Docker & Containers — Level by Level›Level 4 · Cheat sheet & self-check

Level 4 — Daemon & certificates · wrap-up

Cheat sheet & self-check

10 questions across 2 lessons. Each answer links back to the lesson it came from.

Pick an answer to see if you got it, and why.

  1. Q1. You set log-opts max-size in daemon.json and restarted Docker, but an existing container's log keeps growing. Why?

    Show answer

    B. Log driver and options are fixed when a container is created. Recreate it (docker compose up -d --force-recreate, or rm + run) to pick up the new defaults.

    From lesson 08 · Configuring the daemon: daemon.json
  2. Q2. Docker fails to start with 'the following directives are specified both as a flag and in the configuration file: hosts'. Fix?

    Show answer

    B. Many distributions start dockerd with -H fd:// in the systemd unit. A setting may be given as a flag or in daemon.json, never both.

    From lesson 08 · Configuring the daemon: daemon.json
  3. Q3. What does registry-mirrors affect?

    Show answer

    B. The daemon's registry-mirrors setting is used for Docker Hub (docker.io) images. Other registries need their own names in image references.

    From lesson 08 · Configuring the daemon: daemon.json
  4. Q4. What does live-restore: true give you?

    Show answer

    B. With live-restore, dockerd can go down and come back without stopping containers. It isn't compatible with Swarm mode.

    From lesson 08 · Configuring the daemon: daemon.json
  5. Q5. Company VPN users lose access to 172.18.0.0/16 whenever a new Compose project starts on a laptop. Which setting prevents that?

    Show answer

    B. New networks get subnets from the default address pools. Set them to ranges that don't collide with your VPN, VPCs or office networks.

    From lesson 08 · Configuring the daemon: daemon.json
  6. Q6. docker pull from registry.lab.local:5000 fails with 'x509: certificate signed by unknown authority'. What is the proper fix?

    Show answer

    B. The error means the chain doesn't lead to a CA this host trusts. Giving Docker that CA keeps full verification; insecure-registries would switch it off.

    From lesson 09 · Registry certificates & the insecure bypass
  7. Q7. In /etc/docker/certs.d/<host:port>/, what do the file extensions mean?

    Show answer

    B. Docker treats *.crt as CA roots and pairs *.cert with a *.key of the same name as a client certificate for mutual TLS.

    From lesson 09 · Registry certificates & the insecure bypass
  8. Q8. What exactly does listing a registry in insecure-registries do?

    Show answer

    B. Verification is skipped, so anyone who can intercept or impersonate the registry can serve you any image, and with HTTP fallback, credentials and layers travel unencrypted.

    From lesson 09 · Registry certificates & the insecure bypass
  9. Q9. Every docker pull from Docker Hub fails with x509 on a corporate network, but works at home. Most likely cause?

    Show answer

    B. Install the company's root CA into the system trust store and restart Docker. Don't list docker.io as insecure.

    From lesson 09 · Registry certificates & the insecure bypass
  10. Q10. You fixed trust with certs.d on your laptop, but Kubernetes pods on the nodes still fail with ImagePullBackOff x509. Why?

    Show answer

    B. Trust must be configured on every node that pulls, in the runtime that pulls: /etc/containerd/certs.d/<host>/hosts.toml with a ca = entry, or the CA in the node's system trust store.

    From lesson 09 · Registry certificates & the insecure bypass