Home / Alt manpages / docker-context-export(1)

  • docker-context-export(1)
  • User command
  • linux

Export a Docker Context Safely for Backup or Transfer

You will export an existing Docker context as a .dockercontext tar archive, inspect it without unpacking it, and verify that the resulting file is suitable for a later import. Allow about ten minutes. You need the Docker CLI and access to the context you want to save. The examples use Docker Community CLI 29.8.1, installed here from docker-ce-cli version 5:29.8.1-1~ubuntu.24.04~noble.

This command saves client-side context configuration. It is not a container backup, an image export, or a daemon data backup. The archive can contain endpoint details and TLS material, so treat it like a credential-bearing configuration file.

1. Confirm the context name

List the contexts before exporting one. The asterisk identifies the context currently selected by the CLI:

$ docker context ls
NAME        DESCRIPTION                               DOCKER ENDPOINT               ERROR
default *   Current DOCKER_HOST based configuration   unix:///var/run/docker.sock

Use the exact value in the NAME column. This guide uses default because it exists on the machine where the command was tested. Replace it with a named context such as staging when appropriate.

Checkpoint: ask Docker to print the selected name if you are unsure which shell or environment setting is active:

$ docker context show
default

DOCKER_CONTEXT can override the normal selection, but docker context export CONTEXT names its target explicitly. Do not assume that the context marked with an asterisk is the one you intend to archive.

2. Export to an explicit archive path

Choose a new destination in a directory you can write, then pass it after the context name:

$ docker context export staging /path/to/staging-2026-09-23.dockercontext
Written file "/path/to/staging-2026-09-23.dockercontext"

The destination is a tar archive. If you omit the file argument, Docker uses the context name followed by .dockercontext, for example:

$ docker context export staging
Written file "staging.dockercontext"

An explicit path is easier to find in a backup job and avoids leaving an archive in an unexpected working directory. The command has no context-export-specific options in the installed manpage. Its syntax is docker context export [OPTIONS] CONTEXT [FILE|-].

3. Check the archive without extracting it

Use file and tar to check the result. These commands only read the archive:

$ file /path/to/staging-2026-09-23.dockercontext
/path/to/staging-2026-09-23.dockercontext: POSIX tar archive
$ tar -tf /path/to/staging-2026-09-23.dockercontext
meta.json
tls

On the tested local context, the archive contained meta.json and a tls entry. A named context may contain additional TLS files. Do not use tar -x merely to inspect a backup, because extraction writes files into the current directory and can mix exported material with an existing Docker configuration.

If you need to inspect the metadata, stream one member to the terminal:

$ tar -xOf /path/to/staging-2026-09-23.dockercontext meta.json
{"Name":"staging","Metadata":{},"Endpoints":{"docker":{"Host":"tcp://docker.example.invalid:2376","SkipTLSVerify":false}}}

The endpoint shown above is an example shape, not a value to copy. Your archive may show a Unix socket, an SSH endpoint, or a TLS endpoint. Avoid pasting real certificate paths, private material, or hostnames into tickets and logs.

4. Export a tar stream when a pipeline needs it

Use a single hyphen as the file argument to write the archive to standard output:

$ docker context export staging - | tar -tf -
meta.json
tls

This is useful when another process consumes the archive immediately. It also means that Docker's archive bytes and any diagnostic text share the pipeline's output stream, so send only the archive into a program that expects tar data. For a durable backup, redirect the stream to a newly chosen file and then inspect that file:

$ docker context export staging - > /path/to/staging.dockercontext
$ tar -tf /path/to/staging.dockercontext
meta.json
tls

Do not pipe an export directly into an unreviewed remote command. The archive may include credentials or private keys, and the receiving host will receive them as soon as the pipeline runs.

5. Protect and verify the saved file

Limit access to the archive before placing it in backup storage:

$ chmod 600 /path/to/staging-2026-09-23.dockercontext
$ sha256sum /path/to/staging-2026-09-23.dockercontext
0123456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef  /path/to/staging-2026-09-23.dockercontext

The digest is an integrity check for the exact file. Store it separately from the archive if you need to detect accidental changes, but do not treat a digest as encryption. Keep the archive in an access-controlled location and follow your normal secret-retention policy.

Exporting does not change the Docker context, switch the active context, restart a daemon, or require sudo when the CLI configuration is readable. If the destination directory or context files are inaccessible, fix the ownership or access policy deliberately. Do not make the archive world-readable just to get a backup job working.

6. Plan the restore check separately

The matching operation is docker context import CONTEXT FILE|-. Importing creates a context and changes local Docker CLI state, so perform it on a disposable or intended target host, not on the source machine as a casual verification step:

$ docker context import restored-staging /path/to/staging-2026-09-23.dockercontext
restored-staging
Successfully imported context "restored-staging"
$ docker context ls

Import does not prove that the remote Docker endpoint is reachable. After checking the imported definition, test connectivity with a command appropriate to that endpoint, such as docker --context restored-staging info. Do not run that command against production merely because the import succeeded.

If you imported the wrong archive, remove only the newly created context after checking the name:

$ docker context rm restored-staging

Context removal is state-changing and can remove the local definition and its associated context material. Confirm the name first and keep the original archive if you may need to import it again.

Done means

  • The intended context name was confirmed with docker context ls or docker context show.
  • A .dockercontext archive was written to an explicit, access-controlled path.
  • tar -tf verified the archive without extracting it.
  • Any stdout pipeline treated the output as sensitive tar data.
  • The archive permissions and integrity digest were checked before storage.
  • Any import test was performed deliberately on the intended target, not as an accidental local change.