Home / Alt manpages / docker-system(1)

  • docker-system(1)
  • User command
  • linux

Audit Docker Space, State and Events with docker system

You will finish with a short, repeatable Docker host check: confirm the daemon, measure disk usage, inspect recent activity, and decide whether unused data is safe to remove. The examples use Docker Community Edition CLI 29.8.1 from docker-ce-cli package version 5:29.8.1-1~ubuntu.24.04~noble.

Allow about fifteen minutes. You need the Docker CLI and access to the selected Docker daemon. Most commands are ordinary user commands, but daemon access may be restricted by your Docker context or socket permissions. Do not reach for sudo automatically: it can select a different configuration and context, and it does not fix an incorrect target daemon.

1. Confirm the command group and daemon

Start with the command group help. This is read-only and does not contact the daemon:

$ docker system --help
Usage:  docker system COMMAND

Manage Docker

Commands:
  df          Show docker disk usage
  events      Get real time events from the server
  info        Display system-wide information
  prune       Remove unused data

The group is a menu, not one operation. In particular, docker system prune changes state, while df, events and info inspect it.

Checkpoint: ask the daemon for its system information:

$ docker system info
Client: Docker Engine - Community
 Version:    29.8.1
Context:    default
...
Server:
 Containers: 48
 Images: 32
 Storage Driver: overlayfs

Your counts and storage driver will differ. A successful result confirms both the CLI version and the server reached through the current context. If it fails with a socket or permission error, check docker context show, the daemon service and the account's access. Treat a successful command against the wrong context as a failure of your investigation.

2. Measure what is using disk

Run the disk report before deciding what to delete:

$ docker system df
TYPE            TOTAL     ACTIVE    SIZE      RECLAIMABLE
Images          32        28        14.79GB   36.76MB (0%)
Containers      48        48        223.3MB   0B (0%)
Local Volumes   17        5         12.22GB   11.93GB (97%)
Build Cache     132       0         6.266GB   6.218GB

Read RECLAIMABLE as an estimate of objects Docker considers unused, not as a promise that a future command will remove every byte. Volumes deserve extra care: they can contain application data, and an apparently unused volume may be needed when a workload is recreated.

For per-object detail, add --verbose. For machine-readable output, use the documented JSON format:

$ docker system df --format json
{...}

The exact JSON fields and values depend on the daemon. Save the output if you need an audit trail, but do not parse the human table in a script.

3. Inspect recent daemon activity

docker system events streams new events indefinitely unless you bound it. Use a short time window for a checkpoint:

$ docker system events --since 10m --until 0s
2026-09-23T10:20:31.000000000Z container start ...
2026-09-23T10:20:33.000000000Z container die ...

The timestamps and event types are host-specific. The --since and --until values accept Unix timestamps, formatted dates or Go duration strings such as 10m. Without --since, the command waits for new events, which is a common distraction when a one-off report was intended.

Filter noisy output when investigating one class of object:

$ docker system events --since 10m --until 0s --filter 'type=container'

Quote filter values so the shell does not reinterpret them. Use the event stream to correlate a restart, removal or network change with another operation; it is not a replacement for service logs.

4. Review prune boundaries before changing state

Warning

Pruning removes Docker objects. The operation has no general undo command. Recreate anything you remove from its source definition, image registry or backup. Do not use --force until you have reviewed the target and accepted the loss.

By default, docker system prune removes stopped containers, unused networks, dangling images and unused build cache. It does not remove volumes by default. The --all option also targets unused images that are still tagged; --volumes includes unused anonymous volumes. Named volumes remain outside this command's normal scope, but that is not a reason to treat volume data casually.

Use a filter to narrow the candidate set where the daemon supports the expression you need:

$ docker system prune --filter 'until=24h'
WARNING! This will remove:
        - all stopped containers
        - all networks not used by at least one container
        - all dangling images
        - unused build cache
Are you sure you want to continue? [y/N]

At the prompt, answer N or press Enter to cancel. A dry-run mode is not provided by this command, so use docker system df --verbose, container and volume inventories, and the filter as your review step. If you need to preserve data, back it up or remove only a more specific object type with its dedicated prune command.

5. Put the checks into a safe routine

Run the read-only checks together and stop on the first failure:

set -eu
docker system info > /tmp/docker-system-info.txt
docker system df --verbose
docker system events --since 10m --until 0s --filter 'type=container'
printf '%s\n' 'Docker system audit completed'

This writes only a temporary information report and does not alter Docker objects. Remove that report when it is no longer needed if it contains host details. Keep the prune command separate from automation until its object and age policy has been reviewed by the service owner.

Done means

  • docker system info reached the intended daemon and you recorded its context.
  • docker system df --verbose identified the actual reclaimable category.
  • A bounded events query helped explain recent changes without leaving a live stream running.
  • You checked stopped containers, image tags, volumes and build cache before considering prune.
  • Any destructive cleanup has an agreed filter, a backup or rebuild path, and no assumption that Docker can undo it.