## TL;DR
Your generated config points Terraform at a nonsense provider address (`registry.terraform.io/-/docker`) because the provider source is missing. Re-run `cdktf get`, fix the provider source to the real namespace, remove stale `.gen`/`cdktf.out`, and re-synth.

## The error
```
Failed to instantiate provider "registry.terraform.io/-/docker" to obtain
schema: unknown provider "registry.terraform.io/-/docker"

non-zero exit code 1
```

## Fix it
1. Re-run `cdktf get` to regenerate provider bindings with current sources.
2. Check `cdk.tf.json` `required_providers`: the docker entry must have a real `source` (e.g. `kreuzwerker/docker`), never `-`.
3. Remove stale generated output: `rm -rf .gen cdktf.out` (and any compiled `main.js`/`main.d.ts`).
4. Re-run `cdktf synth`, verify the provider address is correct in the JSON, then `cdktf deploy`.

Expected result: deploy plans and applies instead of failing on provider instantiation.

## When to use this
- `cdktf deploy` or `cdktf destroy` fails with `unknown provider "registry.terraform.io/-/[name]"`
- You switched provider namespaces or upgraded cdktf recently

## When NOT to use this
- The provider address is correct but the download fails (registry/network issue)
- Synth itself fails (fix the synth error first)

## Root cause
The `-` in the address is Terraform's placeholder for "no namespace given". It appears when the generated `required_providers` lacks a source, common after namespace moves (the docker provider moved from terraform-providers to kreuzwerker) combined with stale generated bindings that predate the move.

## Edge cases
- `cdktf destroy` hits the same bug on old stacks; clean and re-synth before destroying.
- If you hand-edit `cdk.tf.json`, your edits are overwritten on the next synth; fix the source in code or config instead.