Blog

Jon Clausen

October 31, 2017

Spread the word


Share your thoughts

CommandBox 3.8 Docker image released



Today we released our 3.8 series of docker images ( current source version 2.1.0 ) which include a number of improvements and enhancements.

Change Log

  • Updates to CommandBox v3.8+
  • Adds support for Docker secrets
  • Adds casing aliases for environment variables
  • Adds new opinionated password security
  • Updates to runtime output for clarity
  • Changes image for alpine build to prevent CommandBox errors when installing dependencies

Security Enhancements

Upon container start, if no mechanism is detected for specifying the administrative passwords for the CFML engine (i.e. - CFConfig, custom server home, or environment variables ), a random password is generated. This prevents the image from using a predictable default. This password is available in the console output like so:

WARN: Configuration did not detect any known mechanisms for changing the default password.  Your CF engine administrative password has been set to: VxnrV816IFaHG0CmNemO251tihWeHZGwcLUJBurzj75y9vRwT7EqdFed9cWu2fIRvUn0pWVIINmoa34g

Docker Secrets

The image now provides support for secrets expansion when using Docker secrets in your singular, swarm, or stack deployment.

To employ the use of secrets in your runtime environment, you may map environment variables to secrets using the following syntax: MYVAR={{DOCKER-SECRET:docker_secret_name}} . Upon container start any environment variables containing these placeholders will expand the secrets and derive their values from the contents of the secret file.

Enjoy and happy coding!

Add Your Comment

Recent Entries

Introducing BoxLang AI: Build Intelligent Applications with One Unified AI Platform

Introducing BoxLang AI: Build Intelligent Applications with One Unified AI Platform

Artificial intelligence is opening new possibilities for web applications, but building those experiences can become complicated quickly. Each AI provider brings its own SDK, authentication process, APIs, and model-specific requirements. Add agents, memory, tools, structured responses, or document retrieval, and development teams can find themselves managing integrations instead of improving their applications.

Introduced at Into the Box 2026, BoxLang AI gives developers a more unified way to build AI-powered applications within the BoxLang ecosystem.

Maria Jose Herrera
Maria Jose Herrera
August 06, 2026
bx-toml : Native TOML Support for BoxLang

bx-toml : Native TOML Support for BoxLang

TOML has quietly become the configuration format of the modern toolchain. Rust ships Cargo.toml, Python ships pyproject.toml, and a growing pile of CLIs, deployment platforms, and infrastructure tools expect it. If your BoxLang application needs to read one of those files, or generate one, you now have first class support for it.

Luis Majano
Luis Majano
August 04, 2026
BoxLang 1.16.0 Released!

BoxLang 1.16.0 Released!

BoxLang 1.16.0 is here, closing 50 issues across new features, improvements, and bug fixes. The theme running through this release is control: control over how HTTP clients are created and reused, control over what happens when a request fails, control over how much data a response is allowed to buffer, control over when Java classpaths reload, and tighter alignment with CFML behavior in the edge cases that only show up in production.

Luis Majano
Luis Majano
August 04, 2026