Skip to main content
Docker is the default runtime for managed self-hosted MCP services. Local process execution is available only after explicit selection; the QEMU backend is a non-selectable preview.
Hosted HTTPS MCP integrations connect directly to their remote service. Docker applies to Extensions whose reviewed adapter supplies a self-hosted image and command.

Qualify Docker

  1. Install and start Docker Desktop or Docker Engine.
  2. Open Settings → Servers.
  3. Find MCP runtime, select Docker, and choose Test.
Qualification verifies the Docker CLI, daemon, and required hardened launch flags. It does not pull or run an arbitrary probe image. A successful qualification expires after 24 hours.

Container boundary

Each service receives an unpredictable turen-mcp-* name and reconciliation label. The launch contract requires:
  • Image pinned by sha256 digest
  • No host network, mounts, Docker socket, or inherited host environment
  • Read-only root filesystem
  • All Linux capabilities dropped and no-new-privileges
  • Non-root user 65532:65532
  • Limits of 128 processes, 512 MiB memory, and one CPU
  • A 64 MiB /tmp tmpfs with noexec and nosuid
  • MCP transport over stdin/stdout
Only secrets declared by the reviewed runtime policy are passed by environment-variable name. Diagnostics are bounded and redact secret values.

Network policy

Containers run with --network none. Provider egress allowlisting is not implemented yet, so Docker-backed MCP services must declare no outbound hosts. Integrations that need a hosted API normally use the hosted HTTPS transport instead.

Lifecycle and cleanup

Changing runtime settings invalidates active managed connections. Containers are removed when connections close, and TurenOS reconciles labeled leftovers after interrupted runs. Cleanup uses the qualified absolute Docker executable rather than a shell command.

Local process fallback

Select Local process only for a trusted MCP executable you intentionally installed. TurenOS requires an absolute executable path, fixed safe arguments, restricted environment, project working directory, and timeout cleanup. Local process mode does not provide Docker’s filesystem or process isolation.

Troubleshooting

  • Unqualified: choose Test before starting a managed server.
  • Unavailable: install Docker or start its daemon.
  • Expired: qualification is older than 24 hours; test again.
  • Blocked image: the manifest must use a digest-pinned image.
  • Blocked network policy: Docker MCP egress is not available yet.
Docker improves containment but is not a perfect security boundary. Keep Docker updated and use only reviewed digest-pinned images.