docker - Docker image and container command line interface
docker [OPTIONS] COMMAND [ARG...]
Options you will use
build -t NAME[:TAG] [-f FILE] [--target STAGE] [--no-cache] [--pull] [--progress plain] [--build-arg K=V] [--secret id=x,src=f] [--platform P] PATH- Build an image from a Dockerfile. PATH is the build context: everything in it (minus .dockerignore) is sent to the builder.
build --check PATH- Run the build checks (JSONArgsRecommended, SecretsUsedInArgOrEnv, ...) without building.
run [-d] [--rm] [-it] [--name N] [-p H:C] [-v SRC:DST[:ro]] [-e K=V] [--env-file F] [-u UID:GID] [-m 512m] [--cpus 1.5] [--restart P] [--network N] [--entrypoint X] [--init] [--read-only] [--tmpfs P] [--cap-drop ALL] [--cap-add C] IMAGE [CMD...]- Create and start a container. Anything after the image replaces CMD, not ENTRYPOINT.
ps [-a] [-q] [-s] [--filter k=v] [--format T]- List containers. Exited ones only with -a.
logs [-f] [--tail N] [--since 10m] [-t] C- The container's stdout/stderr. Streams are kept: pipe stderr with 2>&1.
exec [-it] [-u U] [-w DIR] C CMD- Run a command in a RUNNING container. Needs the binary to exist in the image.
inspect [-f TEMPLATE] OBJ- Low-level JSON. -f takes a Go template: {{.State.ExitCode}}, {{json .Config}}, {{range .Mounts}}...{{end}}.
history [--no-trunc] IMAGE- The layers of an image, newest first, with the instruction that made each and its size.
stop [-t N] C / kill [-s SIG] C- stop: StopSignal (default SIGTERM), wait N (10) seconds, then SIGKILL. kill: SIGKILL by default.
images / rmi / tag / pull / push / login / save- Image management and registries.
network ls|create|connect|disconnect|inspect|rm- Networks. Only user-defined networks give DNS by container name.
volume ls|create|inspect|rm|prune- Named volumes. prune only removes anonymous volumes unless -a.
system df [-v] / system prune [-a] [--volumes]- Disk usage by images, containers, volumes and build cache, and cleanup.
stats [--no-stream] / top C / events / port / diff / cp / wait / update- Runtime inspection.
compose ...- Multi-container projects from compose.yaml (see docker-compose).
-H, --host LIST- Daemon socket to connect to (unix:///var/run/docker.sock, ssh://user@host, tcp://...).
--context STRING- Name of the context to use to connect to the daemon (overrides DOCKER_HOST).
--config STRING- Location of client config files (default ~/.docker; config.json holds registry credentials).
-D, --debug- Enable debug mode.
--log-level STRING- Set the logging level: debug, info, warn, error, fatal.
Examples
$ docker build -t app:1.0 .build with the current directory as context
$ docker run --rm -it --entrypoint sh app:1.0get a shell in a broken image
$ docker inspect -f '{{.State.ExitCode}} {{.State.OOMKilled}}' webwhy did it die
$ docker history --no-trunc app:1.0find the bloat - and the secrets
$ docker logs --tail 50 -f webfollow the last 50 lines
Gotchas
- The daemon socket /var/run/docker.sock is group docker. Being in that group is equivalent to root on the host: docker run -v /:/host gives full access.
- Exit codes: 125 the docker command itself failed, 126 not executable, 127 not found, 128+N killed by signal N (137 = SIGKILL, often OOM; 143 = SIGTERM; 139 = SIGSEGV).
Taught in
- 10.1 Installing Docker, the daemon, and the socket
- 10.3 What a container actually is
- 10.5 Images, tags and digests
- 10.8 The Dockerfile, and reading a build
- 10.10 Reading docker history: where the bytes went
- 10.19 Cache mounts, remote caches, and builds in CI
- 10.21 The build context and .dockerignore
- 10.24 Multi-stage builds for Java: from 1GB to under 200MB
Try docker in a real terminal Free, in your browser - a real Ubuntu terminal to try it in, with missions that check your work.