Summary
Docker is a containerization platform that packages applications with their dependencies into lightweight, portable containers using OS-level virtualization. It enables consistent deployment across environments, rapid scaling, and efficient resource utilization. Key components include Docker Engine, images, containers, Dockerfile for building images, and Docker Compose for multi-container applications. Essential for DevOps professionals implementing microservices architectures, CI/CD pipelines, and cloud-native deployments where application portability and infrastructure efficiency are critical.
Docker Fundamentals
What is Docker?
- Containerization platform that packages applications with dependencies
- Uses OS-level virtualization (shares host kernel)
- Lightweight compared to VMs (no guest OS overhead)
Docker Architecture
Client (docker CLI) → Docker Daemon → Container Runtime → Containers
↓
Docker Registry (Hub)
Key Components
- Docker Engine: Core runtime
- Docker Image: Read-only template
- Docker Container: Running instance of image
- Dockerfile: Instructions to build image
- Docker Registry: Image storage (Docker Hub, ECR, GCR)
Container vs VM
| Container | Virtual Machine |
|---|---|
| Shares host OS kernel | Full OS per VM |
| Starts in seconds | Minutes to start |
| MB in size | GB in size |
| Process isolation | Hardware virtualization |
Essential Commands
Container Management
# Run container
docker run -d -p 8080:80 --name webapp nginx
# -d: detached, -p: port mapping, --name: container name
# List containers
docker ps # Running containers
docker ps -a # All containers
# Stop/Start/Restart
docker stop <container>
docker start <container>
docker restart <container>
# Remove container
docker rm <container>
docker rm -f <container> # Force remove running
# Execute command in container
docker exec -it <container> bash
# -it: interactive terminal
# View logs
docker logs <container>
docker logs -f <container> # Follow logs
Image Management
# List images
docker images
# Pull image
docker pull nginx:latest
# Build image
docker build -t myapp:v1 .
# -t: tag
# Push image
docker push myrepo/myapp:v1
# Remove image
docker rmi <image>
# Tag image
docker tag <source> <target>
# Image history
docker history <image>
System Commands
# System info
docker info
docker version
# Clean up
docker system prune # Remove unused data
docker system prune -a # Remove all unused images
docker volume prune # Remove unused volumes
# Resource usage
docker stats
Dockerfile
Basic Structure
# Base image
FROM node:14-alpine
# Working directory
WORKDIR /app
# Copy files
COPY package*.json ./
COPY . .
# Install dependencies
RUN npm install
# Expose port
EXPOSE 3000
# Default command
CMD ["node", "server.js"]
Best Practices
# 1. Use specific tags
FROM node:14-alpine # Good
# FROM node:latest # Bad
# 2. Minimize layers
RUN apt-get update && \
apt-get install -y curl git && \
apt-get clean
# 3. Use multi-stage builds
FROM maven:3.8 AS build
COPY . /app
WORKDIR /app
RUN mvn package
FROM openjdk:11-jre-slim
COPY --from=build /app/target/*.jar app.jar
CMD ["java", "-jar", "app.jar"]
# 4. Order matters (cache optimization)
COPY package.json . # Changes less frequently
RUN npm install # Cached if package.json unchanged
COPY . . # Application code changes often
# 5. Use .dockerignore
# node_modules
# .git
# .env
Dockerfile Instructions
- FROM: Base image
- RUN: Execute commands (creates layers)
- CMD: Default command (can be overridden)
- ENTRYPOINT: Main command (harder to override)
- COPY: Copy files from host
- ADD: Copy files (with URL/tar support)
- WORKDIR: Set working directory
- EXPOSE: Document ports
- ENV: Environment variables
- ARG: Build-time variables
- VOLUME: Create mount point
- USER: Set user for RUN/CMD/ENTRYPOINT
Docker Compose
Basic docker-compose.yml
version: '3.8'
services:
web:
image: nginx:alpine
ports:
- "80:80"
volumes:
- ./html:/usr/share/nginx/html
networks:
- webnet
app:
build: .
ports:
- "3000:3000"
environment:
- DB_HOST=db
- DB_PORT=5432
depends_on:
- db
networks:
- webnet
db:
image: postgres:13
environment:
POSTGRES_PASSWORD: secretpass
volumes:
- db-data:/var/lib/postgresql/data
networks:
- webnet
volumes:
db-data:
networks:
webnet:
Compose Commands
# Start services
docker-compose up
docker-compose up -d # Detached
# Stop services
docker-compose down
docker-compose down -v # Remove volumes
# View logs
docker-compose logs
docker-compose logs -f app # Follow specific service
# Scale services
docker-compose up -d --scale app=3
# Build/Rebuild
docker-compose build
docker-compose up --build
# Execute command
docker-compose exec app bash
Networking
Network Types
- bridge (default): Isolated network on host
- host: Share host's network
- none: No networking
- overlay: Multi-host networking (Swarm)
- macvlan: Assign MAC address
Network Commands
# List networks
docker network ls
# Create network
docker network create mynet
# Connect container
docker run -d --network mynet nginx
docker network connect mynet <container>
# Inspect network
docker network inspect bridge
# Disconnect
docker network disconnect mynet <container>
Container Communication
# Containers in same network can communicate by name
docker run -d --name db --network mynet postgres
docker run -d --name app --network mynet -e DB_HOST=db myapp
Volumes & Storage
Volume Types
- Named Volumes: Managed by Docker
- Bind Mounts: Host path mounted
- tmpfs: Memory only (Linux)
Volume Commands
# Create volume
docker volume create mydata
# List volumes
docker volume ls
# Inspect volume
docker volume inspect mydata
# Use volume
docker run -v mydata:/data nginx
docker run -v /host/path:/container/path nginx # Bind mount
# Remove volume
docker volume rm mydata
Storage Drivers
- overlay2: Default, most compatible
- aufs: Legacy
- devicemapper: Legacy
- btrfs: Advanced features
- zfs: Advanced features
Security Best Practices
Image Security
# 1. Use official/minimal base images
FROM alpine:3.14
# 2. Don't run as root
RUN addgroup -g 1000 appuser && \
adduser -D -u 1000 -G appuser appuser
USER appuser
# 3. Use COPY instead of ADD
COPY app.jar /app/
# 4. Scan for vulnerabilities
# docker scan myimage
Runtime Security
# Read-only filesystem
docker run --read-only nginx
# Drop capabilities
docker run --cap-drop ALL --cap-add NET_BIND_SERVICE nginx
# Security options
docker run --security-opt no-new-privileges nginx
# Resource limits
docker run -m 512m --cpus 0.5 nginx
Secrets Management
# Docker secrets (Swarm)
echo "mypassword" | docker secret create db_pass -
docker service create --secret db_pass myapp
# Environment variables (less secure)
docker run -e API_KEY=secret myapp
# Use volume for config
docker run -v /secure/config:/config:ro myapp
Performance Optimization
Image Optimization
# 1. Multi-stage builds
FROM golang:1.16 AS builder
WORKDIR /app
COPY . .
RUN go build -o main .
FROM alpine:3.14
RUN apk --no-cache add ca-certificates
COPY --from=builder /app/main /main
CMD ["/main"]
# 2. Minimize layers
RUN apt-get update && \
apt-get install -y python3 python3-pip && \
pip3 install -r requirements.txt && \
apt-get clean && \
rm -rf /var/lib/apt/lists/*
# 3. Use cache efficiently
COPY requirements.txt .
RUN pip install -r requirements.txt
COPY . .
Runtime Performance
# CPU limits
docker run --cpus="1.5" nginx
# Memory limits
docker run -m 512m nginx
# Monitoring
docker stats
docker top <container>
# Health checks
HEALTHCHECK --interval=30s --timeout=3s \
CMD curl -f http://localhost/ || exit 1
Container Orchestration
Docker Swarm Basics
# Initialize swarm
docker swarm init
# Deploy service
docker service create --replicas 3 -p 80:80 nginx
# Scale service
docker service scale web=5
# Update service
docker service update --image nginx:latest web
# Stack deployment
docker stack deploy -c docker-compose.yml mystack
Kubernetes Concepts (Interview Context)
- Pod: Smallest deployable unit
- Service: Network endpoint
- Deployment: Manages replica sets
- ConfigMap/Secret: Configuration
- Ingress: External access
- PersistentVolume: Storage
Common Interview Topics
Docker Architecture Deep Dive
Container Runtime Stack:
Docker CLI → Docker API → containerd → runc → Linux Kernel
Key Processes:
- dockerd: Docker daemon managing containers, images, networks
- containerd: Container runtime managing container lifecycle
- runc: Low-level container runtime implementing OCI specification
- shim: Process maintaining stdio streams and signals
Container Lifecycle Management
State Transitions:
Created → Running → Paused → Stopped → Removed
↑ ↓ ↑ ↑
└────────┴─────────┴────────┘
Advanced Container Operations:
# Container inspection and debugging
docker inspect container_name --format='{{.State.Status}}'
docker inspect container_name --format='{{.NetworkSettings.IPAddress}}'
docker diff container_name # Show filesystem changes
# Container process management
docker pause container_name # Freeze all processes
docker unpause container_name # Resume processes
docker kill --signal=TERM container_name
# Resource constraints debugging
docker exec container_name cat /sys/fs/cgroup/memory/memory.limit_in_bytes
docker exec container_name cat /proc/meminfo
Image Optimization Strategies
Multi-Stage Build Patterns:
# Build stage optimization
FROM golang:1.19-alpine AS builder
WORKDIR /build
COPY go.mod go.sum ./
RUN go mod download
COPY . .
RUN CGO_ENABLED=0 GOOS=linux go build -a -installsuffix cgo -o main .
# Runtime stage
FROM scratch
# or FROM gcr.io/distroless/static for better security
COPY --from=builder /build/main /
COPY --from=builder /etc/ssl/certs/ca-certificates.crt /etc/ssl/certs/
EXPOSE 8080
CMD ["/main"]
Layer Optimization Techniques:
# Bad: Creates multiple layers
RUN apt-get update
RUN apt-get install -y python3
RUN apt-get install -y python3-pip
RUN apt-get clean
# Good: Single layer with cleanup
RUN apt-get update && \
apt-get install -y --no-install-recommends python3 python3-pip && \
apt-get clean && \
rm -rf /var/lib/apt/lists/* /tmp/* /var/tmp/*
# Advanced: Using buildkit features
# syntax=docker/dockerfile:1
FROM alpine
RUN --mount=type=cache,target=/var/cache/apk \
apk add --update python3 py3-pip
Networking Deep Dive
Network Driver Comparison:
| Driver | Use Case | Performance | Isolation |
|---|---|---|---|
| bridge | Single host containers | Good | Process level |
| host | High performance needs | Excellent | None |
| overlay | Multi-host clustering | Good | Network level |
| macvlan | Legacy app integration | Excellent | Physical level |
| none | Maximum security | N/A | Complete |
Advanced Networking Patterns:
# Custom bridge network with subnet
docker network create --driver bridge \
--subnet=172.20.0.0/16 \
--ip-range=172.20.240.0/20 \
custom-bridge
# Container with multiple networks
docker run -d --name multi-net \
--network frontend \
--network backend \
nginx
# Network troubleshooting
docker exec container netstat -tlnp
docker exec container ss -tlnp
docker exec container iptables -L
Storage and Volume Management
Volume Performance Comparison:
| Storage Type | Performance | Use Case | Persistence |
|---|---|---|---|
| tmpfs | Fastest | Temporary data | No |
| Named Volume | Good | Database data | Yes |
| Bind Mount | Variable | Development | Yes |
| NFS Volume | Network dependent | Shared storage | Yes |
Advanced Volume Patterns:
# Volume with specific driver
docker volume create --driver local \
--opt type=nfs \
--opt o=addr=192.168.1.100,rw \
--opt device=:/path/to/dir \
nfs-volume
# Backup and restore
docker run --rm -v myvolume:/data -v $(pwd):/backup alpine \
tar czf /backup/backup.tar.gz /data
docker run --rm -v myvolume:/data -v $(pwd):/backup alpine \
tar xzf /backup/backup.tar.gz -C /
Security Best Practices Deep Dive
User Namespace Remapping:
# Enable user namespace in daemon.json
{
"userns-remap": "default"
}
# Check remapped user
docker exec container id
docker exec container ps aux
Capability Management:
# Drop all capabilities and add specific ones
docker run --cap-drop=ALL --cap-add=NET_BIND_SERVICE nginx
# Common capability sets
# --cap-add=SYS_TIME # Change system time
# --cap-add=NET_ADMIN # Network administration
# --cap-add=SYS_PTRACE # Debug processes
Security Scanning Integration:
# Docker Scout (new security tool)
docker scout quickview
docker scout cves --format sarif --output results.sarif
# Trivy integration
trivy image --format json --output results.json myimage:latest
# Runtime security
docker run --security-opt seccomp=unconfined \
--security-opt apparmor=unconfined \
--security-opt no-new-privileges:true \
myapp
Troubleshooting Methodologies
Container Debugging Workflow:
# 1. Check container status
docker ps -a --format "table {{.Names}}\t{{.Status}}\t{{.Ports}}"
# 2. Examine logs with context
docker logs --details --timestamps --since 1h container_name
# 3. Process and resource inspection
docker exec container_name top
docker exec container_name df -h
docker exec container_name free -m
# 4. Network connectivity
docker exec container_name netstat -rn # Routing table
docker exec container_name dig service_name # DNS resolution
# 5. File system analysis
docker exec container_name find /app -name "*.log" -mtime -1
docker diff container_name # Changed files
Performance Profiling:
# Resource utilization over time
docker stats --format "table {{.Container}}\t{{.CPUPerc}}\t{{.MemUsage}}\t{{.NetIO}}" \
--no-stream
# Container process tree
docker exec container_name ps auxf
# System calls tracing
docker exec container_name strace -c -p 1
Production Deployment Patterns
Health Check Strategies:
# HTTP health check
HEALTHCHECK --interval=30s --timeout=10s --start-period=40s --retries=3 \
CMD curl -f http://localhost:8080/health || exit 1
# Custom health check script
HEALTHCHECK --interval=30s --timeout=10s --retries=3 \
CMD ["./health-check.sh"]
# TCP health check
HEALTHCHECK --interval=30s --timeout=5s --retries=3 \
CMD nc -z localhost 5432 || exit 1
Resource Management:
# docker-compose.yml with resource limits
version: '3.8'
services:
app:
image: myapp:latest
deploy:
resources:
limits:
cpus: '2.0'
memory: 1G
reservations:
cpus: '0.5'
memory: 512M
restart: unless-stopped
logging:
driver: "json-file"
options:
max-size: "10m"
max-file: "3"
Container Orchestration Comparison
| Feature | Docker Swarm | Kubernetes | Nomad |
|---|---|---|---|
| Setup Complexity | Simple | Complex | Moderate |
| Scaling | Good | Excellent | Good |
| Load Balancing | Built-in | Requires ingress | Built-in |
| Service Discovery | DNS-based | DNS + API | Consul integration |
| Rolling Updates | Yes | Advanced | Yes |
| Multi-cloud | Limited | Yes | Yes |
CI/CD Integration Patterns
Advanced Pipeline Example:
# .gitlab-ci.yml
stages:
- build
- test
- security
- deploy
variables:
DOCKER_DRIVER: overlay2
DOCKER_TLS_CERTDIR: "/certs"
build:
stage: build
services:
- docker:dind
script:
- docker build --pull -t $CI_REGISTRY_IMAGE:$CI_COMMIT_SHA .
- docker push $CI_REGISTRY_IMAGE:$CI_COMMIT_SHA
only:
- main
security_scan:
stage: security
script:
- trivy image --exit-code 0 --severity HIGH,CRITICAL $CI_REGISTRY_IMAGE:$CI_COMMIT_SHA
allow_failure: true
deploy_production:
stage: deploy
script:
- docker service update --image $CI_REGISTRY_IMAGE:$CI_COMMIT_SHA production_app
environment:
name: production
only:
- main
when: manual
Quick Reference Card
Must-Know Commands
docker run -d -p 8080:80 --name web nginx
docker exec -it web bash
docker logs -f web
docker build -t myapp .
docker-compose up -d
docker system prune -a
Common Flags
-d: Detached mode-it: Interactive terminal-p: Port mapping-v: Volume mount--rm: Remove after exit-e: Environment variable--name: Container name
Best Practices Summary
- ✅ Use specific image tags
- ✅ One process per container
- ✅ Minimize image layers
- ✅ Use .dockerignore
- ✅ Don't store secrets in images
- ✅ Run as non-root user
- ✅ Use health checks
- ✅ Set resource limits
Remember: In interviews, explain the WHY behind Docker practices, not just the HOW!