Level 1 — Containers & images · wrap-up
Cheat sheet & self-check
Every command from this section on one page.
Run & look around
docker run -d --name web -p 8080:80 nginx:1.27 | Start a container in the background, publish port 8080 |
docker ps / docker ps -a | Running containers / all containers, including stopped |
docker logs -f --tail 50 web | Follow the last 50 log lines |
docker exec -it web sh | Open a shell inside a running container |
docker inspect web | Full JSON: config, IPs, mounts, state |
docker inspect -f '{{.State.Status}} {{.State.ExitCode}}' web | Pick one field with a Go template |
docker stats --no-stream | CPU, memory and I/O per container |
docker top web | Processes inside a container |
Lifecycle
docker stop web && docker start web | Graceful stop (SIGTERM, then SIGKILL after 10 s) and start |
docker restart web | Stop + start |
docker rm -f web | Remove a container (force-stops it first) |
docker run --rm -it alpine:3.20 sh | Throwaway interactive container, removed on exit |
Engine info
docker version | Client and server (daemon) versions |
docker info | Storage driver, data root, cgroup driver, registries |
systemctl status docker | Is the daemon running? |
journalctl -u docker -n 100 | Daemon logs |
Build
docker build -t shop/api:1.0 . | Build from the Dockerfile in the current folder |
docker build -f docker/Dockerfile.prod -t shop/api:1.0 . | Use a Dockerfile with another name or path |
docker build --no-cache -t shop/api:1.0 . | Ignore the cache (fresh base layers, fresh package installs) |
docker build --target builder -t shop/api:build . | Stop at one stage of a multi-stage build |
docker build --build-arg VERSION=1.4 . | Pass a build argument (ARG) |
docker buildx build --platform linux/amd64,linux/arm64 -t reg/app:1 --push . | Multi-architecture build, pushed to a registry |
Inspect images
docker images / docker image ls | Local images and sizes |
docker history shop/api:1.0 | Layers and the instruction that made each one |
docker image inspect shop/api:1.0 | Config: CMD, ENTRYPOINT, USER, ENV, labels |
docker image prune | Remove dangling (untagged) images |
Dockerfile instructions
FROM image:tag AS name | Base image; name a stage for multi-stage builds |
COPY --from=builder /out/app /app | Copy files from an earlier stage |
RUN cmd | Run at build time; creates a layer |
ENTRYPOINT ["/app"] + CMD ["--port", "8080"] | Fixed program + default arguments |
USER 10001 | Run as a non-root user |
HEALTHCHECK CMD curl -f http://localhost:8080/healthz || exit 1 | Container health reported by Docker |
Networks
docker network create shopnet | User-defined bridge network (with DNS by container name) |
docker run -d --name db --network shopnet postgres:16 | Attach a container to a network |
docker network connect shopnet web | Attach a running container to another network |
docker network inspect shopnet | Subnet, gateway and attached containers |
docker port web | Which host ports are published |
docker run -p 127.0.0.1:8080:80 nginx | Publish only on localhost, not every interface |
docker run --network host nginx | Share the host's network stack (no isolation, no -p) |
Storage
docker volume create pgdata | Named volume managed by Docker |
docker run -v pgdata:/var/lib/postgresql/data postgres:16 | Mount a named volume |
docker run -v "$PWD/conf":/etc/nginx/conf.d:ro nginx | Bind-mount a host folder, read-only |
docker run --mount type=tmpfs,target=/tmp app | In-memory scratch space |
docker volume ls / docker volume inspect pgdata | List volumes / where the data lives |
docker volume prune | Remove volumes not used by any container (careful) |
Back up a volume
docker run --rm -v pgdata:/data -v "$PWD":/backup alpine tar czf /backup/pgdata.tgz -C /data . | Tar a volume's contents to the current folder |