Docker & Containers — Level by Level
Every Kubernetes pod, CI job and edge appliance runs containers. This track takes you from your first docker run to building small secure images, running multi-service apps with Docker Compose, pushing and pulling from public and private registries, tuning the daemon with daemon.json, and fixing the certificate errors that stop a pull in its tracks, including when (and when not) to bypass them.
What you'll be able to do
- Explain what a container is (namespaces + cgroups + an image) and run, inspect and debug one
- Write Dockerfiles that build small, cached, non-root images with multi-stage builds
- Run multi-service apps with Docker Compose: networks, volumes, health checks, secrets
- Tag, push and pull images from Docker Hub, ECR, Harbor and your own registry
- Run a private registry with TLS and login, and configure the daemon with daemon.json
- Fix x509 certificate errors properly, and know exactly what the insecure-registry bypass does
- Containerise a real two-tier app (Python, and .NET on Linux or Windows) and expose it to other machines
Before you start
Linux command line (Linux — Level by Level, Level 1).
How it works
Each lesson: plain-language idea → how it really works → hands-on. Each section ends with a cheat sheet & self-check.
Curriculum
Lessons marked “Read” are ready; the rest are on the way.
Level 1 — Containers & images
- 01What a container really isNamespaces, cgroups, images, and your first run / exec / logs / inspectRead →
- 02Images & DockerfilesLayers, build cache, CMD vs ENTRYPOINT, .dockerignore, multi-stage buildsRead →
- 03Networking & storageBridge networks, container DNS, published ports, volumes vs bind mountsRead →
- 📋Cheat sheet & self-checkEvery command from this section on one page, then 14 questions to check yourself.Open →
Level 2 — Docker Compose
- 04Docker Compose basicsOne file for a multi-service app: services, networks, volumes, env, up / down / logsRead →
- 05Compose for real environmentsHealth checks, depends_on conditions, override files, profiles, limits, secretsRead →
- 📋Cheat sheet & self-checkEvery command from this section on one page, then 9 questions to check yourself.Open →
Level 3 — Registries
- 06Registries: tag, push & pullNames, tags and digests, docker login, Docker Hub, ECR and Harbor, rate limitsRead →
- 07Run your own private registryregistry with TLS and htpasswd login, the registry API, clean-up, pull-through cacheRead →
- 📋Cheat sheet & self-checkEvery command from this section on one page, then 9 questions to check yourself.Open →
Level 4 — Daemon & certificates
- 08Configuring the daemon: daemon.jsonLogging, data-root, mirrors, address pools, live-restore, proxies, and applying changes safelyRead →
- 09Registry certificates & the insecure bypassx509 errors, certs.d, trust stores, client certificates, insecure-registries and its risksRead →
- 📋Cheat sheet & self-checkEvery command from this section on one page, then 10 questions to check yourself.Open →
Level 5 — Production habits
- 10Security & troubleshootingNon-root, capabilities, read-only rootfs, image scanning, and the errors you will meetRead →
- 11Capstone: ship an app through a private registryBuild, push over TLS, pull on another host and run it with ComposeRead →
- 📋Cheat sheet & self-checkEvery command from this section on one page, then 6 questions to check yourself.Open →
Level 6 — Practical projects
- 12Project: Python front end + back endnginx front end and Flask API in two containers: Dockerfiles, code, a build/run/expose helper, ComposeRead →
- Download project (zip)Dockerfiles, Python + nginx code, compose.yaml, app.shZip ↓
- 13Project: .NET front end + back end (Linux & Windows)ASP.NET Core web + API in two containers, on Linux or Windows Nano Server, with bash and PowerShell helpersRead →
- Download project (zip)Linux + Windows Dockerfiles, .NET code, compose files, app.sh + app.ps1Zip ↓
- 📋Cheat sheet & self-checkEvery command from this section on one page, then 7 questions to check yourself.Open →
Real-world scenarios
Work through each one: symptom → misleading signal → evidence → root cause → prevention.
A new private registry works in the browser but every docker pull fails. Fix it without turning off TLS.
One line added to daemon.json and the daemon is down on a production host.
Container logs and old images ate /var/lib/docker. Clean up and stop it happening again.
CI pipelines fail at pull time. Log in, mirror or cache so builds stop depending on luck.
This site is a public version of my personal engineering knowledge hub. It intentionally excludes confidential company information and internal operational details.