delonix container

Ciclo de vida de containers: run, ps, start, stop, rm, exec, logs, inspect, stats, apply.

Container lifecycle: run, ps, start, stop, rm, exec, logs, inspect, stats, apply.

O grupo container é o dia a dia do runtime — o homólogo do docker container. Cada invocação é um processo efémero (sem daemon): o run faz clone() directo com os namespaces pedidos e o estado fica em JSON no $DELONIX_ROOT. Em rootless, o rootfs é um overlay montado dentro do user namespace do próprio container: as layers da imagem são partilhadas entre todos os containers e cada um tem a sua camada de escrita persistente — as escritas sobrevivem a stop/start, como no Docker.

The container group is the runtime's everyday surface — the counterpart to docker container. Each invocation is an ephemeral process (no daemon): run does a direct clone() with the requested namespaces and the state lands as JSON under $DELONIX_ROOT. In rootless mode, the rootfs is an overlay mounted inside the container's own user namespace: the image layers are shared by every container, and each one has its own persistent writable layer — writes survive stop/start, just like in Docker.

Usage: delonix container [OPTIONS] <COMMAND>

Commands:
  kill         Send a signal to one or more containers (default SIGKILL)
  pause        Suspend a container's processes (cgroup v2 freezer)
  restart      Stop then start one or more containers
  rm           Remove one or more containers
  run          Run a container from an image (pulls it if missing)
  start        (Re)start stopped/crashed containers. Always detached
  stop         Stop one or more containers (SIGTERM, then SIGKILL)
  unpause      Resume a container suspended with `pause`
  wait         Block until one or more containers exit, then print their exit code (one per line, in the order given)
  describe     Human-readable detail of one or more containers, `kubectl describe`-style
  diff         Files changed relative to the image: `A` = created/changed, `D` = deleted
  healthcheck  Run the image's `HEALTHCHECK` inside the container. Exits with 1 if `unhealthy` — usable in a script/CI
  inspect      Show the full spec of one or more containers (Store JSON)
  logs         Show the logs (detached containers)
  port         Published ports of a container (`hostPort/proto -> containerPort`)
  ps           List containers [alias: ls]
  stats        Resource usage (CPU/memory/PIDs) of the running containers
  top          Processes running inside a container (read from `cgroup.procs`)
  attach       Re-attach to a running container's output stream (output only)
  commit       Create an image from a container's CURRENT rootfs state (whatever was written inside becomes a new layer)
  cp           Copy files between the host and a container
  exec         Execute a command inside a running container
  rename       Give a container a new name
  update       **Reconfigure a RUNNING container without stopping it** — ports, volumes, and bandwidth cap
  apply        Apply the `kind: Container` documents of a manifest (idempotent by name)
  init         Initialize a project with a Delonixfile + manifest
  prune        Remove every stopped container and the rootfs debris they left behind
  help         Print this message or the help of the given subcommand(s)

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -h, --help
          Print help (see a summary with '-h')

COMMAND MAP:
  Lifecycle    run · start · stop · kill · wait · restart · rm · pause · unpause
  Inspect      ps · port · healthcheck · top · diff · inspect · describe · stats · logs
  Interact     commit · cp · exec · attach
  Configure    rename · update
  Declarative  init · apply
  Maintenance  prune

EXAMPLES:
  # a web service in seconds — host port 8080 onto the container's 80
  delonix container run -d -p 8080:80 --name web nginx

  # what is running, and for how long
  delonix container ps

  # a shell inside it, without stopping anything
  delonix container exec -it web

SEE ALSO:
  delonix pod · delonix image · delonix workload · delonix compose up

  delonix › container

container run

Run a container from an image (pulls it if missing)

Usage: delonix container run [OPTIONS] <IMAGE> [COMMAND]...

Arguments:
  <IMAGE>
          Image (e.g. `alpine:3.19`)

  [COMMAND]...
          Command + arguments (default: the image's ENTRYPOINT/CMD)

Options:
  -d, --detach
          Run in the background and print the ID

      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

      --name <NAME>
          Container name (default: `dlx-<id>`)

      --hostname <HOSTNAME>
          Hostname inside the container (UTS namespace + `/etc/hostname`). Default: the container name (docker `--hostname`)

  -u, --user <USER>
          Run the process as this user: `uid[:gid]` or `name[:group]` (docker `--user`). Names are resolved in the image's `/etc/passwd`/`/etc/group`

      --net <NET>
          Network: `host` (shares the host's, default), `none` (isolated netns with no connectivity), or the NAME of a network created with `delonix network create`
          
          [default: host]

      --namespace <NAMESPACE>
          Logical ISOLATION namespace (default `default`). Containers in different namespaces cannot reach each other (even on the same network); only a `kind: Dependency` crosses the boundary

      --expose <EXPOSE>
          Auto-register this container's HTTP port in the L7 proxy under its internal FQDN `<name>.<namespace>.delonix.internal` (reachable via the proxy). Needs `--net <network>`. Removed automatically on `container rm`

  -v, --volume <VOLUMES>
          Volume/bind mount, `name:/target[:ro]` or `/host:/target[:ro]`. Repeatable

  -p, --publish <PUBLISH>
          Publish a port, `[hostIp:]hostPort:contPort[/tcp|udp]` or just `port`. Repeatable. SAFE BY DEFAULT: without `hostIp` the port binds to `127.0.0.1` only — reachable from the host itself, NOT from a browser on another machine. Name the address to widen it: `0.0.0.0:8080:80` (every interface), `192.168.1.10:8080:80` (one), or the libvirt gateway to reach it from VMs (see `delonix vm reach`). With `--net host` (the default) the container moves to its own netns with userspace NAT (slirp4netns, like rootless podman); with `--net <network>` it publishes via the ingress (nft DNAT + hostfwd on the single slirp)

      --privileged
          Privileged container (all caps, seccomp off) — trusted workloads

      --entrypoint <ENTRYPOINT>
          Override the image's ENTRYPOINT (COMMAND becomes the arguments to this binary; `--entrypoint ""` clears it and runs just the COMMAND)

  -w, --workdir <WORKDIR>
          Working directory the container's process starts in (default: the image's own configured workdir, or `/`). Persists in the record — an `exec -w` overrides it for that one call only

      --rm
          Remove the container when the process exits (with `-d`, a detached watcher handles removal when the container dies)

      --restart <RESTART>
          Restart policy (only with `-d`): `no` (default), `on-failure[:max]`, `always`, `unless-stopped`. A detached supervisor (one per container, ephemeral — there's no daemon) becomes the container's parent, captures the real exit code, and restarts it according to the policy
          
          [default: no]

      --device <DEVICES>
          Attach a host device, `/dev/x[:/dev/y]`. Repeatable. The container's `/dev` is a tmpfs with a curated list (null/zero/tty/...); this adds real host nodes to it, like `docker --device`

  -e, --env <ENV>
          Additional environment variables (`KEY=VAL`), repeatable

      --label <LABELS>
          Label (`KEY=VAL`), repeatable — e.g. `io.x-k8s.kind.role=control-plane` enables the dedicated cgroup2 delegation for Kind nodes (see `setup_node_cgroup_ns`)

  -m, --memory <MEMORY>
          Memory limit (`64M`, `2G`, `max`). Default: a quarter of the engine's budget (`DELONIX_DEFAULT_PCT`); `max` lifts the cap entirely

  -c, --cpus <CPUS>
          CPU quota (number of cores, e.g. `0.5`, `2`). Default: the lesser of 1.0 and a quarter of the engine's budget

      --cpu-weight <CPU_WEIGHT>
          Relative CPU weight (`cpu.weight`, 1–10000) under contention

      --cpuset <CPUSET>
          CPUs the container is pinned to (`cpuset.cpus`, e.g. `0-3`, `0,2`)

      --io-weight <IO_WEIGHT>
          Relative I/O weight (`io.weight`, 1–10000)

      --device-read-bps <DEVICE_READ_BPS>
          Absolute read limit from the store's disk (`10mb`, `1g`). Docker's `--device-read-bps`

      --device-write-bps <DEVICE_WRITE_BPS>
          Absolute write limit to the store's disk (`10mb`, `1g`). Docker's `--device-write-bps`

      --device-read-iops <DEVICE_READ_IOPS>
          Absolute read IOPS limit from the store's disk

      --device-write-iops <DEVICE_WRITE_IOPS>
          Absolute write IOPS limit to the store's disk

      --read-only
          Read-only rootfs (writes go to tmpfs/volumes)

      --cap-add <CAP_ADD>
          Add a capability (e.g. `NET_ADMIN`). Repeatable

      --cap-drop <CAP_DROP>
          Drop a capability. Repeatable

      --security-opt <SECURITY_OPT>
          Security options (docker-style), repeatable: `seccomp=unconfined` | `seccomp=<profile.json>` (OCI/runc format) | `apparmor=<profile>` | `no-new-privileges[=true|false]` (default true, stricter than docker/podman)

      --apparmor <APPARMOR>
          AppArmor profile to apply (`unconfined`, `delonix-default`, or an already-loaded name). `delonix-default` is loaded automatically

      --selinux <SELINUX>
          SELinux context/profile to apply

      --userns
          User namespace: enables the subuid mapping (default in rootless)

      --no-userns
          Disable the automatic activation of the user namespace

      --host-pid
          Share the host's PID namespace (`--pid host`)

      --host-ipc
          Share the host's IPC namespace

      --detect
          Detection mode: seccomp in log mode (doesn't block), to discover syscalls

      --secret <SECRET>
          Inject a secret from the vault (`name`), as an environment variable. Repeatable. With `--secret-files`, it goes to `/run/secrets/<name>`

      --secret-files
          The `--secret`s come in as files in `/run/secrets/` (tmpfs), not env

      --env-file <ENV_FILE>
          Load variables from a `.env` file (`KEY=VAL` per line). Repeatable

      --tmpfs <TMPFS>
          Mount a tmpfs (`/path[:options]`). Repeatable

      --ulimit <ULIMIT>
          Ulimit (`nofile=1024:2048`). Repeatable

      --dns <DNS>
          DNS server for the container's `/etc/resolv.conf`. Repeatable. Overrides the resolver the engine would pick (network gateway, slirp, or the host's copy)

      --dns-search <DNS_SEARCH>
          DNS search domain. Repeatable

      --dns-option <DNS_OPTION>
          `resolv.conf` option (`ndots:2`, `timeout:1`). Repeatable

      --group-add <GROUP_ADD>
          Supplementary group id for the process (`--group-add 1234`). Repeatable. Applied even when the container runs as root — a root process still needs a group to reach a mounted share

      --masked-path <MASKED_PATH>
          Make a path unreadable inside the container (`--masked-path /proc/kcore`). Repeatable. A file is covered with `/dev/null`, a directory with an empty read-only tmpfs

      --readonly-path <READONLY_PATH>
          Remount a path read-only inside the container (`--readonly-path /proc/sys`). Repeatable

      --sysctl <SYSCTL>
          Container sysctl (`net.core.somaxconn=1024`). Repeatable

      --gpus <GPUS>
          Expose GPUs: `all` | `nvidia` | `dri` (expands to the `/dev` nodes)

      --ip <IP>
          Fixed IP on the network (`--net <network>`), e.g. `10.89.0.10`

      --network-alias <NETWORK_ALIAS>
          The container's DNS alias on the network. Repeatable

      --add-host <ADD_HOST>
          Extra `/etc/hosts` entry, `name:ip` (as Docker/Podman). Repeatable. PERSISTED: survives `stop`/`start` and `restart`, which rewrite `/etc/hosts` from scratch

      --wait
          With `-d`, block until the image's `HEALTHCHECK` passes (or the timeout elapses). Replaces the `until curl ...; do sleep; done` that every script ends up writing. No `HEALTHCHECK` in the image is a clear error, never a silent instant return

      --wait-timeout <WAIT_TIMEOUT>
          How long `--wait` waits before giving up (seconds)
          
          [default: 60]

      --health-cmd <HEALTH_CMD>
          Probe command, run with `/bin/sh -c` inside the container. Without it, the image's own `HEALTHCHECK` is monitored; any other `--health-*` flag turns monitoring on for an image that has one

      --health-interval <HEALTH_INTERVAL>
          Seconds between probes
          
          [default: 30]

      --health-timeout <HEALTH_TIMEOUT>
          A probe that runs longer than this counts as a failure. The probe kills ITSELF (the wrapper is `sh`), so nothing is left stuck inside the container
          
          [default: 30]

      --health-retries <HEALTH_RETRIES>
          Consecutive failures before the container is `unhealthy`
          
          [default: 3]

      --health-start-period <HEALTH_START_PERIOD>
          Grace at startup: failures inside this window do not count, and the container reads `starting` rather than `unhealthy`
          
          [default: 0]

      --knows <KNOWS>
          Restrict DNS resolution to these containers (isolation). Repeatable

      --knows-none
          The container resolves NO other container by name

      --pod <POD>
          Join a pod's netns (`--net <network>`), sharing IP/ports

      --net-bps <NET_BPS>
          Egress bandwidth cap (`10mbit`, `512kbit`). Only with `--net <network>`

      --net-burst <NET_BURST>
          Burst for the bandwidth cap. Only with `--net-bps`

      --log-driver <LOG_DRIVER>
          Log driver (`json`, `cri`, ...)

      --log-file <LOG_FILE>
          Log file path (overrides the default)

      --log-cri
          CRI format in the log file (for the kubelet/`crictl logs`)

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # detached, published on the host, with a name of your own
  delonix container run -d -p 8080:80 --name web nginx

  # a database with a named volume and a network of its own, so the data
  # outlives the container
  delonix container run -d --net app -v pgdata:/var/lib/postgresql/data -e POSTGRES_PASSWORD=dev postgres:16

  # in the foreground, removed on exit — the shape for a one-off task
  delonix container run --rm alpine echo hello

  # with a memory and CPU cap, and a restart policy
  delonix container run -d -m 512M --cpus 1.5 --restart on-failure nginx

SEE ALSO:
  delonix container ps · delonix container logs · delonix container stop ·
  delonix container update

  delonix › container › run

-p e a rede: com --net host (o default) o container muda para um netns próprio com NAT em userspace (slirp4netns — o modelo do podman rootless); com --net <rede> a porta é publicada pelo ingress (hostfwd no slirp único + DNAT nft), o caminho que permite trocar portas a quente sem parar o container. --net none recusa -p.

-p and networking: with --net host (the default) the container switches to its own netns with userspace NAT (slirp4netns — the podman rootless model); with --net <network> the port is published by the ingress (hostfwd on the single slirp + nft DNAT), the path that lets you swap ports on the fly without stopping the container. --net none refuses -p.

ExemplosExamples

Servir nginx na porta 8080 do host (NAT userspace, sem root)
Serve nginx on host port 8080 (userspace NAT, no root)
delonix container run -d --name web -p 8080:80 nginx
Correr numa rede criada pelo utilizador, publicando pelo ingress
Run on a user-created network, published via ingress
delonix network create minha-rede
delonix container run -d --net minha-rede -p 8443:443 caddy
Shell descartável (remove-se sozinho à saída)
Disposable shell (removes itself on exit)
delonix container run --rm -e TERM=xterm alpine sh -c 'echo olá'
Sobrepor o ENTRYPOINT para depurar uma imagem
Override ENTRYPOINT to debug an image
delonix container run --rm --entrypoint /bin/sh nginx -c 'nginx -t'

container ps

List containers

Usage: delonix container ps [OPTIONS]

Options:
  -a, --all
          Include stopped/failed ones

      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -q, --quiet
          Print only the IDs (to compose with `stop`/`rm`)

  -o, --output <OUTPUT>
          Output format: `table` (default) or `json` (ADR-0005). `json` honors `--all` (same filter as the table) and ignores `--quiet`
          
          [default: table]
          [possible values: table, json]

  -n, --namespace <NAMESPACE>
          Show only the containers of this isolation namespace. Omit to list every one

  -s, --size
          Show the SIZE column — each container's own writable-layer usage (never the shared read-only image layers). Off by default: it walks a directory tree per container, the same cost `volumes inspect` already opts into rather than pays on every listing

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # the running ones
  delonix container ps

  # all of them, stopped included
  delonix container ps -a

  # just the IDs, to feed another command
  delonix container ps -q

SEE ALSO:
  delonix container describe · delonix container stats · delonix container
  logs

  delonix › container › ps

ExemplosExamples

Listar (alias `ls` também funciona)
List (the `ls` alias also works)
delonix container ls -a
Compor com stop/rm
Compose with stop/rm
delonix container rm -f $(delonix container ps -aq)

container start

(Re)start stopped/crashed containers. Always detached.

Reuses the persistent rootfs (writes made inside the container survive, like in docker) and the same network/ports/volumes as the original run.

Usage: delonix container start [OPTIONS] <IDS>...

Arguments:
  <IDS>...
          

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # bring a stopped container back, with the same ports, volumes and network
  delonix container start web

  # several at once
  delonix container start web db cache

SEE ALSO:
  delonix container stop · delonix container restart · delonix container ps

  delonix › container › start

Reusa a spec guardada (comando, env, volumes, rede, portas) e o rootfs persistente — ao contrário de rm+run, nada do que o container escreveu se perde.

Reuses the saved spec (command, env, volumes, network, ports) and the persistent rootfs — unlike rm+run, nothing the container wrote is lost.

ExemplosExamples

Rearrancar um container parado, preservando o que foi escrito lá dentro
Restart a stopped container, preserving what was written inside
delonix container start web

container stop

Stop one or more containers (SIGTERM, then SIGKILL)

Usage: delonix container stop [OPTIONS] <IDS>...

Arguments:
  <IDS>...
          

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -t, --time <TIME>
          Seconds until SIGKILL
          
          [default: 10]

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # SIGTERM, then SIGKILL if it does not leave
  delonix container stop web

  # give it 30 seconds to shut down cleanly
  delonix container stop -t 30 db

SEE ALSO:
  delonix container start · delonix container kill · delonix container rm

  delonix › container › stop

ExemplosExamples

SIGTERM, e SIGKILL ao fim de 5s
SIGTERM, then SIGKILL after 5s
delonix container stop -t 5 web db

container rm

Remove one or more containers

Usage: delonix container rm [OPTIONS] <IDS>...

Arguments:
  <IDS>...
          

Options:
  -f, --force
          Force (kill it if running)

      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # remove a stopped container
  delonix container rm web

  # force it even while running
  delonix container rm -f web

  # everything that has already exited
  delonix container rm $(delonix container ps -aq)

SEE ALSO:
  delonix container stop · delonix container ps · delonix volume rm

  delonix › container › rm

ExemplosExamples

Forçar remoção de vários
Force-remove several
delonix container rm -f web db cache

container exec

Execute a command inside a running container.

With no command, tries bash and falls back to sh (which exists in any image) — container exec -it <id> is the interactive shell, same as container exec -it <id> bash would give if bash is there.

Usage: delonix container exec [OPTIONS] <ID> [COMMAND]...

Arguments:
  <ID>
          

  [COMMAND]...
          Command + arguments. Omit it for the bash/sh fallback shell

Options:
  -i, --interactive
          Interactive (attaches stdin)

      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -t, --tty
          Allocate a pseudo-terminal

  -e, --env <ENV>
          Extra environment variable (`KEY=VAL`) for this call only, on top of the container's own env. Repeatable

  -w, --workdir <WORKDIR>
          Working directory for this call only (default: the container's own configured `workdir`, or `/`)

  -u, --user <USER>
          Run as this user for this call only: `uid[:gid]` or `name[:group]` (resolved against the container's own `/etc/passwd`/`/etc/group`). Default: the container's own configured user

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # run a command inside a container that is already up
  delonix container exec web nginx -t

  # an interactive shell, no command needed — tries bash, falls back to sh
  delonix container exec -it web

  # as another user, in another directory, with an extra variable
  delonix container exec -u root -w /srv -e DEBUG=1 web env

SEE ALSO:
  delonix container attach · delonix container logs

  delonix › container › exec

ExemplosExamples

Shell interactiva — sem comando, tenta bash e cai para sh
Interactive shell
delonix container exec -it web

container logs

Show the logs (detached containers)

Usage: delonix container logs [OPTIONS] <ID>

Arguments:
  <ID>
          

Options:
  -f, --follow
          Follow the log continuously (exits when the container stops)

      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

      --tail <TAIL>
          Show only the last N lines. Requires the container to have been run with `--log-cri` (per-line timestamps needed to find "the last N" — see `--timestamps`'s doc for why)

      --since <SINCE>
          Show only lines at or after this Unix timestamp (seconds). Same `--log-cri` requirement as `--tail`

      --timestamps
          Prefix each line with its RFC3339 timestamp. Only available for containers run with `--log-cri` (`container run --log-cri`) — the plain log format is raw bytes with no per-line timestamp to show; a container without it gets a clear error naming the flag, not a silently-blank column

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # everything the container has written
  delonix container logs web

  # follow it live
  delonix container logs -f web

  # the last 50 lines with timestamps (needs --log-cri at run time)
  delonix container logs --tail 50 --timestamps web

SEE ALSO:
  delonix container attach · delonix container ps · delonix container describe

  delonix › container › logs

ExemplosExamples

Seguir em contínuo (sai quando o container parar)
Follow continuously (exits when the container stops)
delonix container logs -f web

container inspect

Show the full spec of one or more containers (Store JSON)

Usage: delonix container inspect [OPTIONS] <IDS>...

Arguments:
  <IDS>...
          

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # the full record as JSON, for a script
  delonix container inspect web

SEE ALSO:
  delonix container describe · delonix container ps

  delonix › container › inspect

ExemplosExamples

Spec completa em JSON
Full spec as JSON
delonix container inspect web | jq .[0].ports

container stats

Resource usage (CPU/memory/PIDs) of the running containers.

One sample and exits (no stream). With no IDs, shows all running ones.

Usage: delonix container stats [OPTIONS] [IDS]...

Arguments:
  [IDS]...
          

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # CPU, memory and PIDs of everything running, one sample
  delonix container stats

  # just these two
  delonix container stats web db

SEE ALSO:
  delonix dashboard · delonix container top · delonix system df

  delonix › container › stats

CPU%/memória/PIDs lidos do cgroup v2 do próprio container (resolvido por /proc/<pid>/cgroup, qualquer que seja a base delegada). Sem delegação de cgroup (rootless sem Delegate=yes), a memória cai para o VmRSS do init do container, marcada com ~.

CPU%/memory/PIDs read from the container's own cgroup v2 (resolved via /proc/<pid>/cgroup, whatever the delegated base is). Without cgroup delegation (rootless with no Delegate=yes), memory falls back to the container init's VmRSS, marked with ~.

ExemplosExamples

Uma amostra de todos os que correm
One sample of everything running
delonix container stats

container apply

Apply the kind: Container documents of a manifest (idempotent by name).

An existing container with that name is neither recreated nor checked for spec drift, see cmd::manifest.

Usage: delonix container apply [OPTIONS]

Options:
  -f, --file <FILE>
          

      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # apply the kind: Container documents of the default manifest
  delonix container apply

  # from another file
  delonix container apply -f prod.yaml

SEE ALSO:
  delonix stack apply · delonix stack plan · delonix container init

  delonix › container › apply

ExemplosExamples

Aplicar só os `kind: Container` de um manifesto
Apply just the `kind: Container` entries from a manifest
delonix container apply -f delonix-manifest.yaml

container init

Initialize a project with a Delonixfile + manifest.

Files ALREADY FILLED IN (images included), ready to use without editing anything.

Usage: delonix container init [OPTIONS] [DIR]

Arguments:
  [DIR]
          Project directory (default: the current one)
          
          [default: .]

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

      --name <NAME>
          Project name (default: the directory name)

      --image <IMAGE>
          Image to use. Omit = fill in with the default image

      --force
          Overwrite existing files

  -t, --template <TEMPLATE>
          Generate a complete PROJECT for a stack (e.g. `python`) with best practices, instead of the generic scaffold. `--template list` shows the available ones

  -v, --template-version <TEMPLATE_VERSION>
          Version parameter some templates read — an image tag, a framework version, or a toolchain version, depending on the template; the exact accepted form is documented in that template's own README. Refused with a clear error on a template that has none

      --up
          After generating, build the image, start it, and wait until it's healthy

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # scaffold a project already filled in, ready to run
  delonix container init

SEE ALSO:
  delonix init · delonix stack init · delonix container apply

  delonix › container › init

ExemplosExamples

Scaffold de um projecto completo, pronto a usar
Scaffold a complete, ready-to-use project
delonix container init myapp && cd myapp

container kill

Send a signal to one or more containers (default SIGKILL).

Unlike stop, does not wait or force a Stopped status: the real outcome (e.g. Crashed for a KILL) is picked up on the next observation.

Usage: delonix container kill [OPTIONS] <IDS>...

Arguments:
  <IDS>...
          

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -s, --signal <SIGNAL>
          Signal name (`KILL`, `SIGKILL`, case-insensitive, `SIG` prefix optional) or number (`9`)
          
          [default: KILL]

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # SIGKILL, no waiting
  delonix container kill web

  # any signal, by name or number — this one asks nginx to reload
  delonix container kill -s HUP web

SEE ALSO:
  delonix container stop · delonix container restart

  delonix › container › kill

Ao contrário de stop, não espera nem força o estado — o resultado real (ex.: Crashed para um KILL) só se confirma na observação seguinte.

Unlike stop, it doesn't wait for or force the state — the real outcome (e.g. Crashed for a KILL) is only confirmed on the next observation.

ExemplosExamples

Sinal arbitrário, sem forçar `Stopped`
Arbitrary signal, without forcing `Stopped`
delonix container kill -s USR1 web

container wait

Block until one or more containers exit, then print their exit code (one per line, in the order given)

Usage: delonix container wait [OPTIONS] <IDS>...

Arguments:
  <IDS>...
          

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # block until it exits, then print the exit code
  delonix container wait job

SEE ALSO:
  delonix container run · delonix container logs · delonix container ps

  delonix › container › wait

O exit code real só é garantido quando um supervisor --restart é o pai real do processo — um container -d simples sem supervisor mostra Crashed/137, limite arquitectural conhecido (o motor não é o pai real desse processo).

The real exit code is only guaranteed when a --restart supervisor is the process's real parent — a plain -d container with no supervisor shows Crashed/137, a known architectural limit (the engine isn't that process's real parent).

ExemplosExamples

Bloqueia até sair, imprime o exit code
Blocks until it exits, prints the exit code
delonix container wait web

container restart

Stop then start one or more containers.

Reuses the persistent rootfs and the original run configuration, like start.

Usage: delonix container restart [OPTIONS] <IDS>...

Arguments:
  <IDS>...
          

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -t, --time <TIME>
          Seconds until SIGKILL, for the `stop` half
          
          [default: 10]

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # stop and start again, keeping the original configuration
  delonix container restart web

SEE ALSO:
  delonix container start · delonix container stop · delonix container update

  delonix › container › restart

ExemplosExamples

Pára e arranca de novo, mesma configuração
Stop and start again, same configuration
delonix container restart web

container rename

Give a container a new name

Usage: delonix container rename [OPTIONS] <ID> <NEW_NAME>

Arguments:
  <ID>
          

  <NEW_NAME>
          

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # give it a new name — the ID does not change
  delonix container rename web frontend

SEE ALSO:
  delonix container ps · delonix container describe

  delonix › container › rename

ExemplosExamples

delonix container rename web frontend

container port

Published ports of a container (hostPort/proto -> containerPort)

Usage: delonix container port [OPTIONS] <ID>

Arguments:
  <ID>
          

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # which host ports reach this container
  delonix container port web

SEE ALSO:
  delonix container update · delonix net ingress ls

  delonix › container › port

ExemplosExamples

Portas publicadas deste container
This container's published ports
delonix container port web

container pause

Suspend a container's processes (cgroup v2 freezer).

The state stays in memory, unlike stop. Resume with unpause.

Usage: delonix container pause [OPTIONS] <IDS>...

Arguments:
  <IDS>...
          

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # freeze the processes — the state stays in memory, unlike stop
  delonix container pause web

SEE ALSO:
  delonix container unpause · delonix container stop

  delonix › container › pause

ExemplosExamples

Suspende os processos (cgroup v2 freezer)
Suspends the processes (cgroup v2 freezer)
delonix container pause web

container unpause

Resume a container suspended with pause

Usage: delonix container unpause [OPTIONS] <IDS>...

Arguments:
  <IDS>...
          

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # resume a frozen container
  delonix container unpause web

SEE ALSO:
  delonix container pause

  delonix › container › unpause

ExemplosExamples

Resume um container suspenso
Resumes a suspended container
delonix container unpause web

container commit

Create an image from a container's CURRENT rootfs state (whatever was written inside becomes a new layer)

Usage: delonix container commit [OPTIONS] <ID> <TAG>

Arguments:
  <ID>
          

  <TAG>
          Tag for the new image (e.g. `app:v2`)

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # turn what was written inside into a new image
  delonix container commit web myapp:v1

SEE ALSO:
  delonix image ls · delonix build · delonix container diff

  delonix › container › commit

ExemplosExamples

Cria uma imagem a partir do rootfs actual do container
Creates an image from the container's current rootfs
delonix container commit web minha-app:debug

container healthcheck

Run the image's HEALTHCHECK inside the container. Exits with 1 if unhealthy — usable in a script/CI

Usage: delonix container healthcheck [OPTIONS] <ID>

Arguments:
  <ID>
          

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # run the image's HEALTHCHECK — exits 1 if unhealthy, so a script can gate
  # on it
  delonix container healthcheck web

SEE ALSO:
  delonix container describe · delonix container run

  delonix › container › healthcheck

ExemplosExamples

Corre o HEALTHCHECK da imagem, exit 1 se unhealthy (usável em CI)
Runs the image's HEALTHCHECK, exit 1 if unhealthy (usable in CI)
delonix container healthcheck web

container top

Processes running inside a container (read from cgroup.procs)

Usage: delonix container top [OPTIONS] <ID>

Arguments:
  <ID>
          

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # the processes inside the container
  delonix container top web

SEE ALSO:
  delonix container stats · delonix container exec

  delonix › container › top

ExemplosExamples

Processos a correr dentro do container
Processes running inside the container
delonix container top web

container diff

Files changed relative to the image: A = created/changed, D = deleted

Usage: delonix container diff [OPTIONS] <ID>

Arguments:
  <ID>
          

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # what changed relative to the image: A created/changed, D deleted
  delonix container diff web

SEE ALSO:
  delonix container commit · delonix container cp

  delonix › container › diff

ExemplosExamples

Ficheiros alterados relativos à imagem (A/D)
Files changed relative to the image (A/D)
delonix container diff web

container cp

Copy files between the host and a container.

Exactly one side is container:/path (e.g. delonix container cp web:/etc/nginx.conf .).

Usage: delonix container cp [OPTIONS] <SRC> <DST>

Arguments:
  <SRC>
          

  <DST>
          

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # out of the container onto the host
  delonix container cp web:/etc/nginx/nginx.conf .

  # from the host into the container
  delonix container cp ./site.conf web:/etc/nginx/conf.d/

SEE ALSO:
  delonix container exec · delonix container diff

  delonix › container › cp

ExemplosExamples

Do container para o host
From the container to the host
delonix container cp web:/etc/nginx.conf .
Do host para o container
From the host to the container
delonix container cp ./nginx.conf web:/etc/nginx.conf

container describe

Human-readable detail of one or more containers, kubectl describe-style.

For humans; use inspect for script-consumable JSON.

Usage: delonix container describe [OPTIONS] <IDS>...

Arguments:
  <IDS>...
          

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # the readable detail — kubectl describe style
  delonix container describe web

SEE ALSO:
  delonix container inspect · delonix container ps

  delonix › container › describe

ExemplosExamples

Detalhe estilo `kubectl describe` (para humanos; `inspect` é para scripts)
`kubectl describe`-style detail (for humans; `inspect` is for scripts)
delonix container describe web

container update

Reconfigure a RUNNING container without stopping it — ports, volumes, and bandwidth cap.

Unlike docker (where changing a port or a volume forces recreating the container), here the dataplane doesn't belong to the process lifecycle: ports are DNAT/hostfwd in front of the network and volumes come in through the kernel's mount API (open_tree/move_mount) in the mount namespace of the already-live container. The PID doesn't change and the process is never interrupted.

For which NETWORKS the container is on, see network connect/network disconnect — Docker's own verb for that, kept apart from ports/ volumes/limits, which Docker cannot reconfigure hot at all.

The changes are persisted in the registry, so a later container start reproduces the new configuration, not the original.

Usage: delonix container update [OPTIONS] <ID>

Arguments:
  <ID>
          

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -p, --publish-add <SPEC>
          Publish one more port hot, `hostPort:contPort[/tcp|udp]`. Repeatable

      --publish-rm <HOST_PORT>
          Unpublish a port hot, by HOST PORT. Repeatable

  -v, --volume-add <SPEC>
          Mount a volume hot, `name:/target[:ro]` or `/host:/target[:ro]`. Repeatable

      --volume-rm <TARGET>
          Unmount hot, by the TARGET path inside the container. Repeatable

      --net-rate <RATE>
          Bandwidth cap, in bit/s with a suffix (`10mbit`, `512kbit`, `1gbit`)

      --net-burst <BURST>
          Burst for the bandwidth cap (default: ~100 ms of throughput, at least 16 KiB). Only with `--net-rate`

      --net-rate-clear
          Remove the bandwidth cap

  -m, --memory <MEMORY>
          New memory limit hot (`64M`, `2G`, `max`)

  -c, --cpus <CPUS>
          New CPU quota hot (number of cores, e.g. `0.5`, `2`)

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # publish a new port on a RUNNING container — the PID does not change
  delonix container update --publish-add 9000:80 web

  # swap a port in one command: removals run before additions
  delonix container update --publish-rm 8080 --publish-add 8080:9000 web

  # raise the memory and CPU caps live
  delonix container update --memory 1G --cpus 2 db

  # cap the bandwidth of its existing network link
  delonix container update --net-rate 10mbit web

SEE ALSO:
  delonix container run · delonix container restart · delonix network connect

  delonix › container › update

Reconfigura portas, volumes, limite de banda e limites de memória/CPU de um container a correr, sem o parar — o PID não muda. Remoções correm antes das adições, para --publish-rm 8080 --publish-add 8080:9000 funcionar num só comando. --memory/--cpus reescrevem o cgroup real de imediato (memory.max/cpu.max) — nada de esperar por um restart. A filiação de REDE (a que redes o container está ligado) mudou-se para delonix network connect/network disconnect — o verbo do próprio Docker para isso.

Reconfigures a running container's ports, volumes, bandwidth limit and memory/CPU limits without stopping it — the PID doesn't change. Removals run before additions, so --publish-rm 8080 --publish-add 8080:9000 works in a single command. --memory/--cpus rewrite the real cgroup immediately (memory.max/cpu.max) — no waiting for a restart. Which NETWORKS the container is on moved to delonix network connect/network disconnect — Docker's own verb for that.

ExemplosExamples

Troca uma porta a QUENTE, sem reiniciar
Hot-swap a port, no restart
delonix container update web --publish-add 9090:80
Limita a banda da rede que já tem
Cap the bandwidth of its existing network link
delonix container update web --net-rate 10mbit
Sobe o limite de memória/CPU a QUENTE, sem reiniciar
Raise the memory/CPU limit on the fly, no restart
delonix container update web --memory 512M --cpus 2

container attach

Re-attach to a running container's output stream (output only).

Same log file logs -f reads. Unlike docker attach, this is OUTPUT-ONLY: a detached container's stdin has nowhere to go (this engine keeps no live conduit to it once started, unlike a persistent per-container shim) — -i/--stdin is refused with a clear error instead of silently doing nothing.

Usage: delonix container attach [OPTIONS] <ID>

Arguments:
  <ID>
          

Options:
  -i, --interactive
          Refused: stdin forwarding isn't supported (see the command's own doc above)

      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # re-attach to the output of a detached container (output only)
  delonix container attach web

SEE ALSO:
  delonix container logs · delonix container exec

  delonix › container › attach

Deliberadamente só output — ao contrário do docker attach, não há stdin ao vivo para um container já iniciado em detached (sem shim persistente por-container). -i/--stdin é recusado com um erro claro a apontar para exec -it.

Deliberately output-only — unlike docker attach, there's no live stdin to an already-started detached container (no persistent per-container shim). -i/--stdin is refused with a clear error pointing at exec -it.

ExemplosExamples

Volta a ligar ao stream de output de um container detached
Reconnect to a detached container's output stream
delonix container attach web

LaboratórioLab

Sobe um nginx publicado, confirma que responde, e prova que o estado sobrevive a um stop/start (ao contrário de recriar o container).

delonix container run -d --name web -p 8080:80 nginx
curl localhost:8080
delonix container logs web
delonix container stop web
delonix container start web
curl localhost:8080

Bring up a published nginx, confirm it answers, and prove the state survives a stop/start (unlike recreating the container).

delonix container run -d --name web -p 8080:80 nginx
curl localhost:8080
delonix container logs web
delonix container stop web
delonix container start web
curl localhost:8080

DesafioChallenge

Sem parar o web, troca a porta publicada a quente com container update (o PID não muda) e confirma com container diff que escrever um ficheiro dentro do container aparece na comparação com a imagem original.

delonix container update web --publish-rm 8080 --publish-add 9090:80
delonix container exec web sh -c 'echo oi > /tmp/marca'
delonix container diff web

Without stopping web, hot-swap the published port with container update (the PID doesn't change) and confirm with container diff that writing a file inside the container shows up against the original image.

delonix container update web --publish-rm 8080 --publish-add 9090:80
delonix container exec web sh -c 'echo hi > /tmp/mark'
delonix container diff web