delonix container
Ciclo de vida de containers: run, ps, start, stop, rm, exec, logs, inspect, stats, apply.
Container lifecycle: run, ps, start, stop, rm, exec, logs, inspect, stats, apply.
O grupo container é o dia a dia do runtime — o homólogo do
docker container. Cada invocação é um processo efémero (sem daemon): o
run faz clone() directo com os namespaces pedidos e o estado fica em
JSON no $DELONIX_ROOT. Em rootless, o rootfs é um overlay montado dentro do user
namespace do próprio container: as layers da imagem são partilhadas entre todos os containers e
cada um tem a sua camada de escrita persistente — as escritas sobrevivem a
stop/start, como no Docker.
The container group is the runtime's everyday surface — the
counterpart to docker container. Each invocation is an ephemeral process (no daemon):
run does a direct clone() with the requested namespaces and the state
lands as JSON under $DELONIX_ROOT. In rootless mode, the rootfs is an overlay mounted
inside the container's own user namespace: the image layers are shared by every container, and
each one has its own persistent writable layer — writes survive
stop/start, just like in Docker.
📄 Implementação real em Rust: cmd/container.rs
Usage: delonix container [OPTIONS] <COMMAND>
Commands:
kill Send a signal to one or more containers (default SIGKILL)
pause Suspend a container's processes (cgroup v2 freezer)
restart Stop then start one or more containers
rm Remove one or more containers
run Run a container from an image (pulls it if missing)
start (Re)start stopped/crashed containers. Always detached
stop Stop one or more containers (SIGTERM, then SIGKILL)
unpause Resume a container suspended with `pause`
wait Block until one or more containers exit, then print their exit code (one per line, in the order given)
describe Human-readable detail of one or more containers, `kubectl describe`-style
diff Files changed relative to the image: `A` = created/changed, `D` = deleted
healthcheck Run the image's `HEALTHCHECK` inside the container. Exits with 1 if `unhealthy` — usable in a script/CI
inspect Show the full spec of one or more containers (Store JSON)
logs Show the logs (detached containers)
port Published ports of a container (`hostPort/proto -> containerPort`)
ps List containers [alias: ls]
stats Resource usage (CPU/memory/PIDs) of the running containers
top Processes running inside a container (read from `cgroup.procs`)
attach Re-attach to a running container's output stream (output only)
commit Create an image from a container's CURRENT rootfs state (whatever was written inside becomes a new layer)
cp Copy files between the host and a container
exec Execute a command inside a running container
rename Give a container a new name
update **Reconfigure a RUNNING container without stopping it** — ports, volumes, and bandwidth cap
apply Apply the `kind: Container` documents of a manifest (idempotent by name)
init Initialize a project with a Delonixfile + manifest
prune Remove every stopped container and the rootfs debris they left behind
help Print this message or the help of the given subcommand(s)
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
COMMAND MAP:
Lifecycle run · start · stop · kill · wait · restart · rm · pause · unpause
Inspect ps · port · healthcheck · top · diff · inspect · describe · stats · logs
Interact commit · cp · exec · attach
Configure rename · update
Declarative init · apply
Maintenance prune
EXAMPLES:
# a web service in seconds — host port 8080 onto the container's 80
delonix container run -d -p 8080:80 --name web nginx
# what is running, and for how long
delonix container ps
# a shell inside it, without stopping anything
delonix container exec -it web
SEE ALSO:
delonix pod · delonix image · delonix workload · delonix compose up
delonix › containercontainer run
Run a container from an image (pulls it if missing)
Usage: delonix container run [OPTIONS] <IMAGE> [COMMAND]...
Arguments:
<IMAGE>
Image (e.g. `alpine:3.19`)
[COMMAND]...
Command + arguments (default: the image's ENTRYPOINT/CMD)
Options:
-d, --detach
Run in the background and print the ID
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
--name <NAME>
Container name (default: `dlx-<id>`)
--hostname <HOSTNAME>
Hostname inside the container (UTS namespace + `/etc/hostname`). Default: the container name (docker `--hostname`)
-u, --user <USER>
Run the process as this user: `uid[:gid]` or `name[:group]` (docker `--user`). Names are resolved in the image's `/etc/passwd`/`/etc/group`
--net <NET>
Network: `host` (shares the host's, default), `none` (isolated netns with no connectivity), or the NAME of a network created with `delonix network create`
[default: host]
--namespace <NAMESPACE>
Logical ISOLATION namespace (default `default`). Containers in different namespaces cannot reach each other (even on the same network); only a `kind: Dependency` crosses the boundary
--expose <EXPOSE>
Auto-register this container's HTTP port in the L7 proxy under its internal FQDN `<name>.<namespace>.delonix.internal` (reachable via the proxy). Needs `--net <network>`. Removed automatically on `container rm`
-v, --volume <VOLUMES>
Volume/bind mount, `name:/target[:ro]` or `/host:/target[:ro]`. Repeatable
-p, --publish <PUBLISH>
Publish a port, `[hostIp:]hostPort:contPort[/tcp|udp]` or just `port`. Repeatable. SAFE BY DEFAULT: without `hostIp` the port binds to `127.0.0.1` only — reachable from the host itself, NOT from a browser on another machine. Name the address to widen it: `0.0.0.0:8080:80` (every interface), `192.168.1.10:8080:80` (one), or the libvirt gateway to reach it from VMs (see `delonix vm reach`). With `--net host` (the default) the container moves to its own netns with userspace NAT (slirp4netns, like rootless podman); with `--net <network>` it publishes via the ingress (nft DNAT + hostfwd on the single slirp)
--privileged
Privileged container (all caps, seccomp off) — trusted workloads
--entrypoint <ENTRYPOINT>
Override the image's ENTRYPOINT (COMMAND becomes the arguments to this binary; `--entrypoint ""` clears it and runs just the COMMAND)
-w, --workdir <WORKDIR>
Working directory the container's process starts in (default: the image's own configured workdir, or `/`). Persists in the record — an `exec -w` overrides it for that one call only
--rm
Remove the container when the process exits (with `-d`, a detached watcher handles removal when the container dies)
--restart <RESTART>
Restart policy (only with `-d`): `no` (default), `on-failure[:max]`, `always`, `unless-stopped`. A detached supervisor (one per container, ephemeral — there's no daemon) becomes the container's parent, captures the real exit code, and restarts it according to the policy
[default: no]
--device <DEVICES>
Attach a host device, `/dev/x[:/dev/y]`. Repeatable. The container's `/dev` is a tmpfs with a curated list (null/zero/tty/...); this adds real host nodes to it, like `docker --device`
-e, --env <ENV>
Additional environment variables (`KEY=VAL`), repeatable
--label <LABELS>
Label (`KEY=VAL`), repeatable — e.g. `io.x-k8s.kind.role=control-plane` enables the dedicated cgroup2 delegation for Kind nodes (see `setup_node_cgroup_ns`)
-m, --memory <MEMORY>
Memory limit (`64M`, `2G`, `max`). Default: a quarter of the engine's budget (`DELONIX_DEFAULT_PCT`); `max` lifts the cap entirely
-c, --cpus <CPUS>
CPU quota (number of cores, e.g. `0.5`, `2`). Default: the lesser of 1.0 and a quarter of the engine's budget
--cpu-weight <CPU_WEIGHT>
Relative CPU weight (`cpu.weight`, 1–10000) under contention
--cpuset <CPUSET>
CPUs the container is pinned to (`cpuset.cpus`, e.g. `0-3`, `0,2`)
--io-weight <IO_WEIGHT>
Relative I/O weight (`io.weight`, 1–10000)
--device-read-bps <DEVICE_READ_BPS>
Absolute read limit from the store's disk (`10mb`, `1g`). Docker's `--device-read-bps`
--device-write-bps <DEVICE_WRITE_BPS>
Absolute write limit to the store's disk (`10mb`, `1g`). Docker's `--device-write-bps`
--device-read-iops <DEVICE_READ_IOPS>
Absolute read IOPS limit from the store's disk
--device-write-iops <DEVICE_WRITE_IOPS>
Absolute write IOPS limit to the store's disk
--read-only
Read-only rootfs (writes go to tmpfs/volumes)
--cap-add <CAP_ADD>
Add a capability (e.g. `NET_ADMIN`). Repeatable
--cap-drop <CAP_DROP>
Drop a capability. Repeatable
--security-opt <SECURITY_OPT>
Security options (docker-style), repeatable: `seccomp=unconfined` | `seccomp=<profile.json>` (OCI/runc format) | `apparmor=<profile>` | `no-new-privileges[=true|false]` (default true, stricter than docker/podman)
--apparmor <APPARMOR>
AppArmor profile to apply (`unconfined`, `delonix-default`, or an already-loaded name). `delonix-default` is loaded automatically
--selinux <SELINUX>
SELinux context/profile to apply
--userns
User namespace: enables the subuid mapping (default in rootless)
--no-userns
Disable the automatic activation of the user namespace
--host-pid
Share the host's PID namespace (`--pid host`)
--host-ipc
Share the host's IPC namespace
--detect
Detection mode: seccomp in log mode (doesn't block), to discover syscalls
--secret <SECRET>
Inject a secret from the vault (`name`), as an environment variable. Repeatable. With `--secret-files`, it goes to `/run/secrets/<name>`
--secret-files
The `--secret`s come in as files in `/run/secrets/` (tmpfs), not env
--env-file <ENV_FILE>
Load variables from a `.env` file (`KEY=VAL` per line). Repeatable
--tmpfs <TMPFS>
Mount a tmpfs (`/path[:options]`). Repeatable
--ulimit <ULIMIT>
Ulimit (`nofile=1024:2048`). Repeatable
--dns <DNS>
DNS server for the container's `/etc/resolv.conf`. Repeatable. Overrides the resolver the engine would pick (network gateway, slirp, or the host's copy)
--dns-search <DNS_SEARCH>
DNS search domain. Repeatable
--dns-option <DNS_OPTION>
`resolv.conf` option (`ndots:2`, `timeout:1`). Repeatable
--group-add <GROUP_ADD>
Supplementary group id for the process (`--group-add 1234`). Repeatable. Applied even when the container runs as root — a root process still needs a group to reach a mounted share
--masked-path <MASKED_PATH>
Make a path unreadable inside the container (`--masked-path /proc/kcore`). Repeatable. A file is covered with `/dev/null`, a directory with an empty read-only tmpfs
--readonly-path <READONLY_PATH>
Remount a path read-only inside the container (`--readonly-path /proc/sys`). Repeatable
--sysctl <SYSCTL>
Container sysctl (`net.core.somaxconn=1024`). Repeatable
--gpus <GPUS>
Expose GPUs: `all` | `nvidia` | `dri` (expands to the `/dev` nodes)
--ip <IP>
Fixed IP on the network (`--net <network>`), e.g. `10.89.0.10`
--network-alias <NETWORK_ALIAS>
The container's DNS alias on the network. Repeatable
--add-host <ADD_HOST>
Extra `/etc/hosts` entry, `name:ip` (as Docker/Podman). Repeatable. PERSISTED: survives `stop`/`start` and `restart`, which rewrite `/etc/hosts` from scratch
--wait
With `-d`, block until the image's `HEALTHCHECK` passes (or the timeout elapses). Replaces the `until curl ...; do sleep; done` that every script ends up writing. No `HEALTHCHECK` in the image is a clear error, never a silent instant return
--wait-timeout <WAIT_TIMEOUT>
How long `--wait` waits before giving up (seconds)
[default: 60]
--health-cmd <HEALTH_CMD>
Probe command, run with `/bin/sh -c` inside the container. Without it, the image's own `HEALTHCHECK` is monitored; any other `--health-*` flag turns monitoring on for an image that has one
--health-interval <HEALTH_INTERVAL>
Seconds between probes
[default: 30]
--health-timeout <HEALTH_TIMEOUT>
A probe that runs longer than this counts as a failure. The probe kills ITSELF (the wrapper is `sh`), so nothing is left stuck inside the container
[default: 30]
--health-retries <HEALTH_RETRIES>
Consecutive failures before the container is `unhealthy`
[default: 3]
--health-start-period <HEALTH_START_PERIOD>
Grace at startup: failures inside this window do not count, and the container reads `starting` rather than `unhealthy`
[default: 0]
--knows <KNOWS>
Restrict DNS resolution to these containers (isolation). Repeatable
--knows-none
The container resolves NO other container by name
--pod <POD>
Join a pod's netns (`--net <network>`), sharing IP/ports
--net-bps <NET_BPS>
Egress bandwidth cap (`10mbit`, `512kbit`). Only with `--net <network>`
--net-burst <NET_BURST>
Burst for the bandwidth cap. Only with `--net-bps`
--log-driver <LOG_DRIVER>
Log driver (`json`, `cri`, ...)
--log-file <LOG_FILE>
Log file path (overrides the default)
--log-cri
CRI format in the log file (for the kubelet/`crictl logs`)
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# detached, published on the host, with a name of your own
delonix container run -d -p 8080:80 --name web nginx
# a database with a named volume and a network of its own, so the data
# outlives the container
delonix container run -d --net app -v pgdata:/var/lib/postgresql/data -e POSTGRES_PASSWORD=dev postgres:16
# in the foreground, removed on exit — the shape for a one-off task
delonix container run --rm alpine echo hello
# with a memory and CPU cap, and a restart policy
delonix container run -d -m 512M --cpus 1.5 --restart on-failure nginx
SEE ALSO:
delonix container ps · delonix container logs · delonix container stop ·
delonix container update
delonix › container › run-p e a rede: com --net host (o default) o
container muda para um netns próprio com NAT em userspace (slirp4netns — o modelo do podman
rootless); com --net <rede> a porta é publicada pelo ingress (hostfwd no
slirp único + DNAT nft), o caminho que permite trocar portas a quente sem parar o container.
--net none recusa -p.
-p and networking: with
--net host (the default) the container switches to its own netns with userspace NAT
(slirp4netns — the podman rootless model); with --net <network> the port is
published by the ingress (hostfwd on the single slirp + nft DNAT), the path that lets you
swap ports on the fly without stopping the container. --net none refuses
-p.
ExemplosExamples
delonix container run -d --name web -p 8080:80 nginxdelonix network create minha-rede
delonix container run -d --net minha-rede -p 8443:443 caddydelonix container run --rm -e TERM=xterm alpine sh -c 'echo olá'delonix container run --rm --entrypoint /bin/sh nginx -c 'nginx -t'container ps
List containers
Usage: delonix container ps [OPTIONS]
Options:
-a, --all
Include stopped/failed ones
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-q, --quiet
Print only the IDs (to compose with `stop`/`rm`)
-o, --output <OUTPUT>
Output format: `table` (default) or `json` (ADR-0005). `json` honors `--all` (same filter as the table) and ignores `--quiet`
[default: table]
[possible values: table, json]
-n, --namespace <NAMESPACE>
Show only the containers of this isolation namespace. Omit to list every one
-s, --size
Show the SIZE column — each container's own writable-layer usage (never the shared read-only image layers). Off by default: it walks a directory tree per container, the same cost `volumes inspect` already opts into rather than pays on every listing
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# the running ones
delonix container ps
# all of them, stopped included
delonix container ps -a
# just the IDs, to feed another command
delonix container ps -q
SEE ALSO:
delonix container describe · delonix container stats · delonix container
logs
delonix › container › psExemplosExamples
delonix container ls -adelonix container rm -f $(delonix container ps -aq)container start
(Re)start stopped/crashed containers. Always detached.
Reuses the persistent rootfs (writes made inside the container survive, like in docker) and the same network/ports/volumes as the original run.
Usage: delonix container start [OPTIONS] <IDS>...
Arguments:
<IDS>...
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# bring a stopped container back, with the same ports, volumes and network
delonix container start web
# several at once
delonix container start web db cache
SEE ALSO:
delonix container stop · delonix container restart · delonix container ps
delonix › container › startReusa a spec guardada (comando, env, volumes, rede, portas) e o rootfs
persistente — ao contrário de rm+run, nada do que o container escreveu se perde.
Reuses the saved spec (command, env, volumes, network, ports)
and the persistent rootfs — unlike rm+run, nothing the container wrote
is lost.
ExemplosExamples
delonix container start webcontainer stop
Stop one or more containers (SIGTERM, then SIGKILL)
Usage: delonix container stop [OPTIONS] <IDS>...
Arguments:
<IDS>...
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-t, --time <TIME>
Seconds until SIGKILL
[default: 10]
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# SIGTERM, then SIGKILL if it does not leave
delonix container stop web
# give it 30 seconds to shut down cleanly
delonix container stop -t 30 db
SEE ALSO:
delonix container start · delonix container kill · delonix container rm
delonix › container › stopExemplosExamples
delonix container stop -t 5 web dbcontainer rm
Remove one or more containers
Usage: delonix container rm [OPTIONS] <IDS>...
Arguments:
<IDS>...
Options:
-f, --force
Force (kill it if running)
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# remove a stopped container
delonix container rm web
# force it even while running
delonix container rm -f web
# everything that has already exited
delonix container rm $(delonix container ps -aq)
SEE ALSO:
delonix container stop · delonix container ps · delonix volume rm
delonix › container › rmExemplosExamples
delonix container rm -f web db cachecontainer exec
Execute a command inside a running container.
With no command, tries bash and falls back to sh (which exists in any image) — container exec -it <id> is the interactive shell, same as container exec -it <id> bash would give if bash is there.
Usage: delonix container exec [OPTIONS] <ID> [COMMAND]...
Arguments:
<ID>
[COMMAND]...
Command + arguments. Omit it for the bash/sh fallback shell
Options:
-i, --interactive
Interactive (attaches stdin)
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-t, --tty
Allocate a pseudo-terminal
-e, --env <ENV>
Extra environment variable (`KEY=VAL`) for this call only, on top of the container's own env. Repeatable
-w, --workdir <WORKDIR>
Working directory for this call only (default: the container's own configured `workdir`, or `/`)
-u, --user <USER>
Run as this user for this call only: `uid[:gid]` or `name[:group]` (resolved against the container's own `/etc/passwd`/`/etc/group`). Default: the container's own configured user
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# run a command inside a container that is already up
delonix container exec web nginx -t
# an interactive shell, no command needed — tries bash, falls back to sh
delonix container exec -it web
# as another user, in another directory, with an extra variable
delonix container exec -u root -w /srv -e DEBUG=1 web env
SEE ALSO:
delonix container attach · delonix container logs
delonix › container › execExemplosExamples
delonix container exec -it webcontainer logs
Show the logs (detached containers)
Usage: delonix container logs [OPTIONS] <ID>
Arguments:
<ID>
Options:
-f, --follow
Follow the log continuously (exits when the container stops)
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
--tail <TAIL>
Show only the last N lines. Requires the container to have been run with `--log-cri` (per-line timestamps needed to find "the last N" — see `--timestamps`'s doc for why)
--since <SINCE>
Show only lines at or after this Unix timestamp (seconds). Same `--log-cri` requirement as `--tail`
--timestamps
Prefix each line with its RFC3339 timestamp. Only available for containers run with `--log-cri` (`container run --log-cri`) — the plain log format is raw bytes with no per-line timestamp to show; a container without it gets a clear error naming the flag, not a silently-blank column
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# everything the container has written
delonix container logs web
# follow it live
delonix container logs -f web
# the last 50 lines with timestamps (needs --log-cri at run time)
delonix container logs --tail 50 --timestamps web
SEE ALSO:
delonix container attach · delonix container ps · delonix container describe
delonix › container › logsExemplosExamples
delonix container logs -f webcontainer inspect
Show the full spec of one or more containers (Store JSON)
Usage: delonix container inspect [OPTIONS] <IDS>...
Arguments:
<IDS>...
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# the full record as JSON, for a script
delonix container inspect web
SEE ALSO:
delonix container describe · delonix container ps
delonix › container › inspectExemplosExamples
delonix container inspect web | jq .[0].portscontainer stats
Resource usage (CPU/memory/PIDs) of the running containers.
One sample and exits (no stream). With no IDs, shows all running ones.
Usage: delonix container stats [OPTIONS] [IDS]...
Arguments:
[IDS]...
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# CPU, memory and PIDs of everything running, one sample
delonix container stats
# just these two
delonix container stats web db
SEE ALSO:
delonix dashboard · delonix container top · delonix system df
delonix › container › statsCPU%/memória/PIDs lidos do cgroup v2 do próprio container (resolvido por
/proc/<pid>/cgroup, qualquer que seja a base delegada). Sem delegação de cgroup
(rootless sem Delegate=yes), a memória cai para o VmRSS do init do container,
marcada com ~.
CPU%/memory/PIDs read from the container's own cgroup v2
(resolved via /proc/<pid>/cgroup, whatever the delegated base is). Without
cgroup delegation (rootless with no Delegate=yes), memory falls back to the container
init's VmRSS, marked with ~.
ExemplosExamples
delonix container statscontainer apply
Apply the kind: Container documents of a manifest (idempotent by name).
An existing container with that name is neither recreated nor checked for spec drift, see cmd::manifest.
Usage: delonix container apply [OPTIONS]
Options:
-f, --file <FILE>
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# apply the kind: Container documents of the default manifest
delonix container apply
# from another file
delonix container apply -f prod.yaml
SEE ALSO:
delonix stack apply · delonix stack plan · delonix container init
delonix › container › applyExemplosExamples
delonix container apply -f delonix-manifest.yamlcontainer init
Initialize a project with a Delonixfile + manifest.
Files ALREADY FILLED IN (images included), ready to use without editing anything.
Usage: delonix container init [OPTIONS] [DIR]
Arguments:
[DIR]
Project directory (default: the current one)
[default: .]
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
--name <NAME>
Project name (default: the directory name)
--image <IMAGE>
Image to use. Omit = fill in with the default image
--force
Overwrite existing files
-t, --template <TEMPLATE>
Generate a complete PROJECT for a stack (e.g. `python`) with best practices, instead of the generic scaffold. `--template list` shows the available ones
-v, --template-version <TEMPLATE_VERSION>
Version parameter some templates read — an image tag, a framework version, or a toolchain version, depending on the template; the exact accepted form is documented in that template's own README. Refused with a clear error on a template that has none
--up
After generating, build the image, start it, and wait until it's healthy
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# scaffold a project already filled in, ready to run
delonix container init
SEE ALSO:
delonix init · delonix stack init · delonix container apply
delonix › container › initExemplosExamples
delonix container init myapp && cd myappcontainer kill
Send a signal to one or more containers (default SIGKILL).
Unlike stop, does not wait or force a Stopped status: the real outcome (e.g. Crashed for a KILL) is picked up on the next observation.
Usage: delonix container kill [OPTIONS] <IDS>...
Arguments:
<IDS>...
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-s, --signal <SIGNAL>
Signal name (`KILL`, `SIGKILL`, case-insensitive, `SIG` prefix optional) or number (`9`)
[default: KILL]
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# SIGKILL, no waiting
delonix container kill web
# any signal, by name or number — this one asks nginx to reload
delonix container kill -s HUP web
SEE ALSO:
delonix container stop · delonix container restart
delonix › container › killAo contrário de stop, não espera nem força o estado —
o resultado real (ex.: Crashed para um KILL) só se confirma na
observação seguinte.
Unlike stop, it doesn't wait for or force the state
— the real outcome (e.g. Crashed for a KILL) is only confirmed on the
next observation.
ExemplosExamples
delonix container kill -s USR1 webcontainer wait
Block until one or more containers exit, then print their exit code (one per line, in the order given)
Usage: delonix container wait [OPTIONS] <IDS>...
Arguments:
<IDS>...
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# block until it exits, then print the exit code
delonix container wait job
SEE ALSO:
delonix container run · delonix container logs · delonix container ps
delonix › container › waitO exit code real só é garantido quando um supervisor
--restart é o pai real do processo — um container -d simples sem
supervisor mostra Crashed/137, limite arquitectural conhecido (o motor não é o pai
real desse processo).
The real exit code is only guaranteed when a
--restart supervisor is the process's real parent — a plain -d container
with no supervisor shows Crashed/137, a known architectural limit (the engine isn't
that process's real parent).
ExemplosExamples
delonix container wait webcontainer restart
Stop then start one or more containers.
Reuses the persistent rootfs and the original run configuration, like start.
Usage: delonix container restart [OPTIONS] <IDS>...
Arguments:
<IDS>...
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-t, --time <TIME>
Seconds until SIGKILL, for the `stop` half
[default: 10]
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# stop and start again, keeping the original configuration
delonix container restart web
SEE ALSO:
delonix container start · delonix container stop · delonix container update
delonix › container › restartExemplosExamples
delonix container restart webcontainer rename
Give a container a new name
Usage: delonix container rename [OPTIONS] <ID> <NEW_NAME>
Arguments:
<ID>
<NEW_NAME>
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# give it a new name — the ID does not change
delonix container rename web frontend
SEE ALSO:
delonix container ps · delonix container describe
delonix › container › renameExemplosExamples
delonix container rename web frontendcontainer port
Published ports of a container (hostPort/proto -> containerPort)
Usage: delonix container port [OPTIONS] <ID>
Arguments:
<ID>
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# which host ports reach this container
delonix container port web
SEE ALSO:
delonix container update · delonix net ingress ls
delonix › container › portExemplosExamples
delonix container port webcontainer pause
Suspend a container's processes (cgroup v2 freezer).
The state stays in memory, unlike stop. Resume with unpause.
Usage: delonix container pause [OPTIONS] <IDS>...
Arguments:
<IDS>...
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# freeze the processes — the state stays in memory, unlike stop
delonix container pause web
SEE ALSO:
delonix container unpause · delonix container stop
delonix › container › pauseExemplosExamples
delonix container pause webcontainer unpause
Resume a container suspended with pause
Usage: delonix container unpause [OPTIONS] <IDS>...
Arguments:
<IDS>...
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# resume a frozen container
delonix container unpause web
SEE ALSO:
delonix container pause
delonix › container › unpauseExemplosExamples
delonix container unpause webcontainer commit
Create an image from a container's CURRENT rootfs state (whatever was written inside becomes a new layer)
Usage: delonix container commit [OPTIONS] <ID> <TAG>
Arguments:
<ID>
<TAG>
Tag for the new image (e.g. `app:v2`)
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# turn what was written inside into a new image
delonix container commit web myapp:v1
SEE ALSO:
delonix image ls · delonix build · delonix container diff
delonix › container › commitExemplosExamples
delonix container commit web minha-app:debugcontainer healthcheck
Run the image's HEALTHCHECK inside the container. Exits with 1 if unhealthy — usable in a script/CI
Usage: delonix container healthcheck [OPTIONS] <ID>
Arguments:
<ID>
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# run the image's HEALTHCHECK — exits 1 if unhealthy, so a script can gate
# on it
delonix container healthcheck web
SEE ALSO:
delonix container describe · delonix container run
delonix › container › healthcheckExemplosExamples
delonix container healthcheck webcontainer top
Processes running inside a container (read from cgroup.procs)
Usage: delonix container top [OPTIONS] <ID>
Arguments:
<ID>
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# the processes inside the container
delonix container top web
SEE ALSO:
delonix container stats · delonix container exec
delonix › container › topExemplosExamples
delonix container top webcontainer diff
Files changed relative to the image: A = created/changed, D = deleted
Usage: delonix container diff [OPTIONS] <ID>
Arguments:
<ID>
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# what changed relative to the image: A created/changed, D deleted
delonix container diff web
SEE ALSO:
delonix container commit · delonix container cp
delonix › container › diffExemplosExamples
delonix container diff webcontainer cp
Copy files between the host and a container.
Exactly one side is container:/path (e.g. delonix container cp web:/etc/nginx.conf .).
Usage: delonix container cp [OPTIONS] <SRC> <DST>
Arguments:
<SRC>
<DST>
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# out of the container onto the host
delonix container cp web:/etc/nginx/nginx.conf .
# from the host into the container
delonix container cp ./site.conf web:/etc/nginx/conf.d/
SEE ALSO:
delonix container exec · delonix container diff
delonix › container › cpExemplosExamples
delonix container cp web:/etc/nginx.conf .delonix container cp ./nginx.conf web:/etc/nginx.confcontainer describe
Human-readable detail of one or more containers, kubectl describe-style.
For humans; use inspect for script-consumable JSON.
Usage: delonix container describe [OPTIONS] <IDS>...
Arguments:
<IDS>...
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# the readable detail — kubectl describe style
delonix container describe web
SEE ALSO:
delonix container inspect · delonix container ps
delonix › container › describeExemplosExamples
delonix container describe webcontainer update
Reconfigure a RUNNING container without stopping it — ports, volumes, and bandwidth cap.
Unlike docker (where changing a port or a volume forces recreating the container), here the dataplane doesn't belong to the process lifecycle: ports are DNAT/hostfwd in front of the network and volumes come in through the kernel's mount API (open_tree/move_mount) in the mount namespace of the already-live container. The PID doesn't change and the process is never interrupted.
For which NETWORKS the container is on, see network connect/network disconnect — Docker's own verb for that, kept apart from ports/ volumes/limits, which Docker cannot reconfigure hot at all.
The changes are persisted in the registry, so a later container start reproduces the new configuration, not the original.
Usage: delonix container update [OPTIONS] <ID>
Arguments:
<ID>
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-p, --publish-add <SPEC>
Publish one more port hot, `hostPort:contPort[/tcp|udp]`. Repeatable
--publish-rm <HOST_PORT>
Unpublish a port hot, by HOST PORT. Repeatable
-v, --volume-add <SPEC>
Mount a volume hot, `name:/target[:ro]` or `/host:/target[:ro]`. Repeatable
--volume-rm <TARGET>
Unmount hot, by the TARGET path inside the container. Repeatable
--net-rate <RATE>
Bandwidth cap, in bit/s with a suffix (`10mbit`, `512kbit`, `1gbit`)
--net-burst <BURST>
Burst for the bandwidth cap (default: ~100 ms of throughput, at least 16 KiB). Only with `--net-rate`
--net-rate-clear
Remove the bandwidth cap
-m, --memory <MEMORY>
New memory limit hot (`64M`, `2G`, `max`)
-c, --cpus <CPUS>
New CPU quota hot (number of cores, e.g. `0.5`, `2`)
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# publish a new port on a RUNNING container — the PID does not change
delonix container update --publish-add 9000:80 web
# swap a port in one command: removals run before additions
delonix container update --publish-rm 8080 --publish-add 8080:9000 web
# raise the memory and CPU caps live
delonix container update --memory 1G --cpus 2 db
# cap the bandwidth of its existing network link
delonix container update --net-rate 10mbit web
SEE ALSO:
delonix container run · delonix container restart · delonix network connect
delonix › container › updateReconfigura portas, volumes, limite de banda e limites de
memória/CPU de um container a correr, sem o parar — o PID não muda. Remoções
correm antes das adições, para --publish-rm 8080 --publish-add 8080:9000 funcionar
num só comando. --memory/--cpus reescrevem o cgroup real de imediato
(memory.max/cpu.max) — nada de esperar por um restart.
A filiação de REDE (a que redes o container está ligado) mudou-se para
delonix network connect/network disconnect — o verbo do próprio Docker
para isso.
Reconfigures a running container's ports,
volumes, bandwidth limit and memory/CPU limits without stopping it — the PID doesn't
change. Removals run before additions, so --publish-rm 8080 --publish-add 8080:9000
works in a single command. --memory/--cpus rewrite the real cgroup
immediately (memory.max/cpu.max) — no waiting for a
restart. Which NETWORKS the container is on moved to
delonix network connect/network disconnect — Docker's own verb for
that.
ExemplosExamples
delonix container update web --publish-add 9090:80delonix container update web --net-rate 10mbitdelonix container update web --memory 512M --cpus 2container attach
Re-attach to a running container's output stream (output only).
Same log file logs -f reads. Unlike docker attach, this is OUTPUT-ONLY: a detached container's stdin has nowhere to go (this engine keeps no live conduit to it once started, unlike a persistent per-container shim) — -i/--stdin is refused with a clear error instead of silently doing nothing.
Usage: delonix container attach [OPTIONS] <ID>
Arguments:
<ID>
Options:
-i, --interactive
Refused: stdin forwarding isn't supported (see the command's own doc above)
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# re-attach to the output of a detached container (output only)
delonix container attach web
SEE ALSO:
delonix container logs · delonix container exec
delonix › container › attachDeliberadamente só output — ao contrário do
docker attach, não há stdin ao vivo para um container já iniciado em detached (sem
shim persistente por-container). -i/--stdin é recusado com um erro claro
a apontar para exec -it.
Deliberately output-only — unlike
docker attach, there's no live stdin to an already-started detached container (no
persistent per-container shim). -i/--stdin is refused with a clear error
pointing at exec -it.
ExemplosExamples
delonix container attach webLaboratórioLab
Sobe um nginx publicado, confirma que responde, e prova que o estado
sobrevive a um stop/start (ao contrário de recriar o container).
delonix container run -d --name web -p 8080:80 nginx
curl localhost:8080
delonix container logs web
delonix container stop web
delonix container start web
curl localhost:8080Bring up a published nginx, confirm it answers, and prove the state
survives a stop/start (unlike recreating the container).
delonix container run -d --name web -p 8080:80 nginx
curl localhost:8080
delonix container logs web
delonix container stop web
delonix container start web
curl localhost:8080DesafioChallenge
Sem parar o web, troca a porta publicada a quente
com container update (o PID não muda) e confirma com container diff que
escrever um ficheiro dentro do container aparece na comparação com a imagem original.
delonix container update web --publish-rm 8080 --publish-add 9090:80
delonix container exec web sh -c 'echo oi > /tmp/marca'
delonix container diff webWithout stopping web, hot-swap the published port with
container update (the PID doesn't change) and confirm with container diff
that writing a file inside the container shows up against the original image.
delonix container update web --publish-rm 8080 --publish-add 9090:80
delonix container exec web sh -c 'echo hi > /tmp/mark'
delonix container diff web