daemon.json

Configuring the Daemon with daemon.json

The daemon reads /etc/docker/daemon.json, which a fresh installation does not have. A stray comma stops the daemon from starting, so check a file with dockerd --validate first; it never touches the running daemon.

daemon.json: log rotation, a private address pool and live restoreJSON
{
  "log-driver": "local",
  "log-opts": { "max-size": "10m", "max-file": "3" },
  "default-address-pools": [{ "base": "10.33.0.0/16", "size": 24 }],
  "live-restore": true
}
Validating daemon.json files before installing themJSON
dockerd --validate --config-file=daemon.json
echo '{ "log-driver": "local", "max-size": "10m" }' > bad.json
sudo dockerd --validate --config-file=bad.json
Output
configuration OK
unable to configure the Docker daemon with file bad.json: the following directives don't match
any configuration option: max-size

The first file rotates container logs at 10 MB, takes new networks' subnets from 10.33.0.0/16 so they cannot clash with a VPN, and keeps containers running while dockerd restarts (live-restore). The second fails because max-size belongs inside log-opts. Other common keys are registry-mirrors, insecure-registries and userns-remap. Apply a file with sudo systemctl restart docker; a few keys, such as debug and registry-mirrors, reload with sudo systemctl reload docker. Never set the same option in the file and as a dockerd flag, or the daemon refuses to start, and remember that existing containers keep their old log settings.