> ## Documentation Index
> Fetch the complete documentation index at: https://docs.turen.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Docker MCP runtime

> Run managed self-hosted MCP services inside hardened containers

Docker is the default runtime for managed self-hosted MCP services. Local process execution is available only after explicit selection; the QEMU backend is a non-selectable preview.

<Note>
  Hosted HTTPS MCP integrations connect directly to their remote service. Docker applies to Extensions whose reviewed adapter supplies a self-hosted image and command.
</Note>

## Qualify Docker

1. Install and start Docker Desktop or Docker Engine.
2. Open **Settings → Servers**.
3. Find **MCP runtime**, select Docker, and choose **Test**.

Qualification verifies the Docker CLI, daemon, and required hardened launch flags. It does not pull or run an arbitrary probe image. A successful qualification expires after 24 hours.

```mermaid theme={null}
flowchart LR
  Settings[Settings / Servers] --> Test[Qualify Docker]
  Test --> Policy{Current qualification?}
  Policy -->|No| Block[Block launch]
  Policy -->|Yes| Manifest[Reviewed runtime policy]
  Manifest --> Pin[Verify sha256 image pin]
  Pin --> Harden[Apply hardened flags]
  Harden --> Stdio[MCP over stdio]
  Stdio --> Cleanup[Remove container]
```

## Container boundary

Each service receives an unpredictable `turen-mcp-*` name and reconciliation label. The launch contract requires:

* Image pinned by `sha256` digest
* No host network, mounts, Docker socket, or inherited host environment
* Read-only root filesystem
* All Linux capabilities dropped and `no-new-privileges`
* Non-root user `65532:65532`
* Limits of 128 processes, 512 MiB memory, and one CPU
* A 64 MiB `/tmp` tmpfs with `noexec` and `nosuid`
* MCP transport over stdin/stdout

Only secrets declared by the reviewed runtime policy are passed by environment-variable name. Diagnostics are bounded and redact secret values.

## Network policy

Containers run with `--network none`. Provider egress allowlisting is not implemented yet, so Docker-backed MCP services must declare no outbound hosts. Integrations that need a hosted API normally use the hosted HTTPS transport instead.

## Lifecycle and cleanup

Changing runtime settings invalidates active managed connections. Containers are removed when connections close, and TurenOS reconciles labeled leftovers after interrupted runs. Cleanup uses the qualified absolute Docker executable rather than a shell command.

## Local process fallback

Select **Local process** only for a trusted MCP executable you intentionally installed. TurenOS requires an absolute executable path, fixed safe arguments, restricted environment, project working directory, and timeout cleanup. Local process mode does not provide Docker's filesystem or process isolation.

## Troubleshooting

* **Unqualified**: choose **Test** before starting a managed server.
* **Unavailable**: install Docker or start its daemon.
* **Expired**: qualification is older than 24 hours; test again.
* **Blocked image**: the manifest must use a digest-pinned image.
* **Blocked network policy**: Docker MCP egress is not available yet.

<Warning>
  Docker improves containment but is not a perfect security boundary. Keep Docker updated and use only reviewed digest-pinned images.
</Warning>
