awesome cli.

Run a Python check with Docker and a coding agent

Run a disposable Python check with Docker CLI and a coding agent. Learn what --rm, --network none and --read-only do, with a copyable task prompt.

Documentation guide. Commands checked against Docker’s official docs; no live Docker test was run for this article.

Docker CLI lets a coding agent run a command inside a container. You can choose the runtime without installing it into the project's host environment.

Start with a disposable Python check. The command below uses an image with Python 3.12, runs one expression and removes the container when it finishes.

Check that Docker can reach its engine

Install Docker using the official instructions. Docker CLI needs a running Docker Engine, either through Docker Desktop or another installation.

docker version

The version reference explains the client and server sections. A client version alone doesn't establish that the engine is available. If the command cannot reach the server, fix that connection before asking the agent to run a container.

You can then try Docker's hello-world example:

docker run --rm hello-world

The engine may download the image before starting the container. That needs network access if the image isn't cached.

Run one Python expression

This command runs Python in a new container:

docker run --rm --network none --read-only \
  python:3.12-slim python -c "print(2 + 2)"

If it succeeds, the Python expression prints 4. That is the expected result, rather than output from a run we performed for this article.

Here's what the arguments do:

Argument Effect
--rm Removes the container when it exits
--network none Gives this container no external network connection
--read-only Makes its root filesystem read-only
python:3.12-slim Selects the image
python -c ... Runs the expression inside that image

The run reference documents these options. The image download happens before the container's command runs. --network none doesn't prevent the engine from pulling a missing image. --rm removes the container; downloaded images remain on the machine.

This example doesn't mount a host directory. If you need project files inside a container, decide which files it needs before adding a mount. Some real tests also need writable temporary storage or network access, so the flags above aren't a template for all tests.

Give the agent a bounded task

An agent with shell access can run Docker CLI directly. Start with a task like this:

Check whether Docker can reach its engine.
Show me the command for a disposable Python 3.12
container that evaluates 2 + 2.

Use no host mounts and no Docker socket mount.
Use --rm. Ask before downloading an image.
Report the command, exit status and output.

The prompt keeps the first test small. Once you have a command that does something useful, put it in a script or project task. A person can run the same command without the agent.

Choose the image for repeatable work

python:3.12-slim is a readable starting point. A tag can change when its maintainer publishes an update. For work that needs the same image contents, use a reviewed digest. Docker's image pull reference shows that syntax.

A container gives you a separate runtime. Docker daemon access is still powerful, and a container is not a complete permission boundary for a coding agent. Keep the first task limited to the command you intend to run.

The CLI-first article explains the wider idea. Browse the directory for other tools your agent can call from the shell.