docker
A general container runtime node. One of the three specs create_node supports.
Provisionable through the control-plane API. docker is one of the 3 specs EC2__Platform._service_for knows how to build, so POST /api/nodes and sg docker create both work.
The CLI, which nobody wrote
Per-spec CLIs are generated, not written. Spec__CLI__Builder registers the same verb set for every registered spec, so docker gets its command surface from the same code that gives every other spec theirs:
# the uniform verb set, for every registered spec list · info · create · wait · health · connect · exec · delete · ami list|bake · cert # so, for this one sg docker create --max-hours 1 sg docker wait sg docker health sg docker delete
This is the strongest single argument that the thing is a platform rather than a service: adding a spec costs a manifest, a route class and a service — the CLI comes free. The three mechanisms →
What a node of this spec does
Every spec rides the same node lifecycle: a per-node API key minted and written to SSM before launch, composed user-data sections, EC2 tags as the registry, a two-phase health poll, then teardown. Teardown means terminate, not stop — systemd-run --on-active paired with InstanceInitiatedShutdownBehavior=terminate, on a default one-hour timer.