
AI DockerMcpClient
CertifiedRun MCP tools in Docker
AI DockerMcpClient
Run MCP tools in Docker
Launches an MCP server inside a Docker container and exposes its tools to the agent. Requires an image; optional command, env, and binds control the container. Docker host defaults to the detected runtime; logEvents defaults to false. Provide registry credentials and TLS settings when pulling from private registries.
type: io.kestra.plugin.ai.tool.DockerMcpClientExamples
Agent calling an MCP server in a Docker container
id: docker_mcp_client
namespace: company.ai
inputs:
- id: prompt
type: STRING
defaults: What is the current UTC time?
tasks:
- id: agent
type: io.kestra.plugin.ai.agent.AIAgent
provider:
type: io.kestra.plugin.ai.provider.GoogleGemini
apiKey: "{{ secret('GEMINI_API_KEY') }}"
modelName: gemini-3.5-flash-lite
prompt: "{{ inputs.prompt }}"
tools:
- type: io.kestra.plugin.ai.tool.DockerMcpClient
image: mcp/timeAgent calling an MCP server in a Docker container and generating output files
id: docker_mcp_client
namespace: company.ai
inputs:
- id: prompt
type: STRING
defaults: Create the file '/tmp/hello.txt' with the content "Hello World".
tasks:
- id: agent
type: io.kestra.plugin.ai.agent.AIAgent
provider:
type: io.kestra.plugin.ai.provider.GoogleGemini
apiKey: "{{ secret('GEMINI_API_KEY') }}"
modelName: gemini-3.5-flash-lite
prompt: "{{ inputs.prompt }}"
systemMessage: |
You are a filesystem assistant. Always use the write_file tool with the exact absolute path provided in the user's request.
tools:
- type: io.kestra.plugin.ai.tool.DockerMcpClient
image: mcp/filesystem
command: ["/tmp"]
# Mount the container path to the task working directory to access the generated file
binds: ["{{ workingDir }}:/tmp"]
outputFiles:
- hello.txtProperties
image *string
Container image
Docker image running the MCP server. No default: this property is required.
apiVersion string
Docker API version
Docker Engine API version used by the client. Not set by default, in which case the version is negotiated with the daemon.
binds array
Volume binds
Host-to-container volume mounts in host_path: container_path form, used for example to share the task working directory with the MCP server. Not set by default (no mount).
command array
MCP server arguments
Arguments passed to the container entrypoint, each element a separate command part. Not set by default, in which case the image's own entrypoint arguments are used.
dockerCertPath string
Docker certificate path
Directory holding the TLS client certificates used to reach the Docker daemon. Not set by default.
dockerConfig string
Docker configuration
Docker client configuration as JSON, typically holding registry credentials. Not set by default, in which case the worker's Docker config is used.
dockerContext string
Docker context
Name of the Docker CLI context selecting which daemon to talk to. Not set by default (the current context is used).
dockerHost string
Docker host
URI of the Docker daemon that runs the container. Not set by default, in which case the host is auto-detected from the worker environment.
dockerTlsVerify booleanstring
Verify Docker TLS certificates
If true, verify the Docker daemon's TLS certificate when connecting over TLS. Not set by default, in which case the Docker client default applies.
env object
Environment variables
Environment variables set inside the container, typically to supply credentials to the MCP server. Not set by default.
logEvents booleanstring
falseLog events
If true, MCP protocol events exchanged with the container are logged. Defaults to false.
registryEmail string
Container registry email
Email associated with the container registry account, required by some private registries. Not set by default.
registryPassword string
Container registry password
Password or token used to pull the image from a private registry. Store it as a Kestra secret rather than inline. Not set by default (anonymous pull).
registryUrl string
Container registry URL
Registry the image is pulled from. Not set by default, in which case Docker Hub is used.
registryUsername string
Container registry username
User authenticating against a private container registry. Not set by default (anonymous pull).