Docker & Containers — Level by Level›Level 1 · Cheat sheet & self-check

Level 1 — Containers & images · wrap-up

Cheat sheet & self-check

Every command from this section on one page.

01 · What a container really is

Run & look around

docker run -d --name web -p 8080:80 nginx:1.27Start a container in the background, publish port 8080
docker ps / docker ps -aRunning containers / all containers, including stopped
docker logs -f --tail 50 webFollow the last 50 log lines
docker exec -it web shOpen a shell inside a running container
docker inspect webFull JSON: config, IPs, mounts, state
docker inspect -f '{{.State.Status}} {{.State.ExitCode}}' webPick one field with a Go template
docker stats --no-streamCPU, memory and I/O per container
docker top webProcesses inside a container

Lifecycle

docker stop web && docker start webGraceful stop (SIGTERM, then SIGKILL after 10 s) and start
docker restart webStop + start
docker rm -f webRemove a container (force-stops it first)
docker run --rm -it alpine:3.20 shThrowaway interactive container, removed on exit

Engine info

docker versionClient and server (daemon) versions
docker infoStorage driver, data root, cgroup driver, registries
systemctl status dockerIs the daemon running?
journalctl -u docker -n 100Daemon logs

02 · Images & Dockerfiles

Build

docker build -t shop/api:1.0 .Build from the Dockerfile in the current folder
docker build -f docker/Dockerfile.prod -t shop/api:1.0 .Use a Dockerfile with another name or path
docker build --no-cache -t shop/api:1.0 .Ignore the cache (fresh base layers, fresh package installs)
docker build --target builder -t shop/api:build .Stop at one stage of a multi-stage build
docker build --build-arg VERSION=1.4 .Pass a build argument (ARG)
docker buildx build --platform linux/amd64,linux/arm64 -t reg/app:1 --push .Multi-architecture build, pushed to a registry

Inspect images

docker images / docker image lsLocal images and sizes
docker history shop/api:1.0Layers and the instruction that made each one
docker image inspect shop/api:1.0Config: CMD, ENTRYPOINT, USER, ENV, labels
docker image pruneRemove dangling (untagged) images

Dockerfile instructions

FROM image:tag AS nameBase image; name a stage for multi-stage builds
COPY --from=builder /out/app /appCopy files from an earlier stage
RUN cmdRun at build time; creates a layer
ENTRYPOINT ["/app"] + CMD ["--port", "8080"]Fixed program + default arguments
USER 10001Run as a non-root user
HEALTHCHECK CMD curl -f http://localhost:8080/healthz || exit 1Container health reported by Docker

03 · Networking & storage

Networks

docker network create shopnetUser-defined bridge network (with DNS by container name)
docker run -d --name db --network shopnet postgres:16Attach a container to a network
docker network connect shopnet webAttach a running container to another network
docker network inspect shopnetSubnet, gateway and attached containers
docker port webWhich host ports are published
docker run -p 127.0.0.1:8080:80 nginxPublish only on localhost, not every interface
docker run --network host nginxShare the host's network stack (no isolation, no -p)

Storage

docker volume create pgdataNamed volume managed by Docker
docker run -v pgdata:/var/lib/postgresql/data postgres:16Mount a named volume
docker run -v "$PWD/conf":/etc/nginx/conf.d:ro nginxBind-mount a host folder, read-only
docker run --mount type=tmpfs,target=/tmp appIn-memory scratch space
docker volume ls / docker volume inspect pgdataList volumes / where the data lives
docker volume pruneRemove volumes not used by any container (careful)

Back up a volume

docker run --rm -v pgdata:/data -v "$PWD":/backup alpine tar czf /backup/pgdata.tgz -C /data .Tar a volume's contents to the current folder