Level 5 — Production habits · wrap-up
Cheat sheet & self-check
Every command from this section on one page.
Least privilege
docker run --user 10001:10001 app | Run as a non-root UID |
docker run --cap-drop ALL --cap-add NET_BIND_SERVICE app | Drop every capability, add back only what's needed |
docker run --read-only --tmpfs /tmp app | Read-only root filesystem with a writable /tmp |
docker run --security-opt no-new-privileges app | Block privilege escalation through setuid binaries |
docker run --memory 512m --cpus 1 --pids-limit 200 app | Resource limits |
Scan
trivy image shop/api:1.4 | List known CVEs in OS packages and app dependencies |
trivy image --severity HIGH,CRITICAL --exit-code 1 shop/api:1.4 | Fail a CI step on serious findings |
trivy fs --scanners secret . | Look for committed secrets in the source |
Troubleshoot
docker ps -a --format '{{.Names}}\t{{.Status}}' | Exit codes at a glance |
docker inspect -f '{{.State.ExitCode}} {{.State.OOMKilled}} {{.State.Error}}' app | Why it stopped |
docker events --since 30m | What the daemon did recently |
sudo ss -ltnp | grep :8080 | Who owns a port |
docker system df -v | What uses the disk |
docker system prune | Remove stopped containers, unused networks, dangling images and build cache |
docker image prune -a --filter until=168h | Remove unused images older than 7 days |
docker run --rm --network container:app nicolaka/netshoot | Network tools inside another container's namespace |
Build host
docker build -t registry.lab.local:5000/shop/api:1.0 . | Build and name it for the registry in one step |
docker login registry.lab.local:5000 | Log in (credentials go to ~/.docker/config.json) |
docker push registry.lab.local:5000/shop/api:1.0 | Push; note the digest it prints |
Run host
sudo cp domain.crt /etc/docker/certs.d/registry.lab.local:5000/ca.crt | Trust the registry |
sudo dockerd --validate --config-file /etc/docker/daemon.json && sudo systemctl restart docker | Apply host settings |
docker compose -f compose.yaml -f compose.prod.yaml up -d --wait | Start the stack and wait for health |
docker compose ps && curl -s localhost:8080/healthz | Verify |