<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News - Newest: &#34;Docker&#34;</title><link>https://news.ycombinator.com/newest</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sun, 12 Apr 2026 17:42:52 +0000</lastBuildDate><atom:link href="https://hnrss.org/newest?q=Docker" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[Tell HN: docker pull fails in spain due to football cloudflare block]]></title><description><![CDATA[
<p>I just spent 1h+ debugging why my locally-hosted gitlab runner would fail to create pipelines. The gitlab job output would just display weird TLS errors when trying to pull a docker images. After debugging gitlab and the runner, I realized after a while I could not even run "docker pull <image>" on my machine as root:<p>> error pulling image configuration: download failed after attempts=6: tls: failed to verify certificate: x509: certificate is not valid for any names, but wanted to match docker-images-prod.6aa30f8b08e16409b46e0173d6de2f56.r2.cloudflarestorage.com<p>First blaming tailscale, dns configuration and all other stuff. Until I just copied that above URL into my browser on my laptop, and received a website banner:<p>> El acceso a la presente dirección IP ha sido bloqueado en cumplimiento de lo dispuesto en la Sentencia de 18 de diciembre de 2024, dictada por el Juzgado de lo Mercantil nº 6 de Barcelona en el marco del procedimiento ordinario (Materia mercantil art. 249.1.4)-1005/2024-H instado por la Liga Nacional de Fútbol Profesional y por Telefónica Audiovisual Digital, S.L.U.
https://www.laliga.com/noticias/nota-informativa-en-relacion-con-el-bloqueo-de-ips-durante-las-ultimas-jornadas-de-laliga-ea-sports-vinculadas-a-las-practicas-ilegales-de-cloudflare<p>For those non-spanish speakers: It means there is football match on, and during that time that specific host is blocked. This is just plain madness. I guess that means my gitlab pipelines will not run when football is on. Thank you, Spain.</p>
<hr>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47738883">https://news.ycombinator.com/item?id=47738883</a></p>
<p>Points: 335</p>
<p># Comments: 146</p>
]]></description><pubDate>Sun, 12 Apr 2026 12:28:57 +0000</pubDate><link>https://news.ycombinator.com/item?id=47738883</link><dc:creator>littlecranky67</dc:creator><comments>https://news.ycombinator.com/item?id=47738883</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47738883</guid></item><item><title><![CDATA[Show HN: Docker-whisper: Self-hosted Whisper speech-to-text server (OpenAI API)]]></title><description><![CDATA[
<p>Article URL: <a href="https://github.com/hwdsl2/docker-whisper">https://github.com/hwdsl2/docker-whisper</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47732384">https://news.ycombinator.com/item?id=47732384</a></p>
<p>Points: 6</p>
<p># Comments: 1</p>
]]></description><pubDate>Sat, 11 Apr 2026 17:31:23 +0000</pubDate><link>https://github.com/hwdsl2/docker-whisper</link><dc:creator>hwdsl2</dc:creator><comments>https://news.ycombinator.com/item?id=47732384</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47732384</guid></item><item><title><![CDATA[Docker and the Linux Kernel Isolate Your Agent, and Where They Don't]]></title><description><![CDATA[
<p>Article URL: <a href="https://timbreai.substack.com/p/how-docker-and-the-linux-kernel-isolate">https://timbreai.substack.com/p/how-docker-and-the-linux-kernel-isolate</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47679882">https://news.ycombinator.com/item?id=47679882</a></p>
<p>Points: 4</p>
<p># Comments: 2</p>
]]></description><pubDate>Tue, 07 Apr 2026 19:05:24 +0000</pubDate><link>https://timbreai.substack.com/p/how-docker-and-the-linux-kernel-isolate</link><dc:creator>bakibab</dc:creator><comments>https://news.ycombinator.com/item?id=47679882</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47679882</guid></item><item><title><![CDATA[We Spent €11/Month Testing Docker Swarm So You Don't Have To]]></title><description><![CDATA[
<p>Article URL: <a href="https://raus.cloud/blog/docker-swarm-test-11-euro-lesson/">https://raus.cloud/blog/docker-swarm-test-11-euro-lesson/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47676678">https://news.ycombinator.com/item?id=47676678</a></p>
<p>Points: 3</p>
<p># Comments: 2</p>
]]></description><pubDate>Tue, 07 Apr 2026 15:15:03 +0000</pubDate><link>https://raus.cloud/blog/docker-swarm-test-11-euro-lesson/</link><dc:creator>eduardosanzb</dc:creator><comments>https://news.ycombinator.com/item?id=47676678</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47676678</guid></item><item><title><![CDATA[Find the latest tag for Docker images]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.schlachter.xyz/projects/find-the-latest-tag-for-docker-images">https://www.schlachter.xyz/projects/find-the-latest-tag-for-docker-images</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47676639">https://news.ycombinator.com/item?id=47676639</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Tue, 07 Apr 2026 15:13:04 +0000</pubDate><link>https://www.schlachter.xyz/projects/find-the-latest-tag-for-docker-images</link><dc:creator>dddddaviddddd</dc:creator><comments>https://news.ycombinator.com/item?id=47676639</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47676639</guid></item><item><title><![CDATA[Running AI agents safely in a microVM using Docker sandbox]]></title><description><![CDATA[
<p>Article URL: <a href="https://andrewlock.net/running-ai-agents-safely-in-a-microvm-using-docker-sandbox/">https://andrewlock.net/running-ai-agents-safely-in-a-microvm-using-docker-sandbox/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47673147">https://news.ycombinator.com/item?id=47673147</a></p>
<p>Points: 3</p>
<p># Comments: 0</p>
]]></description><pubDate>Tue, 07 Apr 2026 10:42:34 +0000</pubDate><link>https://andrewlock.net/running-ai-agents-safely-in-a-microvm-using-docker-sandbox/</link><dc:creator>ingve</dc:creator><comments>https://news.ycombinator.com/item?id=47673147</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47673147</guid></item><item><title><![CDATA[Combine multiple Docker Compose files with profiles]]></title><description><![CDATA[
<p>Article URL: <a href="https://docs.docker.com/compose/how-tos/profiles">https://docs.docker.com/compose/how-tos/profiles</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47665931">https://news.ycombinator.com/item?id=47665931</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Mon, 06 Apr 2026 19:43:37 +0000</pubDate><link>https://docs.docker.com/compose/how-tos/profiles</link><dc:creator>nvahalik</dc:creator><comments>https://news.ycombinator.com/item?id=47665931</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47665931</guid></item><item><title><![CDATA[Show HN: DockerTab – Manage your Docker containers from iOS and Android]]></title><description><![CDATA[
<p>I built DockerTab to give developers a way to monitor and control their Docker hosts directly from their phones. You can start/stop containers, view live logs, and access the terminal without needing port forwarding.<p><pre><code>    The iOS app is available now: https://apps.apple.com/us/app/dockertab/id6759782246
    
    The Android version is currently in the testing phase. 

    I'd love to hear your feedback at support@dockertab.app</code></pre></p>
<hr>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47663862">https://news.ycombinator.com/item?id=47663862</a></p>
<p>Points: 2</p>
<p># Comments: 1</p>
]]></description><pubDate>Mon, 06 Apr 2026 17:17:10 +0000</pubDate><link>https://dockertab.app</link><dc:creator>coffee0748</dc:creator><comments>https://news.ycombinator.com/item?id=47663862</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47663862</guid></item><item><title><![CDATA[Docker Offload]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.docker.com/blog/docker-offload-now-generally-available-the-full-power-of-docker-for-every-developer-everywhere/">https://www.docker.com/blog/docker-offload-now-generally-available-the-full-power-of-docker-for-every-developer-everywhere/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47648638">https://news.ycombinator.com/item?id=47648638</a></p>
<p>Points: 29</p>
<p># Comments: 9</p>
]]></description><pubDate>Sun, 05 Apr 2026 12:23:10 +0000</pubDate><link>https://www.docker.com/blog/docker-offload-now-generally-available-the-full-power-of-docker-for-every-developer-everywhere/</link><dc:creator>redbell</dc:creator><comments>https://news.ycombinator.com/item?id=47648638</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47648638</guid></item><item><title><![CDATA[Dockhand: Docker Management Suite]]></title><description><![CDATA[
<p>Article URL: <a href="https://dockhand.pro/">https://dockhand.pro/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47647566">https://news.ycombinator.com/item?id=47647566</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Sun, 05 Apr 2026 09:17:21 +0000</pubDate><link>https://dockhand.pro/</link><dc:creator>indigodaddy</dc:creator><comments>https://news.ycombinator.com/item?id=47647566</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47647566</guid></item><item><title><![CDATA[How to Containerize a V Language Application with Docker]]></title><description><![CDATA[
<p>Article URL: <a href="https://oneuptime.com/blog/post/2026-02-08-how-to-containerize-a-v-language-application-with-docker/view">https://oneuptime.com/blog/post/2026-02-08-how-to-containerize-a-v-language-application-with-docker/view</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47635393">https://news.ycombinator.com/item?id=47635393</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Sat, 04 Apr 2026 03:28:27 +0000</pubDate><link>https://oneuptime.com/blog/post/2026-02-08-how-to-containerize-a-v-language-application-with-docker/view</link><dc:creator>baranul</dc:creator><comments>https://news.ycombinator.com/item?id=47635393</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47635393</guid></item><item><title><![CDATA[Show HN: Docker setup for Headscale (self-hosted Tailscale control server)]]></title><description><![CDATA[
<p>This provides a Docker-based setup for Headscale with minimal manual configuration. The Docker image is built automatically via GitHub Actions.<p>On first start it:<p>* Generates config<p>* Creates a pre-auth key<p>* Allows a client to connect within a few minutes<p>For non-Docker setups, there is also a simple install script: hwdsl2/headscale-install<p>That script is intended for a one-command VPS setup. It installs and configures Headscale with sensible defaults.<p>This follows the same approach as some of my earlier projects (e.g. docker-ipsec-vpn-server, setup-ipsec-vpn), focusing on making things work out of the box with minimal maintenance.<p>I’ve also been experimenting with related projects in the same space:<p>* docker-wireguard<p>* docker-openvpn<p>Feedback is welcome, especially from others running Headscale.</p>
<hr>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47634187">https://news.ycombinator.com/item?id=47634187</a></p>
<p>Points: 1</p>
<p># Comments: 1</p>
]]></description><pubDate>Sat, 04 Apr 2026 00:28:29 +0000</pubDate><link>https://github.com/hwdsl2/docker-headscale</link><dc:creator>hwdsl2</dc:creator><comments>https://news.ycombinator.com/item?id=47634187</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47634187</guid></item><item><title><![CDATA[Show HN: Run Claude Code autonomously inside your Docker Compose stack (OSS)]]></title><description><![CDATA[
<p>Claude Code's --dangerously-skip-permissions flag lets agents run without 
interruption, but it needs a sandboxed environment to be safe.<p>dangerously is an open source tool that spins up an isolated container 
and runs Claude Code inside it — file system changes are restricted to your 
project directory.<p>The new version detects your docker-compose.yml and spins up your full 
service stack alongside Claude Code, so the agent can test against real 
dependencies — databases, queues, whatever your app needs.<p>npm install -g dangerously</p>
<hr>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47631444">https://news.ycombinator.com/item?id=47631444</a></p>
<p>Points: 8</p>
<p># Comments: 0</p>
]]></description><pubDate>Fri, 03 Apr 2026 19:58:01 +0000</pubDate><link>https://github.com/sayil/dangerously</link><dc:creator>sayil</dc:creator><comments>https://news.ycombinator.com/item?id=47631444</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47631444</guid></item><item><title><![CDATA[Show HN: Docker Alternative for Secure Microvms]]></title><description><![CDATA[
<p><a href="https://github.com/herd-core/herd" rel="nofollow">https://github.com/herd-core/herd</a><p>Lately, I have been trying to understand the security aspect of docker containers, and what I have realized is that all docker containers share the host's kernel. Any zero day vulneerability in the kernel can be used to gain access to the host os.<p>In order to deal with this, I did some research turns out Amazon has open sourced the core technology behind their serverless technology lambda. But in its current state its very hard to setup, let alone run anything securly. This technology is called firecracker microvm's<p>It started off as a go library, for creating process pools to just do a simple firecracker spawn, turned into a full fledged host side daemon.<p>deploying a microvm through an image is now as simple as running<p>`herd deploy --image postgres:latest -p 5432:5432 -e POSTGRES_PASSWORD=postgres`<p>with boot times ~500ms<p>That brings us to today. I am looking for people to test this out and provide some feedback, I have been warned/cautioned by a lot of friends that building in isolation is a recipe for disaster.<p>PS: it only works on linux, macos doesn't have the required isolation, and I stopped caring about winslop.</p>
<hr>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47630810">https://news.ycombinator.com/item?id=47630810</a></p>
<p>Points: 4</p>
<p># Comments: 2</p>
]]></description><pubDate>Fri, 03 Apr 2026 19:11:25 +0000</pubDate><link>https://news.ycombinator.com/item?id=47630810</link><dc:creator>sankalpnarula</dc:creator><comments>https://news.ycombinator.com/item?id=47630810</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47630810</guid></item><item><title><![CDATA[Hosting your own email with Docker (is easy)]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.drcoen.com/2026/04/hosting-your-own-email-with-docker/">https://www.drcoen.com/2026/04/hosting-your-own-email-with-docker/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47616379">https://news.ycombinator.com/item?id=47616379</a></p>
<p>Points: 7</p>
<p># Comments: 0</p>
]]></description><pubDate>Thu, 02 Apr 2026 16:12:16 +0000</pubDate><link>https://www.drcoen.com/2026/04/hosting-your-own-email-with-docker/</link><dc:creator>eclipse31</dc:creator><comments>https://news.ycombinator.com/item?id=47616379</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47616379</guid></item><item><title><![CDATA[API Middleware – self-hosted API gateway with DLP scanning (PHP/Laravel, Docker)]]></title><description><![CDATA[
<p>Article URL: <a href="https://github.com/joshiabir/theapimiddleware">https://github.com/joshiabir/theapimiddleware</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47613861">https://news.ycombinator.com/item?id=47613861</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Thu, 02 Apr 2026 12:58:48 +0000</pubDate><link>https://github.com/joshiabir/theapimiddleware</link><dc:creator>joshiabir</dc:creator><comments>https://news.ycombinator.com/item?id=47613861</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47613861</guid></item><item><title><![CDATA[Docker in Docker]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.docker.com/resources/docker-in-docker-containerized-ci-workflows-dockercon-2023/">https://www.docker.com/resources/docker-in-docker-containerized-ci-workflows-dockercon-2023/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47599233">https://news.ycombinator.com/item?id=47599233</a></p>
<p>Points: 3</p>
<p># Comments: 0</p>
]]></description><pubDate>Wed, 01 Apr 2026 11:00:40 +0000</pubDate><link>https://www.docker.com/resources/docker-in-docker-containerized-ci-workflows-dockercon-2023/</link><dc:creator>seyz</dc:creator><comments>https://news.ycombinator.com/item?id=47599233</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47599233</guid></item><item><title><![CDATA[Show HN: HolyCode – OpenCode in Docker. Use your Claude subscription. 30 tools]]></title><description><![CDATA[
<p>HolyCode is a Docker image that wraps OpenCode (<a href="https://opencode.ai" rel="nofollow">https://opencode.ai</a>), an AI coding agent with a web UI. It ships with 30+ dev tools pre-installed, a headless Chromium/Xvfb/Playwright stack, s6-overlay for process supervision, and UID/GID remapping for correct file permissions on bind mounts.<p>The main problem it solves: rebuilding the same environment every time you switch machines or update a container. All OpenCode state (sessions, settings, MCP configs, plugins) lives in a bind mount outside the container. Rebuild or update the image, your state comes back.<p>*On the API key cost angle:*<p>If you pay for Claude Max or Pro, you can use those credentials directly instead of a separate Anthropic API key. One env var enables it. The plugin reads from the credentials file OpenCode stores on your host. This removes a layer of cost if you're already paying for a subscription.<p>Note: this may be outside what Anthropic's ToS covers. The README is explicit about that.<p>It supports 10+ AI providers (Anthropic, OpenAI, Gemini, Groq, Bedrock, Azure, Ollama, and more). The Claude subscription feature is optional. Set any provider key and it works.<p>oh-my-openagent is also included as an optional plugin (`ENABLE_OH_MY_OPENAGENT=true`). It turns OpenCode into a coordinated multi-agent system with parallel execution and specialized agents.<p>GitHub: <a href="https://github.com/coderluii/holycode" rel="nofollow">https://github.com/coderluii/holycode</a>
Docker Hub: <a href="https://hub.docker.com/r/coderluii/holycode" rel="nofollow">https://hub.docker.com/r/coderluii/holycode</a></p>
<hr>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47584308">https://news.ycombinator.com/item?id=47584308</a></p>
<p>Points: 2</p>
<p># Comments: 1</p>
]]></description><pubDate>Tue, 31 Mar 2026 08:29:46 +0000</pubDate><link>https://github.com/CoderLuii/HolyCode</link><dc:creator>CoderLuii</dc:creator><comments>https://news.ycombinator.com/item?id=47584308</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47584308</guid></item><item><title><![CDATA[Blocking Traffic to Docker Containers]]></title><description><![CDATA[
<p>Article URL: <a href="https://blog.feld.me/posts/2026/03/blocking-traffic-docker/">https://blog.feld.me/posts/2026/03/blocking-traffic-docker/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47577577">https://news.ycombinator.com/item?id=47577577</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Mon, 30 Mar 2026 17:57:42 +0000</pubDate><link>https://blog.feld.me/posts/2026/03/blocking-traffic-docker/</link><dc:creator>speckx</dc:creator><comments>https://news.ycombinator.com/item?id=47577577</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47577577</guid></item><item><title><![CDATA[Immich on Android without Docker or root]]></title><description><![CDATA[
<p>Article URL: <a href="https://github.com/Gennyi07/immich-native-android">https://github.com/Gennyi07/immich-native-android</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47573707">https://news.ycombinator.com/item?id=47573707</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Mon, 30 Mar 2026 12:58:55 +0000</pubDate><link>https://github.com/Gennyi07/immich-native-android</link><dc:creator>Genny_07</dc:creator><comments>https://news.ycombinator.com/item?id=47573707</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47573707</guid></item></channel></rss>