Home / Alt manpages / docker-port(1)

  • docker-port(1)
  • User command
  • linux

Check Docker Port Mappings Without Guessing

You will finish with a reliable way to see which host addresses and ports Docker has published for a container, or to query one private container port. The guide uses the installed Docker CLI 29.8.1 and the docker port command. Allow about ten minutes if the container already exists, or fifteen minutes if you need to identify it first.

You need a running Docker daemon and a container that you can inspect. These checks are normally unprivileged: do not add sudo unless your local Docker installation specifically requires it. Membership of the Docker group is itself security-sensitive because it normally grants control of the Docker daemon.

1. Check the installed command

Start with the local help output. This is a read-only command and does not start, stop or modify a container:

$ docker port --help
Usage:  docker port CONTAINER [PRIVATE_PORT[/PROTO]]

List port mappings or a specific mapping for the container

The local manpage describes docker port as an alias for docker container port. The two spellings use the same positional arguments. There are no options listed by the installed manpage, so do not add guessed flags such as --all or --protocol.

Checkpoint: confirm the CLI version if you are documenting or troubleshooting a particular host:

$ docker version --format '{{.Client.Version}}'
29.8.1

Your version may differ. Keep the local help and manpage beside any automation, because command details can change between Docker releases.

2. Identify the container safely

CONTAINER can be a container name or ID. Use docker ps to list running containers rather than guessing a name:

$ docker ps --format 'table {{.ID}}	{{.Names}}	{{.Status}}	{{.Ports}}'
CONTAINER ID   NAMES      STATUS          PORTS
b650456536c7   web-demo   Up 54 minutes   0.0.0.0:8080->80/tcp

For this guide, set a shell variable to the exact name from your own output:

$ container_name='web-demo'
$ docker inspect --format '{{.Name}}' "$container_name"
/web-demo

This inspection is read-only. If the name is wrong, Docker reports that it cannot find the container. If the daemon is unavailable, fix that service or context problem first. Do not respond to a connection error by deleting and recreating a working container.

3. List every published mapping

Omit the private port to ask for all mappings Docker knows for the container:

$ docker port "$container_name"
80/tcp -> 0.0.0.0:8080

The left side is the container's private port and protocol. The right side is the host address and port. An address of 0.0.0.0 means Docker published the port on all IPv4 interfaces; it is not the same as an address that only local processes can reach. Treat a public host binding as a security boundary worth checking.

Docker can print more than one line. For example, a container with two mappings might produce:

$ docker port web-demo
80/tcp -> 0.0.0.0:8080
443/tcp -> 127.0.0.1:8443

Do not assume the host port equals the private port. The first mapping above exposes private port 80 on host port 8080, while the second exposes private port 443 only on the host loopback address and port 8443.

Checkpoint: save or review the command output before testing an application. It tells you which endpoint Docker published, but not whether the application inside the container is healthy.

4. Query one private port

Supply a private port when you want one mapping instead of the complete list. The protocol is optional:

$ docker port "$container_name" 80
0.0.0.0:8080

Use PRIVATE_PORT/PROTO when the protocol matters or when the container uses both TCP and UDP:

$ docker port "$container_name" 53/udp
0.0.0.0:5353

Keep the slash form exact. 53/tcp and 53/udp are different mappings. If you omit the protocol, Docker's behaviour follows the command's port lookup rules, so specify it in scripts and incident notes.

5. Separate a published port from an intended port

A port shown by an image description or by an application's documentation is not proof that the host can reach it. docker port reports the mappings actually associated with this container. If it prints nothing, there may be no published mapping even though the process listens on a private container port.

Compare the result with the container's port information when the distinction is unclear:

$ docker ps --filter "name=$container_name" --format '{{.Ports}}'
0.0.0.0:8080->80/tcp

The two commands present the same mapping in different formats. Neither command changes it. A successful lookup also does not prove that a firewall permits traffic, that DNS points at the host, or that the service is accepting connections.

6. Diagnose the common failures

If Docker reports that no public port was published for the requested private port, check the protocol and then list all mappings:

$ docker port "$container_name" 80/udp
Error: No public port '80/udp' published for web-demo
$ docker port "$container_name"
80/tcp -> 0.0.0.0:8080

Here the container has TCP port 80 published, not UDP port 80. Correcting the query does not change the container.

If the command says the container does not exist, check the active Docker context and both running and stopped containers:

$ docker context show
default
$ docker ps -a --format '{{.ID}}	{{.Names}}	{{.Status}}'
b650456536c7	web-demo	Up 54 minutes

A context points the CLI at a particular Docker daemon. Inspect the context before switching it. Changing context is an environment change and can make subsequent commands affect a different host; do not run docker context use as a blind repair.

If there is no mapping at all, this command cannot create one. Publishing a new port normally means replacing or recreating the container with the intended port configuration, which can interrupt service and may lose unpersisted data. Take a configuration backup and follow the deployment system's rollback procedure before making that change. Nothing in this guide changes container state, so there is no undo step required.

Done means

  • You identified the intended container by name or ID and confirmed the active Docker CLI version.
  • docker port CONTAINER showed every mapping, including the private protocol and host binding.
  • You queried a specific private port with an explicit protocol where TCP and UDP could differ.
  • You distinguished a published host endpoint from a port that an application merely intends to use.
  • You made no service or configuration changes while inspecting the mappings.