Jesse-njx/dsh-docker

Typed, guarded container control: ps/logs/inspect/exec/start/stop and compose up/down with JSON output, project-aware targeting, and approval-gated destructive ops.

dsh-docker is typed, guarded container control for DSH: it wraps the docker CLI through the ctx.shell seam and gives the agent a structured, project-aware surface — every tool returns canonical JSON (docker_ps/logs/inspect/exec/start/stop/restart/rm plus compose-aware variants), never scraped prose. Destructive operations (rm -f on a running container, rmi on an image in use, system prune, compose down -v) pause and route to the human approval gate with an allow-once token; a denied or unavailable approval refuses the operation, and a monotonic ctx.tools.guard() backstop means no later listener can undo a denial. docker_exec is read-only by default (execReadOnly on): writeful or interactive exec is reclassified into the approval bucket. Ref-based commands are scoped to the detected compose project, so stop dev-api means your local compose service, not a coincidentally-named container.

Tools & Capabilities ★ 1 updated 2026-08-13
View on GitHub ↗

Install

dsh plugin --profile web add github:Jesse-njx/dsh-docker

README EN verified 2026-09-02 (repo Jesse-njx/dsh-docker). Install per README: dsh plugin --profile web add github:Jesse-njx/dsh-docker (npm @dsh-docker/bundle 404 verified — the registry line is labeled 'when published'). Install into whichever profile your agents run under (web for the desktop UI, headless for CLI sessions). The bundle mounts the tools, the policy, the opt-in health context, and the web status renderer.

Compatibility

DSH web or headless profile; wraps the docker CLI through the ctx.shell seam; approval gate via ctx.approval (fails closed).

Details

Recent updates

Typed structured-JSON docker tools; project-aware refs; approval-gated destructive ops (fails closed, allow-once); execReadOnly default; monotonic guard backstop; compose support.

FAQ

Which operations require approval?
Destructive ones — rm -f on a running container, rmi on an image still in use, system prune -a, compose down -v, and any writeful/interactive docker_exec. Reads are free.
What happens if no approval channel exists?
The operation is refused: the gate fails closed, and the monotonic guard backstop means no later listener can undo the denial.
Is docker_exec always dangerous?
No — execReadOnly is on by default, so exec without write/interactive never prompts; adding write/interactive reclassifies it into the approval bucket.

Alternatives

stardustlc666/dsh-docker

More plugins in Tools & Capabilities

Browse more in Tools & Capabilities

Guides for Tools & Capabilities plugins