How do I run an AI agent in Docker?

Updated October 2026 · How we answer

Short answerPut your agent code and its dependencies in a Dockerfile, pass API keys in as environment variables at runtime, and start the container with docker run or Docker Compose. Keep secrets out of the image itself.

Write the Dockerfile

Start from an official base image that matches your language, such as Python or Node.js. Copy in your dependency file first so Docker can cache the install step, then copy the rest of your code. Set a non-root user and a clear start command so the container runs the agent the same way every time.

Keep the image small by installing only what the agent needs. A smaller image builds faster, deploys faster, and has fewer packages that could contain security problems.

Run it safely

Pass API keys with environment variables or a secrets file at runtime, never by writing them into the Dockerfile. Anyone who gets the image could otherwise read the keys. Docker Compose is helpful when the agent also needs a database, a vector store, or a separate tool server.

Mount a volume for any memory or log files you want to keep after the container restarts. Set memory and CPU limits and a restart policy for long-running agents so a runaway process cannot take over the host machine.

  • Use a .dockerignore file to leave out secrets and local files
  • Pass secrets at runtime, not at build time
  • Set memory and CPU limits
  • Use a restart policy for long-running agents
  • Write logs to stdout so they are easy to read

Common mistakes

  • Baking API keys into the image, where anyone with the image can read them.
  • Forgetting to mount a volume, so memory is lost each time the container restarts.
From our shopsTitan Case: Premium MagSafe iPhone cases with a precision fit.