Docker
This screen allows creating a new bot from a Docker image. Instead of sending source code, you provide a ready-made image and Sinfonia runs the container on the selected Docker Host.
Important
Docker bots are a premium feature, purchased separately on the platform. After purchasing it, you need at least one connected Docker Host to run the images. Not set up yet? Follow the steps in Agents → Docker.
What is Docker
Docker is a platform that packages an application together with everything it needs to run (runtime, libraries, system dependencies and configuration) into a unit called an image. When the image is executed it becomes a container: an isolated process that behaves the same way on any machine with Docker installed.
| Term | What it is |
|---|---|
| Image | Immutable package with the automation’s code and dependencies. It is built from a Dockerfile. |
| Container | A running image, isolated from the rest of the machine. |
| Registry | Repository where images are stored and distributed, such as Docker Hub, GitHub Container Registry (GHCR) and Amazon ECR. |
| Tag | Label that identifies a version of the image, such as my-bot:1.0.0. |
Benefits
- Reproducible environment: the bot runs with the same runtime and library versions it was tested with, regardless of what is installed on the machine.
- Any language: the image carries its own runtime, so the bot is not limited to the languages supported by the Script, Zip and Git types.
- System dependencies included: browsers, drivers, operating system packages and command-line tools ship inside the image.
- Isolation: each execution runs in a separate container, with no dependency conflicts between bots.
- CI/CD integration: the same image built and tested in your pipeline is the one that runs in production.
Image requirements
- The image must define the automation’s startup command with
ENTRYPOINTorCMDin theDockerfile. - The image must be compatible with the Docker Host architecture (for example,
linux/amd64). - When using a registry, the Docker Host needs network access to it.
Fields
| Field | Description | Notes |
|---|---|---|
| Name | Bot name. | Expected format: bot-xxx (example: bot-123). |
| Version | Bot version. | Format X.Y.Z (example: 1.0.0). |
| Docker Host | Host that should run the container. | Select one of the connected hosts. If the list is empty, deploy the agent by following Agents → Docker. |
| Image source | Defines where Sinfonia gets the image from. | See the three options in Image source. |
| Parameters (Json) | Bot parameters in JSON format. | Example: {"arg1": "1366", "arg2": "768"} |
| Description | Free text to describe the bot’s function and purpose. | — |
Image source
The form offers three ways to provide the image:
| Option | When to use |
|---|---|
| Image from a repository | The image is in a public registry. |
| Image from a repository with authentication | The image is in a private registry (Docker Hub, GHCR or Amazon ECR). |
| Image from a file | The image is not in a registry and is up to 50 MB. |
Image from a repository
Use this option for public images, which can be pulled without logging in.
Docker image
- Description: Path of the image in the registry, including the tag.
- Important: Always provide a version tag. Without a tag, Docker assumes
latest. Because the Docker Host caches images it has already fetched, publish each version with a new tag: a reused tag is not downloaded again. - Examples:
| Registry | Format |
|---|---|
| Docker Hub | username/my-bot:1.0.0 |
| GHCR | ghcr.io/organization/my-bot:1.0.0 |
| Amazon ECR Public | public.ecr.aws/alias/my-bot:1.0.0 |
Image from a repository with authentication
Use this option for private images. Private registries require a login before the image can be pulled: Sinfonia uses the credentials you provide to authenticate against the registry, the same way the docker login command does, and then pulls the image.
Important
Credentials are not typed into the bot form. Register the username and password beforehand in Environment Variables, then select those variables on the bot creation screen.
To prepare the credentials:
- Go to Environment Variables and click
New variable. - Create one variable for the username and another for the password (for example,
DOCKER_USERandDOCKER_PASSWORD), with the values shown in the table below for your registry. - Check the
Internal use (Git token, AWS token...)scope and restrict visibility toAdmins. - On the bot creation screen, select those variables in the user and password fields.
Docker image
- Description: Image URL, including the registry address and the tag.
Dockerhub User (Access key if ECR)
- Description: Selects the environment variable that holds the registry username. For Amazon ECR, the variable must hold the Access Key ID.
Dockerhub Password (User token if GHCR, Secret key if ECR)
- Description: Selects the environment variable that holds the registry password. For GHCR, the variable must hold the user token. For Amazon ECR, the Secret Access Key.
Value of each variable per registry:
| Registry | Docker image | User variable | Password variable |
|---|---|---|---|
| Docker Hub | username/my-bot:1.0.0 | Docker Hub username | Password or personal access token |
| GHCR | ghcr.io/organization/my-bot:1.0.0 | GitHub username | Personal access token |
| Amazon ECR | <account>.dkr.ecr.<region>.amazonaws.com/my-bot:1.0.0 | Access Key ID | Secret Access Key |
Warning
Use credentials dedicated to Sinfonia with read-only permission. Avoid your personal account password or keys with administrative access.
Docker Hub
Docker Hub accepts the account password, but the recommended approach is to create a personal access token with Read-only permission and use it as the value of the password variable. The token can be revoked at any time without affecting the account.
GitHub Container Registry (GHCR)
GHCR does not accept the GitHub account password. Create a personal access token (classic) with the read:packages scope and use it as the value of the password variable, with your GitHub username in the user variable.
Amazon ECR
Amazon ECR has no fixed username and password. Logging in to the registry uses a temporary token, valid for 12 hours, which AWS issues from IAM credentials. That is why the variables hold the Access Key ID and the Secret Access Key: with them, the token is obtained on each authentication, and you never need to renew it manually.
To set it up:
- Create an IAM user dedicated to Sinfonia.
- Attach the
AmazonEC2ContainerRegistryReadOnlymanaged policy, or a custom policy with the minimum permissions below. - Generate an access key for that user and register the Access Key ID and the Secret Access Key as environment variables in Sinfonia.
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": "ecr:GetAuthorizationToken",
"Resource": "*"
},
{
"Effect": "Allow",
"Action": [
"ecr:BatchCheckLayerAvailability",
"ecr:GetDownloadUrlForLayer",
"ecr:BatchGetImage"
],
"Resource": "arn:aws:ecr:<region>:<account>:repository/my-bot"
}
]
}- Private registry authentication in Amazon ECR
- AWS managed policies for Amazon ECR
- Manage access keys for IAM users
Image from a file
Use this option when the image is not published in a registry. You export the image to a file on your machine and upload it through the form.
Docker Image file (Max 50Mb)
- Description: Upload of the Docker image file.
- Important: The file must be in
.tar.gzor.tgzformat and cannot exceed 50 MB. - Note: The image name and tag are read from the file itself, so the image must be exported by tag, not by ID.
How to generate the image file
In the project folder, create a
Dockerfile. Example for a Python bot:FROM python:3.12-alpine WORKDIR /app COPY requirements.txt . RUN pip install --no-cache-dir -r requirements.txt COPY . . CMD ["python", "main.py"]Build the image, specifying the Docker Host architecture:
docker build --platform linux/amd64 -t my-bot:1.0.0 .Export the image with the
docker savecommand and compress the result withgzip, producing a.tar.gzfile:docker save my-bot:1.0.0 | gzip > my-bot-1.0.0.tar.gzCheck the size of the generated file:
ls -lh my-bot-1.0.0.tar.gzIn the form, select
Image from a fileand upload the.tar.gzfile.
Warning
Use docker save, which exports the image with its layers, tags and startup command. The docker export command produces a container’s filesystem and does not generate a valid image for upload.
How to reduce the image size
If the file is larger than 50 MB:
- Use a smaller base image, such as the
alpineorslimvariants. - Use multi-stage builds to keep build tools out of the final image.
- Create a
.dockerignorefile to exclude.git, tests, caches and other files that are not used at runtime. - Install dependencies without cache (for example,
pip install --no-cache-dir).
Tip
If the image is still above the limit, publish it to a registry and use the Image from a repository with authentication option, which does not have the 50 MB upload restriction.