Docker just made AI agents as distributable as container images. The company open-sourced docker-agent, a CLI plugin that defines an AI agent in a YAML file and runs it with docker agent run — the same mental model you already use for containers. Version 1.149.0 shipped October 7, hit the Hacker News front page the same day, and comes pre-installed in Docker Desktop 4.63+.
What Docker Agent Is (And Isn’t)
Docker Agent is not another Python framework. It’s a YAML runtime. You write a config file, point it at a model, attach tools, and run. No SDK, no dependency graph, no orchestration code. A fully functional agent is about 15 lines:
agents:
root:
model: anthropic/claude-sonnet-4-5
description: A coding assistant
instruction: Help users write clean, efficient code.
toolsets:
- type: filesystem
- type: shell
- type: think
Run it interactively with docker agent run agent.yaml, or non-interactively with docker agent run --exec agent.yaml "create a Dockerfile". It also serves as an HTTP API via docker agent serve api agent.yaml --listen :8080, exposing an OpenAI-compatible chat endpoint.
Supported providers: OpenAI, Anthropic, Google Gemini, AWS Bedrock, Mistral, xAI, and local models via Docker Model Runner or Ollama. Set an API key, point the YAML at a model string, and it routes accordingly.
Multi-Agent Teams
The sub_agents field is where Docker Agent earns its complexity budget. A root coordinator delegates to specialist sub-agents, each with its own model, toolset, and instructions. The root agent gets a transfer_task tool automatically — no wiring required:
agents:
root:
model: anthropic/claude-sonnet-4-5
sub_agents: [researcher, writer]
researcher:
model: openai/gpt-5
toolsets:
- type: mcp
ref: docker:duckduckgo
writer:
model: anthropic/claude-sonnet-4-5
toolsets:
- type: filesystem
Each sub-agent runs in isolation — no shared context. That’s both a design choice and a constraint. Clean handoffs, predictable behavior, but no implicit state passing between agents. If your workflow needs dynamic context sharing, you’ll hit friction here.
MCP Integration and the v1.149.0 Release
Docker Agent speaks MCP natively. Any MCP server — from Docker’s catalog or third-party — attaches via the mcp toolset. The recommended pattern is running MCP servers inside Docker containers, which extends Docker’s existing container security model to agent tool access. That’s a meaningful security story compared to bare-process MCP setups.
The October 7 release added two features worth noting: GitHub skills let the skills: field point directly at a public GitHub repository instead of requiring manual copying; and a dedicated evaluator service replaces LLM-as-judge for agent testing, eliminating an entire class of token costs during development.
The Real Differentiator: OCI Distribution
Here’s where Docker Agent separates itself from LangChain and CrewAI, and why the feature comparison misses the point. LangChain agents live in Python files. Docker agents live in OCI registries — versioned, immutable, pullable anywhere Docker runs:
docker agent run myorg/agent:latest
docker agent run myorg/agent@sha256:abc123 # pinned to digest
That’s Docker Hub as the distribution layer for agents, not just images. Your team ships a tested agent the same way it ships a container. Internal tooling teams can maintain a versioned agent catalog. Consumers pull a specific release. Rollbacks are a tag change. This is a genuinely new capability in the agent space — and it’s the most compelling reason to evaluate Docker Agent beyond “it’s YAML.”
Who Should Look at This Now
DevOps and platform engineers already living in Docker Compose have the lowest adoption friction — the YAML syntax is familiar and the toolset maps directly to their workflow. Platform teams building internal agent catalogs get immediate value from OCI distribution. Developers who want to prototype without managing a Python environment are the third obvious segment.
Who should wait: ML engineers needing LangGraph-style stateful control, teams requiring dynamic context sharing between agents, or workflows that need escape hatches into arbitrary code. Docker Agent is declarative by design — that’s a feature and a ceiling.
The honest take: Docker Agent is most interesting as a distribution layer, not a framework competitor. Compare it to agent hosting services and internal tooling platforms, not to LangChain. If that’s the problem you’re solving, the official Docker Agent documentation is worth reading today.













