`docker logout docker.io` does not remove Docker Hub credentials
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 75/100
Research direction
Look at the login and logout command implementations in the cli codebase, likely under cli/command/registry. Compare how docker.io is normalized to https://index.docker.io/v1/ during login. The fix is to ensure logout uses the same normalization. Start by reproducing the issue locally to confirm the behavior, then find the logout logic and apply the canonicalization. Verify by checking the config.json file after running the patched logout command.
Written by the indexing model from the issue text.
Description
Description
For Docker Hub, docker login canonicalizes docker.io to https://index.docker.io/v1/, while docker logout does not appear to apply the same canonicalization logic.
For example, when a user explicitly logs in with:
docker login docker.io
the credentials are stored in config.json under the canonical Docker Hub key:
{
"auths": {
"https://index.docker.io/v1/": {
"auth": "..."
}
}
}
However, when the user explicitly logs out with:
docker logout docker.io
the logout logic attempts to remove credentials associated with docker.io from config.json.
Since the credentials were actually stored under https://index.docker.io/v1/, no matching docker.io entry exists, so the stored Docker Hub credentials are not removed.
In other words, docker login docker.io and docker logout docker.io use inconsistent registry host normalization for Docker Hub.
docker login docker.io and docker logout docker.io use inconsistent registry host normalization for Docker Hub.
Reproduce
- Run
docker login docker.ioand authenticate successfully. - Check
~/.docker/config.jsonand verify that the credentials are stored underhttps://index.docker.io/v1/. - Run
docker logout docker.io. - Check
~/.docker/config.jsonagain. - Observe that the Docker Hub credentials under
https://index.docker.io/v1/are still present.
Expected behavior
Running docker logout docker.io should remove the Docker Hub credentials stored under https://index.docker.io/v1/.
docker version
Client:
Version: 29.8.0
API version: 1.56
Go version: go1.26.8
Git commit: 88096ef
Built: Thu Sep 3 21:53:38 2026
OS/Arch: windows/amd64
Context: desktop-linux
failed to connect to the docker API at npipe:////./pipe/dockerDesktopLinuxEngine; check if the path is correct and if the daemon is running: open //./pipe/dockerDesktopLinuxEngine: The system cannot find the file specified.
docker info
Client:
Version: 29.8.0
Context: desktop-linux
Debug Mode: false
Plugins:
agent: Docker AI Agent Runner (Docker Inc.)
Version: v1.136.0
Path: C:\Users\yin2hao\.docker\cli-plugins\docker-agent.exe
ai: Docker AI Agent - Ask Gordon (Docker Inc.)
Version: v1.31.0
Path: C:\Users\yin2hao\.docker\cli-plugins\docker-ai.exe
buildx: Docker Buildx (Docker Inc.)
Version: v0.37.0
Path: C:\Users\yin2hao\.docker\cli-plugins\docker-buildx.exe
compose: Docker Compose (Docker Inc.)
Version: v5.5.1
Path: C:\Users\yin2hao\.docker\cli-plugins\docker-compose.exe
debug: Get a shell into any image or container (Docker Inc.)
Version: 0.0.47
Path: C:\Users\yin2hao\.docker\cli-plugins\docker-debug.exe
desktop: Docker Desktop commands (Docker Inc.)
Version: v0.4.4
Path: C:\Users\yin2hao\.docker\cli-plugins\docker-desktop.exe
dhi: CLI for managing Docker Hardened Images (Docker Inc.)
Version: v0.0.7
Path: C:\Users\yin2hao\.docker\cli-plugins\docker-dhi.exe
extension: Manages Docker extensions (Docker Inc.)
Version: v0.2.31
Path: C:\Users\yin2hao\.docker\cli-plugins\docker-extension.exe
init: Creates Docker-related starter files for your project (Docker Inc.)
Version: v1.4.0
Path: C:\Users\yin2hao\.docker\cli-plugins\docker-init.exe
mcp: Docker MCP Plugin (Docker Inc.)
Version: v0.43.3
Path: C:\Users\yin2hao\.docker\cli-plugins\docker-mcp.exe
model: Docker Model Runner (Docker Inc.)
Version: v1.2.6
Path: C:\Users\yin2hao\.docker\cli-plugins\docker-model.exe
offload: Docker Offload (Docker Inc.)
Version: v0.6.17
Path: C:\Users\yin2hao\.docker\cli-plugins\docker-offload.exe
pass: Docker Pass Secrets Manager Plugin (beta) (Docker Inc.)
Version: v0.2.2
Path: C:\Users\yin2hao\.docker\cli-plugins\docker-pass.exe
sandbox: "docker sandbox" is deprecated, use Docker Sandboxes instead (Docker Inc.)
Version: v0.13.0
Path: C:\Users\yin2hao\.docker\cli-plugins\docker-sandbox.exe
scout: Docker Scout (Docker Inc.)
Version: v1.24.0
Path: C:\Users\yin2hao\.docker\cli-plugins\docker-scout.exe
Server:
failed to connect to the docker API at npipe:////./pipe/dockerDesktopLinuxEngine; check if the path is correct and if the daemon is running: open //./pipe/dockerDesktopLinuxEngine: The system cannot find the file specified.
Additional Info
No response
- Dominant language
- Go
- Stars
- 6.1k
- Forks
- 2.2k
- Avg merge
- 1d 10h
- Merged PRs (30d)
- 47
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from docker/cli
-
kind/bug status/0-triage
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 74/100
-
kind/feature status/0-triage
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
-
kind/bug status/0-triage
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
-
kind/bug status/0-triage
Difficulty 2/5 1-3 hours Newbie friendliness 63/100
Similar issues
-
textual definition
Difficulty 1/5 Under an hour Newbie friendliness 90/100
geneontology/go-ontology#32653 ·
-
Difficulty 1/5 Under an hour Newbie friendliness 75/100
-
needs design
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
-
Priority/High ready-for-agent Severity/Major Type/Bug
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 70/100