To run a Docker image on Cloud Foundry, an operator must enable Docker-image support and configure registry access. A developer can then deploy a tagged image with cf push APP-NAME --docker-image REPO/IMAGE:TAG. Cloud Foundry runs the resulting workload through Diego and Garden-runC; it does not run Docker Engine as the application runtime.
What you need before deploying
Docker-image support is disabled by default in the documented Cloud Foundry administration workflow. An operator must enable the diego_docker feature flag and configure access to the image registry, including any required registry certificates or IP allow lists. The exact settings can vary by foundation and release. The Cloud Foundry guide explains the [enablement and operator configuration](https://docs.cloudfoundry.org/adminguide/docker.html).
The image and registry must meet platform requirements:
- The image must include
/etc/passwdwith arootentry, a root home directory, and a shell. - Image layers must fit within the app disk quota. The Cloud Foundry guide gives 2048 MB as the default maximum per app, subject to operator configuration.
- The registry must implement Docker Registry HTTP API V2 and present a valid HTTPS certificate.
- For interactive access with
cf ssh, the image must includeshorbashat a supported path.
See the [Cloud Foundry Docker image requirements](https://docs.cloudfoundry.org/devguide/deploy-apps/push-docker.html) and check the target foundation’s configuration for its applicable limits and registry rules.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11#1 Best Overall
Deploy an image
- Choose a tagged image. Use an explicit tag so the deployment identifies a known image version rather than implicitly selecting
latest. - Push it from the Cloud Foundry CLI. Run
cf push APP-NAME --docker-image REPO/IMAGE:TAG, replacing the placeholders with the app name and the image repository and tag. Cloud Foundry documents Docker Hub, private registries, Amazon ECR, and Google Container Registry workflows in its [push Docker image guide](https://docs.cloudfoundry.org/devguide/deploy-apps/push-docker.html). - Check the application state and route. The platform fetches the image layers, creates the container filesystem, and starts the process. Confirm the app is running and that its configured port is reachable through the route.
When you omit a tag, Cloud Foundry applies latest. The documentation notes that changes to image PORT or ENTRYPOINT may require cf restage before they take effect.
How Cloud Foundry runs a Docker image
A Docker image is the packaging format; it is not a Docker Engine running inside Cloud Foundry. Diego schedules the workload, and Garden-runC provides the container runtime. Garden-runC uses OCI low-level container execution along with Linux namespaces and cgroups. Cloud.gov’s explanation of its runtime states that “No Docker components are involved in this process” and identifies Garden-runC as the runtime: [Cloud.gov Docker apps](https://cloud.gov/docs/management/apps/docker/).
Rank #2
Garden’s GrootFS plugin creates filesystems from remote images, authenticates to registries, maps user and group IDs, and enforces per-container disk quotas. The relevant implementation details are in the [Garden documentation](https://github.com/cloudfoundry/garden-runc-release).
How Cloud Foundry chooses the port and startup command
Ports and routing
Cloud Foundry supplies a dynamic PORT environment variable. An ENV PORT instruction in the Dockerfile does not override the platform-assigned value. If the image declares a port with Dockerfile EXPOSE, Cloud Foundry uses the corresponding port; without EXPOSE, it uses the assigned PORT. When an image exposes multiple ports, the first exposed port is routed by default, and additional destinations can be configured. Consult the [Cloud Foundry Docker image deployment guide](https://docs.cloudfoundry.org/devguide/deploy-apps/push-docker.html) for the platform’s port behavior.
Rank #3
Startup command
The default process comes from the image’s Docker CMD and/or ENTRYPOINT. To override it for a Cloud Foundry deployment, use the -c option with cf push or set the manifest’s command property. This lets you change the process without rebuilding the image, but the command still needs to be valid for the image’s filesystem and installed software.
Do Docker apps use Cloud Foundry stacks?
No. A Docker image supplies its own root filesystem, so stack selection such as cflinuxfs4 applies to buildpack-based apps, not Docker-image apps. Cloud Foundry’s documentation puts it plainly: “Docker apps do not use stacks.” See [Cloud Foundry stacks](https://docs.cloudfoundry.org/devguide/deploy-apps/stacks.html).
Docker-image apps compared with buildpack apps
| Consideration | Docker-image deployment | Buildpack deployment |
|---|---|---|
| Root filesystem | The image author supplies the root filesystem. | The platform supplies a trusted root filesystem. |
| Image and dependency control | The team controls the image contents and can select a specific tag; a mutable tag such as latest is less explicit. |
The buildpack and platform determine the build and runtime environment. |
| Startup and port metadata | Uses image CMD/ENTRYPOINT and port metadata such as EXPOSE, with Cloud Foundry overrides and routing rules. |
Uses buildpack and Cloud Foundry app configuration rather than Docker image metadata. |
| Registry dependency | Requires a reachable, compatible registry and operator-configured access. | Does not require the app to be fetched from a Docker registry. |
| Stack selection | Not applicable; the image provides its filesystem. | Uses a Cloud Foundry stack, such as cflinuxfs4, where supported. |
| Disk quota | Image layers must fit the app’s configured disk quota; the documented default maximum is 2048 MB per app, subject to operator settings. | Uses the app disk quota configured for the foundation and deployment. |
| SSH access | Requires a supported shell such as sh or bash in the image. |
Shell availability depends on the buildpack-provided app environment. |
| Security maintenance | The image owner is responsible for maintaining the chosen image filesystem and its contents. | The app relies on the platform-provided trusted root filesystem, alongside application dependency maintenance. |
Security and operational considerations
Because Docker-image authors control the entire root filesystem, Cloud Foundry describes this deployment path as having a somewhat higher attack surface than a buildpack app. The platform uses user namespaces for Docker apps and, by default, runs app instances and staging tasks in unprivileged containers. Garden-runC also applies AppArmor and seccomp controls. These protections do not remove the need to maintain the image and its software. See the [Cloud Foundry administration guidance](https://docs.cloudfoundry.org/adminguide/docker.html) and [Garden documentation](https://github.com/cloudfoundry/garden-runc-release).
Operators should account for a feature-flag change operationally: disabling diego_docker stops Docker-image apps after a few convergence cycles. Registry authentication methods, supported image formats, quotas, and hardening details can differ by Cloud Foundry distribution and operator configuration, so verify them for the target foundation.
Quick Recap
Best Value
- Docker, Docker Swarm, Docker Compose, Programmer, Developer, Coding, Programming, Software Engineer, Code, DevOps, Deploy, Deployment, Kubernetes, Salt, Puppet, Chef, Terraform, Container, AWS, Azure, Cloud, Geek, Funny, Computer, Software, Tech, IT
- Integration, Scrum, Compile, Compilation, Science, Bug, Debug, Python, Linux, Java, Javascript, Scala, Dotnet, Kotlin
- Lightweight, Classic fit, Double-needle sleeve and bottom hem
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

