Level 4 — Daemon & certificates · wrap-up
Cheat sheet & self-check
Every command from this section on one page.
Edit safely
sudo cp /etc/docker/daemon.json /etc/docker/daemon.json.bak | Back up before changing |
sudo dockerd --validate --config-file /etc/docker/daemon.json | Check the file without starting a daemon (Engine 23.0+) |
python3 -m json.tool /etc/docker/daemon.json | Quick JSON syntax check on older engines |
sudo systemctl reload docker | Apply reloadable settings (SIGHUP) without stopping containers |
sudo systemctl restart docker | Apply everything (containers stop unless live-restore is on) |
Verify
docker info | Logging driver, data root, mirrors, insecure registries, cgroup driver |
docker info -f '{{.LoggingDriver}} {{.DockerRootDir}}' | One or two fields |
docker info -f '{{json .RegistryConfig}}' | python3 -m json.tool | Mirrors and insecure registries in effect |
journalctl -u docker -n 50 --no-pager | Why the daemon failed to start |
systemctl cat docker | The unit file and drop-ins (look for -H or --config flags) |
Diagnose
openssl s_client -connect registry.lab.local:5000 -servername registry.lab.local -showcerts </dev/null | See the certificate chain the registry actually sends |
openssl x509 -in ca.crt -noout -subject -issuer -enddate -ext subjectAltName | Who issued it, when it expires, which names it covers |
curl -v https://registry.lab.local:5000/v2/ | Does the host's trust store accept it? |
docker info -f '{{json .RegistryConfig.IndexConfigs}}' | Which registries the daemon treats as insecure |
Trust one registry (Docker, no restart)
sudo mkdir -p /etc/docker/certs.d/registry.lab.local:5000 | Folder name = host:port exactly as in image names |
sudo cp ca.crt /etc/docker/certs.d/registry.lab.local:5000/ca.crt | CA (or self-signed cert) that signed the registry cert |
sudo cp client.cert client.key /etc/docker/certs.d/registry.lab.local:5000/ | Client certificate for mutual TLS |
Trust a CA system-wide (restart Docker after)
sudo cp corp-ca.crt /usr/local/share/ca-certificates/ && sudo update-ca-certificates | Debian / Ubuntu |
sudo cp corp-ca.crt /etc/pki/ca-trust/source/anchors/ && sudo update-ca-trust | RHEL / Rocky / Fedora |
sudo cp corp-ca.crt /etc/pki/trust/anchors/ && sudo update-ca-certificates | SUSE / SLES |
Bypass (labs only)
"insecure-registries": ["registry.lab.local:5000"] | daemon.json: skip verification / allow HTTP for this registry, then reload |
podman pull --tls-verify=false registry.lab.local:5000/app:1 | Podman, one command |
skip_verify = true | containerd hosts.toml, per registry host |