Repository navigation
urnet docker
full-bars edited this page Aug 24, 2026
·
4 revisions
urnet-docker is the host-side CLI for managing provider Docker containers. It lives on the host, not inside a container. It identifies containers by the JWT inside them, runs commands through docker exec, and can update its own binary.
Install with the one-line installer:
curl -fSsL https://dl.fullbars.xyz/urnet-docker.sh | sh
# GitHub fallback: curl -fSsL https://raw.githubusercontent.com/full-bars/urnetwork-3.23-fix/main/scripts/install-urnet-docker.sh | sh| Command | What it does |
|---|---|
providers (list, ps) |
List all provider containers, identified by the in-container JWT. |
status [target] |
Detailed status of one container. |
exec [target flags] [--] <cmd...> |
Run a command inside the container. Target flags must come before the command. Use -- to forward inner flags verbatim. Example: urnet-docker exec --unit <name> -- urnet-tools proxy add --proxy_file=/tmp/p.txt. |
proxy add <file> |
Add proxies from a host proxy file. Copies the file into the container, then adds via the in-container tool. Example: urnet-docker proxy add ~/proxies.txt. |
proxy trim <N> [--preview] |
(New in 30.4) Set persistent hard cap of <N> running proxies in the targeted container. Sheds worst A-F reachability graded proxies first. proxy trim off clears the cap. |
proxy clear |
Remove all proxies for the targeted container. |
proxy remove [addresses...] [--match=pattern] [--all] |
Remove specific proxies, pattern matches, or all with --all. |
proxy add-source <url> |
Add a URL proxy source. |
proxy remove-source <url> |
Remove a URL proxy source. |
proxy refresh [--force] |
Re-read the proxy source without restarting. --force bypasses warmup lockout. |
proxy remove-dead |
Remove dead or degraded proxies. |
restart [target] |
Restart the container. |
update (self-update) |
Update the tool binary itself. Containers update by image pull, not by this command. Host-side only; never run inside a container. |
logs [target] [N] |
Follow the container logs (last N lines, default 250). RAMLOGS-aware: streams /dev/shm when RAM logs are enabled, else docker logs. Uses an interactive picker when multiple providers exist. |
version |
Print the tool version. |
Targeting flags are required when more than one provider container exists (both --flag value and --flag=value formats supported):
-
--unit <name>โ container name (mapped to the unit). -
--user <user>โ container identity (docker discovery sets this todocker:<containerName>). -
--network <name>โ JWT network name. -
--network-id <id>โ JWT network id, the unique identity. Use when two providers share the same network name. -
--state-dir <dir>โ provider state directory.
One container needs no flag. Multiple containers with no target is refused, never silently guessed.
The two tools split the provider world by how the provider runs:
-
urnet-toolsmanages systemd or native providers on the host. -
urnet-dockermanages containerized providers.
The same targeting concepts and safety model apply to both. See urnet-tools (Go) for the full tool reference.
-
execrefuses to run inside a container. It always operates from the host. -
proxysubcommands use the same targeting asexec: one container = automatic; multiple containers = interactive picker (requires a TTY) or explicit target flags (--unit,--network, etc.). Without a TTY and with multiple containers, the command refuses rather than guessing. - Targeting is explicit. A multi-container host with no target is refused.
-
updateis host-side only. It never touches containers.