Skip to content

ReferenceThe 22 checks

Containers

Health checkcontainers

What it reads

Each container's state, restart count and health status, read from the Docker socket.

Does it need root?

It needs root for part of what it reads. The Docker socket can be read only by root and the docker group. Without root, that part is skipped and never counted as passed. Run sudo kiyesi scan to include it.

When it passes

The report lists it as passed, in these words:

  • count containers running, none failing
  • No containers on this server

What it can find

Warning

Container name has stopped (exit code code)

A stopped container is a service that is not running.

Fix
docker logs --tail 50 name
Warning

Container name is failing its health check

Docker reports the container as unhealthy, so it is running but not answering properly.

Fix
docker inspect --format '{{json .State.Health.Log}}' name
Warning

Container name restarted count times in the last hour

A container that keeps restarting is crashing, and users see errors each time.

Fix
docker logs --tail 100 name