AI DockerMcpClient

AI DockerMcpClient

Certified

Run MCP tools in Docker

Launches an MCP server inside a Docker container and exposes its tools to the agent. Requires an image; optional command, env, and binds control the container. Docker host defaults to the detected runtime; logEvents defaults to false. Provide registry credentials and TLS settings when pulling from private registries.

yaml
type: io.kestra.plugin.ai.tool.DockerMcpClient

Agent calling an MCP server in a Docker container

yaml
id: docker_mcp_client
namespace: company.ai

inputs:
  - id: prompt
    type: STRING
    defaults: What is the current UTC time?

tasks:
  - id: agent
    type: io.kestra.plugin.ai.agent.AIAgent
    provider:
      type: io.kestra.plugin.ai.provider.GoogleGemini
      apiKey: "{{ secret('GEMINI_API_KEY') }}"
      modelName: gemini-3.5-flash-lite
    prompt: "{{ inputs.prompt }}"
    tools:
      - type: io.kestra.plugin.ai.tool.DockerMcpClient
        image: mcp/time

Agent calling an MCP server in a Docker container and generating output files

yaml
id: docker_mcp_client
namespace: company.ai

inputs:
  - id: prompt
    type: STRING
    defaults: Create the file '/tmp/hello.txt' with the content "Hello World".

tasks:
  - id: agent
    type: io.kestra.plugin.ai.agent.AIAgent
    provider:
      type: io.kestra.plugin.ai.provider.GoogleGemini
      apiKey: "{{ secret('GEMINI_API_KEY') }}"
      modelName: gemini-3.5-flash-lite
    prompt: "{{ inputs.prompt }}"
    systemMessage: |
      You are a filesystem assistant. Always use the write_file tool with the exact absolute path provided in the user's request.
    tools:
      - type: io.kestra.plugin.ai.tool.DockerMcpClient
        image: mcp/filesystem
        command: ["/tmp"]
        # Mount the container path to the task working directory to access the generated file
        binds: ["{{ workingDir }}:/tmp"]
    outputFiles:
      - hello.txt
Properties

Container image

Docker image running the MCP server. No default: this property is required.

Docker API version

Docker Engine API version used by the client. Not set by default, in which case the version is negotiated with the daemon.

SubTypestring

Volume binds

Host-to-container volume mounts in host_path: container_path form, used for example to share the task working directory with the MCP server. Not set by default (no mount).

SubTypestring

MCP server arguments

Arguments passed to the container entrypoint, each element a separate command part. Not set by default, in which case the image's own entrypoint arguments are used.

Docker certificate path

Directory holding the TLS client certificates used to reach the Docker daemon. Not set by default.

Docker configuration

Docker client configuration as JSON, typically holding registry credentials. Not set by default, in which case the worker's Docker config is used.

Docker context

Name of the Docker CLI context selecting which daemon to talk to. Not set by default (the current context is used).

Docker host

URI of the Docker daemon that runs the container. Not set by default, in which case the host is auto-detected from the worker environment.

Verify Docker TLS certificates

If true, verify the Docker daemon's TLS certificate when connecting over TLS. Not set by default, in which case the Docker client default applies.

Environment variables

Environment variables set inside the container, typically to supply credentials to the MCP server. Not set by default.

Defaultfalse

Log events

If true, MCP protocol events exchanged with the container are logged. Defaults to false.

Container registry email

Email associated with the container registry account, required by some private registries. Not set by default.

Container registry password

Password or token used to pull the image from a private registry. Store it as a Kestra secret rather than inline. Not set by default (anonymous pull).

Container registry URL

Registry the image is pulled from. Not set by default, in which case Docker Hub is used.

Container registry username

User authenticating against a private container registry. Not set by default (anonymous pull).