Skip to content

Coverage

Docker Compose

Every feature of Docker Compose, and whether Isoloom produces it.

Every feature, in the format's own order: whether every VM target can do it, whether Isoloom produces it, and how (or why not). See the overview for the rule.

Docker Compose

65% of 55 portable features (32 done, 8 partly, 15 to do; 118 features in all). From the compose-spec schema, commit 914ec15d1fa4 (crates/isoloom-core/coverage/compose-spec.json).

Top level

KeyEvery targetImplementedNotes
versionn/aNoObsolete in Compose
nameYesYesFrom name
includen/aNoCompose tooling, not the environment's behavior
servicesYesYesFrom machines
networksYesYesFrom networks
volumesYesYesFrom machines.*.volumes
secretsYesAnother wayVia inputs (values given at launch, never baked into images)
configsYesIn the imageSet it in the image (docker.build) or the VM's provisioning
modelsn/aNoCompose tooling, not the environment's behavior
jobsYesAnother wayVia docker.init (one-shot jobs)

Services

KeyEvery targetImplementedNotes
annotationsn/aNoCompose tooling, not the environment's behavior
attachn/aNoCompose tooling, not the environment's behavior
blkio_configNoNoCloud VMs only choose a size: no CPU or memory scheduling knobs
buildYesYesFrom machines.*.docker.build
cap_addYesPartlyFrom networks.*.gateway; not yet: nothing more: capabilities only exist for containers (root on a VM has them all)
cap_dropn/aNoContainer mechanics: a VM has none; Isoloom sets them itself when a machine needs them
cgroupn/aNoContainer mechanics: a VM has none; Isoloom sets them itself when a machine needs them
cgroup_parentn/aNoContainer mechanics: a VM has none; Isoloom sets them itself when a machine needs them
commandYesIn the imageSet it in the image (docker.build) or the VM's provisioning
configsYesIn the imageSet it in the image (docker.build) or the VM's provisioning
container_nameYesAnother wayVia the machine's name
cpu_countNoNoCloud VMs only choose a size: no CPU or memory scheduling knobs
cpu_percentNoNoCloud VMs only choose a size: no CPU or memory scheduling knobs
cpu_periodNoNoCloud VMs only choose a size: no CPU or memory scheduling knobs
cpu_quotaNoNoCloud VMs only choose a size: no CPU or memory scheduling knobs
cpu_rt_periodNoNoCloud VMs only choose a size: no CPU or memory scheduling knobs
cpu_rt_runtimeNoNoCloud VMs only choose a size: no CPU or memory scheduling knobs
cpu_sharesNoNoCloud VMs only choose a size: no CPU or memory scheduling knobs
cpusYesAnother wayVia machines.*.resources.cpus, written as deploy.resources.limits
cpusetNoNoCloud VMs only choose a size: no CPU or memory scheduling knobs
credential_specNoNoWindows containers only
depends_onYesYesFrom machines.*.depends_on
deployYesPartlyFrom machines.*.resources; not yet: replicas (see scale)
developn/aNoCompose tooling, not the environment's behavior
device_cgroup_rulesn/aNoContainer mechanics: a VM has none; Isoloom sets them itself when a machine needs them
devicesNoNoHost devices: hosting services and cloud VMs have none to pass
dnsYesNot yetDNS servers for a network or a machine
dns_optYesNot yetWith DNS
dns_searchYesNot yetWith DNS (search domains)
domainnameYesNot yetWith DNS (a domain for the environment)
entrypointYesPartlyIsoloom's own containers and init jobs; not yet: a machine's own: set it in its image
env_fileYesAnother wayVia inputs
environmentYesPartlyFrom machines.*.inputs; not yet: fixed values: set them in the image or the provisioning
exposeYesAnother wayVia machines.*.services (every port is reachable on the machine's networks)
extendsn/aNoCompose tooling, not the environment's behavior
external_linksn/aNoLegacy; replaced by networks
extra_hostsYesYesFrom machines.*.networks (names of machines on other networks)
gpusNoNoLocal VMs can't use the host's GPU
group_addYesIn the imageSet it in the image (docker.build) or the VM's provisioning
healthcheckYesYesFrom machines.*.services (a probe of every port)
hostnameYesYesFrom the machine's name
imageYesYesFrom machines.*.docker.image
initn/aNoContainer mechanics: a VM always runs its own init
ipcNoNoShares a kernel namespace with the host or another machine: separate VMs can't
isolationNoNoWindows containers only
label_filen/aNoCompose tooling, not the environment's behavior
labelsn/aNoCompose tooling, not the environment's behavior
linksn/aNoLegacy; replaced by networks
loggingn/aNoWhere the runner collects logs
mac_addressNoNoCloud VMs get their MAC address from the provider
mem_limitYesAnother wayVia machines.*.resources.memory_mb, written as deploy.resources.limits
mem_reservationNoNoCloud VMs only choose a size: no CPU or memory scheduling knobs
mem_swappinessNoNoCloud VMs only choose a size: no CPU or memory scheduling knobs
memswap_limitn/aNoContainer mechanics: a VM has none; Isoloom sets them itself when a machine needs them
modelsn/aNoCompose tooling, not the environment's behavior
network_modeYesPartlyIsoloom's own sidecars and check runner; not yet: nothing more: sharing another machine's network isn't possible between VMs
networksYesYesFrom machines.*.networks (fixed addresses)
oom_kill_disablen/aNoContainer mechanics: a VM has none; Isoloom sets them itself when a machine needs them
oom_score_adjn/aNoContainer mechanics: a VM has none; Isoloom sets them itself when a machine needs them
pidNoNoShares a kernel namespace with the host or another machine: separate VMs can't
pids_limitn/aNoContainer mechanics: a VM has none; Isoloom sets them itself when a machine needs them
platformYesNot yetA CPU architecture (amd64, arm64): images, boxes and instance types all have one
portsYesYesFrom machines.*.services[].publish (on the host's loopback)
post_startYesAnother wayVia machines.*.docker.init (runs once the machine answers)
pre_startYesAnother wayVia machines.*.depends_on and docker.init
pre_stopn/aNoCompose tooling, not the environment's behavior
privilegedYesNot yetWhat it's for, as a machine feature: running containers or VMs inside, loading kernel modules (Isoloom then makes the container privileged)
profilesYesYesFrom checks (a check profile)
providern/aNoCompose tooling, not the environment's behavior
pull_policyn/aNoCompose tooling, not the environment's behavior
pull_refresh_aftern/aNoCompose tooling, not the environment's behavior
read_onlyYesNot yetA read-only root filesystem (VMs can mount it read-only too)
restartYesYesAlways unless-stopped: machines stay up like VMs
runtimen/aNoContainer mechanics: a VM has none; Isoloom sets them itself when a machine needs them
scaleYesNot yetSeveral identical machines (replicas), each with its own address
secretsYesAnother wayVia machines.*.inputs
security_optn/aNoContainer mechanics: a VM has none; Isoloom sets them itself when a machine needs them
shm_sizeYesNot yetThe size of /dev/shm (a mount option on VMs)
stdin_openn/aNoCompose tooling, not the environment's behavior
stop_grace_periodn/aNoCompose tooling, not the environment's behavior
stop_signalYesIn the imageSet it in the image (docker.build) or the VM's provisioning
storage_optn/aNoContainer mechanics: a VM has none; Isoloom sets them itself when a machine needs them
sysctlsYesPartlyFrom networks.*.gateway; not yet: a machine's own network sysctls (net.*): containers only allow those, VMs allow them too
tmpfsYesNot yetMemory-backed mounts (tmpfs works on VMs too)
ttyn/aNoCompose tooling, not the environment's behavior
ulimitsYesNot yetProcess limits (limits.conf or systemd on VMs)
use_api_socketNoNoHands the host's Docker to a machine: VMs and the cloud have none
userYesPartlyIsoloom's check runner, as root to drop its default route on offline networks; not yet: a machine's own user: set it in its image
userns_modeNoNoShares a kernel namespace with the host or another machine: separate VMs can't
utsNoNoShares a kernel namespace with the host or another machine: separate VMs can't
volumesYesPartlyFrom machines.*.volumes (and read-only mounts of init and check scripts); not yet: data shared between machines
volumes_fromYesNot yetWith volumes (data shared between machines)
working_dirYesIn the imageSet it in the image (docker.build) or the VM's provisioning

Networks

KeyEvery targetImplementedNotes
attachablen/aNoCompose tooling, not the environment's behavior
driverNoNoDocker network drivers (overlay, macvlan) have no VM equivalent
driver_optsNoNoDocker network driver options
enable_ipv4n/aNoNetworks are IPv4 (the default)
enable_ipv6YesNot yetIPv6 networks
externalYesNot yetJoining a network outside the environment (a Docker network, a host bridge, a VPC)
internalYesYesFrom networks.*.internet: false (when nothing routes)
ipamYesYesFrom networks.*.cidr
labelsn/aNoCompose tooling, not the environment's behavior
namen/aNoCompose scopes names to the environment

Volumes

KeyEvery targetImplementedNotes
driverNoNoDocker volume drivers have no VM equivalent
driver_optsNoNoDocker volume driver options
externalYesNot yetWith volumes (data that outlives the environment)
labelsn/aNoCompose tooling, not the environment's behavior
namen/aNoCompose scopes names to the environment