Docker in workspaces
Raft development images include Docker daemon and CLI tooling running directly in the unprivileged container without mounting the host Docker socket.
Target workspace handle
Commands in this guide target a running workspace. Select one from raft list (see First working box):
raft list
box="lab:rf-a1b2c3d4e5f60718" # Replace with your actual workspace handleVerifying Docker status
Verify that the guest Docker daemon is initialized and responsive:
raft exec "$box" -- docker version
raft exec "$box" -- docker infoDaemon readiness verification
docker version and docker info query guest dockerd. Running docker --version checks only the client binary without testing daemon health.
Running containers
Run containers inside your workspace:
raft exec "$box" -- docker run --rm alpine uname -aStart background services inside the workspace:
raft exec "$box" -- docker run -d --name cache -p 6379:6379 redis:alpine
raft exec "$box" -- docker psBuilding container images
Build container images within the workspace:
raft exec "$box" -- bash -lc '
mkdir -p /workspace/app
cat << "EOF" > /workspace/app/Dockerfile
FROM alpine:latest
RUN echo "hello from workspace container" > /message.txt
CMD ["cat", "/message.txt"]
EOF
cd /workspace/app
docker build -t my-app .
docker run --rm my-app
'Managing disk space
Nested container layers and volumes reside on the shared 60 GiB raft-data Btrfs storage pool.
Prune dangling images without deleting active container data:
raft exec "$box" -- docker image prune -fData loss risk with system prune
Running docker system prune -af --volumes removes all stopped containers and unused volumes inside the workspace. Run full pruning only when you intend to discard local container state and caches.
Isolation and runtime limits
- Daemon confinement: The Docker daemon runs as a guest systemd unit using
/var/run/docker.sock. The host Docker daemon is never mounted. - Kernel sharing: Workspaces share the host Linux kernel without host kernel module or KVM access.
- Syscall interception: Incus sets
security.nesting=true,security.syscalls.intercept.mknod=true, andsecurity.syscalls.intercept.setxattr=trueto manage image layers safely in unprivileged user namespaces. - Shutdown behavior: Stopping a workspace with
raft stopstops guest processes and nested containers.