Docker & Containers — Level by Level›Level 5 · Cheat sheet & self-check

Level 5 — Production habits · wrap-up

Cheat sheet & self-check

Every command from this section on one page.

10 · Security & troubleshooting

Least privilege

docker run --user 10001:10001 appRun as a non-root UID
docker run --cap-drop ALL --cap-add NET_BIND_SERVICE appDrop every capability, add back only what's needed
docker run --read-only --tmpfs /tmp appRead-only root filesystem with a writable /tmp
docker run --security-opt no-new-privileges appBlock privilege escalation through setuid binaries
docker run --memory 512m --cpus 1 --pids-limit 200 appResource limits

Scan

trivy image shop/api:1.4List known CVEs in OS packages and app dependencies
trivy image --severity HIGH,CRITICAL --exit-code 1 shop/api:1.4Fail a CI step on serious findings
trivy fs --scanners secret .Look for committed secrets in the source

Troubleshoot

docker ps -a --format '{{.Names}}\t{{.Status}}'Exit codes at a glance
docker inspect -f '{{.State.ExitCode}} {{.State.OOMKilled}} {{.State.Error}}' appWhy it stopped
docker events --since 30mWhat the daemon did recently
sudo ss -ltnp | grep :8080Who owns a port
docker system df -vWhat uses the disk
docker system pruneRemove stopped containers, unused networks, dangling images and build cache
docker image prune -a --filter until=168hRemove unused images older than 7 days
docker run --rm --network container:app nicolaka/netshootNetwork tools inside another container's namespace

11 · Capstone: ship an app through a private registry

Build host

docker build -t registry.lab.local:5000/shop/api:1.0 .Build and name it for the registry in one step
docker login registry.lab.local:5000Log in (credentials go to ~/.docker/config.json)
docker push registry.lab.local:5000/shop/api:1.0Push; note the digest it prints

Run host

sudo cp domain.crt /etc/docker/certs.d/registry.lab.local:5000/ca.crtTrust the registry
sudo dockerd --validate --config-file /etc/docker/daemon.json && sudo systemctl restart dockerApply host settings
docker compose -f compose.yaml -f compose.prod.yaml up -d --waitStart the stack and wait for health
docker compose ps && curl -s localhost:8080/healthzVerify