Small image for working in the notebook and installing your own libraries
- Fully-functional Jupyter Notebook 4.3.x
- Miniconda Python 3.x
- No preinstalled scientific computing packages
- Unprivileged user
jovyan
(uid=1000, configurable, see options) in groupusers
(gid=100) with ownership over/home/jovyan
and/opt/conda
- tini as the container entrypoint and start-notebook.sh as the default command
- A start-singleuser.sh script useful for running a single-user instance of the Notebook server, as required by JupyterHub
- A start.sh script useful for running alternative commands in the container (e.g.
ipython
,jupyter kernelgateway
,jupyter lab
) - Options for a self-signed HTTPS certificate and passwordless
sudo
The following command starts a container with the Notebook server listening for HTTP connections on port 8888 with a randomly generated authentication token configured.
docker run -it --rm -p 8888:8888 jupyter/minimal-notebook
Take note of the authentication token included in the notebook startup log messages. Include it in the URL you visit to access the Notebook server or enter it in the Notebook login form.
The Docker container executes a start-notebook.sh
script script by default. The start-notebook.sh
script handles the NB_UID
and GRANT_SUDO
features documented in the next section, and then executes the jupyter notebook
.
You can pass Jupyter command line options through the start-notebook.sh
script when launching the container. For example, to secure the Notebook server with a custom password hashed using IPython.lib.passwd()
instead of the default token, run the following:
docker run -d -p 8888:8888 jupyter/minimal-notebook start-notebook.sh --NotebookApp.password='sha1:74ba40f8a388:c913541b7ee99d15d5ed31d4226bf7838f83a50e'
For example, to set the base URL of the notebook server, run the following:
docker run -d -p 8888:8888 jupyter/minimal-notebook start-notebook.sh --NotebookApp.base_url=/some/path
For example, to disable all authentication mechanisms (not a recommended practice):
docker run -d -p 8888:8888 jupyter/minimal-notebook start-notebook.sh --NotebookApp.token=''
You can sidestep the start-notebook.sh
script and run your own commands in the container. See the Alternative Commands section later in this document for more information.
You may customize the execution of the Docker container and the Notebook server it contains with the following optional arguments.
-e GEN_CERT=yes
- Generates a self-signed SSL certificate and configures Jupyter Notebook to use it to accept encrypted HTTPS connections.-e NB_UID=1000
- Specify the uid of thejovyan
user. Useful to mount host volumes with specific file ownership. For this option to take effect, you must run the container with--user root
. (Thestart-notebook.sh
script willsu jovyan
after adjusting the user id.)-e GRANT_SUDO=yes
- Gives thejovyan
user passwordlesssudo
capability. Useful for installing OS packages. For this option to take effect, you must run the container with--user root
. (Thestart-notebook.sh
script willsu jovyan
after addingjovyan
to sudoers.) You should only enablesudo
if you trust the user or if the container is running on an isolated host.-v /some/host/folder/for/work:/home/jovyan/work
- Host mounts the default working directory on the host to preserve work even when the container is destroyed and recreated (e.g., during an upgrade).
You may mount SSL key and certificate files into a container and configure Jupyter Notebook to use them to accept HTTPS connections. For example, to mount a host folder containing a notebook.key
and notebook.crt
:
docker run -d -p 8888:8888 \
-v /some/host/folder:/etc/ssl/notebook \
jupyter/minimal-notebook start-notebook.sh \
--NotebookApp.keyfile=/etc/ssl/notebook/notebook.key
--NotebookApp.certfile=/etc/ssl/notebook/notebook.crt
Alternatively, you may mount a single PEM file containing both the key and certificate. For example:
docker run -d -p 8888:8888 \
-v /some/host/folder/notebook.pem:/etc/ssl/notebook.pem \
jupyter/minimal-notebook start-notebook.sh \
--NotebookApp.certfile=/etc/ssl/notebook.pem
In either case, Jupyter Notebook expects the key and certificate to be a base64 encoded text file. The certificate file or PEM may contain one or more certificates (e.g., server, intermediate, and root).
For additional information about using SSL, see the following:
- The docker-stacks/examples for information about how to use Let's Encrypt certificates when you run these stacks on a publicly visible domain.
- The jupyter_notebook_config.py file for how this Docker image generates a self-signed certificate.
- The Jupyter Notebook documentation for best practices about running a public notebook server in general, most of which are encoded in this image.
The default Python 3.x Conda environment resides in /opt/conda
. The commands ipython
, python
, pip
, easy_install
, and conda
(among others) are available in this environment.
JupyterHub requires a single-user instance of the Jupyter Notebook server per user. To use this stack with JupyterHub and DockerSpawner, you must specify the container image name and override the default container run command in your jupyterhub_config.py
:
# Spawn user containers from this image
c.DockerSpawner.container_image = 'jupyter/minimal-notebook'
# Have the Spawner override the Docker run command
c.DockerSpawner.extra_create_kwargs.update({
'command': '/usr/local/bin/start-singleuser.sh'
})
The start.sh
script supports the same features as the default start-notebook.sh
script (e.g., GRANT_SUDO
), but allows you to specify an arbitrary command to execute. For example, to run the text-based ipython
console in a container, do the following:
docker run -it --rm jupyter/minimal-notebook start.sh ipython
This script is particularly useful when you derive a new Dockerfile from this image and install additional Jupyter applications with subcommands like jupyter console
, jupyter kernelgateway
, and jupyter lab
.
You can bypass the provided scripts and specify your an arbitrary start command. If you do, keep in mind that certain features documented above will not function (e.g., GRANT_SUDO
).