Attach to a Running Docker Container Without Losing It
You will finish with a safe way to connect your terminal to a running Docker container, leave it running when you detach, and recognise when a keyboard signal will stop the container instead. Allow about ten minutes. You need Docker CLI 29.8.1 or a compatible Docker installation, permission to access its daemon, and the name or ID of a running container.
The route
Jump straight to the step you need, or tick off Done means at the end.
Safety boundary
Attaching is not a read-only viewing mode. Your terminal can provide the container's standard input, and keys such as Ctrl-C can be forwarded to its process. Do not experiment against a production container. The examples below create a disposable container, so the cleanup step removes it.
1. Check the installed command
Read the local command contract before connecting to anything. This is an ordinary command and normally needs no elevated privileges:
$ docker --version
Docker version 29.8.1, build 4a63305
$ docker attach --help
Usage: docker attach [OPTIONS] CONTAINER
Attach local standard input, output, and error streams to a running container
The installed manual defines docker attach [OPTIONS] CONTAINER. It is an alias for docker container attach and accepts a container name or ID. If your Docker installation requires sudo, use it consistently, but do not add sudo merely because the container process runs as root. Access to the Docker daemon is the relevant permission.
Checkpoint
The command exists, the version is known, and you have identified a container that is meant to accept an interactive connection.
2. Create a disposable interactive test container
If you already have a suitable running container, skip to step 3. Otherwise, start this short-lived Alpine shell in detached interactive TTY mode. The command changes Docker state and may pull the image if it is not cached:
$ docker run -dit --name attach-demo alpine /bin/sh
<container-id>
The -d option leaves it running in the background, while -i keeps standard input open and -t allocates a terminal. Confirm that the container is running before attaching:
$ docker ps --filter name=attach-demo
CONTAINER ID IMAGE COMMAND STATUS NAMES
<container-id> alpine "/bin/sh" Up ... attach-demo
Exact IDs, elapsed times and column spacing vary. If the status is not Up, inspect the reason with docker ps -a --filter name=attach-demo before trying to attach.
3. Attach to the container
Connect your terminal to the container's standard input, output and error streams:
$ docker attach attach-demo
/ #
You are now at the shell inside the container. Run a harmless check:
/ # printf 'attached: '; uname -s
attached: Linux
The command may appear to hang when the container's main process is running but has no output. That is normal: attach displays the output of the container's entrypoint and command; it does not create a new shell. For a non-interactive process, use docker logs when you want to review output without taking over its terminal.
Multiple host sessions can attach to the same process. Treat every attached session as an active control path, especially when standard input is enabled.
4. Detach while leaving the container running
With the interactive TTY from step 2, press the two-key sequence Ctrl-P, then Ctrl-Q. Docker should return you to the host shell while the container continues running. The keystrokes are not typed into the container as ordinary input.
Verify the result from the host:
$ docker ps --filter name=attach-demo
CONTAINER ID IMAGE COMMAND STATUS NAMES
<container-id> alpine "/bin/sh" Up ... attach-demo
This is the normal recovery path if you only meant to observe or briefly interact with a long-running process. If your terminal or application uses that key sequence, choose a per-command alternative with --detach-keys, such as:
$ docker attach --detach-keys='ctrl-]' attach-demo
The local manpage lists --detach-keys as the override for the detach sequence. Confirm the exact sequence against the Docker version in use before putting it into an operational runbook.
5. Keep signals and standard input under control
The default --sig-proxy=true proxies signals received by the Docker client to the container process. That makes Ctrl-C potentially disruptive. For a test container it can stop the shell; for an important workload, disconnect with the detach sequence instead.
If you only need to watch output and do not want this client to send input, use --no-stdin:
$ docker attach --no-stdin attach-demo
That option does not make the session risk-free: signals and the container's terminal behaviour still matter. To avoid forwarding signals from this client, use:
$ docker attach --no-stdin --sig-proxy=false attach-demo
These options change this attachment only. They do not change how the container was created, and they do not alter the container's restart policy or command.
Do not press Ctrl-C as a way to leave an attached production container. Depending on the container's TTY and signal handling, it may terminate the main process. If that has already happened, confirm the state with docker ps -a. Recovery depends on the workload: restart only when its owner and restart procedure permit it.
6. Understand exit status and output limits
When the container's main process exits, docker attach returns to the host shell. Its exit status can reflect the attached process. Check it immediately if a script needs the result:
$ docker attach attach-demo
/ # exit 13
$ printf 'attach exit status: %s\n' "$?"
attach exit status: 13
In this example, exiting the shell changed the disposable container's state, so do not copy it against a service merely to test a status. For large or performance-sensitive output streams, prefer docker logs. Docker keeps an approximately 1 MB client-side buffer for an attached stdio connection; a slow client can therefore affect the process writing output once that buffer fills.
7. Remove the disposable test container
Only run this step for the container created in step 2, or another container you have explicit approval to remove. Removal is destructive: it deletes the container's writable layer, although it does not delete the Alpine image.
$ docker rm --force attach-demo
attach-demo
$ docker ps -a --filter name=attach-demo
CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES
If you detached without exiting and want to preserve the test container for another session, omit this step. The undo for an accidental removal is not a container-level restore; recreate it with the original docker run command and restore any data from your normal backup or image workflow.
Done means
- You checked the installed Docker version and attach syntax.
- You attached to the intended container by name or ID.
- You used Ctrl-P, then Ctrl-Q to detach without stopping an interactive test container.
- You know that
--sig-proxy=trueis the default and that Ctrl-C can be disruptive. - You used
--no-stdin,--sig-proxy=falseordocker logswhen the workflow called for less interaction. - You removed the disposable container only after checking that it was safe to delete.