Skip to content

Prerequisites

Working on the code instead of running it has its own toolchain, listed in Development setup.

  • A Docker socket, usually at /var/run/docker.sock. Podman’s rootless socket works too. See Podman.
  • Skopeo, required for remote image update detection. It is included in the production image; you only need it on the host for a source build.
  • Trivy is not required on the host: vulnerability scans run aquasec/trivy as a throwaway container.

The container image bundles docker-cli-compose, so the host does not need the Compose plugin either: stack operations run inside the container against the mounted socket.

The user running the server must be able to read and write the Docker socket: either a member of the docker group, or the owner of the rootless Podman socket. See Troubleshooting if you hit permission errors.

The socket is mounted read-only in the reference Compose file. That is enough for the Docker API, which takes its commands over the HTTP protocol spoken on the socket, not through writes to the file itself.

Kaio, built by Régis Gaidot