.md). ### Run a domain audit diff --git a/content/manuals/security/provisioning/scim/group-mapping.md b/content/manuals/security/provisioning/scim/group-mapping.md index b30f4e912557..9813891d9ab6 100644 --- a/content/manuals/security/provisioning/scim/group-mapping.md +++ b/content/manuals/security/provisioning/scim/group-mapping.md @@ -196,4 +196,4 @@ Once complete, a user who signs in to Docker through SSO is automatically added ## Next steps - [Assign roles](/manuals/security/roles-and-permissions/core-roles.md) to members of your org. -- [Enforce sign in](/manuals/security/authentication/enforce-sign-in.md), if needed. +- [Enforce sign in](/manuals/enterprise/security/enforce-sign-in.md), if needed. diff --git a/content/manuals/security/provisioning/scim/migrate-scim.md b/content/manuals/security/provisioning/scim/migrate-scim.md index 1bc55491f44d..9a6a52f6337e 100644 --- a/content/manuals/security/provisioning/scim/migrate-scim.md +++ b/content/manuals/security/provisioning/scim/migrate-scim.md @@ -179,4 +179,4 @@ For more troubleshooting guidance, see - Set up [Group mapping](/manuals/security/provisioning/scim/group-mapping.md). - [Assign roles](/manuals/security/roles-and-permissions/core-roles.md) to members of your org. -- [Enforce sign in](/manuals/security/authentication/enforce-sign-in.md), if needed. +- [Enforce sign in](/manuals/enterprise/security/enforce-sign-in.md), if needed. diff --git a/content/manuals/unassociated-machines/_index.md b/content/manuals/unassociated-machines/_index.md index 035b0f54f786..d99aa6fb601c 100644 --- a/content/manuals/unassociated-machines/_index.md +++ b/content/manuals/unassociated-machines/_index.md @@ -72,12 +72,12 @@ You can: > [!NOTE] > > Sign-in enforcement for unassociated machines is different from -> the [organization-level sign-in enforcement](/security/authentication/enforce-sign-in/) +> the [organization-level sign-in enforcement](/enterprise/security/enforce-sign-in/) > available through `registry.json` and configuration profiles. This sign-in > enforcement only requires users to sign in so admins can identify who is > using the machine, meaning users can sign in with any email address. For more > stringent security controls that limit sign-ins to users who are already part -> of your organization, see [Enforce sign-in](/security/authentication/enforce-sign-in/). +> of your organization, see [Enforce sign-in](/enterprise/security/enforce-sign-in/). Sign-in enforcement helps you identify who is using unassociated machines in your organization. When you enable enforcement, users on these machines will From 0ad32530b8a9d5eb49c20a3338f028314b78d9ac Mon Sep 17 00:00:00 2001 From: Alexa Date: Mon, 31 Aug 2026 14:45:18 -0500 Subject: [PATCH 09/19] docs: fold SSO enforcement FAQs into SSO FAQ; order Security after Deploy Co-authored-by: Cursor --- content/manuals/enterprise/security/_index.md | 2 +- .../security/single-sign-on/FAQs/_index.md | 8 ---- .../single-sign-on/FAQs/enforcement-faqs.md | 43 ------------------- .../security/single-sign-on/_index.md | 9 ---- content/manuals/faqs/sso-faqs.md | 41 +++++++++++++++++- .../authentication/single-sign-on/_index.md | 1 + 6 files changed, 41 insertions(+), 63 deletions(-) delete mode 100644 content/manuals/enterprise/security/single-sign-on/FAQs/_index.md delete mode 100644 content/manuals/enterprise/security/single-sign-on/FAQs/enforcement-faqs.md delete mode 100644 content/manuals/enterprise/security/single-sign-on/_index.md diff --git a/content/manuals/enterprise/security/_index.md b/content/manuals/enterprise/security/_index.md index 4ebdc93483b6..6d358c12721a 100644 --- a/content/manuals/enterprise/security/_index.md +++ b/content/manuals/enterprise/security/_index.md @@ -3,7 +3,7 @@ linkTitle: Security title: Security for enterprises description: Learn about enterprise level security features Docker has to offer and explore best practices keywords: docker, docker hub, docker desktop, security, enterprises, scale -weight: 10 +weight: 30 params: sidebar: group: Enterprise diff --git a/content/manuals/enterprise/security/single-sign-on/FAQs/_index.md b/content/manuals/enterprise/security/single-sign-on/FAQs/_index.md deleted file mode 100644 index ca4e6173d530..000000000000 --- a/content/manuals/enterprise/security/single-sign-on/FAQs/_index.md +++ /dev/null @@ -1,8 +0,0 @@ ---- -build: - render: never -title: FAQs -description: Frequently asked questions about Docker single sign-on. -keywords: FAQ, SSO, single sign-on -weight: 50 ---- diff --git a/content/manuals/enterprise/security/single-sign-on/FAQs/enforcement-faqs.md b/content/manuals/enterprise/security/single-sign-on/FAQs/enforcement-faqs.md deleted file mode 100644 index d153fd06bf5c..000000000000 --- a/content/manuals/enterprise/security/single-sign-on/FAQs/enforcement-faqs.md +++ /dev/null @@ -1,43 +0,0 @@ ---- -title: SSO enforcement FAQs -linkTitle: Enforcement -description: Frequently asked questions about Docker single sign-on enforcement and its effects on users -keywords: SSO enforcement, single sign-on, personal access tokens, CLI authentication, guest users -tags: [FAQ] -weight: 60 -aliases: - - /single-sign-on/enforcement-faqs/ - - /faq/security/single-sign-on/enforcement-faqs/ - - /security/faqs/single-sign-on/enforcement-faqs/ ---- - -## Does Docker SSO support authenticating through the command line? - -When SSO is enforced, [passwords are prevented from accessing the Docker CLI](/manuals/security/security-announcements.md#deprecation-of-password-logins-on-cli-when-sso-enforced). You must use a personal access token (PAT) for CLI authentication instead. - -Each user must create a PAT to access the CLI. To learn how to create a PAT, see [Manage personal access tokens](/manuals/security/access-tokens/personal-access-tokens.md). Users who already used a PAT before SSO enforcement can continue using that PAT. - -## How does SSO affect automation systems and CI/CD pipelines? - -Before enforcing SSO, you must [create personal access tokens](/manuals/security/access-tokens/personal-access-tokens.md) to replace passwords in automation systems and CI/CD pipelines. - -## Can I turn on SSO without enforcing it immediately? - -Yes, you can turn on SSO without enforcement. Users can choose between Docker ID (standard email and password) or domain-verified email address (SSO) at the sign-in screen. - -## SSO is enforced, but a user can sign in using a username and password. Why is this happening? - -Guest users who aren't part of your registered domain but have been invited to your organization don't sign in through your SSO identity provider. SSO enforcement only applies to users who belong to your verified domain. - -## Can I test SSO functionality before going to production? - -Yes, you can create a test organization with a 5-seat Business subscription. When testing, turn on SSO but don't enforce it, or all domain email users will be forced to sign in to the test environment. - -## What is enforcing SSO versus enforcing sign-in? - -These are separate features you can use independently or together: - -- Enforcing SSO ensures users sign in using SSO credentials instead of their Docker ID, enabling better credential management. -- Enforcing sign-in to Docker Desktop ensures users always sign in to accounts that are members of your organization, so security settings and subscription benefits are always applied. - -For more details, see [Enforce sign-in for Desktop](/manuals/enterprise/security/enforce-sign-in/_index.md#enforcing-sign-in-versus-enforcing-single-sign-on-sso). diff --git a/content/manuals/enterprise/security/single-sign-on/_index.md b/content/manuals/enterprise/security/single-sign-on/_index.md deleted file mode 100644 index cb2f0611da75..000000000000 --- a/content/manuals/enterprise/security/single-sign-on/_index.md +++ /dev/null @@ -1,9 +0,0 @@ ---- -build: - render: never -title: Single sign-on overview -linkTitle: Single sign-on -description: Configure single sign-on for your organization. -keywords: SSO, single sign-on, enterprise, security -weight: 10 ---- diff --git a/content/manuals/faqs/sso-faqs.md b/content/manuals/faqs/sso-faqs.md index 3b4f77628f20..119aeb6ed25f 100644 --- a/content/manuals/faqs/sso-faqs.md +++ b/content/manuals/faqs/sso-faqs.md @@ -1,6 +1,6 @@ --- -description: Frequently asked questions about Docker single sign-on, identity providers, and user management -keywords: Docker, Docker Hub, SSO FAQs, single sign-on, identity providers, IdP, SAML, Entra ID, user management, SCIM, JIT, administration, security +description: Frequently asked questions about Docker single sign-on, identity providers, user management, and SSO enforcement +keywords: Docker, Docker Hub, SSO FAQs, single sign-on, identity providers, IdP, SAML, Entra ID, user management, SCIM, JIT, administration, security, SSO enforcement title: SSO FAQs linkTitle: SSO weight: 40 @@ -24,6 +24,10 @@ aliases: - /platform/security/authentication/single-sign-on/FAQs/users-faqs/ - /platform/security/faqs/users-faqs/ - /platform/security/faqs/sso-faqs/ +- /single-sign-on/enforcement-faqs/ +- /faq/security/single-sign-on/enforcement-faqs/ +- /security/faqs/single-sign-on/enforcement-faqs/ +- /enterprise/security/single-sign-on/FAQs/enforcement-faqs/ --- ## What SSO flows does Docker support? @@ -138,3 +142,36 @@ Turning on SCIM doesn't immediately remove or modify existing licensed users. Th ## Is user information visible in Docker Hub? All Docker accounts have public profiles associated with their namespace. If you don't want user information (like full names) to be visible, remove those attributes from your SSO and SCIM mappings, or use different identifiers to replace users' full names. + +## Enforcement + +### Does Docker SSO support authenticating through the command line? + +When SSO is enforced, [passwords are prevented from accessing the Docker CLI](/manuals/security/security-announcements.md#deprecation-of-password-logins-on-cli-when-sso-enforced). You must use a personal access token (PAT) for CLI authentication instead. + +Each user must create a PAT to access the CLI. To learn how to create a PAT, see [Manage personal access tokens](/manuals/security/access-tokens/personal-access-tokens.md). Users who already used a PAT before SSO enforcement can continue using that PAT. + +### How does SSO affect automation systems and CI/CD pipelines? + +Before enforcing SSO, you must [create personal access tokens](/manuals/security/access-tokens/personal-access-tokens.md) to replace passwords in automation systems and CI/CD pipelines. + +### Can I turn on SSO without enforcing it immediately? + +Yes, you can turn on SSO without enforcement. Users can choose between Docker ID (standard email and password) or domain-verified email address (SSO) at the sign-in screen. + +### SSO is enforced, but a user can sign in using a username and password. Why is this happening? + +Guest users who aren't part of your registered domain but have been invited to your organization don't sign in through your SSO identity provider. SSO enforcement only applies to users who belong to your verified domain. + +### Can I test SSO functionality before going to production? + +Yes, you can create a test organization with a 5-seat Business subscription. When testing, turn on SSO but don't enforce it, or all domain email users will be forced to sign in to the test environment. + +### What is enforcing SSO versus enforcing sign-in? + +These are separate features you can use independently or together: + +- Enforcing SSO ensures users sign in using SSO credentials instead of their Docker ID, enabling better credential management. +- Enforcing sign-in to Docker Desktop ensures users always sign in to accounts that are members of your organization, so security settings and subscription benefits are always applied. + +For more details, see [Enforce sign-in for Desktop](/manuals/enterprise/security/enforce-sign-in/_index.md#enforcing-sign-in-versus-enforcing-single-sign-on-sso). diff --git a/content/manuals/security/authentication/single-sign-on/_index.md b/content/manuals/security/authentication/single-sign-on/_index.md index c954d30e5257..23168323d73e 100644 --- a/content/manuals/security/authentication/single-sign-on/_index.md +++ b/content/manuals/security/authentication/single-sign-on/_index.md @@ -8,6 +8,7 @@ aliases: - /admin/company/settings/sso/ - /admin/organization/security-settings/sso-management/ - /security/for-admins/single-sign-on/ + - /enterprise/security/single-sign-on/ - /platform/security/authentication/single-sign-on/ weight: 10 --- From a5c80c2344be9da33250f28bd1a4428ce8a64bee Mon Sep 17 00:00:00 2001 From: Alexa Date: Mon, 31 Aug 2026 15:10:36 -0500 Subject: [PATCH 10/19] docs: consolidate Platform FAQs into Accounts, Security, and billing Platform FAQs were split across Accounts, Organizations, Companies, SSO, Domain, and nested billing pages. Merge them into one page per Platform category so the sidebar matches the IA. Co-authored-by: Cursor --- content/manuals/accounts/individual/_index.md | 2 +- .../manuals/accounts/organization/_index.md | 2 +- .../accounts/organization/company/_index.md | 2 +- content/manuals/docker-hub/usage/pulls.md | 6 +- content/manuals/faqs/_index.md | 32 ++-- content/manuals/faqs/accounts.md | 181 ++++++++++++++++++ content/manuals/faqs/company-faqs.md | 51 ----- content/manuals/faqs/domain-faqs.md | 26 --- content/manuals/faqs/general-faqs.md | 64 ------- content/manuals/faqs/organization-faqs.md | 74 ------- .../manuals/faqs/{sso-faqs.md => security.md} | 121 +++++++----- .../subscription-billing.md} | 54 +++++- .../authentication/single-sign-on/_index.md | 2 +- .../manuals/subscription-billing/_index.md | 4 - .../subscription-billing/faqs/_index.md | 9 - .../subscription-billing/faqs/subscription.md | 37 ---- 16 files changed, 316 insertions(+), 351 deletions(-) create mode 100644 content/manuals/faqs/accounts.md delete mode 100644 content/manuals/faqs/company-faqs.md delete mode 100644 content/manuals/faqs/domain-faqs.md delete mode 100644 content/manuals/faqs/general-faqs.md delete mode 100644 content/manuals/faqs/organization-faqs.md rename content/manuals/faqs/{sso-faqs.md => security.md} (70%) rename content/manuals/{subscription-billing/faqs/billing.md => faqs/subscription-billing.md} (54%) delete mode 100644 content/manuals/subscription-billing/faqs/_index.md delete mode 100644 content/manuals/subscription-billing/faqs/subscription.md diff --git a/content/manuals/accounts/individual/_index.md b/content/manuals/accounts/individual/_index.md index 3137914f56bf..68295c2a0cfd 100644 --- a/content/manuals/accounts/individual/_index.md +++ b/content/manuals/accounts/individual/_index.md @@ -32,7 +32,7 @@ grid: - title: Account FAQs description: Explore frequently asked questions about Docker accounts. icon: question-mark-circle - link: /faqs/general-faqs/ + link: /faqs/accounts/ --- A Docker account is how Docker identifies you. Use it to access products like diff --git a/content/manuals/accounts/organization/_index.md b/content/manuals/accounts/organization/_index.md index e84bc743be6e..39b501a7ae8b 100644 --- a/content/manuals/accounts/organization/_index.md +++ b/content/manuals/accounts/organization/_index.md @@ -100,7 +100,7 @@ subscriber has at least one organization. Organization owners hold the organization owner administrator role and manage organization settings, users, and access controls. Each owner occupies a -[seat](/manuals/faqs/organization-faqs.md#what-is-the-difference-between-user-invitee-seat-and-member). +[seat](/manuals/faqs/accounts.md#what-is-the-difference-between-user-invitee-seat-and-member). [Upgrading to a Docker Business plan](https://www.docker.com/pricing?ref=Docs&refAction=DocsAdmin) grants you the company owner role so you can manage multiple organizations. diff --git a/content/manuals/accounts/organization/company/_index.md b/content/manuals/accounts/organization/company/_index.md index 3579755f68c8..dd1349de3d08 100644 --- a/content/manuals/accounts/organization/company/_index.md +++ b/content/manuals/accounts/organization/company/_index.md @@ -23,7 +23,7 @@ grid: link: /security/provisioning/domain-management/ - title: FAQs description: Explore frequently asked questions about companies. - link: /faqs/company-faqs/ + link: /faqs/accounts/ icon: question-mark-circle aliases: - /admin/company/ diff --git a/content/manuals/docker-hub/usage/pulls.md b/content/manuals/docker-hub/usage/pulls.md index 880944894c29..74d5b83e168b 100644 --- a/content/manuals/docker-hub/usage/pulls.md +++ b/content/manuals/docker-hub/usage/pulls.md @@ -41,7 +41,7 @@ A pull is defined as the following: ## Pull attribution Pulls from authenticated users can be attributed to either a personal or an -[organization namespace](/manuals/faqs/general-faqs.md#whats-an-organization-name-or-namespace). +[organization namespace](/manuals/faqs/accounts.md#whats-an-organization-name-or-namespace). Attribution is based on the following: @@ -51,11 +51,11 @@ Attribution is based on the following: determined based on domain affiliation and organization membership. - Verified domain ownership: When pulling an image from an account linked to a verified domain, the attribution is set to be the owner of that - [domain](/manuals/faqs/domain-faqs.md). + [domain](/manuals/faqs/security.md). - Single organization membership: - If the owner of the verified domain is a company and the user is part of only one organization within that - [company](../../faqs/company-faqs.md), + [company](/manuals/faqs/accounts.md), the pull is attributed to that specific organization. - If the user is part of only one organization, the pull is attributed to that specific organization. diff --git a/content/manuals/faqs/_index.md b/content/manuals/faqs/_index.md index c68e0cfc2aae..10004962c473 100644 --- a/content/manuals/faqs/_index.md +++ b/content/manuals/faqs/_index.md @@ -1,8 +1,8 @@ --- title: FAQs linkTitle: FAQs -description: Frequently asked questions about Docker accounts, organizations, companies, and security. -keywords: FAQ, FAQs, accounts, organizations, companies, Docker ID, Docker Home, security FAQs, SSO FAQs +description: Frequently asked questions about Docker accounts, subscriptions, billing, and security. +keywords: FAQ, FAQs, accounts, Docker ID, Docker Home, subscription FAQs, billing FAQs, security FAQs, SSO FAQs weight: 45 params: sidebar: @@ -12,29 +12,21 @@ aliases: - /faq/security/ grid: - title: Account FAQs - description: FAQs about Docker IDs, account creation, and organization names. + description: FAQs about Docker IDs, account creation, organizations, and companies. icon: question-mark-circle - link: /faqs/general-faqs/ - - title: Organization FAQs - description: FAQs about organization members, seats, and authentication. - icon: user-group - link: /faqs/organization-faqs/ - - title: Company FAQs - description: FAQs about companies, seats, and company owners. - icon: building-office-2 - link: /faqs/company-faqs/ - - title: SSO FAQs - description: FAQs about single sign-on, identity providers, and user management. + link: /faqs/accounts/ + - title: Security FAQs + description: FAQs about single sign-on, identity providers, enforcement, and domains. icon: lock-closed - link: /faqs/sso-faqs/ - - title: SSO domain FAQs - description: FAQs about domain verification and management for SSO. - icon: globe-alt - link: /faqs/domain-faqs/ + link: /faqs/security/ + - title: Subscription and billing FAQs + description: FAQs about Docker plans, payments, taxes, and invoices. + icon: credit-card + link: /faqs/subscription-billing/ --- Answers to common questions about Docker accounts, organizations, companies, -security, authentication, and related topics. +subscriptions, billing, security, authentication, and related topics. ## Next steps diff --git a/content/manuals/faqs/accounts.md b/content/manuals/faqs/accounts.md new file mode 100644 index 000000000000..145d16ffd1f8 --- /dev/null +++ b/content/manuals/faqs/accounts.md @@ -0,0 +1,181 @@ +--- +title: Account FAQs +linkTitle: Accounts +weight: 10 +description: FAQs about Docker IDs, account creation, organizations, companies, seats, and members +keywords: + docker ID, docker account FAQ, change docker ID, username taken, trademark, + organization name, organization namespace, create account, Google, GitHub, + deactivate docker ID, organizations, members, seats, company, company owners +tags: [FAQ] +toc_max: 4 +aliases: + - /accounts/general-faqs/ + - /accounts/individual/general-faqs/ + - /docker-hub/general-faqs/ + - /docker-hub/onboarding-faqs/ + - /faq/admin/general-faqs/ + - /admin/faqs/general-faqs/ + - /admin/organization/organization-faqs/ + - /docker-hub/organization-faqs/ + - /faq/admin/organization-faqs/ + - /admin/faqs/organization-faqs/ + - /accounts/organization/organization-faqs/ + - /admin/company/company-faqs/ + - /docker-hub/company-faqs/ + - /faq/admin/company-faqs/ + - /admin/faqs/company-faqs/ + - /accounts/organization/company/company-faqs/ + - /faqs/general-faqs/ + - /faqs/organization-faqs/ + - /faqs/company-faqs/ +--- + +## Individual accounts + +### What is a Docker ID? + +A Docker ID is a username for your Docker account that lets you access Docker +products. To create a Docker ID you need one of the following: + +- An email address +- A Google account +- A GitHub account + +Your Docker ID must be between 4 and 30 characters long, and can only contain +numbers and lowercase letters. You can't use any special characters or spaces. + +For more information, see +[Create a Docker account](/manuals/accounts/individual/create-account.md). + +### Can I change my Docker ID? + +No. You can't change your Docker ID once it's created. If you need a different +Docker ID, you must create a new Docker account with a new Docker ID. + +Docker IDs can't be reused after deactivation. + +### What if my Docker ID is taken? + +All Docker IDs are first-come, first-served except for companies that have a +U.S. Trademark on a username. + +If you have a trademark for your Docker ID, +[Docker Support](https://hub.docker.com/support/contact/) can retrieve the +Docker ID for you. + +## Organizations + +### What's an organization name or namespace? + +The organization name, sometimes referred to as the organization namespace or +the organization ID, is the unique identifier of a Docker organization. The +organization name can't be the same as an existing Docker ID. + +For more information, see +[Organization accounts](/manuals/accounts/organization/_index.md). + +### How can I see how many active users are in my organization? + +If your organization uses a Software Asset Management tool, you can use it to +find out how many users have Docker Desktop installed. If your organization +doesn't use this software, you can run an internal survey +to find out who is using Docker Desktop. + +For more information, see [Identify your Docker users and their Docker accounts](/manuals/accounts/organization/setup/onboard.md#step-one-identify-your-docker-users). + +### Do users need to authenticate with Docker before an owner can add them to an organization? + +No. Organization owners can invite users with their email addresses, and also +assign them to a team during the invite process. + +### Can I force my organization's members to authenticate before using Docker Desktop and are there any benefits? + +Yes. You can +[enforce sign-in](/manuals/enterprise/security/enforce-sign-in/_index.md). + +Some benefits of enforcing sign-in are: + +- Ensures users receive the benefits of your subscription. +- Ensures security features like [Image Access Management](/manuals/enterprise/security/hardened-desktop/image-access-management.md) and [Registry Access Management](/manuals/enterprise/security/hardened-desktop/registry-access-management.md) are applied. +- Ensures you gain insights into users' activity. + +### Can I convert my personal Docker ID to an organization account? + +Yes. You can convert your user account to an organization account. Once you +convert a user account into an organization, it's not possible to +revert it to a personal user account. + +For prerequisites and instructions, see +[Convert an account into an organization](/manuals/accounts/organization/setup/convert-account.md). + +### Do organization invitees take up seats? + +Yes. A user invited to an organization will take up one of the provisioned +seats, even if that user hasn’t accepted their invitation yet. + +To manage invites, see [Manage organization members](/manuals/accounts/organization/manage/members.md). + +### Do organization owners take a seat? + +Yes. Organization owners occupy a seat. + +### What is the difference between user, invitee, seat, and member? + +- User: Docker user with a Docker ID. +- Invitee: A user that an administrator has invited to join an organization but + has not yet accepted their invitation. +- Seats: The number of purchased seats in an organization. +- Member: A user who has received and accepted an invitation to join an + organization. Member can also refer to a member of a team within an + organization. + +### If I have two organizations and a user belongs to both organizations, do they take up two seats? + +Yes. In a scenario where a user belongs to two organizations, they take up one +seat in each organization. + +### Companies + +#### Some of my organizations don’t have a Docker Business subscription. Can I still use a parent company? + +Yes, but you can only add organizations with a Docker Business subscription +to a company. For more details, see [Add more organizations](/manuals/accounts/organization/company/manage.md#add-more-organizations). + +#### What happens if one of my organizations downgrades from Docker Business, but I still need access as a company owner? + +To access and manage a nested organization, it must have a Docker Business +subscription. If an organization downgrades from Docker Business, its owner must +manage it outside of the company. For more details, see +[Add more organizations](/manuals/accounts/organization/company/manage.md#add-more-organizations). + +#### Do company owners occupy a subscription seat? + +Company owners don't occupy a seat unless one of the following is true: + +- They are added as a member of an organization under your company +- SSO is enabled and the company owner signs in through SSO, which + automatically adds them as an organization member + +When you first create a company, your account is both a company owner and an +organization owner, so it occupies a seat as long as you remain an organization +owner. To free up that seat, +[assign another user as the organization owner](/manuals/accounts/organization/manage/members.md#update-a-member-role) +and remove yourself from the organization. You keep full administrative access +as a company owner without using a subscription seat. + +#### What permissions does the company owner have in the associated/nested organizations? + +Company owners can navigate to the **Organizations** page to view all their +nested organizations in a single location. They can also view or edit +organization members and change single sign-on (SSO) and System for +Cross-domain Identity Management (SCIM) settings. Changes to company settings +impact all users in each organization under the company. + +For more information, see [Roles and permissions](/manuals/security/roles-and-permissions.md). + +## Next steps + +- [Create a Docker account](/manuals/accounts/individual/create-account.md) +- [Manage a Docker account](/manuals/accounts/individual/manage-account.md) +- [Organization accounts](/manuals/accounts/organization/_index.md) diff --git a/content/manuals/faqs/company-faqs.md b/content/manuals/faqs/company-faqs.md deleted file mode 100644 index 4e027434e4a5..000000000000 --- a/content/manuals/faqs/company-faqs.md +++ /dev/null @@ -1,51 +0,0 @@ ---- -title: Company FAQs -linkTitle: Companies -weight: 30 -description: Frequently asked questions about Docker companies, including subscriptions, seats, company owners, and permissions. -keywords: Docker, Docker Hub, SSO FAQs, single sign-on, company, administration, company management -tags: [FAQ] -aliases: - - /admin/company/company-faqs/ - - /docker-hub/company-faqs/ - - /faq/admin/company-faqs/ - - /admin/faqs/company-faqs/ - - /accounts/organization/company/company-faqs/ ---- - -### Some of my organizations don’t have a Docker Business subscription. Can I still use a parent company? - -Yes, but you can only add organizations with a Docker Business subscription -to a company. For more details, see [Add more organizations](/manuals/accounts/organization/company/manage.md#add-more-organizations). - -### What happens if one of my organizations downgrades from Docker Business, but I still need access as a company owner? - -To access and manage a nested organization, it must have a Docker Business -subscription. If an organization downgrades from Docker Business, its owner must -manage it outside of the company. For more details, see -[Add more organizations](/manuals/accounts/organization/company/manage.md#add-more-organizations). - -### Do company owners occupy a subscription seat? - -Company owners don't occupy a seat unless one of the following is true: - -- They are added as a member of an organization under your company -- SSO is enabled and the company owner signs in through SSO, which - automatically adds them as an organization member - -When you first create a company, your account is both a company owner and an -organization owner, so it occupies a seat as long as you remain an organization -owner. To free up that seat, -[assign another user as the organization owner](/manuals/accounts/organization/manage/members.md#update-a-member-role) -and remove yourself from the organization. You keep full administrative access -as a company owner without using a subscription seat. - -### What permissions does the company owner have in the associated/nested organizations? - -Company owners can navigate to the **Organizations** page to view all their -nested organizations in a single location. They can also view or edit -organization members and change single sign-on (SSO) and System for -Cross-domain Identity Management (SCIM) settings. Changes to company settings -impact all users in each organization under the company. - -For more information, see [Roles and permissions](/manuals/security/roles-and-permissions.md). diff --git a/content/manuals/faqs/domain-faqs.md b/content/manuals/faqs/domain-faqs.md deleted file mode 100644 index b793cf8fb7b6..000000000000 --- a/content/manuals/faqs/domain-faqs.md +++ /dev/null @@ -1,26 +0,0 @@ ---- -title: SSO domain FAQs -linkTitle: Domain -description: Frequently asked questions about domain verification and management for Docker single sign-on -keywords: SSO domains, domain verification, DNS, TXT records, single sign-on -tags: [FAQ] -weight: 50 -aliases: -- /single-sign-on/domain-faqs/ -- /faq/security/single-sign-on/domain-faqs/ -- /security/faqs/single-sign-on/domain-faqs/ -- /platform/security/authentication/single-sign-on/FAQs/domain-faqs/ -- /platform/security/faqs/domain-faqs/ ---- - -## Can I add sub-domains? - -Yes, you can add sub-domains to your SSO connection. All email addresses must use domains you've added to the connection. Verify that your DNS provider supports multiple TXT records for the same domain. - -## Do I need to keep the DNS TXT record permanently? - -You can remove the TXT record after one-time verification to add the domain. However, if your organization changes identity providers and needs to set up SSO again, you'll need to verify the domain again. - -## Can I verify the same domain for multiple organizations? - -You can't verify the same domain for multiple organizations at the organization level. To verify one domain for multiple organizations, you must have a Docker Business subscription and create a company. Companies allow centralized management of organizations and domain verification at the company level. diff --git a/content/manuals/faqs/general-faqs.md b/content/manuals/faqs/general-faqs.md deleted file mode 100644 index 452f725fb4fd..000000000000 --- a/content/manuals/faqs/general-faqs.md +++ /dev/null @@ -1,64 +0,0 @@ ---- -title: Docker account FAQs -linkTitle: Accounts -weight: 10 -description: FAQs about Docker IDs, account creation, and organization names -keywords: - docker ID, docker account FAQ, change docker ID, username taken, trademark, - organization name, organization namespace, create account, Google, GitHub, - deactivate docker ID -tags: [FAQ] -aliases: - - /accounts/general-faqs/ - - /accounts/individual/general-faqs/ - - /docker-hub/general-faqs/ - - /docker-hub/onboarding-faqs/ - - /faq/admin/general-faqs/ - - /admin/faqs/general-faqs/ ---- - -## What is a Docker ID? - -A Docker ID is a username for your Docker account that lets you access Docker -products. To create a Docker ID you need one of the following: - -- An email address -- A Google account -- A GitHub account - -Your Docker ID must be between 4 and 30 characters long, and can only contain -numbers and lowercase letters. You can't use any special characters or spaces. - -For more information, see -[Create a Docker account](/manuals/accounts/individual/create-account.md). - -## Can I change my Docker ID? - -No. You can't change your Docker ID once it's created. If you need a different -Docker ID, you must create a new Docker account with a new Docker ID. - -Docker IDs can't be reused after deactivation. - -## What if my Docker ID is taken? - -All Docker IDs are first-come, first-served except for companies that have a -U.S. Trademark on a username. - -If you have a trademark for your Docker ID, -[Docker Support](https://hub.docker.com/support/contact/) can retrieve the -Docker ID for you. - -## What's an organization name or namespace? - -The organization name, sometimes referred to as the organization namespace or -the organization ID, is the unique identifier of a Docker organization. The -organization name can't be the same as an existing Docker ID. - -For more information, see -[Organization accounts](/manuals/accounts/organization/_index.md). - -## Next steps - -- [Create a Docker account](/manuals/accounts/individual/create-account.md) -- [Manage a Docker account](/manuals/accounts/individual/manage-account.md) -- [Organization accounts](/manuals/accounts/organization/_index.md) diff --git a/content/manuals/faqs/organization-faqs.md b/content/manuals/faqs/organization-faqs.md deleted file mode 100644 index 845ecde913a7..000000000000 --- a/content/manuals/faqs/organization-faqs.md +++ /dev/null @@ -1,74 +0,0 @@ ---- -title: Organization FAQs -linkTitle: Organizations -weight: 20 -description: Organization FAQs -keywords: Docker, Docker Hub, SSO FAQs, single sign-on, organizations, administration, Docker Home, members, organization management, manage orgs -tags: [FAQ] -aliases: - - /admin/organization/organization-faqs/ - - /docker-hub/organization-faqs/ - - /faq/admin/organization-faqs/ - - /admin/faqs/organization-faqs/ - - /accounts/organization/organization-faqs/ ---- - -### How can I see how many active users are in my organization? - -If your organization uses a Software Asset Management tool, you can use it to -find out how many users have Docker Desktop installed. If your organization -doesn't use this software, you can run an internal survey -to find out who is using Docker Desktop. - -For more information, see [Identify your Docker users and their Docker accounts](/manuals/accounts/organization/setup/onboard.md#step-one-identify-your-docker-users). - -### Do users need to authenticate with Docker before an owner can add them to an organization? - -No. Organization owners can invite users with their email addresses, and also -assign them to a team during the invite process. - -### Can I force my organization's members to authenticate before using Docker Desktop and are there any benefits? - -Yes. You can -[enforce sign-in](/manuals/enterprise/security/enforce-sign-in/_index.md). - -Some benefits of enforcing sign-in are: - -- Ensures users receive the benefits of your subscription. -- Ensures security features like [Image Access Management](/manuals/enterprise/security/hardened-desktop/image-access-management.md) and [Registry Access Management](/manuals/enterprise/security/hardened-desktop/registry-access-management.md) are applied. -- Ensures you gain insights into users' activity. - -### Can I convert my personal Docker ID to an organization account? - -Yes. You can convert your user account to an organization account. Once you -convert a user account into an organization, it's not possible to -revert it to a personal user account. - -For prerequisites and instructions, see -[Convert an account into an organization](/manuals/accounts/organization/setup/convert-account.md). - -### Do organization invitees take up seats? - -Yes. A user invited to an organization will take up one of the provisioned -seats, even if that user hasn’t accepted their invitation yet. - -To manage invites, see [Manage organization members](/manuals/accounts/organization/manage/members.md). - -### Do organization owners take a seat? - -Yes. Organization owners occupy a seat. - -### What is the difference between user, invitee, seat, and member? - -- User: Docker user with a Docker ID. -- Invitee: A user that an administrator has invited to join an organization but - has not yet accepted their invitation. -- Seats: The number of purchased seats in an organization. -- Member: A user who has received and accepted an invitation to join an - organization. Member can also refer to a member of a team within an - organization. - -### If I have two organizations and a user belongs to both organizations, do they take up two seats? - -Yes. In a scenario where a user belongs to two organizations, they take up one -seat in each organization. diff --git a/content/manuals/faqs/sso-faqs.md b/content/manuals/faqs/security.md similarity index 70% rename from content/manuals/faqs/sso-faqs.md rename to content/manuals/faqs/security.md index 119aeb6ed25f..d6fcd02ef664 100644 --- a/content/manuals/faqs/sso-faqs.md +++ b/content/manuals/faqs/security.md @@ -1,71 +1,80 @@ --- -description: Frequently asked questions about Docker single sign-on, identity providers, user management, and SSO enforcement -keywords: Docker, Docker Hub, SSO FAQs, single sign-on, identity providers, IdP, SAML, Entra ID, user management, SCIM, JIT, administration, security, SSO enforcement -title: SSO FAQs -linkTitle: SSO -weight: 40 +description: Frequently asked questions about Docker single sign-on, identity providers, user management, SSO enforcement, and domain verification +keywords: Docker, Docker Hub, SSO FAQs, single sign-on, identity providers, IdP, SAML, Entra ID, user management, SCIM, JIT, administration, security, SSO enforcement, SSO domains, domain verification, DNS, TXT records +title: Security FAQs +linkTitle: Security +weight: 20 tags: [FAQ] aliases: -- /single-sign-on/faqs/ -- /faq/security/single-sign-on/faqs/ -- /single-sign-on/saml-faqs/ -- /faq/security/single-sign-on/saml-faqs/ -- /security/faqs/single-sign-on/saml-faqs/ -- /security/faqs/single-sign-on/faqs/ -- /platform/security/authentication/single-sign-on/FAQs/general/ -- /single-sign-on/idp-faqs/ -- /faq/security/single-sign-on/idp-faqs/ -- /security/faqs/single-sign-on/idp-faqs/ -- /platform/security/authentication/single-sign-on/FAQs/idp-faqs/ -- /platform/security/faqs/idp-faqs/ -- /single-sign-on/users-faqs/ -- /faq/security/single-sign-on/users-faqs/ -- /security/faqs/single-sign-on/users-faqs/ -- /platform/security/authentication/single-sign-on/FAQs/users-faqs/ -- /platform/security/faqs/users-faqs/ -- /platform/security/faqs/sso-faqs/ -- /single-sign-on/enforcement-faqs/ -- /faq/security/single-sign-on/enforcement-faqs/ -- /security/faqs/single-sign-on/enforcement-faqs/ -- /enterprise/security/single-sign-on/FAQs/enforcement-faqs/ + - /single-sign-on/faqs/ + - /faq/security/single-sign-on/faqs/ + - /single-sign-on/saml-faqs/ + - /faq/security/single-sign-on/saml-faqs/ + - /security/faqs/single-sign-on/saml-faqs/ + - /security/faqs/single-sign-on/faqs/ + - /platform/security/authentication/single-sign-on/FAQs/general/ + - /single-sign-on/idp-faqs/ + - /faq/security/single-sign-on/idp-faqs/ + - /security/faqs/single-sign-on/idp-faqs/ + - /platform/security/authentication/single-sign-on/FAQs/idp-faqs/ + - /platform/security/faqs/idp-faqs/ + - /single-sign-on/users-faqs/ + - /faq/security/single-sign-on/users-faqs/ + - /security/faqs/single-sign-on/users-faqs/ + - /platform/security/authentication/single-sign-on/FAQs/users-faqs/ + - /platform/security/faqs/users-faqs/ + - /platform/security/faqs/sso-faqs/ + - /single-sign-on/enforcement-faqs/ + - /faq/security/single-sign-on/enforcement-faqs/ + - /security/faqs/single-sign-on/enforcement-faqs/ + - /enterprise/security/single-sign-on/FAQs/enforcement-faqs/ + - /single-sign-on/domain-faqs/ + - /faq/security/single-sign-on/domain-faqs/ + - /security/faqs/single-sign-on/domain-faqs/ + - /platform/security/authentication/single-sign-on/FAQs/domain-faqs/ + - /platform/security/faqs/domain-faqs/ + - /faqs/sso-faqs/ + - /faqs/domain-faqs/ --- -## What SSO flows does Docker support? +## SSO + +### What SSO flows does Docker support? Docker supports Service Provider Initiated (SP-initiated) SSO flow. Users must sign in to Docker Hub or Docker Desktop to initiate the SSO authentication process. -## Does Docker SSO support multi-factor authentication? +### Does Docker SSO support multi-factor authentication? When an organization uses SSO, multi-factor authentication is controlled at the identity provider level, not on the Docker platform. -## Can I retain my Docker ID when using SSO? +### Can I retain my Docker ID when using SSO? Users with personal Docker IDs retain ownership of their repositories, images, and assets. When SSO is enforced, existing accounts with company domain emails are connected to the organization. Users signing in without existing accounts automatically have new accounts and Docker IDs created. -## Are there any firewall rules required for SSO configuration? +### Are there any firewall rules required for SSO configuration? No specific firewall rules are required as long as `login.docker.com` is accessible. This domain is commonly accessible by default, but some organizations may need to allow it in their firewall settings if SSO setup encounters issues. -## Does Docker use my IdP's default session timeout? +### Does Docker use my IdP's default session timeout? Yes, Docker supports your IdP's session timeout using a custom `dockerSessionMinutes` SAML attribute instead of the standard `SessionNotOnOrAfter` element. See [SSO attributes](/manuals/security/provisioning/_index.md#sso-attributes) for more information. -## Can I use multiple identity providers with Docker SSO? +### Can I use multiple identity providers with Docker SSO? Yes, Docker supports multiple IdP configurations. A domain can be associated with multiple IdPs. Docker supports Entra ID (formerly Azure AD) and identity providers that support SAML 2.0. -## Can I change my identity provider after configuring SSO? +### Can I change my identity provider after configuring SSO? Yes. Delete your existing IdP configuration in your Docker SSO connection, then [configure SSO using your new IdP](/manuals/security/authentication/single-sign-on/connect.md). If you had already turned on enforcement, turn off enforcement before updating the provider connection. -## What information do I need from my identity provider to configure SSO? +### What information do I need from my identity provider to configure SSO? To turn on SSO in Docker, you need the following from your IdP: - SAML: Entity ID, ACS URL, Single Logout URL, and the public X.509 certificate - Entra ID (formerly Azure AD): Client ID, Client Secret, AD Domain -## What happens if my existing certificate expires? +### What happens if my existing certificate expires? Contact your identity provider to retrieve a new X.509 certificate. Update with the new certificate in [SSO configuration settings](/manuals/security/authentication/single-sign-on/manage.md#manage-sso-connections) from Docker Home. @@ -74,39 +83,39 @@ Contact your identity provider to retrieve a new X.509 certificate. Update with If you need additional help, contact [Docker support](https://app.docker.com/support/contact). -## What happens if my IdP goes down when SSO is turned on? +### What happens if my IdP goes down when SSO is turned on? If SSO is enforced, users can't access Docker Hub when your IdP is down. Users can still access Docker Hub images from the CLI using personal access tokens. If SSO is turned on but not enforced, users can fall back to username/password authentication. -## Do bot accounts need seats to access organizations using SSO? +### Do bot accounts need seats to access organizations using SSO? Yes, bot accounts need seats like regular users, requiring a non-aliased domain email in the IdP and using a seat in Docker Hub. You can add bot accounts to your IdP and create access tokens to replace other credentials. -## Does SAML SSO use Just-in-Time provisioning? +### Does SAML SSO use Just-in-Time provisioning? The SSO implementation uses Just-in-Time (JIT) provisioning by default. You can optionally turn off JIT in Docker Home if you turn on auto-provisioning using SCIM. See [Just-in-Time provisioning](/manuals/security/provisioning/just-in-time.md). -## How can I troubleshoot an Entra ID SSO connection error? +### How can I troubleshoot an Entra ID SSO connection error? Confirm that you've configured the necessary API permissions in Entra ID for your SSO connection. You need to grant administrator consent within your Entra ID tenant. See [Entra ID (formerly Azure AD) documentation](https://learn.microsoft.com/en-us/azure/active-directory/manage-apps/grant-admin-consent?pivots=portal#grant-admin-consent-in-app-registrations). -## Do I need to manually add users to my organization? +### Do I need to manually add users to my organization? No, you don't need to manually add users to your organization. Just ensure user accounts exist in your IdP. When users sign in to Docker with their domain email address, they're automatically added to the organization after successful authentication. -## Can users use different email addresses to authenticate through SSO? +### Can users use different email addresses to authenticate through SSO? All users must authenticate using the email domain specified during SSO setup. Users with email addresses that don't match the verified domain can sign in as guests with username and password if SSO isn't enforced, but only if they've been invited. -## How will users know they're being added to a Docker organization? +### How will users know they're being added to a Docker organization? When SSO is turned on, users are prompted to authenticate through SSO the next time they sign in to Docker Hub or Docker Desktop. The system detects their domain email and prompts them to sign in with SSO credentials instead. For CLI access, users must authenticate using personal access tokens. -## Can I convert existing users from non-SSO to SSO accounts? +### Can I convert existing users from non-SSO to SSO accounts? Yes, you can convert existing users to SSO accounts. Ensure users have: @@ -117,7 +126,7 @@ Yes, you can convert existing users to SSO accounts. Ensure users have: For detailed instructions, see [Configure single sign-on](/manuals/security/authentication/single-sign-on/connect.md). -## Is Docker SSO fully synced with the IdP? +### Is Docker SSO fully synced with the IdP? Docker SSO provides Just-in-Time (JIT) provisioning by default. Users are provisioned when they authenticate with SSO. If users leave the organization, administrators must manually [remove the user](/manuals/accounts/organization/manage/members.md#remove-members-from-teams) from the organization. @@ -125,21 +134,21 @@ Docker SSO provides Just-in-Time (JIT) provisioning by default. Users are provis Additionally, you can use the [Docker Hub API](/reference/api/hub/latest.md) to complete this process. -## How does turning off Just-in-Time provisioning affect user sign-in? +### How does turning off Just-in-Time provisioning affect user sign-in? When JIT is turned off (available with SCIM in Docker Home), users must be organization members or have pending invitations to access Docker. Users who don't meet these criteria get an "Access denied" error and need administrator invitations. See [SSO authentication with JIT provisioning disabled](/manuals/security/provisioning/just-in-time.md#sso-authentication-with-jit-provisioning-disabled). -## Can someone join an organization without an invitation? +### Can someone join an organization without an invitation? Not without SSO. Joining requires an invite from an organization owner. When SSO is enforced, users with verified domain emails can automatically join the organization when they sign in. -## What happens to existing licensed users when SCIM is turned on? +### What happens to existing licensed users when SCIM is turned on? Turning on SCIM doesn't immediately remove or modify existing licensed users. They retain current access and roles, but you'll manage them through your IdP after SCIM is active. If SCIM is later turned off, previously SCIM-managed users remain in Docker but are no longer automatically updated based on your IdP. -## Is user information visible in Docker Hub? +### Is user information visible in Docker Hub? All Docker accounts have public profiles associated with their namespace. If you don't want user information (like full names) to be visible, remove those attributes from your SSO and SCIM mappings, or use different identifiers to replace users' full names. @@ -175,3 +184,17 @@ These are separate features you can use independently or together: - Enforcing sign-in to Docker Desktop ensures users always sign in to accounts that are members of your organization, so security settings and subscription benefits are always applied. For more details, see [Enforce sign-in for Desktop](/manuals/enterprise/security/enforce-sign-in/_index.md#enforcing-sign-in-versus-enforcing-single-sign-on-sso). + +## Domain + +### Can I add sub-domains? + +Yes, you can add sub-domains to your SSO connection. All email addresses must use domains you've added to the connection. Verify that your DNS provider supports multiple TXT records for the same domain. + +### Do I need to keep the DNS TXT record permanently? + +You can remove the TXT record after one-time verification to add the domain. However, if your organization changes identity providers and needs to set up SSO again, you'll need to verify the domain again. + +### Can I verify the same domain for multiple organizations? + +You can't verify the same domain for multiple organizations at the organization level. To verify one domain for multiple organizations, you must have a Docker Business subscription and create a company. Companies allow centralized management of organizations and domain verification at the company level. diff --git a/content/manuals/subscription-billing/faqs/billing.md b/content/manuals/faqs/subscription-billing.md similarity index 54% rename from content/manuals/subscription-billing/faqs/billing.md rename to content/manuals/faqs/subscription-billing.md index 813bf1bee653..87911f9b9730 100644 --- a/content/manuals/subscription-billing/faqs/billing.md +++ b/content/manuals/faqs/subscription-billing.md @@ -1,14 +1,49 @@ --- -title: Billing FAQs -linkTitle: Billing FAQ -description: Find answers to common questions about Docker billing, failed payments, taxes, and pay by invoice. -keywords: billing, renewal, failed payments, sales tax, VAT, academic pricing, pay by invoice +title: Subscription and billing FAQs +linkTitle: Subscription and billing +description: Frequently asked questions about Docker subscriptions, billing, failed payments, taxes, and plans. +keywords: subscription faqs, billing, docker plans, renewal, failed payments, sales tax, VAT, academic pricing, pay by invoice, subscription transfer tags: [FAQ] -weight: 20 +weight: 35 aliases: + - /subscription/faq/ - /billing/faqs/ + - /subscription-billing/faqs/subscription/ + - /subscription-billing/faqs/billing/ --- +For more information on Docker subscriptions, see +[Subscription and billing](/manuals/subscription-billing/_index.md). + +## Can I transfer my subscription from one user or organization account to another? + +Subscriptions are non-transferable between accounts or organizations. + +## Can I pause or delay my Docker subscription? + +You can't pause or delay a subscription, but you can downgrade your +subscription. If a subscription invoice isn't paid by the due date, there's a +15-day grace period starting from the due date. + +## Does Docker offer academic pricing? + +For academic pricing, contact the +[Docker Sales Team](https://www.docker.com/company/contact). + +## How can I contribute to Docker content? + +Docker offers two content contribution programs: + +- [Docker-Sponsored Open Source Program (DSOS)](/manuals/docker-hub/repos/manage/trusted-content/dsos-program.md) + for open source projects +- [Docker Verified Publisher (DVP)](/manuals/docker-hub/repos/manage/trusted-content/dvp-program.md) + for commercial publishers + +You can also join the +[Developer Preview Program](https://www.docker.com/community/get-involved/developer-preview/) +or sign up for early access programs to participate in research and try new +features. + ## What happens if my subscription payment fails? If your subscription payment fails, there is a grace period of 15 days, @@ -50,11 +85,6 @@ To help ensure correct tax assessments, keep your adding a VAT number or submitting a US tax exemption certificate, see [Taxes](/manuals/subscription-billing/manage/tax-certificate.md). -## Does Docker offer academic pricing? - -For academic pricing, contact the -[Docker Sales Team](https://www.docker.com/company/contact). - ## Can I use pay by invoice for upgrades or additional seats? No. Pay by invoice is only available for renewing annual subscriptions, not for @@ -63,3 +93,7 @@ accounts for these changes. For a list of supported payment methods, see [Add or update a payment method](/manuals/subscription-billing/manage/payment-method.md). + +> [!TIP] +> +> Need to upgrade? Compare Docker Team and Docker Business to choose the plan that best fits your team's needs. diff --git a/content/manuals/security/authentication/single-sign-on/_index.md b/content/manuals/security/authentication/single-sign-on/_index.md index 23168323d73e..7927a24e3f85 100644 --- a/content/manuals/security/authentication/single-sign-on/_index.md +++ b/content/manuals/security/authentication/single-sign-on/_index.md @@ -57,5 +57,5 @@ assigned to an organization, and added to a team. ## Next steps - Start [configuring SSO](connect.md). -- Read the [FAQs](/manuals/faqs/sso-faqs.md). +- Read the [FAQs](/manuals/faqs/security.md). - [Troubleshoot](/manuals/security/authentication/single-sign-on/troubleshoot-sso.md) SSO issues. diff --git a/content/manuals/subscription-billing/_index.md b/content/manuals/subscription-billing/_index.md index ac22d1c0bd37..7ac27dd07ce9 100644 --- a/content/manuals/subscription-billing/_index.md +++ b/content/manuals/subscription-billing/_index.md @@ -30,10 +30,6 @@ grid_subscriptions: description: Review the terms of the Docker Subscription Service Agreement. link: /subscription-billing/desktop-license/ icon: document-text - - title: Plan FAQs - description: Find the answers you need and explore common questions. - link: /subscription-billing/faqs/subscription/ - icon: question-mark-circle grid_core: - title: Add or update a payment method description: Learn how to add or update a payment method for your personal account or organization. diff --git a/content/manuals/subscription-billing/faqs/_index.md b/content/manuals/subscription-billing/faqs/_index.md deleted file mode 100644 index cb24091059ef..000000000000 --- a/content/manuals/subscription-billing/faqs/_index.md +++ /dev/null @@ -1,9 +0,0 @@ ---- -build: - render: never -title: FAQs -linkTitle: FAQs -description: Frequently asked questions about Docker subscriptions and billing -keywords: subscription faq, billing faq, docker plans -weight: 40 ---- diff --git a/content/manuals/subscription-billing/faqs/subscription.md b/content/manuals/subscription-billing/faqs/subscription.md deleted file mode 100644 index 949bcf7b4000..000000000000 --- a/content/manuals/subscription-billing/faqs/subscription.md +++ /dev/null @@ -1,37 +0,0 @@ ---- -title: Plan FAQs -linkTitle: Subscription FAQ -description: Frequently asked questions about Docker subscriptions and billing -keywords: subscription faqs, docker billing, subscription transfer, academic pricing, docker programs -tags: [FAQ] -weight: 10 -aliases: - - /subscription/faq/ ---- - -For more information on Docker subscriptions, see [Docker subscription overview](/manuals/subscription-billing/_index.md). - -## Can I transfer my subscription from one user or organization account to another? - -Subscriptions are non-transferable between accounts or organizations. - -## Can I pause or delay my Docker subscription? - -You can't pause or delay a subscription, but you can downgrade your subscription. If a subscription invoice isn't paid by the due date, there's a 15-day grace period starting from the due date. - -## Does Docker offer academic pricing? - -Contact the [Docker Sales Team](https://www.docker.com/company/contact) for information about academic pricing options. - -## How can I contribute to Docker content? - -Docker offers two content contribution programs: - -- [Docker-Sponsored Open Source Program (DSOS)](/manuals/docker-hub/repos/manage/trusted-content/dsos-program.md) for open source projects -- [Docker Verified Publisher (DVP)](/manuals/docker-hub/repos/manage/trusted-content/dvp-program.md) for commercial publishers - -You can also join the [Developer Preview Program](https://www.docker.com/community/get-involved/developer-preview/) or sign up for early access programs to participate in research and try new features. - -> [!TIP] -> -> Need to upgrade? Compare Docker Team and Docker Business to choose the plan that best fits your team's needs. \ No newline at end of file From 327ee8c4810a129993a78c7792c51bfb20b63565 Mon Sep 17 00:00:00 2001 From: Alexa Date: Mon, 31 Aug 2026 15:13:58 -0500 Subject: [PATCH 11/19] docs: template FAQ pages with H2 topics and H3 questions Co-authored-by: Cursor --- content/manuals/faqs/accounts.md | 12 ++--- content/manuals/faqs/security.md | 1 + content/manuals/faqs/subscription-billing.md | 47 +++++++++++--------- 3 files changed, 34 insertions(+), 26 deletions(-) diff --git a/content/manuals/faqs/accounts.md b/content/manuals/faqs/accounts.md index 145d16ffd1f8..ff5c46e31a5d 100644 --- a/content/manuals/faqs/accounts.md +++ b/content/manuals/faqs/accounts.md @@ -8,7 +8,7 @@ keywords: organization name, organization namespace, create account, Google, GitHub, deactivate docker ID, organizations, members, seats, company, company owners tags: [FAQ] -toc_max: 4 +toc_max: 2 aliases: - /accounts/general-faqs/ - /accounts/individual/general-faqs/ @@ -135,21 +135,21 @@ Yes. Organization owners occupy a seat. Yes. In a scenario where a user belongs to two organizations, they take up one seat in each organization. -### Companies +## Companies -#### Some of my organizations don’t have a Docker Business subscription. Can I still use a parent company? +### Some of my organizations don’t have a Docker Business subscription. Can I still use a parent company? Yes, but you can only add organizations with a Docker Business subscription to a company. For more details, see [Add more organizations](/manuals/accounts/organization/company/manage.md#add-more-organizations). -#### What happens if one of my organizations downgrades from Docker Business, but I still need access as a company owner? +### What happens if one of my organizations downgrades from Docker Business, but I still need access as a company owner? To access and manage a nested organization, it must have a Docker Business subscription. If an organization downgrades from Docker Business, its owner must manage it outside of the company. For more details, see [Add more organizations](/manuals/accounts/organization/company/manage.md#add-more-organizations). -#### Do company owners occupy a subscription seat? +### Do company owners occupy a subscription seat? Company owners don't occupy a seat unless one of the following is true: @@ -164,7 +164,7 @@ owner. To free up that seat, and remove yourself from the organization. You keep full administrative access as a company owner without using a subscription seat. -#### What permissions does the company owner have in the associated/nested organizations? +### What permissions does the company owner have in the associated/nested organizations? Company owners can navigate to the **Organizations** page to view all their nested organizations in a single location. They can also view or edit diff --git a/content/manuals/faqs/security.md b/content/manuals/faqs/security.md index d6fcd02ef664..8e966d2e563b 100644 --- a/content/manuals/faqs/security.md +++ b/content/manuals/faqs/security.md @@ -5,6 +5,7 @@ title: Security FAQs linkTitle: Security weight: 20 tags: [FAQ] +toc_max: 2 aliases: - /single-sign-on/faqs/ - /faq/security/single-sign-on/faqs/ diff --git a/content/manuals/faqs/subscription-billing.md b/content/manuals/faqs/subscription-billing.md index 87911f9b9730..7a9f8ac02b9b 100644 --- a/content/manuals/faqs/subscription-billing.md +++ b/content/manuals/faqs/subscription-billing.md @@ -4,6 +4,7 @@ linkTitle: Subscription and billing description: Frequently asked questions about Docker subscriptions, billing, failed payments, taxes, and plans. keywords: subscription faqs, billing, docker plans, renewal, failed payments, sales tax, VAT, academic pricing, pay by invoice, subscription transfer tags: [FAQ] +toc_max: 2 weight: 35 aliases: - /subscription/faq/ @@ -15,22 +16,24 @@ aliases: For more information on Docker subscriptions, see [Subscription and billing](/manuals/subscription-billing/_index.md). -## Can I transfer my subscription from one user or organization account to another? +## Subscriptions + +### Can I transfer my subscription from one user or organization account to another? Subscriptions are non-transferable between accounts or organizations. -## Can I pause or delay my Docker subscription? +### Can I pause or delay my Docker subscription? You can't pause or delay a subscription, but you can downgrade your subscription. If a subscription invoice isn't paid by the due date, there's a 15-day grace period starting from the due date. -## Does Docker offer academic pricing? +### Does Docker offer academic pricing? For academic pricing, contact the [Docker Sales Team](https://www.docker.com/company/contact). -## How can I contribute to Docker content? +### How can I contribute to Docker content? Docker offers two content contribution programs: @@ -44,7 +47,9 @@ You can also join the or sign up for early access programs to participate in research and try new features. -## What happens if my subscription payment fails? +## Payments + +### What happens if my subscription payment fails? If your subscription payment fails, there is a grace period of 15 days, including the due date. Docker attempts to collect the payment three times using @@ -62,7 +67,7 @@ If the invoice remains unpaid after the grace period, the subscription downgrades to a free subscription and all paid features are disabled. -## Can I manually retry a failed payment? +### Can I manually retry a failed payment? Yes. If your payment fails, select **Pay now** to retry the payment through Stripe. @@ -71,7 +76,22 @@ Before retrying, verify that your default payment method is up to date. For instructions, see [Manage a payment method](/manuals/subscription-billing/manage/payment-method.md#manage-payment-method). -## Does Docker collect sales tax and VAT? +### Can I use pay by invoice for upgrades or additional seats? + +No. Pay by invoice is only available for renewing annual subscriptions, not for +purchasing upgrades or additional seats. You must use card payment or US bank +accounts for these changes. + +For a list of supported payment methods, see +[Add or update a payment method](/manuals/subscription-billing/manage/payment-method.md). + +> [!TIP] +> +> Need to upgrade? Compare Docker Team and Docker Business to choose the plan that best fits your team's needs. + +## Taxes + +### Does Docker collect sales tax and VAT? Docker collects sales tax or VAT from the following customers: @@ -84,16 +104,3 @@ To help ensure correct tax assessments, keep your [billing information](/manuals/subscription-billing/manage/details.md) up to date. For details on adding a VAT number or submitting a US tax exemption certificate, see [Taxes](/manuals/subscription-billing/manage/tax-certificate.md). - -## Can I use pay by invoice for upgrades or additional seats? - -No. Pay by invoice is only available for renewing annual subscriptions, not for -purchasing upgrades or additional seats. You must use card payment or US bank -accounts for these changes. - -For a list of supported payment methods, see -[Add or update a payment method](/manuals/subscription-billing/manage/payment-method.md). - -> [!TIP] -> -> Need to upgrade? Compare Docker Team and Docker Business to choose the plan that best fits your team's needs. From 82222dafdebf1cc9dacf2c56e14af5d38a7a7ed6 Mon Sep 17 00:00:00 2001 From: Alexa Date: Mon, 31 Aug 2026 15:14:59 -0500 Subject: [PATCH 12/19] docs: add Platform FAQs from general, container, and network/VM pages Leftover Security FAQ pages had no home after Accounts/Security/billing consolidation. Merge them into /faqs/platform/ and alias the old URLs. Co-authored-by: Cursor --- content/manuals/faqs/_index.md | 4 + content/manuals/faqs/platform.md | 126 ++++++++++++++++++ content/manuals/security/_index.md | 2 +- content/manuals/security/faqs/_index.md | 6 - content/manuals/security/faqs/containers.md | 33 ----- content/manuals/security/faqs/general.md | 69 ---------- .../security/faqs/networking-and-vms.md | 30 ----- 7 files changed, 131 insertions(+), 139 deletions(-) create mode 100644 content/manuals/faqs/platform.md delete mode 100644 content/manuals/security/faqs/_index.md delete mode 100644 content/manuals/security/faqs/containers.md delete mode 100644 content/manuals/security/faqs/general.md delete mode 100644 content/manuals/security/faqs/networking-and-vms.md diff --git a/content/manuals/faqs/_index.md b/content/manuals/faqs/_index.md index 10004962c473..bc6cbe5d4fa6 100644 --- a/content/manuals/faqs/_index.md +++ b/content/manuals/faqs/_index.md @@ -23,6 +23,10 @@ grid: description: FAQs about Docker plans, payments, taxes, and invoices. icon: credit-card link: /faqs/subscription-billing/ + - title: Platform FAQs + description: FAQs about Docker Desktop containers, networking, VMs, and general platform security. + icon: cpu-chip + link: /faqs/platform/ --- Answers to common questions about Docker accounts, organizations, companies, diff --git a/content/manuals/faqs/platform.md b/content/manuals/faqs/platform.md new file mode 100644 index 000000000000..847f2ae333cf --- /dev/null +++ b/content/manuals/faqs/platform.md @@ -0,0 +1,126 @@ +--- +title: Platform FAQs +linkTitle: Platform +description: Frequently asked questions about Docker platform security, containers, networking, and VMs. +keywords: Docker security, FAQs, authentication, vulnerability reporting, session management, container security, docker desktop isolation, enhanced container isolation, file sharing, docker desktop networking, virtualization, hyper-v, wsl2, network security, firewall +weight: 40 +tags: [FAQ] +toc_max: 3 +aliases: + - /faq/security/general/ + - /security/faqs/general/ + - /faq/security/containers/ + - /security/faqs/containers/ + - /faq/security/networking-and-vms/ + - /security/faqs/networking-and-vms/ +--- + +## General + +### How do I report a vulnerability? + +If you've discovered a security vulnerability in Docker, report it responsibly to security@docker.com so Docker can quickly address it. + +### Does Docker lockout users after failed sign-ins? + +Docker Hub locks out users after 10 failed sign-in attempts within 5 minutes. The lockout duration is 5 minutes. This policy applies to Docker Hub, Docker Desktop, and Docker Scout authentication. + +### Do you support physical multi-factor authentication (MFA) with YubiKeys? + +You can configure physical multi-factor authentication (MFA) through SSO using your identity provider (IdP). Check with your IdP if they support physical MFA devices like YubiKeys. + +### How are sessions managed and do they expire? + +Docker uses tokens to manage user sessions with different expiration periods: + +- Docker Desktop: Signs you out after 90 days, or 30 days of inactivity +- Docker Hub and Docker Home: Sign you out after 24 hours + +Docker also supports your IdP's default session timeout through SAML attributes. For more information, see [SSO attributes](/manuals/security/provisioning/_index.md#sso-attributes). + +### How does Docker distinguish between employee users and contractor users? + +Organizations use verified domains to distinguish user types. Team members with email domains other than verified domains appear as "Guest" users in the organization. + +### How long are activity logs available? + +Docker activity logs are available for 90 days. You're responsible for exporting logs or setting up drivers to send logs to your internal systems for longer retention. + +### Can I export a list of users with their roles and privileges? + +Yes, use the [Export Members](/manuals/accounts/organization/manage/members.md#export-members-csv-file) feature to export a CSV file containing your organization's users with role and team information. + +### How do I remove users who aren't part of my IdP when using SSO without SCIM? + +If SCIM isn't turned on, you must manually remove users from the organization. SCIM can automate user removal, but only for users added after SCIM is turned on. Users added before SCIM was turned on must be removed manually. + +For more information, see [Manage organization members](/manuals/accounts/organization/manage/members.md). + +### What metadata does Scout collect from container images? + +For information about metadata stored by Docker Scout, see [Data handling](/manuals/scout/deep-dive/data-handling.md). + +### How are Marketplace extensions vetted for security? + +Security vetting for extensions isn't implemented. Extensions aren't covered as part of Docker's Third-Party Risk Management Program. + +### Can I prevent users from pushing images to Docker Hub private repositories? + +No direct setting exists to disable private repositories. However, [Registry Access Management](/manuals/enterprise/security/hardened-desktop/registry-access-management.md) lets administrators control which registries developers can access through Docker Desktop via Docker Home. + +## Docker Desktop + +### How does Docker Desktop handle authentication information? + +Docker Desktop uses the host operating system's secure key management to store authentication tokens: + +- macOS: [Keychain](https://support.apple.com/guide/security/keychain-data-protection-secb0694df1a/web) +- Windows: [Security and Identity API via Wincred](https://learn.microsoft.com/en-us/windows/win32/api/wincred/) +- Linux: [Pass](https://www.passwordstore.org/). + +### Containers + +#### How are containers isolated from the host in Docker Desktop? + +Docker Desktop runs all containers inside a customized Linux virtual machine (except for native Windows containers). This adds strong isolation between containers and the host machine, even when containers run as root. + +Important considerations include: + +- Containers have access to host files configured for file sharing via Docker Desktop settings +- Containers run as root with limited capabilities inside the Docker Desktop VM by default +- Privileged containers (`--privileged`, `--pid=host`, `--cap-add`) run with elevated privileges inside the VM, giving them access to VM internals and Docker Engine + +With Enhanced Container Isolation turned on, each container runs in a dedicated Linux user namespace inside the Docker Desktop VM. Even privileged containers only have privileges within their container boundary, not the VM. ECI uses advanced techniques to prevent containers from breaching the Docker Desktop VM and Docker Engine. + +#### Which portions of the host filesystem can containers access? + +Containers can only access host files that are: + +1. Shared using Docker Desktop settings +1. Explicitly bind-mounted into the container (e.g., `docker run -v /path/to/host/file:/mnt`) + +#### Can containers running as root access admin-owned files on the host? + +No. Host file sharing uses a user-space file server (running in `com.docker.backend` as the Docker Desktop user), so containers can only access files that the Docker Desktop user already has permission to access. + +### Networking and VMs + +#### How can I limit container internet access? + +Docker Desktop doesn't have a built-in mechanism for this, but you can use process-level firewalls on the host. Apply rules to the `com.docker.vpnkit` user-space process to control where it can connect (DNS allowlists, packet filters) and which ports/protocols it can use. + +For enterprise environments, consider [Air-gapped containers](/manuals/enterprise/security/hardened-desktop/air-gapped-containers.md) which provide network access controls for containers. + +#### Can I apply firewall rules to container network traffic? + +Yes. Docker Desktop uses a user-space process (`com.docker.vpnkit`) for network connectivity, which inherits constraints like firewall rules, VPN settings, and HTTP proxy properties from the user that launched it. + +#### Does Docker Desktop for Windows with Hyper-V allow users to create other VMs? + +No. The `DockerDesktopVM` name is hard-coded in the service, so you cannot use Docker Desktop to create or manipulate other virtual machines. + +#### How does Docker Desktop achieve network isolation with Hyper-V and WSL 2? + +Docker Desktop uses the same VM processes for both WSL 2 (in the `docker-desktop` distribution) and Hyper-V (in `DockerDesktopVM`). Host/VM communication uses `AF_VSOCK` hypervisor sockets (shared memory) rather than network switches or interfaces. All host networking is performed using standard TCP/IP sockets from the `com.docker.vpnkit.exe` and `com.docker.backend.exe` processes. + +For more information, see [How Docker Desktop networking works under the hood](https://www.docker.com/blog/how-docker-desktop-networking-works-under-the-hood/). diff --git a/content/manuals/security/_index.md b/content/manuals/security/_index.md index 58fa86f66d18..cf7436317ce9 100644 --- a/content/manuals/security/_index.md +++ b/content/manuals/security/_index.md @@ -35,7 +35,7 @@ grid_resources: - title: Security FAQs description: Explore common security FAQs. icon: question-mark-circle - link: /faq/security/general/ + link: /faqs/platform/ - title: Security best practices description: Understand the steps you can take to improve the security of your container. icon: squares-2x2 diff --git a/content/manuals/security/faqs/_index.md b/content/manuals/security/faqs/_index.md deleted file mode 100644 index 4aebbca68bbb..000000000000 --- a/content/manuals/security/faqs/_index.md +++ /dev/null @@ -1,6 +0,0 @@ ---- -build: - render: never -title: FAQs -weight: 70 ---- diff --git a/content/manuals/security/faqs/containers.md b/content/manuals/security/faqs/containers.md deleted file mode 100644 index 5c3496f338eb..000000000000 --- a/content/manuals/security/faqs/containers.md +++ /dev/null @@ -1,33 +0,0 @@ ---- -title: Container security FAQs -linkTitle: Container -description: Frequently asked questions about Docker container security and isolation -keywords: container security, docker desktop isolation, enhanced container isolation, file sharing -weight: 20 -tags: [FAQ] -aliases: -- /faq/security/containers/ ---- - -## How are containers isolated from the host in Docker Desktop? - -Docker Desktop runs all containers inside a customized Linux virtual machine (except for native Windows containers). This adds strong isolation between containers and the host machine, even when containers run as root. - -Important considerations include: - -- Containers have access to host files configured for file sharing via Docker Desktop settings -- Containers run as root with limited capabilities inside the Docker Desktop VM by default -- Privileged containers (`--privileged`, `--pid=host`, `--cap-add`) run with elevated privileges inside the VM, giving them access to VM internals and Docker Engine - -With Enhanced Container Isolation turned on, each container runs in a dedicated Linux user namespace inside the Docker Desktop VM. Even privileged containers only have privileges within their container boundary, not the VM. ECI uses advanced techniques to prevent containers from breaching the Docker Desktop VM and Docker Engine. - -## Which portions of the host filesystem can containers access? - -Containers can only access host files that are: - -1. Shared using Docker Desktop settings -1. Explicitly bind-mounted into the container (e.g., `docker run -v /path/to/host/file:/mnt`) - -## Can containers running as root access admin-owned files on the host? - -No. Host file sharing uses a user-space file server (running in `com.docker.backend` as the Docker Desktop user), so containers can only access files that the Docker Desktop user already has permission to access. diff --git a/content/manuals/security/faqs/general.md b/content/manuals/security/faqs/general.md deleted file mode 100644 index 04c69d11f98b..000000000000 --- a/content/manuals/security/faqs/general.md +++ /dev/null @@ -1,69 +0,0 @@ ---- -description: Frequently asked questions about Docker security, authentication, and organization management -keywords: Docker security, FAQs, authentication, SSO, vulnerability reporting, session management -title: General security FAQs -linkTitle: General -weight: 10 -tags: [FAQ] -aliases: -- /faq/security/general/ ---- - -## How do I report a vulnerability? - -If you've discovered a security vulnerability in Docker, report it responsibly to security@docker.com so Docker can quickly address it. - -## Does Docker lockout users after failed sign-ins? - -Docker Hub locks out users after 10 failed sign-in attempts within 5 minutes. The lockout duration is 5 minutes. This policy applies to Docker Hub, Docker Desktop, and Docker Scout authentication. - -## Do you support physical multi-factor authentication (MFA) with YubiKeys? - -You can configure physical multi-factor authentication (MFA) through SSO using your identity provider (IdP). Check with your IdP if they support physical MFA devices like YubiKeys. - -## How are sessions managed and do they expire? - -Docker uses tokens to manage user sessions with different expiration periods: - -- Docker Desktop: Signs you out after 90 days, or 30 days of inactivity -- Docker Hub and Docker Home: Sign you out after 24 hours - -Docker also supports your IdP's default session timeout through SAML attributes. For more information, see [SSO attributes](/manuals/security/provisioning/_index.md#sso-attributes). - -## How does Docker distinguish between employee users and contractor users? - -Organizations use verified domains to distinguish user types. Team members with email domains other than verified domains appear as "Guest" users in the organization. - -## How long are activity logs available? - -Docker activity logs are available for 90 days. You're responsible for exporting logs or setting up drivers to send logs to your internal systems for longer retention. - -## Can I export a list of users with their roles and privileges? - -Yes, use the [Export Members](/manuals/accounts/organization/manage/members.md#export-members-csv-file) feature to export a CSV file containing your organization's users with role and team information. - -## How does Docker Desktop handle authentication information? - -Docker Desktop uses the host operating system's secure key management to store authentication tokens: - -- macOS: [Keychain](https://support.apple.com/guide/security/keychain-data-protection-secb0694df1a/web) -- Windows: [Security and Identity API via Wincred](https://learn.microsoft.com/en-us/windows/win32/api/wincred/) -- Linux: [Pass](https://www.passwordstore.org/). - -## How do I remove users who aren't part of my IdP when using SSO without SCIM? - -If SCIM isn't turned on, you must manually remove users from the organization. SCIM can automate user removal, but only for users added after SCIM is turned on. Users added before SCIM was turned on must be removed manually. - -For more information, see [Manage organization members](/manuals/accounts/organization/manage/members.md). - -## What metadata does Scout collect from container images? - -For information about metadata stored by Docker Scout, see [Data handling](/manuals/scout/deep-dive/data-handling.md). - -## How are Marketplace extensions vetted for security? - -Security vetting for extensions isn't implemented. Extensions aren't covered as part of Docker's Third-Party Risk Management Program. - -## Can I prevent users from pushing images to Docker Hub private repositories? - -No direct setting exists to disable private repositories. However, [Registry Access Management](/manuals/enterprise/security/hardened-desktop/registry-access-management.md) lets administrators control which registries developers can access through Docker Desktop via Docker Home. diff --git a/content/manuals/security/faqs/networking-and-vms.md b/content/manuals/security/faqs/networking-and-vms.md deleted file mode 100644 index 668697d482a5..000000000000 --- a/content/manuals/security/faqs/networking-and-vms.md +++ /dev/null @@ -1,30 +0,0 @@ ---- -title: Network and VM FAQs -linkTitle: Network and VM -description: Frequently asked questions about Docker Desktop networking and virtualization security -keywords: docker desktop networking, virtualization, hyper-v, wsl2, network security, firewall -weight: 30 -tags: [FAQ] -aliases: -- /faq/security/networking-and-vms/ ---- - -## How can I limit container internet access? - -Docker Desktop doesn't have a built-in mechanism for this, but you can use process-level firewalls on the host. Apply rules to the `com.docker.vpnkit` user-space process to control where it can connect (DNS allowlists, packet filters) and which ports/protocols it can use. - -For enterprise environments, consider [Air-gapped containers](/manuals/enterprise/security/hardened-desktop/air-gapped-containers.md) which provide network access controls for containers. - -## Can I apply firewall rules to container network traffic? - -Yes. Docker Desktop uses a user-space process (`com.docker.vpnkit`) for network connectivity, which inherits constraints like firewall rules, VPN settings, and HTTP proxy properties from the user that launched it. - -## Does Docker Desktop for Windows with Hyper-V allow users to create other VMs? - -No. The `DockerDesktopVM` name is hard-coded in the service, so you cannot use Docker Desktop to create or manipulate other virtual machines. - -## How does Docker Desktop achieve network isolation with Hyper-V and WSL 2? - -Docker Desktop uses the same VM processes for both WSL 2 (in the `docker-desktop` distribution) and Hyper-V (in `DockerDesktopVM`). Host/VM communication uses `AF_VSOCK` hypervisor sockets (shared memory) rather than network switches or interfaces. All host networking is performed using standard TCP/IP sockets from the `com.docker.vpnkit.exe` and `com.docker.backend.exe` processes. - -For more information, see [How Docker Desktop networking works under the hood](https://www.docker.com/blog/how-docker-desktop-networking-works-under-the-hood/). From f2b59e12d586f84d609b05cdd5a9932a661e40f5 Mon Sep 17 00:00:00 2001 From: Alexa Date: Mon, 31 Aug 2026 15:15:30 -0500 Subject: [PATCH 13/19] docs: nest Companies under Organizations in Account FAQs Co-authored-by: Cursor --- content/manuals/faqs/accounts.md | 16 +++++----------- 1 file changed, 5 insertions(+), 11 deletions(-) diff --git a/content/manuals/faqs/accounts.md b/content/manuals/faqs/accounts.md index ff5c46e31a5d..840d4ba9d66b 100644 --- a/content/manuals/faqs/accounts.md +++ b/content/manuals/faqs/accounts.md @@ -135,21 +135,21 @@ Yes. Organization owners occupy a seat. Yes. In a scenario where a user belongs to two organizations, they take up one seat in each organization. -## Companies +### Companies -### Some of my organizations don’t have a Docker Business subscription. Can I still use a parent company? +#### Some of my organizations don’t have a Docker Business subscription. Can I still use a parent company? Yes, but you can only add organizations with a Docker Business subscription to a company. For more details, see [Add more organizations](/manuals/accounts/organization/company/manage.md#add-more-organizations). -### What happens if one of my organizations downgrades from Docker Business, but I still need access as a company owner? +#### What happens if one of my organizations downgrades from Docker Business, but I still need access as a company owner? To access and manage a nested organization, it must have a Docker Business subscription. If an organization downgrades from Docker Business, its owner must manage it outside of the company. For more details, see [Add more organizations](/manuals/accounts/organization/company/manage.md#add-more-organizations). -### Do company owners occupy a subscription seat? +#### Do company owners occupy a subscription seat? Company owners don't occupy a seat unless one of the following is true: @@ -164,7 +164,7 @@ owner. To free up that seat, and remove yourself from the organization. You keep full administrative access as a company owner without using a subscription seat. -### What permissions does the company owner have in the associated/nested organizations? +#### What permissions does the company owner have in the associated/nested organizations? Company owners can navigate to the **Organizations** page to view all their nested organizations in a single location. They can also view or edit @@ -173,9 +173,3 @@ Cross-domain Identity Management (SCIM) settings. Changes to company settings impact all users in each organization under the company. For more information, see [Roles and permissions](/manuals/security/roles-and-permissions.md). - -## Next steps - -- [Create a Docker account](/manuals/accounts/individual/create-account.md) -- [Manage a Docker account](/manuals/accounts/individual/manage-account.md) -- [Organization accounts](/manuals/accounts/organization/_index.md) From 4051391c45c6f622cfbd64e79441e16e15a4b14d Mon Sep 17 00:00:00 2001 From: Alexa Date: Mon, 31 Aug 2026 15:16:04 -0500 Subject: [PATCH 14/19] docs: limit Platform FAQ table of contents to H2 headings Co-authored-by: Cursor --- content/manuals/faqs/platform.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/content/manuals/faqs/platform.md b/content/manuals/faqs/platform.md index 847f2ae333cf..cd4e6383099d 100644 --- a/content/manuals/faqs/platform.md +++ b/content/manuals/faqs/platform.md @@ -5,7 +5,7 @@ description: Frequently asked questions about Docker platform security, containe keywords: Docker security, FAQs, authentication, vulnerability reporting, session management, container security, docker desktop isolation, enhanced container isolation, file sharing, docker desktop networking, virtualization, hyper-v, wsl2, network security, firewall weight: 40 tags: [FAQ] -toc_max: 3 +toc_max: 2 aliases: - /faq/security/general/ - /security/faqs/general/ From b7013ceef9fc9278448bc80a83eac345db2d1d64 Mon Sep 17 00:00:00 2001 From: Alexa Date: Mon, 31 Aug 2026 15:23:17 -0500 Subject: [PATCH 15/19] docs: rename Platform nav group to Accounts and admin Match the manuals landing heading, shorten the billing details sidebar label, and fix the MSI Settings Management link after the security path move. Co-authored-by: Cursor --- content/manuals/_index.md | 9 ++++----- content/manuals/accounts/_index.md | 2 +- .../enterprise-deployment/msi-install-and-configure.md | 2 +- content/manuals/faqs/_index.md | 2 +- content/manuals/platform-release-notes.md | 2 +- content/manuals/security/_index.md | 2 +- content/manuals/subscription-billing/_index.md | 2 +- content/manuals/subscription-billing/manage/details.md | 2 +- content/manuals/support/_index.md | 2 +- 9 files changed, 12 insertions(+), 13 deletions(-) diff --git a/content/manuals/_index.md b/content/manuals/_index.md index ad846c8c6bc8..1c3cda8dd285 100644 --- a/content/manuals/_index.md +++ b/content/manuals/_index.md @@ -12,7 +12,7 @@ params: - AI and agents - Application development - Supply chain security - - Platform + - Accounts and admin - Enterprise notoc: true ai-and-agents: @@ -92,7 +92,7 @@ params: icon: lock-closed link: /security/ - title: FAQs - description: Frequently asked questions about Docker accounts, organizations, companies, and security. + description: Frequently asked questions about Docker accounts, organizations, companies, subscriptions, billing, and security. icon: question-mark-circle link: /faqs/ enterprise: @@ -127,10 +127,9 @@ Security guardrails and image analysis for your software supply chain. {{< grid items=supply-chain-security >}} -## Platform +## Accounts and admin -Documentation related to the Docker platform, such as administration and -subscription management. +Manage Docker accounts, administration, subscriptions, billing, and security. {{< grid items=platform >}} diff --git a/content/manuals/accounts/_index.md b/content/manuals/accounts/_index.md index d36e836c6684..c7aa6999d4c4 100644 --- a/content/manuals/accounts/_index.md +++ b/content/manuals/accounts/_index.md @@ -8,7 +8,7 @@ keywords: accounts, admin, Docker ID, organization, company, Docker Home, weight: 10 params: sidebar: - group: Platform + group: Accounts and admin grid: - title: Docker individual accounts description: Create and manage your Docker ID, email, and sign-in methods. diff --git a/content/manuals/enterprise/enterprise-deployment/msi-install-and-configure.md b/content/manuals/enterprise/enterprise-deployment/msi-install-and-configure.md index a6d404629050..68fe0a96f0c6 100644 --- a/content/manuals/enterprise/enterprise-deployment/msi-install-and-configure.md +++ b/content/manuals/enterprise/enterprise-deployment/msi-install-and-configure.md @@ -41,7 +41,7 @@ If your administrator account is different from your user account, you must add > [!NOTE] > > When installing Docker Desktop with the MSI, in-app updates are automatically disabled by default. This ensures organizations can maintain version consistency and prevent unapproved updates. -> Starting with Docker Desktop version 4.60 and later, in-app updates from an MSI installation can be enabled by changing the `disableUpdate` setting to `false` through [Settings Management](../hardened-desktop/settings-management/). +> Starting with Docker Desktop version 4.60 and later, in-app updates from an MSI installation can be enabled by changing the `disableUpdate` setting to `false` through [Settings Management](../security/hardened-desktop/settings-management/). > > Docker Desktop notifies you when an update is available. To update Docker Desktop, download the latest installer from Docker Home. Navigate to the **Deploy** page. > diff --git a/content/manuals/faqs/_index.md b/content/manuals/faqs/_index.md index bc6cbe5d4fa6..74131629f730 100644 --- a/content/manuals/faqs/_index.md +++ b/content/manuals/faqs/_index.md @@ -6,7 +6,7 @@ keywords: FAQ, FAQs, accounts, Docker ID, Docker Home, subscription FAQs, billin weight: 45 params: sidebar: - group: Platform + group: Accounts and admin aliases: - /platform/security/faqs/ - /faq/security/ diff --git a/content/manuals/platform-release-notes.md b/content/manuals/platform-release-notes.md index 5c649dcadcad..4ba130ee1e50 100644 --- a/content/manuals/platform-release-notes.md +++ b/content/manuals/platform-release-notes.md @@ -6,7 +6,7 @@ keywords: Docker Home, billing, subscription, security, admin, releases, what's weight: 60 params: sidebar: - group: Platform + group: Accounts and admin tags: [Release notes, admin] --- diff --git a/content/manuals/security/_index.md b/content/manuals/security/_index.md index cf7436317ce9..9e1355ad11fa 100644 --- a/content/manuals/security/_index.md +++ b/content/manuals/security/_index.md @@ -9,7 +9,7 @@ aliases: - /platform/security/ params: sidebar: - group: Platform + group: Accounts and admin grid_developers: - title: Set up two-factor authentication description: Add an extra layer of authentication to your Docker account. diff --git a/content/manuals/subscription-billing/_index.md b/content/manuals/subscription-billing/_index.md index 7ac27dd07ce9..9df97583d3f5 100644 --- a/content/manuals/subscription-billing/_index.md +++ b/content/manuals/subscription-billing/_index.md @@ -6,7 +6,7 @@ keywords: subscription, billing, docker plans, payments, invoices, pricing weight: 20 params: sidebar: - group: Platform + group: Accounts and admin aliases: - /subscription/ - /billing/ diff --git a/content/manuals/subscription-billing/manage/details.md b/content/manuals/subscription-billing/manage/details.md index d3f060b215ec..63bfbaf5b832 100644 --- a/content/manuals/subscription-billing/manage/details.md +++ b/content/manuals/subscription-billing/manage/details.md @@ -1,6 +1,6 @@ --- title: Update your billing details -linkTitle: Update details +linkTitle: Billing details weight: 40 description: Learn how to update billing details, like contact information, addresses, and notification email for Docker subscriptions. keywords: payments, billing, subscription, invoices, update billing email, change billing address, Docker billing account diff --git a/content/manuals/support/_index.md b/content/manuals/support/_index.md index 6364b9ba9eb2..61e362454496 100644 --- a/content/manuals/support/_index.md +++ b/content/manuals/support/_index.md @@ -6,7 +6,7 @@ keywords: support, help, docker desktop, subscriptions, community, troubleshooti weight: 50 params: sidebar: - group: Platform + group: Accounts and admin --- Docker offers multiple support channels depending on your subscription level and needs. From c45dffbdeb2b68a3cd572ca943f4c46e2c90ad26 Mon Sep 17 00:00:00 2001 From: Alexa Date: Mon, 31 Aug 2026 15:31:41 -0500 Subject: [PATCH 16/19] docs: fix Vale heading punctuation and duplicate SCIM alias FAQ headings cannot contain a period, and two SCIM pages both aliased /platform/security/provisioning/scim/, which made Hugo panic on duplicate paths. Co-authored-by: Cursor --- content/manuals/faqs/accounts.md | 2 +- content/manuals/faqs/security.md | 2 +- content/manuals/security/provisioning/scim/provision-scim.md | 1 - 3 files changed, 2 insertions(+), 3 deletions(-) diff --git a/content/manuals/faqs/accounts.md b/content/manuals/faqs/accounts.md index 840d4ba9d66b..df37bda90cc9 100644 --- a/content/manuals/faqs/accounts.md +++ b/content/manuals/faqs/accounts.md @@ -137,7 +137,7 @@ seat in each organization. ### Companies -#### Some of my organizations don’t have a Docker Business subscription. Can I still use a parent company? +#### Can I use a parent company if some of my organizations don’t have a Docker Business subscription? Yes, but you can only add organizations with a Docker Business subscription to a company. For more details, see [Add more organizations](/manuals/accounts/organization/company/manage.md#add-more-organizations). diff --git a/content/manuals/faqs/security.md b/content/manuals/faqs/security.md index 8e966d2e563b..d4a079dba41c 100644 --- a/content/manuals/faqs/security.md +++ b/content/manuals/faqs/security.md @@ -169,7 +169,7 @@ Before enforcing SSO, you must [create personal access tokens](/manuals/security Yes, you can turn on SSO without enforcement. Users can choose between Docker ID (standard email and password) or domain-verified email address (SSO) at the sign-in screen. -### SSO is enforced, but a user can sign in using a username and password. Why is this happening? +### Why can a user sign in with a username and password when SSO is enforced? Guest users who aren't part of your registered domain but have been invited to your organization don't sign in through your SSO identity provider. SSO enforcement only applies to users who belong to your verified domain. diff --git a/content/manuals/security/provisioning/scim/provision-scim.md b/content/manuals/security/provisioning/scim/provision-scim.md index 9a6220064640..e45fbdff0d35 100644 --- a/content/manuals/security/provisioning/scim/provision-scim.md +++ b/content/manuals/security/provisioning/scim/provision-scim.md @@ -4,7 +4,6 @@ linkTitle: Setup description: Learn how System for Cross-domain Identity Management works and how to set it up. weight: 10 aliases: - - /platform/security/provisioning/scim/ - /platform/security/provisioning/scim/provision-scim/ --- From 9ce82d357ed8f5b5788516eec14b5fb21edabd42 Mon Sep 17 00:00:00 2001 From: Alexa Date: Mon, 31 Aug 2026 15:38:48 -0500 Subject: [PATCH 17/19] docs: point DHI plans link at Manage plans upgrade heading The relative manage.md fragment did not resolve after billing flatten, so htmltest failed on a missing #upgrade-plans hash. Co-authored-by: Cursor --- content/manuals/subscription-billing/plans/dhi.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/content/manuals/subscription-billing/plans/dhi.md b/content/manuals/subscription-billing/plans/dhi.md index 2538a3f8b951..26c2bbf4d8a9 100644 --- a/content/manuals/subscription-billing/plans/dhi.md +++ b/content/manuals/subscription-billing/plans/dhi.md @@ -35,7 +35,7 @@ For details on setting up and managing repositories, see [Get started with DHI S ## Billing cycle -DHI Select is an annual plan billed per repository from the date your plan starts. Repositories added mid-cycle are prorated for the remainder of the billing period. You can add more repositories to your DHI Select plan by going to **Active plans** in the billing portal. For steps, see [Manage plans](../manage.md#upgrade-plans). +DHI Select is an annual plan billed per repository from the date your plan starts. Repositories added mid-cycle are prorated for the remainder of the billing period. You can add more repositories to your DHI Select plan by going to **Active plans** in the billing portal. For steps, see [Manage plans](/manuals/subscription-billing/manage/plans.md#upgrade-plans). ## Disable auto-renewal From 01d2ed03386e8c0e8850401c0dbc8568faaf7732 Mon Sep 17 00:00:00 2001 From: Alexa Date: Wed, 2 Sep 2026 07:36:53 -0500 Subject: [PATCH 18/19] docs: point Scout registry OAT link at the new access-tokens path htmltest failed because /enterprise/security/access-tokens/ is now an alias without the #create-an-organization-access-token heading. Co-authored-by: Cursor --- content/manuals/scout/integrations/registry.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/content/manuals/scout/integrations/registry.md b/content/manuals/scout/integrations/registry.md index 7c09f767e9cd..372ef3cad1e7 100644 --- a/content/manuals/scout/integrations/registry.md +++ b/content/manuals/scout/integrations/registry.md @@ -82,7 +82,7 @@ see [Data handling](/manuals/scout/deep-dive/data-handling.md). 4. Set up your Scout credentials. 1. Generate an organization access token. For more details, see - [Create an organization access token](/enterprise/security/access-tokens/#create-an-organization-access-token). + [Create an organization access token](/manuals/security/access-tokens/organization-access-tokens.md#create-an-organization-access-token). 2. Sign in to Docker using the organization access token. ```console From 78f4a0cab45a97d55a3b08c97beda45a23051511 Mon Sep 17 00:00:00 2001 From: Alexa Kristensen <81787716+akristen@users.noreply.github.com> Date: Wed, 2 Sep 2026 10:49:06 -0500 Subject: [PATCH 19/19] docs: fill Accounts and admin section landings * docs: fill empty Authentication, Access tokens, and Manage billing landings These section indexes used render: never, so the published URLs had no page. They now render as chooser landings with grids of child topics. Co-authored-by: Cursor * docs: move billing portal walkthrough onto Manage billing The Subscription and billing parent was carrying the portal tutorial. That content now lives on Manage billing, the parent is a plans chooser, and #credits/#usage links point at the new page. Agentic Platform stays off the parent table and grids. Co-authored-by: Cursor * docs: make Accounts a chooser and complete org and manage grids Account-type comparison belongs on the Accounts landing. Organization and Manage grids were missing Activity logs, Insights, Teams, Seats, and Licenses even though those pages already exist. Co-authored-by: Cursor * docs: expand Plans and FAQs landings and complete the Manuals admin grid Plans was repeating Manage plans instead of helping readers choose. FAQs needed a short map of each collection. The Manuals Accounts and admin grid was missing Support and Release notes from the sidebar group. Co-authored-by: Cursor * docs: drop duplicate account, token, and role recaps from child indexes Account types, OIDC versus OAT, and core versus custom roles each had a second copy after the parent landings took that job. Company keeps owner and seat rules and links up to the hierarchy diagram. Co-authored-by: Cursor * docs: split the Security landing into administrator and developer grids The page was still titled Security for developers and omitted SSO, provisioning, roles, OATs, and OIDC even though those pages already live in this section. Co-authored-by: Cursor * docs: add a conceptual overview to the Security landing The page was still framed for developers and split into three grids. Individual and organization sections plus one child grid match the rest of Accounts and admin. Co-authored-by: Cursor * docs: add individual summary bars and point Security H2s at product pages The banner only appeared on enterprise admin docs, and the landing linked choosers instead of 2FA, PAT, SSO, OIDC, and OATs. Co-authored-by: Cursor * docs: order organization Security setup as sign-in, join, then access SSO and provisioning come before automation credentials, and roles apply after members join. Co-authored-by: Cursor * docs: promote Company to a top-level Accounts section Company lived under Organization, so the Accounts landing could not treat it as a sibling account type. A top-level section matches how owners switch between org and company. Co-authored-by: Cursor --------- Co-authored-by: Cursor --- COMPONENTS.md | 2 +- content/guides/admin-set-up.md | 2 +- content/manuals/_index.md | 8 ++ content/manuals/accounts/_index.md | 35 ++++- .../{organization => }/company/_index.md | 28 ++-- .../{organization => }/company/manage.md | 2 +- .../{organization => }/company/new-company.md | 0 content/manuals/accounts/individual/_index.md | 8 +- .../accounts/individual/create-account.md | 2 +- .../manuals/accounts/organization/_index.md | 72 +++------- .../accounts/organization/manage/_index.md | 12 ++ .../organization/manage/general-settings.md | 2 +- content/manuals/faqs/_index.md | 2 +- content/manuals/faqs/accounts.md | 4 +- content/manuals/security/_index.md | 107 +++++++------- .../manuals/security/access-tokens/_index.md | 30 +++- .../access-tokens/personal-access-tokens.md | 2 + .../security/authentication/2fa/_index.md | 2 + .../authentication/2fa/recover-hub-account.md | 2 + .../manuals/security/authentication/_index.md | 41 +++++- .../authentication/oidc-connections/_index.md | 15 +- .../roles-and-permissions/core-roles.md | 4 +- .../custom-roles/_index.md | 16 +-- .../manuals/subscription-billing/_index.md | 130 +++++------------- .../subscription-billing/manage/_index.md | 77 ++++++++++- .../subscription-billing/manage/plans.md | 2 +- .../subscription-billing/plans/_index.md | 17 ++- .../plans/docker-agentic-platform.md | 4 +- data/summary.yaml | 7 + layouts/_shortcodes/summary-bar.html | 13 +- 30 files changed, 379 insertions(+), 269 deletions(-) rename content/manuals/accounts/{organization => }/company/_index.md (68%) rename content/manuals/accounts/{organization => }/company/manage.md (98%) rename content/manuals/accounts/{organization => }/company/new-company.md (100%) diff --git a/COMPONENTS.md b/COMPONENTS.md index 69eeef375181..8a35a66a5918 100644 --- a/COMPONENTS.md +++ b/COMPONENTS.md @@ -296,7 +296,7 @@ features: | subscription | Subscription tier required | All, Personal, Pro, Team, Business | | availability | Product development stage | Experimental, Beta, Early Access, GA, Retired | | requires | Minimum version requirement | String describing version (link to release notes) | -| for | Indicates administrator-only features | Administrators | +| for | Audience for the feature | Administrators, Individuals | ### Buttons diff --git a/content/guides/admin-set-up.md b/content/guides/admin-set-up.md index d1676f550dc7..99f7e6db7b0a 100644 --- a/content/guides/admin-set-up.md +++ b/content/guides/admin-set-up.md @@ -186,7 +186,7 @@ settings, along with your chosen method for [enforcing sign-in](/manuals/enterpr If you have more than one organization, consider either [consolidating them into one organization](/manuals/accounts/organization/setup/orgs.md) or creating a -[Docker company](/manuals/accounts/organization/company/_index.md) to manage multiple +[Docker company](/manuals/accounts/company/_index.md) to manage multiple organizations. ### Begin setup diff --git a/content/manuals/_index.md b/content/manuals/_index.md index 1c3cda8dd285..51b69b2d9239 100644 --- a/content/manuals/_index.md +++ b/content/manuals/_index.md @@ -95,6 +95,14 @@ params: description: Frequently asked questions about Docker accounts, organizations, companies, subscriptions, billing, and security. icon: question-mark-circle link: /faqs/ + - title: Support + description: Support options for paid subscriptions and community resources. + icon: chat-bubble-left + link: /support/ + - title: Release notes + description: Features, bug fixes, and breaking changes for Docker Home, billing, security, and subscriptions. + icon: document-plus + link: /platform-release-notes/ enterprise: - title: Deploy Docker Desktop description: Deploy Docker Desktop at scale within your company diff --git a/content/manuals/accounts/_index.md b/content/manuals/accounts/_index.md index c7aa6999d4c4..0c8bebc8369b 100644 --- a/content/manuals/accounts/_index.md +++ b/content/manuals/accounts/_index.md @@ -15,14 +15,41 @@ grid: icon: user-circle link: /accounts/individual/ - title: Organization accounts - description: Manage organizations, companies, members, and teams. + description: Manage members, teams, and organization settings. icon: building-storefront link: /accounts/organization/ + - title: Company accounts + description: Group multiple organizations for centralized administration. + icon: building-office-2 + link: /accounts/company/ + - title: Security + description: Authentication, tokens, and roles for accounts and organizations. + icon: lock-closed + link: /security/ + - title: Subscription and billing + description: Plans, payments, and invoices for your account or organization. + icon: credit-card + link: /subscription-billing/ + - title: FAQs + description: Common questions about accounts, billing, and security. + icon: question-mark-circle + link: /faqs/ --- -A Docker account identifies you and lets you access Docker products. Use an -individual account for your Docker ID and personal settings. Use an -organization account to manage members, teams, and company-wide settings. +A Docker account identifies you and lets you access Docker products. You +manage it in [Docker Home](https://app.docker.com/). Docker has two +primary account types: individual and organization. A company groups +multiple organizations. + +| Account type | What it is | Who it's for | +| --- | --- | --- | +| Individual | A Docker ID with personal settings, Hub repositories, and sign-in methods | A person | +| Organization | A shared workspace for members, teams, and repositories | Teams on Docker Team or Business | +| Company | Multiple organizations under centralized administration | Docker Business subscribers | + +You always sign in with your individual account, then work in the +organizations you own or belong to. Those organizations sit under a +company when you administer more than one. ## Next steps diff --git a/content/manuals/accounts/organization/company/_index.md b/content/manuals/accounts/company/_index.md similarity index 68% rename from content/manuals/accounts/organization/company/_index.md rename to content/manuals/accounts/company/_index.md index dd1349de3d08..e55aaf076e05 100644 --- a/content/manuals/accounts/organization/company/_index.md +++ b/content/manuals/accounts/company/_index.md @@ -1,18 +1,18 @@ --- title: Company overview -linkTitle: Companies -weight: 30 +linkTitle: Company +weight: 20 description: Learn how to manage multiple organizations using companies, including managing users, owners, and security. keywords: company, multiple organizations, manage companies, Docker Home, Docker Business settings grid: - title: Create a company description: Get started by learning how to create a company. icon: building-office-2 - link: /accounts/organization/company/new-company/ + link: /accounts/company/new-company/ - title: Manage your company description: Add organizations, manage company owners, and invite members. icon: building-storefront - link: /accounts/organization/company/manage/ + link: /accounts/company/manage/ - title: Configure SSO and SCIM description: Set up single sign-on and SCIM provisioning for your company. icon: key @@ -39,13 +39,21 @@ and manage it through Docker Home. ## Company structure -The following diagram shows how a company relates to its associated -organizations. +A company sits at the top of the hierarchy and groups multiple Docker +organizations for centralized configuration. Companies are only available +for Docker Business subscribers. -![Diagram showing how companies relate to Docker organizations](/accounts/organization/images/docker-admin-structure.webp) +![Diagram showing Docker’s administration hierarchy with Company at the top, followed by Organizations, Teams, and Members](../organization/images/docker-admin-structure.webp) -For the full administration hierarchy, see -[Company and organization hierarchy](/manuals/accounts/organization/_index.md#company-and-organization-hierarchy). +An organization sits below the company. You group teams and members there +and assign access to repositories. Every Docker Team and Business +subscriber has at least one organization. + +For organization structure, including teams and members, see +[Organization accounts](/manuals/accounts/organization/_index.md). + +[Upgrading to a Docker Business plan](https://www.docker.com/pricing?ref=Docs&refAction=DocsAdmin) +grants you the company owner role so you can manage multiple organizations. ## Company roles @@ -63,7 +71,7 @@ organization owners. automatically adds them as an organization member. To add or remove company owners, see -[Manage your company](/manuals/accounts/organization/company/manage.md#company-owners). +[Manage your company](/manuals/accounts/company/manage.md#company-owners). ## Next steps diff --git a/content/manuals/accounts/organization/company/manage.md b/content/manuals/accounts/company/manage.md similarity index 98% rename from content/manuals/accounts/organization/company/manage.md rename to content/manuals/accounts/company/manage.md index d7a1d3898eb4..a7b466825003 100644 --- a/content/manuals/accounts/organization/company/manage.md +++ b/content/manuals/accounts/company/manage.md @@ -47,7 +47,7 @@ longer manage it through the company, and its owner must manage it separately. A company can have multiple owners who manage the company and all of its organizations. For details about the company owner role and how it affects -seats, see [Company roles](/manuals/accounts/organization/company/_index.md#company-roles). +seats, see [Company roles](/manuals/accounts/company/_index.md#company-roles). ### Add a company owner diff --git a/content/manuals/accounts/organization/company/new-company.md b/content/manuals/accounts/company/new-company.md similarity index 100% rename from content/manuals/accounts/organization/company/new-company.md rename to content/manuals/accounts/company/new-company.md diff --git a/content/manuals/accounts/individual/_index.md b/content/manuals/accounts/individual/_index.md index 68295c2a0cfd..ad0cf10392c1 100644 --- a/content/manuals/accounts/individual/_index.md +++ b/content/manuals/accounts/individual/_index.md @@ -9,7 +9,7 @@ keywords: accounts, docker ID, username, email, Google, GitHub, sign-in, organization account, account types, Docker Hub, SSO, deactivate account weight: 10 grid: - - title: Create an account + - title: Set up your account description: Get started with Docker and create an account. icon: finger-print link: /accounts/individual/create-account/ @@ -38,9 +38,9 @@ grid: A Docker account is how Docker identifies you. Use it to access products like Docker Hub and Docker Desktop, manage settings, and join organizations. -Docker has two primary account types: individual and organization. You create -and administer organizations with your individual account. For organization -accounts, including companies, see +For how individual, organization, and company accounts compare, see +[Accounts](/manuals/accounts/_index.md). For organization accounts, including +companies, see [Organization accounts](/manuals/accounts/organization/_index.md). ## Docker ID, email, and sign-in diff --git a/content/manuals/accounts/individual/create-account.md b/content/manuals/accounts/individual/create-account.md index 6147e8d9d162..3db92002274e 100644 --- a/content/manuals/accounts/individual/create-account.md +++ b/content/manuals/accounts/individual/create-account.md @@ -1,6 +1,6 @@ --- title: Create a Docker account -linkTitle: Create +linkTitle: Setup weight: 10 description: Create a Docker ID with email, Google, or GitHub, then verify your account diff --git a/content/manuals/accounts/organization/_index.md b/content/manuals/accounts/organization/_index.md index 39b501a7ae8b..f270382e28ab 100644 --- a/content/manuals/accounts/organization/_index.md +++ b/content/manuals/accounts/organization/_index.md @@ -16,10 +16,14 @@ grid: description: Manage members, teams, seats, and product access. icon: user-plus link: /accounts/organization/manage/ - - title: Company administration - description: Explore how to manage a company. - icon: building-office-2 - link: /accounts/organization/company/ + - title: Activity logs + description: Review member activity across your organization and repositories. + icon: clipboard-document-list + link: /accounts/organization/activity-logs/ + - title: Insights + description: See how people in your organization use Docker. + icon: chart-bar + link: /accounts/organization/insights/ - title: Security description: Explore security features for administrators. icon: shield-check @@ -48,19 +52,9 @@ As an organization or company owner, you can: - Set company-wide policies, including SCIM provisioning and security enforcement -## Individual and organization accounts - -Docker has two primary account types: - -- Individual accounts that are identified by a Docker ID. -- Organization accounts that are shared workspaces for teams and - repositories. - -Every organization is created and administered by one or more individual -accounts. You always sign in with your individual account, then work in the -organizations you own or belong to. Organization owners and members are -individual accounts that hold a role in that organization. For individual -accounts, see [Docker individual accounts](/manuals/accounts/individual/_index.md). +For how individual, organization, and company accounts compare, see +[Accounts](/manuals/accounts/_index.md). For individual accounts, see +[Docker individual accounts](/manuals/accounts/individual/_index.md). ## Organization structure @@ -70,40 +64,7 @@ The following diagram shows how organizations relate to teams and members. organization](./images/org-structure.webp) An organization includes owners, members, and optional teams. Organization -owners have full administrator access to manage members, roles, and teams. A -team is an optional grouping of members that share the same repository -permissions. - -For details about each role and its permissions, see -[Roles and -permissions](/manuals/security/roles-and-permissions/_index.md). - -## Company and organization hierarchy - -To provide centralized administration, Docker organizes companies and -organizations into the following hierarchy and roles. - -![Diagram showing Docker’s administration hierarchy with Company at the top, followed by Organizations, Teams, and Members](./images/docker-admin-structure.webp) - -### Company - -A company groups multiple Docker organizations for centralized configuration. -Companies are only available for Docker Business subscribers. For company -structure, owners, and seats, see -[Company overview](/manuals/accounts/organization/company/_index.md). - -### Organization - -An organization sits below the company and is where you group teams and -members and assign access to repositories. Every Docker Team and Business -subscriber has at least one organization. - -Organization owners hold the organization owner administrator role and manage -organization settings, users, and access controls. Each owner occupies a -[seat](/manuals/faqs/accounts.md#what-is-the-difference-between-user-invitee-seat-and-member). - -[Upgrading to a Docker Business plan](https://www.docker.com/pricing?ref=Docs&refAction=DocsAdmin) -grants you the company owner role so you can manage multiple organizations. +owners have full administrator access to manage members, roles, and teams. ### Team @@ -116,8 +77,15 @@ or functions. A member is any Docker user added to an organization. Organization and company owners can assign roles to members to define their level of access. +For details about each role and its permissions, see +[Roles and +permissions](/manuals/security/roles-and-permissions/_index.md). + +For how companies relate to organizations, see +[Company structure](/manuals/accounts/company/_index.md#company-structure). + ## Next steps -Learn how to manage companies and organizations in the following sections. +Learn how to manage organizations in the following sections. {{< grid >}} diff --git a/content/manuals/accounts/organization/manage/_index.md b/content/manuals/accounts/organization/manage/_index.md index 7427a0300a1f..8d4089572255 100644 --- a/content/manuals/accounts/organization/manage/_index.md +++ b/content/manuals/accounts/organization/manage/_index.md @@ -9,6 +9,18 @@ grid: description: Invite, manage, and assign roles to your organization members. icon: user-plus link: /accounts/organization/manage/members/ + - title: Teams + description: Create teams and manage repository access for groups of members. + icon: user-group + link: /accounts/organization/manage/manage-a-team/ + - title: Seats + description: Add or remove seats for Docker Team and Business subscriptions. + icon: user-circle + link: /accounts/organization/manage/manage-seats/ + - title: Licenses + description: Assign and revoke product licenses for organization members. + icon: key + link: /accounts/organization/manage/manage-licenses/ - title: Product access and usage description: Manage access and view usage for Docker products across your organization. icon: squares-2x2 diff --git a/content/manuals/accounts/organization/manage/general-settings.md b/content/manuals/accounts/organization/manage/general-settings.md index 0ffc3d317e65..f3560c801512 100644 --- a/content/manuals/accounts/organization/manage/general-settings.md +++ b/content/manuals/accounts/organization/manage/general-settings.md @@ -38,4 +38,4 @@ After configuring your organization information, you can: - [Configure single sign-on (SSO)](/manuals/security/authentication/single-sign-on/connect.md) - [Set up SCIM provisioning](/manuals/security/provisioning/scim/_index.md) - [Manage domains](/manuals/security/provisioning/domain-management.md) -- [Create a company](/manuals/accounts/organization/company/new-company.md) +- [Create a company](/manuals/accounts/company/new-company.md) diff --git a/content/manuals/faqs/_index.md b/content/manuals/faqs/_index.md index 74131629f730..79617019d3a5 100644 --- a/content/manuals/faqs/_index.md +++ b/content/manuals/faqs/_index.md @@ -30,7 +30,7 @@ grid: --- Answers to common questions about Docker accounts, organizations, companies, -subscriptions, billing, security, authentication, and related topics. +subscriptions, billing, and security. ## Next steps diff --git a/content/manuals/faqs/accounts.md b/content/manuals/faqs/accounts.md index df37bda90cc9..c6147b53b617 100644 --- a/content/manuals/faqs/accounts.md +++ b/content/manuals/faqs/accounts.md @@ -140,14 +140,14 @@ seat in each organization. #### Can I use a parent company if some of my organizations don’t have a Docker Business subscription? Yes, but you can only add organizations with a Docker Business subscription -to a company. For more details, see [Add more organizations](/manuals/accounts/organization/company/manage.md#add-more-organizations). +to a company. For more details, see [Add more organizations](/manuals/accounts/company/manage.md#add-more-organizations). #### What happens if one of my organizations downgrades from Docker Business, but I still need access as a company owner? To access and manage a nested organization, it must have a Docker Business subscription. If an organization downgrades from Docker Business, its owner must manage it outside of the company. For more details, see -[Add more organizations](/manuals/accounts/organization/company/manage.md#add-more-organizations). +[Add more organizations](/manuals/accounts/company/manage.md#add-more-organizations). #### Do company owners occupy a subscription seat? diff --git a/content/manuals/security/_index.md b/content/manuals/security/_index.md index 9e1355ad11fa..1723f70a97f5 100644 --- a/content/manuals/security/_index.md +++ b/content/manuals/security/_index.md @@ -1,8 +1,11 @@ --- -title: Security for developers +title: Security linkTitle: Security -description: Learn about developer-level security features like 2FA and access tokens -keywords: docker, docker hub, docker desktop, security, developer security, 2FA, access tokens +description: > + Secure Docker accounts, manage access, and control membership for + individuals and organizations in Docker Home. +keywords: docker, docker hub, security, 2FA, access tokens, SSO, OIDC, + provisioning, roles, Docker Home weight: 40 aliases: - /security/for-developers/ @@ -10,60 +13,60 @@ aliases: params: sidebar: group: Accounts and admin -grid_developers: -- title: Set up two-factor authentication - description: Add an extra layer of authentication to your Docker account. - link: /security/authentication/2fa/ - icon: device-phone-mobile -- title: Manage access tokens - description: Create personal access tokens as an alternative to your password. - icon: lock-closed - link: /security/access-tokens/personal-access-tokens/ -- title: Static vulnerability scanning - description: Automatically run a point-in-time scan on your Docker images for vulnerabilities. - icon: magnifying-glass - link: /docker-hub/repos/manage/vulnerability-scanning/ -- title: Docker Engine security - description: Understand how to keep Docker Engine secure. - icon: shield-check - link: /engine/security/ -- title: Secrets in Docker Compose - description: Learn how to use secrets in Docker Compose. - icon: shield-exclamation - link: /compose/how-tos/use-secrets/ -grid_resources: -- title: Security FAQs - description: Explore common security FAQs. - icon: question-mark-circle - link: /faqs/platform/ -- title: Security best practices - description: Understand the steps you can take to improve the security of your container. - icon: squares-2x2 - link: /develop/security-best-practices/ -- title: Suppress CVEs with VEX - description: Learn how to suppress non-applicable or fixed vulnerabilities found in your images. - icon: chart-bar - link: /scout/guides/vex/ -- title: Docker Hardened Images - description: Learn how to use Docker Hardened Images to enhance your software supply security. - icon: lock-closed - link: /dhi/ +grid: + - title: Authentication + description: Two-factor authentication, single sign-on, and OIDC connections. + icon: key + link: /security/authentication/ + - title: Access tokens + description: Personal and organization access tokens for the Docker CLI and automation. + icon: lock-closed + link: /security/access-tokens/ + - title: Provisioning + description: Add users with SCIM, JIT, auto-provisioning, and domain management. + icon: arrow-path + link: /security/provisioning/ + - title: Roles and permissions + description: Assign core or custom roles to control access in your organization. + icon: shield-check + link: /security/roles-and-permissions/ --- -Docker helps you protect your local environments, infrastructure, and networks -with its developer-level security features. +Security helps individual users and organization owners secure their +accounts, manage access, and control membership. You configure these +settings in [Docker Home](https://app.docker.com/). -Use tools like two-factor authentication (2FA), personal access tokens, and -Docker Scout to manage access and detect vulnerabilities early in your workflow. -You can also integrate secrets securely into your development stack using Docker Compose, -or enhance your software supply security with Docker Hardened Images. +## Individual accounts -Explore the following sections to learn more. +You sign in with your individual account. -## For developers +- [Two-factor authentication](/manuals/security/authentication/2fa/_index.md) +(2FA) adds a time-based one-time password (TOTP) from an authenticator +app to your password. +- A [personal access token](/manuals/security/access-tokens/personal-access-tokens.md) +(PAT) authenticates the Docker CLI and tools without your password, and +is required for CLI sign-in when 2FA is on or single sign-on (SSO) is +enforced. -{{< grid items="grid_developers" >}} +## Organization accounts -## More resources +Organization and company owners set up how members sign in, add them to +the organization, configure automation, and control what members can do. -{{< grid items="grid_resources" >}} +- [Single sign-on](/manuals/security/authentication/single-sign-on/_index.md) +(SSO) federates sign-in through your identity provider, which can cover +one organization or every organization in a company. +- [Provisioning](/manuals/security/provisioning/_index.md) adds users with +System for Cross-domain Identity Management (SCIM), Just-in-Time (JIT) +provisioning, auto-provisioning, or domain matching. +- An [organization access token](/manuals/security/access-tokens/organization-access-tokens.md) +(OAT) stays with the organization when membership changes. +- [OIDC connections](/manuals/security/authentication/oidc-connections/_index.md) +use OpenID Connect to authenticate GitHub Actions with short-lived +tokens, as an alternative to a long-lived OAT. +- [Roles and permissions](/manuals/security/roles-and-permissions/_index.md) +control what members can do after they join. + +## Next steps + +{{< grid >}} diff --git a/content/manuals/security/access-tokens/_index.md b/content/manuals/security/access-tokens/_index.md index daa986403e80..eb933ede9584 100644 --- a/content/manuals/security/access-tokens/_index.md +++ b/content/manuals/security/access-tokens/_index.md @@ -1,6 +1,4 @@ --- -build: - render: never title: Access tokens linkTitle: Access tokens description: Create and manage personal and organization access tokens for Docker Hub authentication. @@ -8,4 +6,32 @@ keywords: access tokens, personal access tokens, organization access tokens, PAT weight: 10 aliases: - /platform/security/access-tokens/ +grid: + - title: Personal access tokens + description: Authenticate the Docker CLI and tools with a token tied to your account. + icon: lock-closed + link: /security/access-tokens/personal-access-tokens/ + - title: Organization access tokens + description: Grant org-owned Hub access to CI/CD and other automation. + icon: building-office-2 + link: /security/access-tokens/organization-access-tokens/ --- + +Access tokens let you authenticate to Docker Hub without using your password. +Use a token for the Docker CLI, automation, and any account that has +two-factor authentication (2FA) or enforced single sign-on (SSO), because +password sign-in to the CLI is not supported in those cases. + +## Choose a token type + +| Token | Ownership | Use when | Limitations | +| --- | --- | --- | --- | +| Personal access token (PAT) | Tied to an individual Docker account | CLI access, local tools, and automation that should run as you. Required for CLI sign-in when 2FA is on or SSO is enforced | Access ends if the account leaves the organization or the token is revoked | +| Organization access token (OAT) | Owned by the organization. Any organization owner can manage it | CI/CD and other automation that must keep working when membership changes | Incompatible with Docker Desktop and Image Access Management | + +For GitHub Actions, [OIDC connections](/manuals/security/authentication/oidc-connections/_index.md) +are an alternative to storing a long-lived organization access token. + +## Next steps + +{{< grid >}} diff --git a/content/manuals/security/access-tokens/personal-access-tokens.md b/content/manuals/security/access-tokens/personal-access-tokens.md index fe185b6f434a..76b8a5d7d7aa 100644 --- a/content/manuals/security/access-tokens/personal-access-tokens.md +++ b/content/manuals/security/access-tokens/personal-access-tokens.md @@ -12,6 +12,8 @@ aliases: - /platform/security/access-tokens/personal-access-tokens/ --- +{{< summary-bar feature_name="PATs" >}} + Personal access tokens (PATs) provide a secure alternative to passwords for Docker CLI authentication. Use PATs to authenticate automated systems, CI/CD pipelines, and development tools without exposing your Docker Hub password. ## Key benefits diff --git a/content/manuals/security/authentication/2fa/_index.md b/content/manuals/security/authentication/2fa/_index.md index 5dd4af329acb..842e9dd8290a 100644 --- a/content/manuals/security/authentication/2fa/_index.md +++ b/content/manuals/security/authentication/2fa/_index.md @@ -13,6 +13,8 @@ aliases: - /platform/security/authentication/2fa/ --- +{{< summary-bar feature_name="2FA" >}} + Two-factor authentication (2FA) adds an essential security layer to your Docker account by requiring a unique security code in addition to your password when signing in. This prevents unauthorized access even if your password is compromised. When you turn on two-factor authentication, Docker provides a unique recovery code specific to your account. Store this code securely as it lets you recover your account if you lose access to your authenticator app. diff --git a/content/manuals/security/authentication/2fa/recover-hub-account.md b/content/manuals/security/authentication/2fa/recover-hub-account.md index d549a2b4214d..9bcc06f9cfd9 100644 --- a/content/manuals/security/authentication/2fa/recover-hub-account.md +++ b/content/manuals/security/authentication/2fa/recover-hub-account.md @@ -10,6 +10,8 @@ aliases: weight: 20 --- +{{< summary-bar feature_name="2FA" >}} + This page explains how to recover your Docker account and manage recovery codes for two-factor authentication. ## Generate a new recovery code diff --git a/content/manuals/security/authentication/_index.md b/content/manuals/security/authentication/_index.md index f9fdf00c4217..8e8332286152 100644 --- a/content/manuals/security/authentication/_index.md +++ b/content/manuals/security/authentication/_index.md @@ -1,6 +1,4 @@ --- -build: - render: never title: Authentication linkTitle: Authentication description: Configure single sign-on, OIDC connections, and two-factor authentication. @@ -8,4 +6,43 @@ keywords: authentication, SSO, OIDC, two-factor authentication, 2FA, Docker secu weight: 20 aliases: - /platform/security/authentication/ +grid: + - title: Single sign-on + description: Authenticate users through your identity provider. + icon: key + link: /security/authentication/single-sign-on/ + - title: Two-factor authentication + description: Add a TOTP security code to an individual Docker account. + icon: device-phone-mobile + link: /security/authentication/2fa/ + - title: OIDC connections + description: Authenticate GitHub Actions with short-lived tokens. + icon: lock-closed + link: /security/authentication/oidc-connections/ --- + +Authentication in Docker Home is how users and workloads prove who they are +before they access Docker products. + +Two-factor authentication (2FA) protects an individual account. Single +sign-on (SSO) federates sign-in for an organization or company. OpenID +Connect (OIDC) connections authenticate CI workloads such as GitHub Actions. + +## Choose an authentication method + +| Method | Who it covers | Who configures it | How authentication works | +| --- | --- | --- | --- | +| Two-factor authentication (2FA) | An individual Docker account | The account holder | Password plus a time-based one-time password (TOTP) from an authenticator app | +| Single sign-on (SSO) | An organization or company | An organization or company owner | Users sign in through the organization's identity provider (IdP) | +| OIDC connections | GitHub Actions and similar workloads | An organization owner or editor | Docker exchanges short-lived tokens issued per workflow run | + +SSO requires a Docker Business subscription. OIDC connections require a +Docker Team or Business subscription. + +To require Docker Desktop users to sign in as organization members, see +[Enforce sign-in](/manuals/enterprise/security/enforce-sign-in/_index.md). +Enforce sign-in is configured in Enterprise, not in this section. + +## Next steps + +{{< grid >}} diff --git a/content/manuals/security/authentication/oidc-connections/_index.md b/content/manuals/security/authentication/oidc-connections/_index.md index bca796dcf123..43b78274f313 100644 --- a/content/manuals/security/authentication/oidc-connections/_index.md +++ b/content/manuals/security/authentication/oidc-connections/_index.md @@ -35,19 +35,8 @@ GitHub follows these steps: All tokens created and exchanged during an OIDC workflow are short-lived and issued on a per-workflow basis. -## OIDC connections and OATs - -[Organization access tokens (OATs)](/manuals/security/access-tokens/organization-access-tokens.md) -provide programmatic access to your Docker resources at the organization -level. Unlike personal access tokens, OATs aren't tied to individual -members, so access continues when membership changes. - -OIDC connections don't replace OATs. OIDC connections authenticate a -workflow as if it were a user, then authorize access after authentication. - -While OATs govern access to your Docker resources through organization -membership, OIDC connections authenticate GitHub Actions workflows when -they request a change to your Docker resources. +For how OIDC connections compare to organization access tokens, see +[Access tokens](/manuals/security/access-tokens/_index.md). ## Next steps diff --git a/content/manuals/security/roles-and-permissions/core-roles.md b/content/manuals/security/roles-and-permissions/core-roles.md index 1054582dd501..9cce5c460480 100644 --- a/content/manuals/security/roles-and-permissions/core-roles.md +++ b/content/manuals/security/roles-and-permissions/core-roles.md @@ -37,7 +37,7 @@ Docker organizations have three core roles: A company owner has the same organization-management permissions as an organization owner. Content and registry permissions, such as repository pull and push, don't apply to company owners. For more information, see -[Company overview](/manuals/accounts/organization/company/_index.md). +[Company overview](/manuals/accounts/company/_index.md). ## Permissions reference @@ -135,5 +135,5 @@ _\* If not part of a company_ Create tailored permission sets on a Docker Business plan - [Manage organization members](/manuals/accounts/organization/manage/members.md): Invite users and assign roles -- [Company overview](/manuals/accounts/organization/company/_index.md): Understand company +- [Company overview](/manuals/accounts/company/_index.md): Understand company owner permissions versus organization owner permissions diff --git a/content/manuals/security/roles-and-permissions/custom-roles/_index.md b/content/manuals/security/roles-and-permissions/custom-roles/_index.md index 8ba69af1b31a..85e10d2b614a 100644 --- a/content/manuals/security/roles-and-permissions/custom-roles/_index.md +++ b/content/manuals/security/roles-and-permissions/custom-roles/_index.md @@ -25,16 +25,12 @@ aliases: {{< summary-bar feature_name="Custom roles" >}} -Custom roles are permission sets that you choose to grant access to users or teams based on specific use cases. Use custom roles when you need: +Custom roles are permission sets that you choose to grant access to users +or teams based on specific use cases. Use custom roles when you need +specialized roles, department-specific access, or least-privilege grants. -- Specialized roles such as billing administrators, security auditors, or - repository managers -- Department-specific access control -- Least-privilege access with precise permission grants - -If Docker's predefined -permission sets meet your needs, use -[core roles](/manuals/security/roles-and-permissions/core-roles.md) +If Docker's predefined permission sets meet your needs, use +[core roles](/manuals/security/roles-and-permissions/_index.md) instead. ## Prerequisites @@ -48,8 +44,6 @@ To create a custom role, you select permissions from organization management, Docker Hub, billing, AI Governance, Docker Hardened Images, and Docker Offload. You then assign custom roles you created to individual users or to teams. -Users and teams get either a core role or a custom role, but not both. - ## Next steps {{< grid >}} diff --git a/content/manuals/subscription-billing/_index.md b/content/manuals/subscription-billing/_index.md index fcbf0ef46fa4..f098754e56c6 100644 --- a/content/manuals/subscription-billing/_index.md +++ b/content/manuals/subscription-billing/_index.md @@ -13,119 +13,63 @@ aliases: - /docker-hub/billing/ - /docker-hub/billing/faq/ - /billing/docker-hub-pricing/ -grid_subscriptions: - - title: Compare Docker plans - description: Visit the pricing page to see what's included in different Docker plans. - link: "https://www.docker.com/pricing?ref=Docs&refAction=DocsSubscription" - icon: magnifying-glass - - title: Manage plans - description: Add a new plan, upgrade an active plan, or cancel auto-renewal. - link: /subscription-billing/manage/plans/ - icon: shopping-cart +grid: - title: Explore plans description: Browse available Docker plans and add-ons for individuals, teams, and organizations. link: /subscription-billing/plans/ icon: chart-bar - - title: Docker Desktop license agreement - description: Review the terms of the Docker Subscription Service Agreement. - link: /subscription-billing/desktop-license/ - icon: document-text -grid_core: - - title: Add or update a payment method - description: Learn how to add or update a payment method for your personal account or organization. - link: /subscription-billing/manage/payment-method/ + - title: Manage billing + description: Manage payment methods, invoices, credits, and billing details in the billing portal. + link: /subscription-billing/manage/ icon: credit-card - - title: Update billing information - description: Learn how to update billing information for your personal account or organization. - link: /subscription-billing/manage/details/ - icon: pencil-square - - title: View billing history - description: Learn how to view billing history and download past invoices. - link: /subscription-billing/manage/history/ - icon: credit-card - - title: 3D Secure authentication - description: Learn how 3DS works and how to troubleshoot verification issues. - link: /subscription-billing/manage/3d-secure/ - icon: wallet - - title: Taxes - description: Learn how to submit a US tax exemption certificate or add a VAT number. - link: /subscription-billing/manage/tax-certificate/ - icon: document-text --- -You can subscribe to several Docker plans that range from free to paid plans. When you upgrade a plan, you expand your usage entitlements and feature sets for Docker products. You can also top up some plans, extending usage to more users without changing your plan type. +A Docker plan is a subscription tied to a personal account, an organization +account, or a specific product. When you upgrade a plan, you expand your +usage entitlements and feature sets. You can also top up some plans, +extending usage without changing your plan type. ## Docker plans -You can subscribe to plans for individual or organization accounts, or plans for specific products. The following table summarizes the available plans. +The following table summarizes the available plans. -| Plans | Billing model | Types | -| ---------------------------------------------------------------------- | --------------------------------------------------------- | --------------------------------------------------------- | -| [Docker](/manuals/subscription-billing/plans/docker.md) | Flat-rate plans for personal and organization accounts | Docker Personal, Docker Pro, Docker Team, Docker Business | -| [Docker Agentic Platform](/manuals/subscription-billing/plans/docker-agentic-platform.md) | Pay-as-you-go (PayGo) for cloud sandbox usage | Docker Agentic Platform | -| [Docker Hardened Images (DHI)](/manuals/subscription-billing/plans/dhi.md) | Graduated security features for hardened container images | DHI Community, DHI Select, DHI Enterprise | -| [Gordon](/manuals/subscription-billing/plans/gordon.md) | Prepaid usage for the Gordon AI agent | Gordon Plus, Gordon Max, Gordon Ultra | -| [AI Governance](/manuals/subscription-billing/plans/ai-governance.md) | Purchase set amount of licenses | AI Governance | -| [Docker Verified Publisher (DVP)](/manuals/subscription-billing/plans/docker-verified-publisher.md) | Annual plans based on consuming domains | DVP Starter, DVP Growth | +| Plans | Billing model | Types | +| --- | --- | --- | +| [Docker](/manuals/subscription-billing/plans/docker.md) | Flat-rate plans for personal and organization accounts | Docker Personal, Docker Pro, Docker Team, Docker Business | +| [Docker Hardened Images (DHI)](/manuals/subscription-billing/plans/dhi.md) | Graduated security features for hardened container images | DHI Community, DHI Select, DHI Enterprise | +| [Gordon](/manuals/subscription-billing/plans/gordon.md) | Prepaid usage for the Gordon AI agent | Gordon Plus, Gordon Max, Gordon Ultra | +| [AI Governance](/manuals/subscription-billing/plans/ai-governance.md) | Purchase set amount of licenses | AI Governance | +| [Docker Verified Publisher (DVP)](/manuals/subscription-billing/plans/docker-verified-publisher.md) | Annual plans based on consuming domains | DVP Starter, DVP Growth | -Docker plans that upgrade your account (Docker Pro or Docker Team and Business) can provide a foundation for most use cases. Some product plans may require an upgraded Docker account while other product plans let you subscribe without an upgraded account. To learn more, see [Docker plans](/manuals/subscription-billing/plans/_index.md). +Docker plans that upgrade your account (Docker Pro, Team, and Business) cover +most use cases. Some product plans require an upgraded Docker account. Others +let you subscribe without one. For details, see +[Plans](/manuals/subscription-billing/plans/_index.md). ## Top up your plan -Plans come with usage entitlements that can be extended without upgrading to a different plan. +Plans come with usage entitlements that can be extended without upgrading to +a different plan. -| Unit | Description | Examples | -| ----------------- | ------------------------------------------------------------------------------------- | ----------------------------- | -| Seats | Each seat extends entitlements to one more member. | Docker Team, Docker Business | -| Licenses | Access to specific products or features. | AI Governance, Docker Offload | -| Minutes | Cloud build capacity, sold in blocks and consumed within the billing period. | Docker Build Cloud | -| Repositories | Additional container repositories covered by security scanning and analysis features. | DHI | -| Consuming domains | Additional consuming domains tracked in publisher analytics, sold in blocks of 25. | DVP Starter, DVP Growth | +| Unit | Description | Examples | +| --- | --- | --- | +| Seats | Each seat extends entitlements to one more member. | Docker Team, Docker Business | +| Licenses | Access to specific products or features. | AI Governance, Docker Offload | +| Minutes | Cloud build capacity, sold in blocks and consumed within the billing period. | Docker Build Cloud | +| Repositories | Additional container repositories covered by security scanning and analysis features. | DHI | +| Consuming domains | Additional consuming domains tracked in publisher analytics, sold in blocks of 25. | DVP Starter, DVP Growth | ## Manage your plans -To subscribe to a new plan or upgrade an active plan, see [Manage plans](/manuals/subscription-billing/manage/plans.md). See [Docker plans](/manuals/subscription-billing/plans/docker.md) to learn about Docker Team, Business, and Pro. You can also contact sales. - -You can use the billing portal to manage your Docker subscriptions, such -as updating payment methods, reviewing billing details, and tracking -invoice history. - -## Billing - -You can manage your Docker plans from the billing portal: - -1. Sign in to [Docker Home](https://app.docker.com/), then choose your - account. -1. Go to **Billing** to view the **Overview** page. -1. Select the page you want to explore. - -### Usage - -The billing **Usage** page helps you compare usage-based charges across -billing periods. You can track usage by changing the period, product, -and how the product is metered. +To subscribe to a new plan or upgrade an active plan, see +[Manage plans](/manuals/subscription-billing/manage/plans.md). See +[Docker plans](/manuals/subscription-billing/plans/docker.md) to learn about +Docker Team, Business, and Pro. You can also +contact sales. -### Costs - -The billing **Costs** page aggregates all costs by billing period. It -breaks down charges by resource (the product accruing a charge), the -status of your billing period, and costs to date. - -### Credits - -The billing **Credits** page shows credits applied to your costs. If you -received a promotional credit, you can see how it applies to your bill -from this page. - -## Docker plans and billing cycle - -Your invoice history is a reference to the Docker plans you subscribe -to. For information about your billing cycle and renewal dates, see -[Billing cycle](/manuals/subscription-billing/manage/details.md#billing-cycle). To upgrade or add -a new plan, see [Subscription](/manuals/subscription-billing/_index.md). +To update payment methods, review usage and credits, or download invoices, see +[Manage billing](/manuals/subscription-billing/manage/_index.md). ## Next steps -{{< grid items="grid_subscriptions" >}} - -{{< grid items="grid_core" >}} +{{< grid >}} diff --git a/content/manuals/subscription-billing/manage/_index.md b/content/manuals/subscription-billing/manage/_index.md index 544dc81a316c..da9471e652de 100644 --- a/content/manuals/subscription-billing/manage/_index.md +++ b/content/manuals/subscription-billing/manage/_index.md @@ -1,9 +1,80 @@ --- -build: - render: never -title: Manage +title: Manage billing linkTitle: Manage description: Manage Docker plans, payment methods, billing details, invoices, and taxes. keywords: manage plans, billing, payment methods, invoices, taxes, docker subscription weight: 20 +grid: + - title: Manage plans + description: Add a new plan, upgrade an active plan, or cancel auto-renewal. + icon: shopping-cart + link: /subscription-billing/manage/plans/ + - title: Add or update a payment method + description: Add or update a payment method for your personal account or organization. + icon: credit-card + link: /subscription-billing/manage/payment-method/ + - title: Update billing information + description: Update billing information for your personal account or organization. + icon: pencil-square + link: /subscription-billing/manage/details/ + - title: View billing history + description: View billing history and download past invoices. + icon: credit-card + link: /subscription-billing/manage/history/ + - title: 3D Secure authentication + description: Learn how 3DS works and how to troubleshoot verification issues. + icon: wallet + link: /subscription-billing/manage/3d-secure/ + - title: Taxes + description: Submit a US tax exemption certificate or add a VAT number. + icon: document-text + link: /subscription-billing/manage/tax-certificate/ --- + +You manage Docker plans, payment methods, invoices, credits, and taxes from +Docker Home. Billing is scoped to the account you +select. To manage billing: + +1. Sign in to [Docker Home](https://app.docker.com/), then choose your + personal account or organization. +1. Select **Billing**. +1. Select the page you want in the sidebar, or stay on **Overview**. + +To add or upgrade a plan, see +[Manage plans](/manuals/subscription-billing/manage/plans.md). To compare +plan types, see [Plans](/manuals/subscription-billing/plans/_index.md). + +## Overview + +When you select **Billing**, you are taken to the **Overview** page, where you review active plans, payment +method, and subscription totals for that account. From there you add +self-serve products, manage a plan you already have, or open another +billing page in the sidebar. + +## Invoices + +The billing **Invoices** page lists invoices issued when a plan renews or +changes. You can open an invoice, check payment status, and download a +copy. + +## Usage + +The billing **Usage** page helps you compare usage-based charges across +billing periods. You can track usage by changing the period, product, +and how the product is metered. + +## Costs + +The billing **Costs** page aggregates all costs by billing period. It +breaks down charges by resource (the product accruing a charge), the +status of your billing period, and costs to date. + +## Credits + +The billing **Credits** page shows credits applied to your costs. If you +received a promotional credit, you can see how it applies to your bill +from this page. + +## Next steps + +{{< grid >}} diff --git a/content/manuals/subscription-billing/manage/plans.md b/content/manuals/subscription-billing/manage/plans.md index bcf6431059bf..1e0d2b021f7a 100644 --- a/content/manuals/subscription-billing/manage/plans.md +++ b/content/manuals/subscription-billing/manage/plans.md @@ -69,7 +69,7 @@ You can upgrade active plans from the billing Overview page. Docker displays available account credits in the billing portal. Credits offset eligible usage automatically before Docker charges your payment method. To review credit balance and applied credits, see -[Credits](/manuals/subscription-billing/_index.md#credits). +[Credits](/manuals/subscription-billing/manage/_index.md#credits). Credits apply to [Docker Agentic Platform](/manuals/subscription-billing/plans/docker-agentic-platform.md). diff --git a/content/manuals/subscription-billing/plans/_index.md b/content/manuals/subscription-billing/plans/_index.md index 37a1bac78e82..e2999cf023f7 100644 --- a/content/manuals/subscription-billing/plans/_index.md +++ b/content/manuals/subscription-billing/plans/_index.md @@ -6,7 +6,7 @@ description: organizations. keywords: docker products, docker subscriptions, docker core, ai governance, dhi select, - docker build cloud, gordon plans, docker agentic platform, product catalog + docker build cloud, gordon plans, product catalog weight: 10 aliases: - /subscription/plans/ @@ -43,11 +43,20 @@ grid: > Interested in pricing details? Check out the > pricing page to compare plans. -To subscribe to a plan, see [Manage plans](../manage.md) or [Docker plans](docker.md). Plans can be tied to personal or organization account types, and include options to extend usage limits. +Docker plans attach to a personal account, an organization, or a specific +product. Personal plans (Docker Personal and Docker Pro) upgrade an individual +account. Organization plans (Docker Team and Docker Business) upgrade an +organization. Product add-ons add usage or features without changing that +account's Docker plan type: Gordon increases usage on a personal account, and +DHI, AI Governance, and DVP add product features on an organization. -This section covers usage entitlements, billing cycle, and plan management options for each available plan. +Topping up extends a plan's entitlements, such as seats, licenses, or +minutes, without changing the plan type. For the units you can top up, see +[Top up your plan](/manuals/subscription-billing/_index.md#top-up-your-plan). -To manage your plans by adding a new plan or upgrading an active plan, see [Manage plans](/manuals/subscription-billing/manage/plans.md). +Each plan page covers usage entitlements, billing cycle, and management +options. To add or upgrade a plan, see +[Manage plans](/manuals/subscription-billing/manage/plans.md). ## Product catalog diff --git a/content/manuals/subscription-billing/plans/docker-agentic-platform.md b/content/manuals/subscription-billing/plans/docker-agentic-platform.md index 5391463183b2..fef6a45d5d23 100644 --- a/content/manuals/subscription-billing/plans/docker-agentic-platform.md +++ b/content/manuals/subscription-billing/plans/docker-agentic-platform.md @@ -18,7 +18,7 @@ aliases: > [!TIP] > Docker Agentic Platform signups receive a one-time promotional > credit toward cloud compute usage. To review your balance, see -> [Credits](/manuals/subscription-billing/_index.md#credits). +> [Credits](/manuals/subscription-billing/manage/_index.md#credits). [Docker Agentic Platform](https://agentic-platform.docker.com/) is a pay-as-you-go plan for running agent and tool workloads in isolated @@ -81,4 +81,4 @@ the plan period. - To add or cancel a plan, see [Manage plans](/manuals/subscription-billing/manage/plans.md) - To track usage across plans, see - [Usage](/manuals/subscription-billing/_index.md#usage) + [Usage](/manuals/subscription-billing/manage/_index.md#usage) diff --git a/data/summary.yaml b/data/summary.yaml index 3aa4b6c78eeb..8bd05925c54b 100644 --- a/data/summary.yaml +++ b/data/summary.yaml @@ -1,3 +1,6 @@ +2FA: + subscription: [Personal, Pro] + for: Individuals AI Governance Audit Logs: subscription: [AI Governance] requires: Docker Sandboxes [0.39.0](/manuals/ai/sandboxes/release-notes.md) or later @@ -261,6 +264,10 @@ MSI installer: for: Administrators OATs: subscription: [Team, Business] + for: Administrators +PATs: + subscription: [Personal, Pro] + for: Individuals Pay by invoice: subscription: [Team, Business] PKG installer: diff --git a/layouts/_shortcodes/summary-bar.html b/layouts/_shortcodes/summary-bar.html index 98f037117756..aa434c1dd17c 100644 --- a/layouts/_shortcodes/summary-bar.html +++ b/layouts/_shortcodes/summary-bar.html @@ -23,12 +23,13 @@ "Retired" "archive-box" }} {{ $requiresIcon := "arrow-down-circle" }} - {{ $forIcon := "shield-check" }} + {{ $forIcons := dict + "Administrators" "shield-check" + "Individuals" "user-circle" + }} -
+
{{ with $feature.subscription }}
Subscription: @@ -75,9 +76,9 @@
For: {{ . }} - {{ if eq . "Administrators" }} + {{ with index $forIcons . }} - {{ partialCached "icon" $forIcon $forIcon }} + {{ partialCached "icon" . . }} {{ end }}