Skip to content
CAI
Software that uses CAICheck a score

sous-chefs/docker

64.2

Adequate · 19 September 2026

2.8k

lines of production code

Ruby

primary language

1

measurement over time

CAI band scale
CAI lens gauges

What this system is

This system is a Chef cookbook designed to manage the installation, configuration, and lifecycle of Docker and containerd on Linux systems. It provides resources for orchestrating containers, images, networks, volumes, and Docker Swarm clusters, while handling service management via systemd. The codebase has been modernized to replace legacy installation methods and Upstart support with robust, modular custom resources and comprehensive testing suites.

How it got here

2013 — Legacy cleanup and resource modernization

12 changes.

This period focused on removing obsolete infrastructure, including legacy installation recipes, Upstart templates, and deprecated minitest test suites. Concurrently, Docker resources were refactored from legacy LWRPs to modern custom resources to improve consistency and support newer features.

2014–2026 — modularization and test coverage expansion

9 changes.

The project refactored internal Docker helper methods into modular library files to improve maintainability and introduced comprehensive systemd unit templates for better service management. This period focused heavily on expanding test coverage through new ChefSpec unit tests and InSpec integration tests, while also regenerating and expanding documentation for all Docker resources.

Removals

Removal of Upstart configuration template

The Upstart configuration template for the Docker daemon has been removed. This file previously defined how the service started (on runlevel 3), restarted on crash, and handled locale settings. Its removal indicates a shift away from Upstart-based service management for this component.

templates/default · high confidence

Removal of legacy Docker installation and configuration recipes

The \aufs\, \binary\, \default\, \package\, \source\, and \upstart\ recipes have been removed from the \recipes\ directory. This change eliminates the previous mechanisms for installing Docker via Ubuntu APT repositories, manual binary extraction, or building from Go source, as well as the Upstart service management and AUFS storage driver setup. These files are no longer part of the cookbook's structure, indicating a shift away from these specific installation and configuration methods.

recipes · high confidence

Architecture

Refactored Docker helpers into modular library files

The internal helper methods for the Docker cookbook have been reorganized from a single large file into distinct, modular library files (base, coerce, container, json, network, service, swarm). This change improves code maintainability and readability by grouping related functionality, such as network mode normalization, JSON generation for pruning, and Swarm cluster commands, into their respective modules. Users benefit from a more structured codebase that is easier to extend and debug, although the external API and resource behavior remain unchanged.

libraries · high confidence

Behavioural changes

HTTP proxy configuration support for RHEL/sysvinit systems

The default sysconfig template for Docker on RHEL/sysvinit systems now supports HTTP proxy settings. Users can configure http\_proxy, https\_proxy, and no\_proxy variables, which will be exported in the Docker environment if specified in the configuration.

templates/default/sysconfig · high confidence

New systemd unit templates for Docker, containerd, and socket management

This change introduces a comprehensive set of new systemd unit templates to manage the Docker daemon, containerd runtime, and Docker API socket. The \docker.service\ and its override now support binding to \containerd.service\, configuring proxy environments, and setting mount flags, while the \docker.socket\ templates allow for configurable socket paths, modes, and groups. Additionally, a \containerd.service\ template is added to enable the containerd runtime when the binary is present, and a \docker-wait-ready\ script is provided to handle service startup synchronization. These templates ensure the Docker service configuration aligns more closely with official Docker packaging standards.

templates/default/systemd · high confidence

Refactor Docker resources to use custom resource classes and partials

The Docker cookbook resources (container, image, service, network, etc.) have been converted from legacy LWRPs to modern Chef custom resources. This change introduces shared partials (\_base, \_logging, \_service\_base) to centralize common logic like connection handling, retry mechanisms, and logging configuration. Users benefit from improved consistency across resources, better support for modern Docker features (such as cgroupv2, GPU support, and Swarm), and more robust property handling with unified\_mode enabled.

resources · high confidence

Removal of default Docker configuration attributes

The \attributes/default.rb\ file has been removed, eliminating the default configuration values for Docker installation. This includes the removal of defaults for the installation type (package vs. binary), architecture detection, binary download URLs, package repository URLs, and source code references. Users relying on these implicit defaults will need to explicitly configure these attributes or ensure they are provided by other included cookbooks or node data.

attributes · high confidence

Test coverage

Add comprehensive InSpec integration tests for Docker cookbook; Added ChefSpec tests for container, registry, and image pruning helpers; Added comprehensive test suite for Docker cookbook resources and service configuration; Added stubbed ChefSpec test files for helper modules; Added unit tests for Docker Swarm resource recipes; Removal of default test recipe; Removal of legacy Chef test support files; Removal of legacy docker\_test cookbook scaffolding; Removal of legacy minitest test infrastructure; Removed empty test attributes file; Removed minitest test files for docker::default and docker::package recipes; Removed test helper module for Docker assertions.

Housekeeping

Documentation for Docker resources is regenerated and expanded; Standardized repository configuration and tooling.

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 64.

Lenses

  • Code Health 96
  • Architecture 100
  • Maturity 54
  • Readiness 61
  • Security 75

Changes since last survey

  • 300 commits — 284 feature/other, 16 fixes

By area

  • (root) — 263 commits
  • .github/workflows — 31 commits
  • test/cookbooks — 2 commits
  • .circleci/config.yml — 1 commit
  • .vscode/extensions.json — 1 commit
  • documentation/docker_container.md — 1 commit
  • libraries/docker_installation_package.rb — 1 commit

Notable commits

  • fix: Bugfix #1226 (#1227)
  • fix: Fix arguments to generate_json (#1219)
  • fix: Fix breaking change introduced by #1253 (#1256)
  • fix: Fix generate_json not accepting a variable number of arguments (#1211)
  • fix: Fix group resource for docker_installation_tarball library in #1205 (#1206)
  • fix: Fix issue with container network mode causing unnecessary redeployment (#1290)
  • fix: Fix raise when using mixed address families with a network (#1210)
  • fix: Fix various CI issues (#1229)
  • fix: [skip ci] Fix yaml (#1237)
  • fix: fix(ci): Update workflows to use release pipeline (#1320)
  • fix: fix(docs): Fix markdown (#1329)
  • fix: fix(docs): Ignore multiple blank lines (#1330)
  • fix: fix: avoid Docker restart on apt refresh (#1347)
  • fix: fix: correct install version for ubuntu jammy (#1255)
  • fix: fix: migrate dependency resolution to Policyfile (#1343)
  • fix: fix: remove version constraint on chef-client (#1331)
  • change: Add CentOS Stream 8 to CI pipeline (#1204)
  • change: Add Docker Swarm support (#1296)
  • change: Add GPU support (#1289)
  • change: Add debian 11 support (#1208)
  • …and 280 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

sous-chefs/docker was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 19 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit c8b9ee7e7e52c2c65dc41a615862bd356f6931b1 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-b51f968c9b10.