Skip to main content

Overview

The ContainersClient lets you run temporary containers inside a room. Use it for one-off jobs, debugging, image management, or testing code in the same room environment that deployed services use.

CLI commands

Start with the CLI help, then use a few common commands:
bash

Why use the Containers API?

  • Pull and manage images without leaving the room context.
  • Run short-lived workloads or exploratory commands on demand.
  • Inspect logs or open an interactive terminal in a running container.

How it works

Containers are room-scoped workloads. You can pull images, run a container, stream logs, exec into it, stop it, and delete its metadata when you are done. Deployed Room Services and Project Services rely on the same underlying container infrastructure, but the Containers API gives you direct, on-demand control.

Permissions and grants

The Containers API is controlled by the containers grant on the participant token. In practice:
  • use_containers is the main switch for container operations
  • pull and run can be narrowed to specific image names or prefixes
  • logs controls access to container log streaming
See API Scopes and Service YAML.

API reference

Use the methods below to manage room images, start and inspect containers, and clean up container state. The SDKs also expose image-transfer helpers such as push_image, load / load_image, save_image, build helpers such as build, list_builds, cancel_build, delete_build, and get_build_logs, and service helpers such as run_service.

list_images()

  • Description: List images currently available to the room (built or pulled previously).
  • Parameters: None.
  • Returns: list[Image] summary records including id, preferred_ref, references, labels, created_at, updated_at, and target_media_type.

inspect_image(image_id)

  • Description: Inspect a room image by ID and return detailed content metadata from the container runtime.
  • Parameters:
    • image_id: Image ID from list_images().
  • Returns: ImageInspection including the image summary, target descriptor, selected manifest, manifests, config descriptor, layers, and content_size.

delete_image(image)

  • Description: Delete an unused image from the room.
  • Parameters:
    • image: Tag or digest string to delete.
  • Returns: None.

pull_image(tag, credentials=None)

  • Description: Pull an image into the room. Supports passing registry credentials when needed.
  • Parameters:
    • tag: Image reference (e.g. myrepo/app:latest).
    • credentials: Optional list of DockerSecret credentials for private registries.
  • Returns: None once the pull completes.

run(image, ...)

  • Description: Start a container in the room.
  • Parameters (all optional except image):
    • image: Container image to run.
    • command: Override the default command (str).
    • working_dir: Working directory for the container process.
    • env: Environment variables injected as dict[str, str].
    • mount_path, mount_subpath: Mount configuration when using storage.
    • mounts: Structured container mount configuration for advanced mount layouts.
    • role, participant_name: Launch on behalf of a specific room identity.
    • ports: Port mappings {container_port: host_port}.
    • credentials: Registry secrets for the image.
    • name: Friendly name for the container.
    • template: Runtime defaults to apply. "none" (default) applies no template defaults; "agent" mounts room storage at /data and injects MeshAgent/OpenAI/Anthropic/SMTP proxy environment variables using a token for the container name with role agent.
    • writable_root_fs: Override whether the container root filesystem is writable.
    • private: Request private container placement where supported.
  • Returns: Container ID string.

exec(container_id, ...)

  • Description: Attach an interactive command to an existing container and stream its output.
  • Parameters:
    • container_id: Target container.
    • command: Optional command list; defaults to the container’s shell.
    • tty: Request a TTY session (True for interactive).
  • Returns: An exec-session object (ExecSession in Python) exposing helpers to read output, send input, resize the terminal, and await completion.
The CLI streams a non-TTY exec session. Use the SDK directly when you need an explicit TTY session and terminal resize control.

Image transfer helpers

In addition to pulling an image into a room, the CLI can push an image from the room to a registry, load an OCI archive from room storage, or save an image as an OCI archive:
bash
The Python SDK exposes these container image, build, service, and lifecycle helpers:
Python

logs(container_id, follow=False)

  • Description: Stream container logs and optionally follow until exit.
  • Parameters:
    • container_id: Target container.
    • follow: True to keep streaming until the container exits.
  • Returns: LogStream[None], which you can iterate for log lines or await for completion.

list(all=None)

  • Description: List containers in the room, optionally including exited ones.
  • Parameters:
    • all: True to include stopped containers.
  • Returns: list[RoomContainer] with name, image, state, status, applicable manifest, and metadata about who started it.

stop(container_id, force=False)

  • Description: Request a graceful stop (or force stop) of a running container.
  • Parameters:
    • container_id: Target container.
    • force: Send a forceful termination signal when True.
  • Returns: None.

delete(container_id)

  • Description: Remove container metadata after it has stopped. Useful for cleaning up history.
  • Parameters:
    • container_id: Container to delete.
  • Returns: None.