-
Notifications
You must be signed in to change notification settings - Fork 23
Docker API regex pattern index
Configuring this Docker socket proxy can be quite daunting. It uses big scary unreadable regexp to explicitly authorize certain calls from a container to the equally unscrutable Docker API. It is a very simple tool, but it requires prior knowledge of two different languages only spoken by computers in private digital conversations.
This document lists all these calls with an index of example patterns and reusable snippets to make configuration of this socket proxy easier a little bit more accessible to people who can already deal with a docker-compose.yml and the daring souls who play with the .env.
Calls to the Docker Engine API take the form of a path, like an URL, to which the socket answers by sending back information and/or performing an action. All these calls have been designed, their form is thus known and documented. This regularity allows to write filters in the form of form of regular expression for the socket proxy to determine which ones it should authorize or block. When a call to the docker socket matches one of these preconfigured reg exp, the socket proxy authorizes it.
This example document was written using version 1.55 of the Docker API documentation. This API is often updated (see version history) but most of its changes are not relevant to the use of this Docker socket proxy like the request body and the structure of the response. The only changes that are within the scope of this Docker proxy's filtering features are:
- query parameters which are not covered in this example document
- the recent deprecation and planned removal of the
POST /grpcandPOST /sessionendpoints in version 1.53
This Docker Socket Proxy uses the Go regexp syntax, which can be tested in regex101 by selecting the "Golang" flavor in the let side menu.
In this regexp syntax, the forward slash character / is not a delimiter and does not need to be escaped.
Delimiters for the beginning ^ and end $ of the matched string are omitted as this Docker Socket proxy's regex processor adds them automatically at runtime.
The following example patterns use POSIX character classes for ease of human reading.
They can be replaced by shorter equivalents detailed in the snippets below.
Other basic concepts used include parentheses are used for grouping (like in maths) and allows the use of the ? quantifier, which means an element can be present or not.
Calls to the Docker API are HTTP requests in the following format: {method} /{api-version}/{api-section}/{id-name}/{api-endpoint}?{query-parameters}.
E.g. Get the whoami container's logs: GET /v1.55/containers/whoaimi/logs?since=1&until=9×tamps=true
Each snippet includes its preceding separating character (/ or ?).
| Request | {method} |
/{api-version} |
/{api-section} |
/{id-name} |
/{api-endpoint} |
?{query-parameters} |
|---|---|---|---|---|---|---|
| POSIX regex | {method} |
(/v[[:digit:].]+)? |
/{api-section} |
(/[[:word:]-.]+) |
/{api-endpoint} |
(\?[[:graph:]]+)? |
| Shorthand regex | {method} |
(/v[\d.]+)? |
/{api-section} |
(/[\w-.]+) |
/{api-endpoint} |
(\?\S+)? |
The Docker API uses 5 HTTP request methods: GET, HEAD, POST, PUT and DELETE.
GET and HEAD roughly correspond to read only actions and are allowed by default by other socket proxies.
Allowing POST, PUT and DELETE enable write operations.
Other socket proxies group their use together behind the POST=1 option.
This Docker socket proxy uses CLI parameters and environment variables to allow request methods, with the CLI parameters taking priority when both are used.
| HTTP method | CLI parameter | Environment variable |
|---|---|---|
GET |
-allowGET |
SP_ALLOW_GET |
HEAD |
-allowHEAD |
SP_ALLOW_HEAD |
POST |
-allowPOST |
SP_ALLOW_POST |
PUT |
-allowPUT |
SP_ALLOW_PUT |
DELETE |
-allowDELETE |
SP_ALLOW_DELETE |
This socket proxy also supports 4 other request methods: CONNECT (-allowCONNECT), OPTIONS (-allowOPTIONS), TRACE (-allowTRACE) and PATCH (-allowPATCH).
As they are not currently used by the Docker API, it is not recommended to allow any requests via these methods.
Doing so would only open to potential vulnerabilities with no usability benefit at all.
Calls are made to a specific Docker API version, with the exceptions of /_ping and /version.
The version number uses a v prefix and colons as a separator, e.g. v1.55.
As this part of the request can be omitted, the snippet uses a ?.
| POSIX snippet | Shorthand snippet |
|---|---|
(/v[[:digit:].]+)? |
(/v[\d.]+)? |
API sections regroup endpoints and operations.
Allowing a section opens access to all its endpoints.
It is not very precise, except when the endpoint is the section (e.g. /_ping or /version).
Other socket proxies define their filters at this level and their configuration can be converted to matching regex using the Socket Proxy Configuration Converter.
The following snippet allows the whole section: it matches any combination of /{id-name}, /{api-endpoint} and ?{query-parameters}.
| POSIX snippet | Shorthand snippet |
|---|---|
/{api-section}((/|\?)[[:graph:]]+)? |
/{api-section}((/|\?)\S+)? |
The POSIX [:graph:] (visible characters) and the shorthand \S (non-whitespace characters) character classes are not strictly equivalent but both cover the characters expected in a URL.
Endpoints that perform an operation on a container, network, image, service, etc. require it to be part of the request as a path parameter.
It is refered either by its ID or name.
IDs are random strings of lowercase letters and numbers while name are user-defined and follow the regex format of [a-zA-Z0-9][a-zA-Z0-9_.-]+ (lowercase and uppercase letters, numbers, plus 3 special characters: underscore, colon and hyphen).
This part of the request can not be omitted if the endpoint requires it.
| POSIX snippet | Shorthand snippet |
|---|---|
(/[[:word:]-.]+) |
(/[\w-.]+) |
This is the actual precise request to the API. It uses predetermined endpoints listed in Docker's documentation and in the examples below. Allowing an endpoint means allowing only one operation, so filtering by endpoint is a more granular approach compared to allowing a whole section.
This is the preciser request.
Query parameters are optional and use a ? prefix that needs to be escaped in regex.
E.g. ?since=1&until=9×tamps=true
The API endpoint's query parameters often change with each version but "the server will ignore any extra query parameters and request body properties".
| POSIX snippet | Shorthand snippet |
|---|---|
(\?[[:graph:]]+)? |
(\?\S+)? |
The POSIX [:graph:] (visible characters) and the shorthand \S (non-whitespace characters) character classes are not strictly equivalent but both cover the characters expected in a URL.
| API sections (required) | GET |
HEAD |
POST |
PUT |
DELETE |
Equivalent |
|---|---|---|---|---|---|---|
/version |
-allowGET=(/v[[:digit:].]+)?/version |
VERSION=1 |
||||
/_ping |
-allowGET=(/v[[:digit:].]+)?/_ping |
-allowHEAD=(/v[[:digit:].]+)?/_ping |
PING=1 |
|||
/events |
-allowGET=(/v[[:digit:].]+)?/events((/|\?)[[:graph:]]+)? |
EVENTS=1 |
| API sections (optional) | GET |
HEAD |
POST |
PUT |
DELETE |
Equivalent |
|---|---|---|---|---|---|---|
/containers |
-allowGET=(/v[[:digit:].]+)?/containers((/|\?)[[:graph:]]+)? |
-allowHEAD=(/v[[:digit:].]+)?/containers((/|\?)[[:graph:]]+)? |
-allowPOST=(/v[[:digit:].]+)?/containers((/|\?)[[:graph:]]+)? |
-allowPUT=(/v[[:digit:].]+)?/containers((/|\?)[[:graph:]]+)? |
-allowDELETE=(/v[[:digit:].]+)?/containers((/|\?)[[:graph:]]+)? |
CONTAINERS=1 + POST=1
|
/images |
-allowGET=(/v[[:digit:].]+)?/images((/|\?)[[:graph:]]+)? |
-allowHEAD=(/v[[:digit:].]+)?/images((/|\?)[[:graph:]]+)? |
-allowPOST=(/v[[:digit:].]+)?/images((/|\?)[[:graph:]]+)? |
-allowDELETE=(/v[[:digit:].]+)?/images((/|\?)[[:graph:]]+)? |
IMAGES=1 + POST=1
|
|
/build |
-allowPOST=(/v[[:digit:].]+)?/build((/|\?)[[:graph:]]+)? |
BUILD=1 + POST=1
|
||||
/commit |
-allowPOST=(/v[[:digit:].]+)?/commit((/|\?)[[:graph:]]+)? |
COMMIT=1 + POST=1
|
||||
/networks |
-allowGET=(/v[[:digit:].]+)?/networks((/|\?)[[:graph:]]+)? |
-allowPOST=(/v[[:digit:].]+)?/networks((/|\?)[[:graph:]]+)? |
-allowDELETE=(/v[[:digit:].]+)?/networks((/|\?)[[:graph:]]+)? |
NETWORKS=1 + POST=1
|
||
/volumes |
-allowGET=(/v[[:digit:].]+)?/volumes((/|\?)[[:graph:]]+)? |
-allowPOST=(/v[[:digit:].]+)?/volumes((/|\?)[[:graph:]]+)? |
-allowPUT=(/v[[:digit:].]+)?/volumes((/|\?)[[:graph:]]+)? |
-allowDELETE=(/v[[:digit:].]+)?/volumes((/|\?)[[:graph:]]+)? |
VOLUMES=1 + POST=1
|
|
/exec |
-allowGET=(/v[[:digit:].]+)?/exec((/|\?)[[:graph:]]+)? |
-allowPOST=(/v[[:digit:].]+)?/exec((/|\?)[[:graph:]]+)? |
EXEC=1 + POST=1
|
|||
/plugins |
-allowGET=(/v[[:digit:].]+)?/plugins((/|\?)[[:graph:]]+)? |
-allowPOST=(/v[[:digit:].]+)?/plugins((/|\?)[[:graph:]]+)? |
-allowDELETE=(/v[[:digit:].]+)?/plugins((/|\?)[[:graph:]]+)? |
PLUGINS=1 + POST=1
|
||
/info |
-allowGET=(/v[[:digit:].]+)?/info |
INFO=1 |
||||
/system |
-allowGET=(/v[[:digit:].]+)?/system((/|\?)[[:graph:]]+)? |
SYSTEM=1 |
||||
/distribution |
-allowGET=(/v[[:digit:].]+)?/distribution((/|\?)[[:graph:]]+)? |
DISTRIBUTION=1 |
| API sections (Swarm mode only) | GET |
HEAD |
POST |
PUT |
DELETE |
Equivalent |
|---|---|---|---|---|---|---|
/swarm |
-allowGET=(/v[[:digit:].]+)?/swarm((/|\?)[[:graph:]]+)? |
-allowPOST=(/v[[:digit:].]+)?/swarm((/|\?)[[:graph:]]+)? |
SWARM=1 + POST=1
|
|||
/nodes |
-allowGET=(/v[[:digit:].]+)?/nodes((/|\?)[[:graph:]]+)? |
-allowPOST=(/v[[:digit:].]+)?/nodes((/|\?)[[:graph:]]+)? |
-allowDELETE=(/v[[:digit:].]+)?/nodes((/|\?)[[:graph:]]+)? |
NODES=1 + POST=1
|
||
/services |
-allowGET=(/v[[:digit:].]+)?/services((/|\?)[[:graph:]]+)? |
-allowPOST=(/v[[:digit:].]+)?/services((/|\?)[[:graph:]]+)? |
-allowDELETE=(/v[[:digit:].]+)?/services((/|\?)[[:graph:]]+)? |
SERVICES=1 + POST=1
|
||
/tasks |
-allowGET=(/v[[:digit:].]+)?/tasks((/|\?)[[:graph:]]+)? |
TASKS=1 |
||||
/configs |
-allowGET=(/v[[:digit:].]+)?/configs((/|\?)[[:graph:]]+)? |
-allowPOST=(/v[[:digit:].]+)?/configs((/|\?)[[:graph:]]+)? |
-allowDELETE=(/v[[:digit:].]+)?/configs((/|\?)[[:graph:]]+)? |
CONFIGS=1 + POST=1
|
| API sections (security-critical) | GET |
HEAD |
POST |
PUT |
DELETE |
Equivalent |
|---|---|---|---|---|---|---|
/auth |
-allowPOST=(/v[[:digit:].]+)?/auth |
AUTH=1 + POST=1
|
||||
/secrets |
-allowGET=(/v[[:digit:].]+)?/secrets((/|\?)[[:graph:]]+)? |
-allowPOST=(/v[[:digit:].]+)?/secrets((/|\?)[[:graph:]]+)? |
-allowDELETE=(/v[[:digit:].]+)?/secrets((/|\?)[[:graph:]]+)? |
SECRETS=1 + POST=1
|
| API sections (deprecated) | GET |
HEAD |
POST |
PUT |
DELETE |
Equivalent |
|---|---|---|---|---|---|---|
/session |
-allowPOST=(/v[[:digit:].]+)?/session |
SESSION=1 + POST=1
|
Create and manage containers.
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 |
GET, HEAD, POST, DELETE, PUT
|
(/v[[:digit:].]+)?/containers((/|\?)[[:graph:]]+)? |
CONTAINERS=1 + POST=1
|
Returns a list of containers.
| API version | Method | Regex | Equivalent |
|---|---|---|---|
| v1.55 | GET |
(/v[[:digit:].]+)?/containers/json(\?[[:graph:]]+)? |
CONTAINERS=1 |
| API version | Method | Regex | Equivalent (section) |
|---|---|---|---|
| v1.55 | POST |
(/v[[:digit:].]+)?/containers/create(\?[[:graph:]]+)? |
CONTAINERS=1 + POST=1
|
Return low-level information about a container.
Same as "List containers" but with a path parameter.(/[[:word:]-.]+)
| API version | Method | Regex | Equivalent |
|---|---|---|---|
| v1.55 | GET |
(/v[[:digit:].]+)?/containers(/[[:word:]-.]+)/json(\?[[:graph:]]+)? |
CONTAINERS=1 |
On Unix systems, this is done by running the
pscommand. This endpoint is not supported on Windows.
| API version | Method | Regex | Equivalent |
|---|---|---|---|
| v1.55 | GET |
(/v[[:digit:].]+)?/containers(/[[:word:]-.]+)/top(\?[[:graph:]]+)? |
CONTAINERS=1 or ALLOW_TOP=1
|
Get
stdoutandstderrlogs from a container.
| API version | Method | Regex | Equivalent |
|---|---|---|---|
| v1.55 | GET |
(/v[[:digit:].]+)?/containers(/[[:word:]-.]+)/logs(\?[[:graph:]]+)? |
CONTAINERS=1 or ALLOW_LOGS=1
|
Returns which files in a container's filesystem have been added, deleted, or modified.
| API version | Method | Regex | Equivalent |
|---|---|---|---|
| v1.55 | GET |
(/v[[:digit:].]+)?/containers(/[[:word:]-.]+)/changes |
CONTAINERS=1 or ALLOW_CHANGES=1
|
Export the contents of a container as a tarball.
| API version | Method | Regex | Equivalent |
|---|---|---|---|
| v1.55 | GET |
(/v[[:digit:].]+)?/containers(/[[:word:]-.]+)/export |
CONTAINERS=1 or ALLOW_EXPORT=1
|
This endpoint returns a live stream of a container’s resource usage statistics.
| API version | Method | Regex | Equivalent |
|---|---|---|---|
| v1.55 | GET |
(/v[[:digit:].]+)?/containers(/[[:word:]-.]+)/stats(\?[[:graph:]]+)? |
CONTAINERS=1 |
Resize the TTY for a container.
| API version | Method | Regex | Equivalent |
|---|---|---|---|
| v1.55 | POST |
(/v[[:digit:].]+)?/containers(/[[:word:]-.]+)/resize(\?[[:graph:]]+)? |
CONTAINERS=1 + POST=1
|
| API version | Method | Regex | Equivalent |
|---|---|---|---|
| v1.55 | POST |
(/v[[:digit:].]+)?/containers(/[[:word:]-.]+)/start(\?[[:graph:]]+)? |
ALLOW_START=1 = CONTAINERS=1 + POST=1
|
| API version | Method | Regex | Equivalent |
|---|---|---|---|
| v1.55 | POST |
(/v[[:digit:].]+)?/containers(/[[:word:]-.]+)/stop(\?[[:graph:]]+)? |
ALLOW_STOP=1 = ALLOW_RESTARTS=1 = CONTAINERS=1 + POST=1
|
| API version | Method | Regex | Equivalent |
|---|---|---|---|
| v1.55 | POST |
(/v[[:digit:].]+)?/containers(/[[:word:]-.]+)/restart(\?[[:graph:]]+)? |
ALLOW_RESTARTS=1 = CONTAINERS=1 + POST=1
|
| API version | Method | Regex | Equivalent |
|---|---|---|---|
| v1.55 | POST |
(/v[[:digit:].]+)?/containers(/[[:word:]-.]+)/kill(\?[[:graph:]]+)? |
ALLOW_RESTARTS=1 = CONTAINERS=1 + POST=1
|
Change various configuration options of a container without having to recreate it.
| API version | Method | Regex | Equivalent |
|---|---|---|---|
| v1.55 | POST |
(/v[[:digit:].]+)?/containers(/[[:word:]-.]+)/update(\?[[:graph:]]+)? |
CONTAINERS=1 + POST=1
|
| API version | Method | Regex | Equivalent |
|---|---|---|---|
| v1.55 | POST |
(/v[[:digit:].]+)?/containers(/[[:word:]-.]+)/rename(\?[[:graph:]]+)? |
CONTAINERS=1 + POST=1
|
Use the freezer cgroup to suspend all processes in a container.
| API version | Method | Regex | Equivalent |
|---|---|---|---|
| v1.55 | POST |
(/v[[:digit:].]+)?/containers(/[[:word:]-.]+)/pause |
ALLOW_PAUSE=1 = CONTAINERS=1 + POST=1
|
Resume a container which has been paused.
| API version | Method | Regex | Equivalent |
|---|---|---|---|
| v1.55 | POST |
(/v[[:digit:].]+)?/containers(/[[:word:]-.]+)/unpause |
ALLOW_UNPAUSE=1 = CONTAINERS=1 + POST=1
|
Attach to a container to read its output or send it input. You can attach to the same container multiple times and you can reattach to containers that have been detached.
| API version | Method | Regex | Equivalent |
|---|---|---|---|
| v1.55 | POST |
(/v[[:digit:].]+)?/containers(/[[:word:]-.]+)/attach(\?[[:graph:]]+)? |
CONTAINERS=1 + POST=1
|
| API version | Method | Regex | Equivalent |
|---|---|---|---|
| v1.55 | GET |
(/v[[:digit:].]+)?/containers(/[[:word:]-.]+)/attach/ws(\?[[:graph:]]+)? |
CONTAINERS=1 |
Block until a container stops, then returns the exit code.
| API version | Method | Regex | Equivalent |
|---|---|---|---|
| v1.55 | POST |
(/v[[:digit:].]+)?/containers(/[[:word:]-.]+)/wait(\?[[:graph:]]+)? |
CONTAINERS=1 + POST=1
|
| API version | Method | Regex | Equivalent |
|---|---|---|---|
| v1.55 | DELETE |
(/v[[:digit:].]+)?/containers(/[[:word:]-.]+)(\?[[:graph:]]+)? |
CONTAINERS=1 + POST=1
|
A response header
X-Docker-Container-Path-Statis returned, containing a base64-encoded JSON object with some filesystem header information about the path.
| API version | Method | Regex | Equivalent |
|---|---|---|---|
| v1.55 | HEAD |
(/v[[:digit:].]+)?/containers(/[[:word:]-.]+)/archive(\?[[:graph:]]+)? |
ALLOW_ARCHIVE=1 or CONTAINERS=1
|
Get a tar archive of a resource in the filesystem of container id.
| API version | Method | Regex | Equivalent |
|---|---|---|---|
| v1.55 | GET |
(/v[[:digit:].]+)?/containers(/[[:word:]-.]+)/archive(\?[[:graph:]]+)? |
ALLOW_ARCHIVE=1 or CONTAINERS=1
|
Upload a tar archive to be extracted to a path in the filesystem of container id.
pathparameter is asserted to be a directory. If it exists as a file, 400 error will be returned with message "not a directory".
| API version | Method | Regex | Equivalent |
|---|---|---|---|
| v1.55 | PUT |
(/v[[:digit:].]+)?/containers(/[[:word:]-.]+)/archive(\?[[:graph:]]+)? |
ALLOW_ARCHIVE=1 or CONTAINERS=1
|
| API version | Method | Regex | Equivalent |
|---|---|---|---|
| v1.55 | POST |
(/v[[:digit:].]+)?/containers/prune(\?[[:graph:]]+)? |
CONTAINERS=1 + POST=1
|
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 |
GET, POST, DELETE
|
(/v[[:digit:].]+)?/(images|build|commit)((/|\?)[[:graph:]]+)? |
IMAGES=1 + BUILD=1 + COMMIT=1 + POST=1
|
Returns a list of images on the server. Note that it uses a different, smaller representation of an image than inspecting a single image.
| API version | Method | Regex | Equivalent |
|---|---|---|---|
| v1.55 | GET |
(/v[[:digit:].]+)?/images/json(\?[[:graph:]]+)? |
IMAGES=1 |
Build an image from a tar archive with a
Dockerfilein it.
| API version | Method | Regex | Equivalent |
|---|---|---|---|
| v1.55 | POST |
(/v[[:digit:].]+)?/build(\?[[:graph:]]+)? |
BUILD=1 + POST=1
|
| API version | Method | Regex | Equivalent |
|---|---|---|---|
| v1.55 | POST |
(/v[[:digit:].]+)?/build/prune(\?[[:graph:]]+)? |
BUILD=1 + POST=1
|
Pull or import an image.
| API version | Method | Regex | Equivalent |
|---|---|---|---|
| v1.55 | POST |
(/v[[:digit:].]+)?/images/create(\?[[:graph:]]+)? |
IMAGES=1 + POST=1
|
Return low-level information about an image.
Same as "List images" but with a path parameter.
| API version | Method | Regex | Equivalent |
|---|---|---|---|
| v1.55 | GET |
(/v[[:digit:].]+)?/images(/[[:word:]-.]+)/json(\?[[:graph:]]+)? |
IMAGES=1 |
Return the in-toto attestation statements attached to the image for the given platform.
| API version | Method | Regex | Equivalent |
|---|---|---|---|
| v1.55 | GET |
(/v[[:digit:].]+)?/images(/[[:word:]-.]+)/attestations(\?[[:graph:]]+)? |
IMAGES=1 |
Return parent layers of an image.
| API version | Method | Regex | Equivalent |
|---|---|---|---|
| v1.55 | GET |
(/v[[:digit:].]+)?/images(/[[:word:]-.]+)/history(\?[[:graph:]]+)? |
IMAGES=1 |
Push an image to a registry.
| API version | Method | Regex | Equivalent |
|---|---|---|---|
| v1.55 | POST |
(/v[[:digit:].]+)?/images(/[[:word:]-.]+)/push(\?[[:graph:]]+)? |
IMAGES=1 + POST=1
|
Create a tag that refers to a source image.
| API version | Method | Regex | Equivalent |
|---|---|---|---|
| v1.55 | POST |
(/v[[:digit:].]+)?/images(/[[:word:]-.]+)/tag(\?[[:graph:]]+)? |
IMAGES=1 + POST=1
|
Remove an image, along with any untagged parent images that were referenced by that image.
| API version | Method | Regex | Equivalent |
|---|---|---|---|
| v1.55 | DELETE |
(/v[[:digit:].]+)?/images(/[[:word:]-.]+)(\?[[:graph:]]+)? |
IMAGES=1 + POST=1
|
Search for an image on Docker Hub.
| API version | Method | Regex | Equivalent |
|---|---|---|---|
| v1.55 | GET |
(/v[[:digit:].]+)?/images/search(\?[[:graph:]]+)? |
IMAGES=1 |
| API version | Method | Regex | Equivalent |
|---|---|---|---|
| v1.55 | POST |
(/v[[:digit:].]+)?/images/prune(\?[[:graph:]]+)? |
IMAGES=1 + POST=1
|
| API version | Method | Regex | Equivalent |
|---|---|---|---|
| v1.55 | POST |
(/v[[:digit:].]+)?/commit(\?[[:graph:]]+)? |
COMMIT=1 + POST=1
|
Get a tarball containing all images and metadata for a repository.
| API version | Method | Regex | Equivalent |
|---|---|---|---|
| v1.55 | GET |
(/v[[:digit:].]+)?/images(/[[:word:]-.]+)/get(\?[[:graph:]]+)? |
IMAGES=1 |
Get a tarball containing all images and metadata for several image repositories.
| API version | Method | Regex | Equivalent |
|---|---|---|---|
| v1.55 | GET |
(/v[[:digit:].]+)?/images/get(\?[[:graph:]]+)? |
IMAGES=1 |
Load a set of images and tags into a repository.
| API version | Method | Regex | Equivalent |
|---|---|---|---|
| v1.55 | POST |
(/v[[:digit:].]+)?/images/load(\?[[:graph:]]+)? |
IMAGES=1 + POST=1
|
Networks are user-defined networks that containers can be attached to.
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 |
GET, POST, DELETE
|
(/v[[:digit:].]+)?/networks((/|\?)[[:graph:]]+)? |
NETWORKS=1 + POST=1
|
Returns a list of networks.
| API version | Method | Regex | Equivalent |
|---|---|---|---|
| v1.55 | GET |
(/v[[:digit:].]+)?/networks(\?[[:graph:]]+)? |
NETWORKS=1 |
| API version | Method | Regex | Equivalent |
|---|---|---|---|
| v1.55 | GET |
(/v[[:digit:].]+)?/networks(/[[:word:]-.]+)(\?[[:graph:]]+)? |
NETWORKS=1 |
| API version | Method | Regex | Equivalent |
|---|---|---|---|
| v1.55 | DELETE |
(/v[[:digit:].]+)?/networks(/[[:word:]-.]+) |
NETWORKS=1 + POST=1
|
| API version | Method | Regex | Equivalent |
|---|---|---|---|
| v1.55 | POST |
(/v[[:digit:].]+)?/networks/create |
NETWORKS=1 + POST=1
|
The network must be either a local-scoped network or a swarm-scoped network with the
attachableoption set.
| API version | Method | Regex | Equivalent |
|---|---|---|---|
| v1.55 | POST |
(/v[[:digit:].]+)?/networks(/[[:word:]-.]+)/connect |
NETWORKS=1 + POST=1
|
| API version | Method | Regex | Equivalent |
|---|---|---|---|
| v1.55 | POST |
(/v[[:digit:].]+)?/networks(/[[:word:]-.]+)/disconnect |
NETWORKS=1 + POST=1
|
| API version | Method | Regex | Equivalent |
|---|---|---|---|
| v1.55 | POST |
(/v[[:digit:].]+)?/networks/prune(\?[[:graph:]]+)? |
NETWORKS=1 + POST=1
|
Create and manage persistent storage that can be attached to containers.
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 |
GET, POST, DELETE, PUT
|
(/v[[:digit:].]+)?/volumes((/|\?)[[:graph:]]+)? |
VOLUMES=1 + POST=1
|
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 | GET |
(/v[[:digit:].]+)?/volumes(\?[[:graph:]]+)? |
VOLUMES=1 |
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 | POST |
(/v[[:digit:].]+)?/volumes/create |
VOLUMES=1 + POST=1
|
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 | GET |
(/v[[:digit:].]+)?/volumes(/[[:word:]-.]+) |
VOLUMES=1 |
Valid only for Swarm cluster volumes.
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 | PUT |
(/v[[:digit:].]+)?/volumes(/[[:word:]-.]+)(\?[[:graph:]]+)? |
VOLUMES=1 + POST=1
|
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 | DELETE |
(/v[[:digit:].]+)?/volumes(/[[:word:]-.]+)(\?[[:graph:]]+)? |
VOLUMES=1 + POST=1
|
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 | POST |
(/v[[:digit:].]+)?/volumes/prune(\?[[:graph:]]+)? |
VOLUMES=1 + POST=1
|
Run new commands inside running containers.
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 |
GET, POST
|
(/v[[:digit:].]+)?/(containers|exec)((/|\?)[[:graph:]]+)? |
CONTAINERS=1 + EXEC=1 + POST=1
|
Run a command inside a running container.
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 | POST |
(/v[[:digit:].]+)?/container(/[[:word:]-.]+)/exec |
CONTAINERS=1 + POST=1
|
Starts a previously set up exec instance.
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 | POST |
(/v[[:digit:].]+)?/container(/[[:word:]-.]+)/start |
CONTAINERS=1 + POST=1
|
Resize the TTY session used by an exec instance.
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 | POST |
(/v[[:digit:].]+)?/exec(/[[:word:]-.]+)/start(\?[[:graph:]]+)? |
EXEC=1 + POST=1
|
Return low-level information about an exec instance.
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 | GET |
(/v[[:digit:].]+)?/exec(/[[:word:]-.]+)/json |
EXEC=1 |
Engines can be clustered together in a swarm.
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 |
GET, POST
|
(/v[[:digit:].]+)?/swarm((/|\?)[[:graph:]]+)? |
SWARM=1 + POST=1
|
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 | GET |
(/v[[:digit:].]+)?/swarm |
SWARM=1 |
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 | POST |
(/v[[:digit:].]+)?/swarm/init |
SWARM=1 + POST=1
|
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 | POST |
(/v[[:digit:].]+)?/swarm/join |
SWARM=1 + POST=1
|
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 | POST |
(/v[[:digit:].]+)?/swarm/leave(\?[[:graph:]]+)? |
SWARM=1 + POST=1
|
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 | POST |
(/v[[:digit:].]+)?/swarm/update(\?[[:graph:]]+)? |
SWARM=1 + POST=1
|
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 | GET |
(/v[[:digit:].]+)?/swarm/unlockkey |
SWARM=1 |
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 | POST |
(/v[[:digit:].]+)?/swarm/unlock |
SWARM=1 + POST=1
|
Nodes are instances of the Engine participating in a swarm.
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 |
GET, POST, DELETE
|
(/v[[:digit:].]+)?/nodes((/|\?)[[:graph:]]+)? |
NODES=1 + POST=1
|
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 | GET |
(/v[[:digit:].]+)?/nodes(\?[[:graph:]]+)? |
NODES=1 |
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 | GET |
(/v[[:digit:].]+)?/nodes(/[[:word:]-.]+) |
NODES=1 |
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 | DELETE |
(/v[[:digit:].]+)?/nodes(/[[:word:]-.]+)(\?[[:graph:]]+)? |
NODES=1 + POST=1
|
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 | POST |
(/v[[:digit:].]+)?/nodes(/[[:word:]-.]+)/update(\?[[:graph:]]+)? |
NODES=1 + POST=1
|
Services are the definitions of tasks to run on a swarm.
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 |
GET, POST, DELETE
|
(/v[[:digit:].]+)?/services((/|\?)[[:graph:]]+)? |
SERVICES=1 + POST=1
|
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 | GET |
(/v[[:digit:].]+)?/services(\?[[:graph:]]+)? |
SERVICES=1 |
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 | POST |
(/v[[:digit:].]+)?/services/create |
SERVICES=1 + POST=1
|
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 | GET |
(/v[[:digit:].]+)?/services(/[[:word:]-.]+)(\?[[:graph:]]+)? |
SERVICES=1 |
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 | DELETE |
(/v[[:digit:].]+)?/services(/[[:word:]-.]+) |
SERVICES=1+ POST=1
|
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 | POST |
(/v[[:digit:].]+)?/services(/[[:word:]-.]+)/update(\?[[:graph:]]+)? |
SERVICES=1+ POST=1
|
Get
stdoutandstderrlogs from a service.
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 | GET |
(/v[[:digit:].]+)?/services(/[[:word:]-.]+)/logs(\?[[:graph:]]+)? |
SERVICES=1 |
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 | GET |
(/v[[:digit:].]+)?/tasks((/|\?)[[:graph:]]+)? |
TASKS=1 |
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 | GET |
(/v[[:digit:].]+)?/tasks(\?[[:graph:]]+)? |
TASKS=1 |
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 | GET |
(/v[[:digit:].]+)?/tasks(/[[:word:]-.]+) |
TASKS=1 |
Get
stdoutandstderrlogs from a task.
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 | GET |
(/v[[:digit:].]+)?/tasks(/[[:word:]-.]+)/logs(\?[[:graph:]]+)? |
TASKS=1 |
Secrets are sensitive data that can be used by services.
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 |
GET, POST, DELETE
|
(/v[[:digit:].]+)?/secrets((/|\?)[[:graph:]]+)? |
SECRETS=1 + POST=1
|
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 | GET |
(/v[[:digit:].]+)?/secrets(\?[[:graph:]]+)? |
SECRETS=1 |
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 | POST |
(/v[[:digit:].]+)?/secrets/create |
SECRETS=1 + POST=1
|
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 | GET |
(/v[[:digit:].]+)?/secrets(/[[:word:]-.]+) |
SECRETS=1 |
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 | DELETE |
(/v[[:digit:].]+)?/secrets(/[[:word:]-.]+) |
SECRETS=1 + POST=1
|
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 | POST |
(/v[[:digit:].]+)?/secrets(/[[:word:]-.]+)/update(\?[[:graph:]]+)? |
SECRETS=1 + POST=1
|
Configs are application configurations that can be used by services.
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 |
GET, POST, DELETE
|
(/v[[:digit:].]+)?/configs((/|\?)[[:graph:]]+)? |
CONFIGS=1 + POST=1
|
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 | GET |
(/v[[:digit:].]+)?/configs(\?[[:graph:]]+)? |
CONFIGS=1 |
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 | POST |
(/v[[:digit:].]+)?/configs/create |
CONFIGS=1 + POST=1
|
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 | GET |
(/v[[:digit:].]+)?/configs(/[[:word:]-.]+) |
CONFIGS=1 |
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 | DELETE |
(/v[[:digit:].]+)?/configs(/[[:word:]-.]+) |
CONFIGS=1 + POST=1
|
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 | POST |
(/v[[:digit:].]+)?/configs(/[[:word:]-.]+)/update(\?[[:graph:]]+)? |
CONFIGS=1 + POST=1
|
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 |
GET, POST, DELETE
|
(/v[[:digit:].]+)?/plugins((/|\?)[[:graph:]]+)? |
PLUGINS=1 + POST=1
|
Returns information about installed plugins.
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 | GET |
(/v[[:digit:].]+)?/plugins(\?[[:graph:]]+)? |
PLUGINS=1 |
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 | GET |
(/v[[:digit:].]+)?/plugins/privileges(\?[[:graph:]]+)? |
PLUGINS=1 |
Pulls and installs a plugin.
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 | POST |
(/v[[:digit:].]+)?/plugins/pull(\?[[:graph:]]+)? |
PLUGINS=1 + POST=1
|
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 | GET |
(/v[[:digit:].]+)?/plugins(/[[:word:]-.]+)/json |
PLUGINS=1 |
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 | DELETE |
(/v[[:digit:].]+)?/plugins(/[[:word:]-.]+)(\?[[:graph:]]+)? |
PLUGINS=1 + POST=1
|
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 | POST |
(/v[[:digit:].]+)?/plugins(/[[:word:]-.]+)/enable(\?[[:graph:]]+)? |
PLUGINS=1 + POST=1
|
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 | POST |
(/v[[:digit:].]+)?/plugins(/[[:word:]-.]+)/disable(\?[[:graph:]]+)? |
PLUGINS=1 + POST=1
|
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 | POST |
(/v[[:digit:].]+)?/plugins(/[[:word:]-.]+)/upgrade(\?[[:graph:]]+)? |
PLUGINS=1 + POST=1
|
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 | POST |
(/v[[:digit:].]+)?/plugins/create(\?[[:graph:]]+)? |
PLUGINS=1 + POST=1
|
Push a plugin to the registry.
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 | POST |
(/v[[:digit:].]+)?/plugins(/[[:word:]-.]+)/push(\?[[:graph:]]+)? |
PLUGINS=1 + POST=1
|
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 | POST |
(/v[[:digit:].]+)?/plugins(/[[:word:]-.]+)/set |
PLUGINS=1 + POST=1
|
Validate credentials for a registry and, if available, get an identity token for accessing the registry without password.
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 | POST |
(/v[[:digit:].]+)?/auth |
AUTH=1 + POST=1
|
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 | GET |
(/v[[:digit:].]+)?/info |
INFO=1 |
Returns the version of Docker that is running and various information about the system that Docker is running on.
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 | GET |
(/v[[:digit:].]+)?/version |
VERSION=1 |
This is a dummy endpoint you can use to test if the server is accessible.
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
v1.55 (GET) & v1.55 (HEAD)
|
GET, HEAD
|
(/v[[:digit:].]+)?/_ping |
PING=1 |
Stream real-time events from the server.
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 | GET |
(/v[[:digit:].]+)?/events(\?[[:graph:]]+)? |
EVENTS=1 |
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 | GET |
(/v[[:digit:].]+)?/system/df(\?[[:graph:]]+)? |
SYSTEM=1 |
Return image digest and platform information by contacting the registry.
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 | GET |
(/v[[:digit:].]+)?/distribution(/[[:word:]-.]+)/json |
DISTRIBUTION=1 |
v1.53: This endpoint is deprecated and will be removed in a future version.
Start a new interactive session with a server.
| API version | Methods | Regex | Equivalent |
|---|---|---|---|
| v1.55 | POST |
(/v[[:digit:].]+)?/session |
SESSION=1 + POST=1
|