Repository navigation
Releases: friendlygeorge/docker-mcp-server
Release list
v0.4.0 — Registry, Security, Context
What's New
8 new tools bringing total from 42 to 50:
Registry Operations
registry_login— Authenticate with Docker Hub, ECR, ACR, GCRregistry_search— Search Docker Hub for imagesregistry_push— Push images to registries
Security Scanning
scan_image— Scan Docker images for CVEs using Trivyvulnerability_report— Detailed report with remediation recommendations
Context Management
list_contexts— List available Docker contextsuse_context— Switch between local/remote Docker hostsinspect_context— Inspect context configurations
Changes
- Tier 1 features from roadmap
- All tools verified: TypeScript compiles clean, wrangler dry-run passes
v0.3.5 — Prune, Resource Limits & Glama Quality A
What's New
prune_containers— Remove stopped containers with label filtersprune_images— Remove unused images (dangling + unreferenced)update_container— Update CPU/memory limits on running containers- Improved tool descriptions for Glama Quality A optimization
- GitHub Actions CI workflow (Node 18/20/22)
relatedServersadded to glama.json
v0.3.4 -- File Transfer Tools
What's New
Container File Transfer (2 new tools)
- copy_from_container — Read files from running containers using docker exec. Returns content, size, and permissions.
- copy_to_container — Write files into containers at any path. Supports custom file permissions.
Technical Details
- 39 total tools (was 37)
- copy_from uses docker exec cat (reliable, no tar parsing)
- copy_to uses putArchive with hand-crafted TAR format
- 9 new tests, 78 total passing
- TypeScript compiles clean
v0.3.3 — System Info & Disk Usage
v0.3.3 — System Info & Disk Usage (June 13, 2026)
New Tools
- docker_info — Docker daemon system information: server version, OS, kernel, CPU count, memory, storage driver, container/image counts
- disk_usage — Disk usage breakdown by images, containers, volumes, and build cache with human-readable sizes
Stats
- 37 total tools
- 69 tests passing
- TypeScript compiles clean
v0.3.2: Retry with Exponential Backoff
What Changed
Retry with Exponential Backoff
- withRetry wrapper — all Docker API calls now retry on transient errors (ECONNRESET, ETIMEDOUT, socket hang up, 5xx)
- Smart error classification — 4xx errors (not found, permission denied) are NOT retried; connection timeouts ARE retried
- Exponential backoff — 1s -> 2s -> 4s, max 3 retries, with stderr logging for debugging
- 10 new tests — dedicated retry test suite covering transient errors, permanent errors, and retry exhaustion
Why This Matters
Production MCP servers face transient Docker API failures (daemon busy, network blips, socket resets). Without retry, a single transient error kills the entire tool call. With retry, the server self-heals on 3/4 of common failure modes.
Files Changed
src/docker.ts— added withRetry, isRetryableErrorsrc/tools/container.ts— wrapped listContainers, inspect, start, stop, restart, removesrc/tools/image.ts— wrapped listImagessrc/tools/health.ts— wrapped container inspectsrc/tools/network.ts— wrapped listNetworkssrc/tools/volume.ts— wrapped createVolumesrc/tools/logs.ts— wrapped container logstests/retry.test.ts— 10 new tests
Test Results
62/62 tests passing (52 original + 10 new retry tests)
v0.3.1 — Error Handling Hardening
v0.3.1 — Error Handling Hardening
Based on production error handling research (backlog item #108).
Added
- Startup health check: Verifies Docker daemon is reachable before starting the server. Clear error messages for common failures (permission denied, socket not found, daemon not running).
- Configurable timeout:
withTimeout()wrapper prevents indefinite hangs on slow Docker API calls. Default 30s, configurable viaServerOptions. - Structured error classes:
DockerConnectionError(non-retryable),DockerTimeoutError(retryable),DockerPermissionError(non-retryable). Helps AI clients decide whether to retry or report. - Enhanced formatError(): Now recognizes structured error types for cleaner output.
Fixed
- Tool error responses now include structured context (error type, retryable flag) instead of plain strings.
Tests
- 52 tests passing (container, image, volume, monitoring)
- TypeScript compiles clean
v0.3.0 — Volume Management + sanitizeOutput fix
What's New
Volume Management (4 tools)
create_volume— Create Docker volumes with driver options and labelsinspect_volume— Get detailed volume information (driver, mountpoint, labels, scope)remove_volume— Remove volumes (with force option)prune_volumes— Remove all unused volumes to free disk space
Bug Fixes
- Fixed sanitizeOutput Unicode regex that was corrupting log output. The regex
/[\uE0001-\uE007F]/was invalid — interpreted as a range covering ALL characters including ASCII, causingsearch_logsand monitoring tools to fail. Fixed with proper Unicode escapes and theuflag. - Fixed test mocks in monitoring.test.ts and image.test.ts to match the 5-arg tool registration signature (added MCP annotations parameter).
Tool Count
35 tools total (31 existing + 4 volume management)
Testing
All 52 tests passing (4 test files).
v0.2.5: Security Hardening
Security Hardening Release
Changes
- Input validation (8.1): exec_in_container command/working_dir/env regex validation
- Path validation (8.2): build_image context path rejects URLs, enforces absolute local paths
- Output sanitization (8.3): sanitizeOutput helper strips ANSI escapes, invisible Unicode, Docker stream headers
- Size caps (8.4): logs 100KB, general 1MB, schema bounds on tail/pattern/containers
- Timeout caps (8.6): watch_health 600s, watch_events 300s
- Security policy (8.8): SECURITY.md with threat model and disclosure process
- README expansion (8.10): Threat model, hardening details, SECURITY.md link
Security Notes
This release implements 6 findings from a security audit. All tool inputs are now validated against allowlists. Output is sanitized to prevent injection attacks. Resource consumption is bounded.
v0.2.4 — MCP annotations + TDQS optimization
Changes
- Added MCP protocol annotations (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to all 31 tools
- Rewrote 3 C-grade tool descriptions (compose_logs, restart_container, stream_logs) for Glama Quality B→A improvement
- Added monitoring tool descriptions with TDQS-optimized format (verb+resource, sibling diff, return format, failure mode)
Impact
- Glama Quality score should improve from B to A after re-indexing
- All tools now have proper MCP annotations for behavioral transparency
- Tool descriptions follow the 30-80 word optimal range per TDQS research
v0.1.6 — Auto-pull missing images
What's New
Auto-pull missing images in run_container
When run_container is called with an image that isn't available locally, the server now automatically pulls it from the registry before creating the container. This matches the UX of docker run which auto-pulls missing images.
Before: Error "no such image" requiring manual pull_image first.
After: Seamless experience — just specify the image and it works.
Bug Fixes
- BUG-3 (E2E testing):
run_containernow auto-pulls missing images (HTTP 404 → pull → retry)
Stats
- 20/20 unit tests pass
- 25 tools registered
- All prior bug fixes included (compose path, stop_container 304)