LearnThatStack Ace your next interview
DevOps · Free

Docker DevOps.
Interview cheat sheet.

Quick reference for Docker DevOps - sectioned for fast scanning. Skim the part you're shaky on, walk in confident.

DevOps 12-section reference ~10 min read

Summary

Docker is a containerization platform that packages applications with their dependencies into lightweight, portable containers using OS-level virtualization. It enables consistent deployment across environments, rapid scaling, and efficient resource utilization. Key components include Docker Engine, images, containers, Dockerfile for building images, and Docker Compose for multi-container applications. Essential for DevOps professionals implementing microservices architectures, CI/CD pipelines, and cloud-native deployments where application portability and infrastructure efficiency are critical.

Docker Fundamentals

What is Docker?

  • Containerization platform that packages applications with dependencies
  • Uses OS-level virtualization (shares host kernel)
  • Lightweight compared to VMs (no guest OS overhead)

Docker Architecture

Client (docker CLI) → Docker Daemon → Container Runtime → Containers
                    ↓
              Docker Registry (Hub)

Key Components

  • Docker Engine: Core runtime
  • Docker Image: Read-only template
  • Docker Container: Running instance of image
  • Dockerfile: Instructions to build image
  • Docker Registry: Image storage (Docker Hub, ECR, GCR)

Container vs VM

Container Virtual Machine
Shares host OS kernel Full OS per VM
Starts in seconds Minutes to start
MB in size GB in size
Process isolation Hardware virtualization

Essential Commands

Container Management

# Run container
docker run -d -p 8080:80 --name webapp nginx
# -d: detached, -p: port mapping, --name: container name

# List containers
docker ps          # Running containers
docker ps -a       # All containers

# Stop/Start/Restart
docker stop <container>
docker start <container>
docker restart <container>

# Remove container
docker rm <container>
docker rm -f <container>  # Force remove running

# Execute command in container
docker exec -it <container> bash
# -it: interactive terminal

# View logs
docker logs <container>
docker logs -f <container>  # Follow logs

Image Management

# List images
docker images

# Pull image
docker pull nginx:latest

# Build image
docker build -t myapp:v1 .
# -t: tag

# Push image
docker push myrepo/myapp:v1

# Remove image
docker rmi <image>

# Tag image
docker tag <source> <target>

# Image history
docker history <image>

System Commands

# System info
docker info
docker version

# Clean up
docker system prune       # Remove unused data
docker system prune -a    # Remove all unused images
docker volume prune       # Remove unused volumes

# Resource usage
docker stats

Dockerfile

Basic Structure

# Base image
FROM node:14-alpine

# Working directory
WORKDIR /app

# Copy files
COPY package*.json ./
COPY . .

# Install dependencies
RUN npm install

# Expose port
EXPOSE 3000

# Default command
CMD ["node", "server.js"]

Best Practices

# 1. Use specific tags
FROM node:14-alpine  # Good
# FROM node:latest   # Bad

# 2. Minimize layers
RUN apt-get update && \
    apt-get install -y curl git && \
    apt-get clean

# 3. Use multi-stage builds
FROM maven:3.8 AS build
COPY . /app
WORKDIR /app
RUN mvn package

FROM openjdk:11-jre-slim
COPY --from=build /app/target/*.jar app.jar
CMD ["java", "-jar", "app.jar"]

# 4. Order matters (cache optimization)
COPY package.json .     # Changes less frequently
RUN npm install         # Cached if package.json unchanged
COPY . .               # Application code changes often

# 5. Use .dockerignore
# node_modules
# .git
# .env

Dockerfile Instructions

  • FROM: Base image
  • RUN: Execute commands (creates layers)
  • CMD: Default command (can be overridden)
  • ENTRYPOINT: Main command (harder to override)
  • COPY: Copy files from host
  • ADD: Copy files (with URL/tar support)
  • WORKDIR: Set working directory
  • EXPOSE: Document ports
  • ENV: Environment variables
  • ARG: Build-time variables
  • VOLUME: Create mount point
  • USER: Set user for RUN/CMD/ENTRYPOINT

Docker Compose

Basic docker-compose.yml

version: '3.8'

services:
  web:
    image: nginx:alpine
    ports:
      - "80:80"
    volumes:
      - ./html:/usr/share/nginx/html
    networks:
      - webnet

  app:
    build: .
    ports:
      - "3000:3000"
    environment:
      - DB_HOST=db
      - DB_PORT=5432
    depends_on:
      - db
    networks:
      - webnet

  db:
    image: postgres:13
    environment:
      POSTGRES_PASSWORD: secretpass
    volumes:
      - db-data:/var/lib/postgresql/data
    networks:
      - webnet

volumes:
  db-data:

networks:
  webnet:

Compose Commands

# Start services
docker-compose up
docker-compose up -d        # Detached

# Stop services
docker-compose down
docker-compose down -v      # Remove volumes

# View logs
docker-compose logs
docker-compose logs -f app  # Follow specific service

# Scale services
docker-compose up -d --scale app=3

# Build/Rebuild
docker-compose build
docker-compose up --build

# Execute command
docker-compose exec app bash

Networking

Network Types

  1. bridge (default): Isolated network on host
  2. host: Share host's network
  3. none: No networking
  4. overlay: Multi-host networking (Swarm)
  5. macvlan: Assign MAC address

Network Commands

# List networks
docker network ls

# Create network
docker network create mynet

# Connect container
docker run -d --network mynet nginx
docker network connect mynet <container>

# Inspect network
docker network inspect bridge

# Disconnect
docker network disconnect mynet <container>

Container Communication

# Containers in same network can communicate by name
docker run -d --name db --network mynet postgres
docker run -d --name app --network mynet -e DB_HOST=db myapp

Volumes & Storage

Volume Types

  1. Named Volumes: Managed by Docker
  2. Bind Mounts: Host path mounted
  3. tmpfs: Memory only (Linux)

Volume Commands

# Create volume
docker volume create mydata

# List volumes
docker volume ls

# Inspect volume
docker volume inspect mydata

# Use volume
docker run -v mydata:/data nginx
docker run -v /host/path:/container/path nginx  # Bind mount

# Remove volume
docker volume rm mydata

Storage Drivers

  • overlay2: Default, most compatible
  • aufs: Legacy
  • devicemapper: Legacy
  • btrfs: Advanced features
  • zfs: Advanced features

Security Best Practices

Image Security

# 1. Use official/minimal base images
FROM alpine:3.14

# 2. Don't run as root
RUN addgroup -g 1000 appuser && \
    adduser -D -u 1000 -G appuser appuser
USER appuser

# 3. Use COPY instead of ADD
COPY app.jar /app/

# 4. Scan for vulnerabilities
# docker scan myimage

Runtime Security

# Read-only filesystem
docker run --read-only nginx

# Drop capabilities
docker run --cap-drop ALL --cap-add NET_BIND_SERVICE nginx

# Security options
docker run --security-opt no-new-privileges nginx

# Resource limits
docker run -m 512m --cpus 0.5 nginx

Secrets Management

# Docker secrets (Swarm)
echo "mypassword" | docker secret create db_pass -
docker service create --secret db_pass myapp

# Environment variables (less secure)
docker run -e API_KEY=secret myapp

# Use volume for config
docker run -v /secure/config:/config:ro myapp

Performance Optimization

Image Optimization

# 1. Multi-stage builds
FROM golang:1.16 AS builder
WORKDIR /app
COPY . .
RUN go build -o main .

FROM alpine:3.14
RUN apk --no-cache add ca-certificates
COPY --from=builder /app/main /main
CMD ["/main"]

# 2. Minimize layers
RUN apt-get update && \
    apt-get install -y python3 python3-pip && \
    pip3 install -r requirements.txt && \
    apt-get clean && \
    rm -rf /var/lib/apt/lists/*

# 3. Use cache efficiently
COPY requirements.txt .
RUN pip install -r requirements.txt
COPY . .

Runtime Performance

# CPU limits
docker run --cpus="1.5" nginx

# Memory limits
docker run -m 512m nginx

# Monitoring
docker stats
docker top <container>

# Health checks
HEALTHCHECK --interval=30s --timeout=3s \
  CMD curl -f http://localhost/ || exit 1

Container Orchestration

Docker Swarm Basics

# Initialize swarm
docker swarm init

# Deploy service
docker service create --replicas 3 -p 80:80 nginx

# Scale service
docker service scale web=5

# Update service
docker service update --image nginx:latest web

# Stack deployment
docker stack deploy -c docker-compose.yml mystack

Kubernetes Concepts (Interview Context)

  • Pod: Smallest deployable unit
  • Service: Network endpoint
  • Deployment: Manages replica sets
  • ConfigMap/Secret: Configuration
  • Ingress: External access
  • PersistentVolume: Storage

Common Interview Topics

Docker Architecture Deep Dive

Container Runtime Stack:

Docker CLI → Docker API → containerd → runc → Linux Kernel

Key Processes:

  • dockerd: Docker daemon managing containers, images, networks
  • containerd: Container runtime managing container lifecycle
  • runc: Low-level container runtime implementing OCI specification
  • shim: Process maintaining stdio streams and signals

Container Lifecycle Management

State Transitions:

Created → Running → Paused → Stopped → Removed
    ↑        ↓         ↑        ↑
    └────────┴─────────┴────────┘

Advanced Container Operations:

# Container inspection and debugging
docker inspect container_name --format='{{.State.Status}}'
docker inspect container_name --format='{{.NetworkSettings.IPAddress}}'
docker diff container_name  # Show filesystem changes

# Container process management
docker pause container_name    # Freeze all processes
docker unpause container_name  # Resume processes
docker kill --signal=TERM container_name

# Resource constraints debugging
docker exec container_name cat /sys/fs/cgroup/memory/memory.limit_in_bytes
docker exec container_name cat /proc/meminfo

Image Optimization Strategies

Multi-Stage Build Patterns:

# Build stage optimization
FROM golang:1.19-alpine AS builder
WORKDIR /build
COPY go.mod go.sum ./
RUN go mod download
COPY . .
RUN CGO_ENABLED=0 GOOS=linux go build -a -installsuffix cgo -o main .

# Runtime stage
FROM scratch
# or FROM gcr.io/distroless/static for better security
COPY --from=builder /build/main /
COPY --from=builder /etc/ssl/certs/ca-certificates.crt /etc/ssl/certs/
EXPOSE 8080
CMD ["/main"]

Layer Optimization Techniques:

# Bad: Creates multiple layers
RUN apt-get update
RUN apt-get install -y python3
RUN apt-get install -y python3-pip
RUN apt-get clean

# Good: Single layer with cleanup
RUN apt-get update && \
    apt-get install -y --no-install-recommends python3 python3-pip && \
    apt-get clean && \
    rm -rf /var/lib/apt/lists/* /tmp/* /var/tmp/*

# Advanced: Using buildkit features
# syntax=docker/dockerfile:1
FROM alpine
RUN --mount=type=cache,target=/var/cache/apk \
    apk add --update python3 py3-pip

Networking Deep Dive

Network Driver Comparison:

Driver Use Case Performance Isolation
bridge Single host containers Good Process level
host High performance needs Excellent None
overlay Multi-host clustering Good Network level
macvlan Legacy app integration Excellent Physical level
none Maximum security N/A Complete

Advanced Networking Patterns:

# Custom bridge network with subnet
docker network create --driver bridge \
  --subnet=172.20.0.0/16 \
  --ip-range=172.20.240.0/20 \
  custom-bridge

# Container with multiple networks
docker run -d --name multi-net \
  --network frontend \
  --network backend \
  nginx

# Network troubleshooting
docker exec container netstat -tlnp
docker exec container ss -tlnp
docker exec container iptables -L

Storage and Volume Management

Volume Performance Comparison:

Storage Type Performance Use Case Persistence
tmpfs Fastest Temporary data No
Named Volume Good Database data Yes
Bind Mount Variable Development Yes
NFS Volume Network dependent Shared storage Yes

Advanced Volume Patterns:

# Volume with specific driver
docker volume create --driver local \
  --opt type=nfs \
  --opt o=addr=192.168.1.100,rw \
  --opt device=:/path/to/dir \
  nfs-volume

# Backup and restore
docker run --rm -v myvolume:/data -v $(pwd):/backup alpine \
  tar czf /backup/backup.tar.gz /data

docker run --rm -v myvolume:/data -v $(pwd):/backup alpine \
  tar xzf /backup/backup.tar.gz -C /

Security Best Practices Deep Dive

User Namespace Remapping:

# Enable user namespace in daemon.json
{
  "userns-remap": "default"
}

# Check remapped user
docker exec container id
docker exec container ps aux

Capability Management:

# Drop all capabilities and add specific ones
docker run --cap-drop=ALL --cap-add=NET_BIND_SERVICE nginx

# Common capability sets
# --cap-add=SYS_TIME     # Change system time
# --cap-add=NET_ADMIN    # Network administration
# --cap-add=SYS_PTRACE   # Debug processes

Security Scanning Integration:

# Docker Scout (new security tool)
docker scout quickview
docker scout cves --format sarif --output results.sarif

# Trivy integration
trivy image --format json --output results.json myimage:latest

# Runtime security
docker run --security-opt seccomp=unconfined \
  --security-opt apparmor=unconfined \
  --security-opt no-new-privileges:true \
  myapp

Troubleshooting Methodologies

Container Debugging Workflow:

# 1. Check container status
docker ps -a --format "table {{.Names}}\t{{.Status}}\t{{.Ports}}"

# 2. Examine logs with context
docker logs --details --timestamps --since 1h container_name

# 3. Process and resource inspection
docker exec container_name top
docker exec container_name df -h
docker exec container_name free -m

# 4. Network connectivity
docker exec container_name netstat -rn  # Routing table
docker exec container_name dig service_name  # DNS resolution

# 5. File system analysis
docker exec container_name find /app -name "*.log" -mtime -1
docker diff container_name  # Changed files

Performance Profiling:

# Resource utilization over time
docker stats --format "table {{.Container}}\t{{.CPUPerc}}\t{{.MemUsage}}\t{{.NetIO}}" \
  --no-stream

# Container process tree
docker exec container_name ps auxf

# System calls tracing
docker exec container_name strace -c -p 1

Production Deployment Patterns

Health Check Strategies:

# HTTP health check
HEALTHCHECK --interval=30s --timeout=10s --start-period=40s --retries=3 \
  CMD curl -f http://localhost:8080/health || exit 1

# Custom health check script
HEALTHCHECK --interval=30s --timeout=10s --retries=3 \
  CMD ["./health-check.sh"]

# TCP health check
HEALTHCHECK --interval=30s --timeout=5s --retries=3 \
  CMD nc -z localhost 5432 || exit 1

Resource Management:

# docker-compose.yml with resource limits
version: '3.8'
services:
  app:
    image: myapp:latest
    deploy:
      resources:
        limits:
          cpus: '2.0'
          memory: 1G
        reservations:
          cpus: '0.5'
          memory: 512M
    restart: unless-stopped
    logging:
      driver: "json-file"
      options:
        max-size: "10m"
        max-file: "3"

Container Orchestration Comparison

Feature Docker Swarm Kubernetes Nomad
Setup Complexity Simple Complex Moderate
Scaling Good Excellent Good
Load Balancing Built-in Requires ingress Built-in
Service Discovery DNS-based DNS + API Consul integration
Rolling Updates Yes Advanced Yes
Multi-cloud Limited Yes Yes

CI/CD Integration Patterns

Advanced Pipeline Example:

# .gitlab-ci.yml
stages:
  - build
  - test
  - security
  - deploy

variables:
  DOCKER_DRIVER: overlay2
  DOCKER_TLS_CERTDIR: "/certs"

build:
  stage: build
  services:
    - docker:dind
  script:
    - docker build --pull -t $CI_REGISTRY_IMAGE:$CI_COMMIT_SHA .
    - docker push $CI_REGISTRY_IMAGE:$CI_COMMIT_SHA
  only:
    - main

security_scan:
  stage: security
  script:
    - trivy image --exit-code 0 --severity HIGH,CRITICAL $CI_REGISTRY_IMAGE:$CI_COMMIT_SHA
  allow_failure: true

deploy_production:
  stage: deploy
  script:
    - docker service update --image $CI_REGISTRY_IMAGE:$CI_COMMIT_SHA production_app
  environment:
    name: production
  only:
    - main
  when: manual

Quick Reference Card

Must-Know Commands

docker run -d -p 8080:80 --name web nginx
docker exec -it web bash
docker logs -f web
docker build -t myapp .
docker-compose up -d
docker system prune -a

Common Flags

  • -d: Detached mode
  • -it: Interactive terminal
  • -p: Port mapping
  • -v: Volume mount
  • --rm: Remove after exit
  • -e: Environment variable
  • --name: Container name

Best Practices Summary

  1. ✅ Use specific image tags
  2. ✅ One process per container
  3. ✅ Minimize image layers
  4. ✅ Use .dockerignore
  5. ✅ Don't store secrets in images
  6. ✅ Run as non-root user
  7. ✅ Use health checks
  8. ✅ Set resource limits

Remember: In interviews, explain the WHY behind Docker practices, not just the HOW!

Found this useful? Pass it on.
Pro · $10/mo

The sheet is free. Pro goes deeper.

Pro opens the full question library behind every sheet, every refresher and a monthly AI allowance. One subscription, all formats.

Full question library All refreshers Cancel anytime