Explains how Docker run options provide configuration flexibility for containers managed by Application Manager.
A Docker run option is a container configuration parameter that
-
controls resource allocation such as CPU, memory, and networking
-
enables fine-tuning of security, health checks, and process behavior, and
-
allows customization during container launch for precise operation.
Docker run options are used in IOS-XR environments through the Application Manager (AppMgr). These options can be configured during the launch of a docker containerized application using the appmgr activate command. AppMgr oversees these containers and ensures runtime options can override default configurations for aspects like CPU, security, and health checks. Configuration is flexible: you can use CLI or Netconf, but all runtime options must be added under docker-run-opts as needed.
| Feature Name |
Release Information |
Description |
|---|---|---|
| Customize docker run options using application manager |
Release 25.4.1 |
Introduced in this release on: Fixed Systems (8010 [ASIC: A100])(select variants only*) *This feature is supported on:
|
| Customize docker run options using application manager |
Release 25.1.1 |
Introduced in this release on: Fixed Systems (8700 [ASIC: K100], 8010 [ASIC: A100])(select variants only*) *This feature is supported on:
|
| Customize docker run options using application manager |
Release 24.4.1 |
Introduced in this release on: Fixed Systems (8200 [ASIC: P100], 8700 [ASIC: P100])(select variants only*); Modular Systems (8800 [LC ASIC: P100])(select variants only*) *This feature is now supported on:
|
| Customize docker run options using application manager |
Release 24.1.1 |
You can now leverage Application Manager to efficiently overwrite default docker runtime configurations, tailoring them to specific parameters like CPU usage, security settings, and health checks. You can thus optimize application performance, maintain fair resource allocation among multiple dockers, and establish non-default network security settings to meet specific security requirements. Additionally, you can accurately monitor and reflect the health of individual applications. This feature modifies the docker-run-opts option command. |
| Docker run option |
Description |
|---|---|
| --cpus |
Number of CPUs |
| --cpuset-cpus |
CPUs in which to allow execution (0-3, 0,1) |
| --cap-drop |
Drop Linux capabilities |
| --user, -u |
Sets the username or UID |
| --group-add |
Add additional groups to run |
| --health-cmd |
Run to check health |
| --health-interval |
Time between running the check |
| --health-retries |
Consecutive failures needed to report unhealthy |
| --health-start-period |
Start period for the container to initialize before starting health-retries countdown |
| --health-timeout |
Maximum time to allow one check to run |
| --no-healthcheck |
Disable any container-specified HEALTHCHECK |
| --add-host |
Add a custom host-to-IP mapping (host:ip) |
| --dns |
Set custom DNS servers |
| --dns-opt |
Set DNS options |
| --dns-search |
Set custom DNS search domains |
| --domainname |
Container NIS domain name |
| --oom-score-adj |
Tune host's OOM preferences (-1000 to 1000) |
| --shm-size |
Option to set the size of /dev/shm |
| --init |
Run an init inside the container that forwards signals and reaps processes |
| --label, -l |
Set meta data on a container |
| --label-file |
Read in a line delimited file of labels |
| --pids-limit |
Tune container pids limit (set -1 for unlimited) |
| --work-dir |
Working directory inside the container |
| --ulimit |
Ulimit options |
| --read-only |
Mount the container's root filesystem as read only |
| --volumes-from |
Mount volumes from the specified container(s) |
| --stop-signal |
Signal to stop the container |
| --stop-timeout |
Timeout (in seconds) to stop a container |
| --cap-addNET_RAW |
Enable NET_RAW capabilities |
| --publish |
Publish a container's port(s) to the host |
| --entrypoint |
Overwrite the default ENTRYPOINT of the image |
| --expose |
Expose a port or a range of ports |
| --link |
Add link to another container |
| --env |
Set environment variables |
| --env-file |
Read in a file of environment variables |
| --network |
Connect a container to a network |
| --hostname |
Container host name |
| --interactive |
Keep STDIN open even if not attached |
| --tty |
Allocate a pseudo-TTY |
| --publish-all |
Publish all exposed ports to random ports |
| --volume |
Bind mount a volume |
| --mount |
Attach a filesystem mount to the container |
| --restart |
Restart policy to apply when a container exits |
| --cap-add |
Add Linux capabilities |
| --log-driver |
Logging driver for the container |
| --log-opt |
Log driver options |
| --detach |
Run container in background and print container ID |
| --memory |
Memory limit |
| --memory-reservation |
Memory soft limit |
| --cpu-shares |
CPU shares (relative weight) |
| --sysctl |
Sysctl options |