How do I run an AI agent in Docker?
Write the Dockerfile
Start from an official base image that matches your language, such as Python or Node.js. Copy in your dependency file first so Docker can cache the install step, then copy the rest of your code. Set a non-root user and a clear start command so the container runs the agent the same way every time.
Keep the image small by installing only what the agent needs. A smaller image builds faster, deploys faster, and has fewer packages that could contain security problems.
Run it safely
Pass API keys with environment variables or a secrets file at runtime, never by writing them into the Dockerfile. Anyone who gets the image could otherwise read the keys. Docker Compose is helpful when the agent also needs a database, a vector store, or a separate tool server.
Mount a volume for any memory or log files you want to keep after the container restarts. Set memory and CPU limits and a restart policy for long-running agents so a runaway process cannot take over the host machine.
- Use a .dockerignore file to leave out secrets and local files
- Pass secrets at runtime, not at build time
- Set memory and CPU limits
- Use a restart policy for long-running agents
- Write logs to stdout so they are easy to read
Common mistakes
- Baking API keys into the image, where anyone with the image can read them.
- Forgetting to mount a volume, so memory is lost each time the container restarts.
