HostConfig, while the container-side port declaration belongs in
ContainersCreatePostBody. Declaring an exposed port alone does not publish it.
Ports, a bind mount and restart policy
This example creates, but does not start, a development container. Pullnginx:alpine first using the image pull recipe. Create
/srv/docker-php-example/html on the daemon host, with an index.html file,
before running it. Choose an unused example name and host port.
containerStart($created->getId()) to start
that container. The example deliberately leaves it stopped. Remove only that
created container when you are done; do not use a broad prune operation.
Details worth checking
- Port keys include the protocol:
80/tcpand80/udpare different entries. - Each port maps to a list of
PortBindingmodels, even for one binding. HostPortis a string. An empty string requests a daemon-assigned host port; inspect the container after starting it to discover the binding.HostIpabove binds the published port to the daemon host’s loopback address. It does not refer to the PHP client’s machine when using a remote daemon.- Bind-mount source paths are on the daemon host, not the PHP client. Docker Desktop may add another host/VM file-sharing boundary.
- Mounting over a container path hides its existing contents. A read-only mount still exposes its files to the container, so do not mount secrets casually.
- Environment entries are
NAME=valuestrings. Do not log sensitive values or treat ordinary container environment variables as a secret store. containerCreate()does not pull a missing image. Pull and check the progress stream before creating the container.
on-failure and set
MaximumRetryCount; do not set that count as a general limit on always or
unless-stopped.
For networking beyond port publication, look at NetworkingConfig and its
EndpointsConfig map of EndpointSettings models. Keep network attachment
and port publication separate; attaching to a network does not expose a port
on the host.