Docker & Containers — Level by Level›Level 5 · Cheat sheet & self-check

Level 5 — Production habits · wrap-up

Cheat sheet & self-check

6 questions across 2 lessons. Each answer links back to the lesson it came from.

Pick an answer to see if you got it, and why.

  1. Q1. A container keeps exiting with code 137. What does that usually mean?

    Show answer

    B. Exit codes above 128 are 128 + the signal number. Check docker inspect for OOMKilled: true, then raise the limit or fix the memory use.

    From lesson 10 · Security & troubleshooting
  2. Q2. Why is --privileged dangerous?

    Show answer

    B. A privileged container can mount host disks and load kernel modules. Grant the specific capability or device it needs instead.

    From lesson 10 · Security & troubleshooting
  3. Q3. `docker run -p 8080:80` fails with 'port is already allocated'. First step?

    Show answer

    B. Another container or a host process already listens on 8080. Stop it, or publish on a different host port.

    From lesson 10 · Security & troubleshooting
  4. Q4. /var/lib/docker is 95% full. What is the safest first clean-up?

    Show answer

    B. Never delete Docker's files by hand. Measure with docker system df, prune what's safe, and check for huge container log files (fix with log rotation in daemon.json). Only prune volumes once you know no data is needed.

    From lesson 10 · Security & troubleshooting
  5. Q5. The run host pulls fine by name, but you deploy with the digest. Why bother?

    Show answer

    B. Tags can move. The digest pins the content, which is what makes a deployment reproducible and auditable.

    From lesson 11 · Capstone: ship an app through a private registry
  6. Q6. At the end of the capstone, which of these should the run host NOT have?

    Show answer

    C. The registry has a certificate the host trusts through certs.d, so there's no reason to switch verification off.

    From lesson 11 · Capstone: ship an app through a private registry