Define and run multi-container applications with Docker https://docs.docker.com/compose/
Find a file
Nicolas De Loof 95929928c1
Some checks failed
ci / validate (lint) (push) Has been cancelled
ci / validate (relay-lint) (push) Has been cancelled
ci / validate (relay-test) (push) Has been cancelled
ci / validate (validate-docs) (push) Has been cancelled
ci / validate (validate-go-mod) (push) Has been cancelled
ci / validate (validate-headers) (push) Has been cancelled
ci / validate (validate-mocks) (push) Has been cancelled
ci / binary (push) Has been cancelled
ci / bin-image-test (push) Has been cancelled
ci / relay-image-test (push) Has been cancelled
ci / test (push) Has been cancelled
ci / e2e (plugin, oldstable, graphdriver) (push) Has been cancelled
ci / e2e (standalone, oldstable, graphdriver) (push) Has been cancelled
ci / e2e (plugin, stable, containerd) (push) Has been cancelled
ci / e2e (plugin, stable, graphdriver) (push) Has been cancelled
ci / e2e (standalone, stable, containerd) (push) Has been cancelled
ci / e2e (standalone, stable, graphdriver) (push) Has been cancelled
merge / bin-image-prepare (push) Has been cancelled
merge / relay-image (push) Has been cancelled
merge / module-image (push) Has been cancelled
Scorecards supply-chain security / Scorecards analysis (push) Has been cancelled
zizmor / zizmor (push) Has been cancelled
ci / binary-finalize (push) Has been cancelled
ci / coverage (push) Has been cancelled
ci / release (push) Has been cancelled
merge / bin-image (push) Has been cancelled
fix(provider): drop the relay's capabilities to the strict minimum
The relay only dials an upstream and forwards bytes: it needs none of
Docker's default Linux capabilities. Run it with CapDrop: ["ALL"],
keeping only NET_BIND_SERVICE back via CapAdd since a route commonly
targets a privileged port (e.g. 80, 443) that the relay -- running
unprivileged as UID 65532 -- must still be able to listen on inside
its own container.

Validated end-to-end against a real provider project: a container on
the relay's network reaches the provider through its published, low
port with the hardened capability set in place.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Signed-off-by: Nicolas De Loof <nicolas.deloof@gmail.com>
2026-09-17 17:51:23 +02:00
.github ci: lint, vet and test relay/ as its own module 2026-09-17 09:23:54 +02:00
cmd fix(port): preserve tie order for dual-stack port publishers 2026-09-14 10:48:03 +02:00
desktop-module build and push Docker Desktop module image on release 2026-04-10 16:12:09 +02:00
docs docs: dedicated section for compose-native addressing via publish-endpoint 2026-09-16 17:03:23 +02:00
internal fix(publish): report OCI fallback as a bool, not the OCI version 2026-09-15 14:54:03 +02:00
pkg fix(provider): drop the relay's capabilities to the strict minimum 2026-09-17 17:51:23 +02:00
relay ci: lint, vet and test relay/ as its own module 2026-09-17 09:23:54 +02:00
.dockerignore Better sandboxed workflow and enhanced cross compilation 2022-08-12 15:05:58 +02:00
.gitattributes Removed test requiring linux containers 2020-06-11 12:58:58 +02:00
.gitignore distinguish event (short) status text and details 2025-11-04 10:18:55 +01:00
.go-version Update to go1.26.8 2026-09-02 18:44:40 +02:00
.golangci.yml golangci-lint: enable perfsprint linter 2026-09-10 10:25:34 +02:00
AGENTS.md test(e2e): gate the e2e suite behind the build tag the docs already promise 2026-08-27 11:02:07 +02:00
BUILDING.md Add go as a prerequesite in build instructions 2025-08-06 15:27:09 +02:00
CLAUDE.md docs: adopt AGENTS.md standard, symlink CLAUDE.md to it 2026-07-21 17:43:06 +02:00
codecov.yml ci: merge Go coverage reports before upload (#10666) 2023-06-08 14:58:21 -04:00
CONTRIBUTING.md docs(contributing): legibility guidelines — comments state behavior, not history 2026-08-27 11:17:14 +02:00
docker-bake.hcl ci: lint, vet and test relay/ as its own module 2026-09-17 09:23:54 +02:00
Dockerfile Update to go1.26.8 2026-09-02 18:44:40 +02:00
go.mod build(deps): github.com/docker/cli v29.8.0 2026-09-15 11:56:34 +02:00
go.sum build(deps): github.com/docker/cli v29.8.0 2026-09-15 11:56:34 +02:00
LICENSE Add LICENSE and NOTICE files 2020-08-17 10:20:49 +02:00
logo.png move compose-cli code into docker/compose/v2 2021-08-31 19:09:19 +02:00
Makefile ci: lint, vet and test relay/ as its own module 2026-09-17 09:23:54 +02:00
NOTICE move compose-cli code into docker/compose/v2 2021-08-31 19:09:19 +02:00
README.md README: remove Go Report Card badge 2026-07-16 11:39:14 +02:00

Table of Contents

Docker Compose

GitHub release PkgGoDev Build Status Codecov OpenSSF Scorecard Docker Compose

Docker Compose is a tool for running multi-container applications on Docker defined using the Compose file format. A Compose file is used to define how one or more containers that make up your application are configured. Once you have a Compose file, you can create and start your application with a single command: docker compose up.

Note

Docker Swarm used to rely on the legacy compose file format but did not adopt the compose specification so is missing some of the recent enhancements in the compose syntax. After acquisition by Mirantis swarm isn't maintained by Docker Inc, and as such some Docker Compose features aren't accessible to swarm users.

Where to get Docker Compose

Windows and macOS

Docker Compose is included in Docker Desktop for Windows and macOS.

Linux

You can download Docker Compose binaries from the release page on this repository.

Rename the relevant binary for your OS to docker-compose and copy it to $HOME/.docker/cli-plugins

Or copy it into one of these folders to install it system-wide:

  • /usr/local/lib/docker/cli-plugins OR /usr/local/libexec/docker/cli-plugins
  • /usr/lib/docker/cli-plugins OR /usr/libexec/docker/cli-plugins

(might require making the downloaded file executable with chmod +x)

Quick Start

Using Docker Compose is a three-step process:

  1. Define your app's environment with a Dockerfile so it can be reproduced anywhere.
  2. Define the services that make up your app in compose.yaml so they can be run together in an isolated environment.
  3. Lastly, run docker compose up and Compose will start and run your entire app.

A Compose file looks like this:

services:
  web:
    build: .
    ports:
      - "5000:5000"
    volumes:
      - .:/code
  redis:
    image: redis

Contributing

Want to help develop Docker Compose? Check out our contributing documentation.

If you find an issue, please report it on the issue tracker.

Legacy

The Python version of Compose is available under the v1 branch.