Docker & Containers — Level by Level›Level 4 · Cheat sheet & self-check

Level 4 — Daemon & certificates · wrap-up

Cheat sheet & self-check

Every command from this section on one page.

08 · Configuring the daemon: daemon.json

Edit safely

sudo cp /etc/docker/daemon.json /etc/docker/daemon.json.bakBack up before changing
sudo dockerd --validate --config-file /etc/docker/daemon.jsonCheck the file without starting a daemon (Engine 23.0+)
python3 -m json.tool /etc/docker/daemon.jsonQuick JSON syntax check on older engines
sudo systemctl reload dockerApply reloadable settings (SIGHUP) without stopping containers
sudo systemctl restart dockerApply everything (containers stop unless live-restore is on)

Verify

docker infoLogging driver, data root, mirrors, insecure registries, cgroup driver
docker info -f '{{.LoggingDriver}} {{.DockerRootDir}}'One or two fields
docker info -f '{{json .RegistryConfig}}' | python3 -m json.toolMirrors and insecure registries in effect
journalctl -u docker -n 50 --no-pagerWhy the daemon failed to start
systemctl cat dockerThe unit file and drop-ins (look for -H or --config flags)

09 · Registry certificates & the insecure bypass

Diagnose

openssl s_client -connect registry.lab.local:5000 -servername registry.lab.local -showcerts </dev/nullSee the certificate chain the registry actually sends
openssl x509 -in ca.crt -noout -subject -issuer -enddate -ext subjectAltNameWho issued it, when it expires, which names it covers
curl -v https://registry.lab.local:5000/v2/Does the host's trust store accept it?
docker info -f '{{json .RegistryConfig.IndexConfigs}}'Which registries the daemon treats as insecure

Trust one registry (Docker, no restart)

sudo mkdir -p /etc/docker/certs.d/registry.lab.local:5000Folder name = host:port exactly as in image names
sudo cp ca.crt /etc/docker/certs.d/registry.lab.local:5000/ca.crtCA (or self-signed cert) that signed the registry cert
sudo cp client.cert client.key /etc/docker/certs.d/registry.lab.local:5000/Client certificate for mutual TLS

Trust a CA system-wide (restart Docker after)

sudo cp corp-ca.crt /usr/local/share/ca-certificates/ && sudo update-ca-certificatesDebian / Ubuntu
sudo cp corp-ca.crt /etc/pki/ca-trust/source/anchors/ && sudo update-ca-trustRHEL / Rocky / Fedora
sudo cp corp-ca.crt /etc/pki/trust/anchors/ && sudo update-ca-certificatesSUSE / SLES

Bypass (labs only)

"insecure-registries": ["registry.lab.local:5000"]daemon.json: skip verification / allow HTTP for this registry, then reload
podman pull --tls-verify=false registry.lab.local:5000/app:1Podman, one command
skip_verify = truecontainerd hosts.toml, per registry host