# push_image

Push a Docker image

Agent View of the PolicyLayer registry record for `push_image`. HTML page: https://policylayer.com/tools/docker/push-image

## Facts

- Tool: `push_image`
- Server: Docker (`@ckreiling/mcp-server-docker`) — https://policylayer.com/tools/docker.md
- Install: `npx -y @ckreiling/mcp-server-docker`
- Homepage: https://github.com/ckreiling/mcp-server-docker
- Risk category: Write (Medium risk)
- Registry record: grade F, identity verified
- Server rate-limited: no
- Parameters: 0
- Recommended policy verdict: Rate-limited

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "push_image",
    "arguments": {}
  }
}
```

## Why push_image is rated Medium

Pushing an image to a registry is a write operation that creates or uploads data to a remote system. It is reversible (images can be deleted or overwritten in registries), so it is not Destructive. It does not execute arbitrary code on the host system and does not move money, making it Write rather than Execute or Financial.

From the tool's own definition: "Tool named 'push_image' with description 'Push a Docker image' — the action uploads/writes a Docker image to a registry, modifying state in the remote registry."

## Use case

AI agents use push_image to create or update resources in Docker, usually the action step of a workflow, after the agent has gathered context. Every call changes real data in your Docker environment.

## Recommended policy (PolicyLayer)

Verdict: **Rate-limited**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches Docker:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "push_image": {
      "limits": [
        {
          "counter": "push_image_rate",
          "window": "minute",
          "max": 30,
          "scope": "grant"
        }
      ]
    }
  }
}
```

## Other tools on Docker (18)

- `recreate_container` — Destructive — https://policylayer.com/tools/docker/recreate-container.md
- `remove_container` — Destructive — https://policylayer.com/tools/docker/remove-container.md
- `remove_image` — Destructive — https://policylayer.com/tools/docker/remove-image.md
- `remove_network` — Destructive — https://policylayer.com/tools/docker/remove-network.md
- `remove_volume` — Destructive — https://policylayer.com/tools/docker/remove-volume.md
- `build_image` — Execute — https://policylayer.com/tools/docker/build-image.md
- `create_container` — Execute — https://policylayer.com/tools/docker/create-container.md
- `pull_image` — Execute — https://policylayer.com/tools/docker/pull-image.md
- `run_container` — Execute — https://policylayer.com/tools/docker/run-container.md
- `start_container` — Execute — https://policylayer.com/tools/docker/start-container.md
- `stop_container` — Execute — https://policylayer.com/tools/docker/stop-container.md
- `fetch_container_logs` — Read — https://policylayer.com/tools/docker/fetch-container-logs.md
- `list_containers` — Read — https://policylayer.com/tools/docker/list-containers.md
- `list_images` — Read — https://policylayer.com/tools/docker/list-images.md
- `list_networks` — Read — https://policylayer.com/tools/docker/list-networks.md
- `list_volumes` — Read — https://policylayer.com/tools/docker/list-volumes.md
- `create_network` — Write — https://policylayer.com/tools/docker/create-network.md
- `create_volume` — Write — https://policylayer.com/tools/docker/create-volume.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=docker · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/docker
