docker
Docker is a containerization platform that enables developers to package applications together with their dependencies and configuration into portable, isolated containers. These containers provide a consistent environment for developing, testing, deploying, and running software across different systems. By reducing differences between development and production environments, Docker helps simplify application deployment and improve scalability and reliability.
This section explores the fundamental concepts of Docker, including images, containers, Dockerfiles, volumes, networks, registries, and Docker Compose. It also examines container lifecycle management, application deployment, resource isolation, and Docker’s role in DevOps and cloud-based environments, providing a practical foundation for building and managing containerized applications.

Introduction To docker
wwww
- Learn Docker Made Easy
- Chapter 1: Introduction to Docker
- Chapter 2: Detailed Setup and First Application
- 2.1 Prerequisites for Environment Setup
- 2.2 Linux Command-Line Environment
- Step 1: Update System Packages
- Step 2: Install Required Dependencies
- Step 3: Add Docker's Official GPG Key
- Step 4: Add Docker Repository
- Step 5: Install Docker Engine
- Step 6: Verify Installation
- Step 7: Start Docker Service
- Step 8: Verify Docker is Running
- Step 9: Run Your First Container
- Step 10: Add User to Docker Group (Optional, Avoids sudo)
- 2.3 Linux GUI/IDE Environment
- 2.4 Linux AI-Integrated Workflow
- 2.5 Windows Command-Line Environment
- 2.6 Windows GUI/IDE Environment
- 2.7 Windows AI-Integrated Workflow
- 2.8 macOS Command-Line Environment
- 2.9 macOS GUI/IDE Environment
- 2.10 macOS AI-Integrated Workflow
- 2.11 Software Execution Lifecycle
- Chapter 3: AI Integration with Docker
- Chapter 4: Docker Fundamentals
- Chapter 5: Docker Images and Dockerfiles
- Chapter 6: Docker Containers
- Chapter 7: Docker Networking
- Chapter 8: Docker Storage
- Chapter 9: Docker Compose
- Chapter 10: Docker in Production
- Chapter 11: Security
- Chapter 12: Real-World Projects
- Docker Master Roadmap — Complete Learning Path
- Common Errors and Troubleshooting
- Final Thoughts
Learn Docker Made Easy
Introduction
Every modern application, microservice, API gateway, cloud platform, and DevOps pipeline depends on containerization. When a developer builds an application, they need a consistent way to package, ship, and run it across different environments—from a developer’s laptop to a production server.
Whether you are deploying a simple web application, a complex machine learning pipeline, a microservices architecture, or a full cloud-native platform, Docker is involved somewhere in the process.
For beginners, one of the most confusing topics is understanding the difference between virtualization and containerization, or between writing code and packaging it for deployment. Many tutorials start with programming languages and ignore the containerization layer that makes modern deployment possible.
This guide focuses entirely on practical Docker usage using the most popular containerization platform in the world:
- Docker – An open-source platform that automates the deployment of applications inside lightweight, portable containers. Docker provides a consistent environment for applications, ensuring they run the same way on any system.
By the end of this guide, you will understand:
- What containerization is and how Docker works
- Docker architecture (client, daemon, registry)
- How to install Docker on Linux, Windows, and macOS
- How to run your first container
- Docker images and Dockerfiles
- Docker Compose for multi-container applications
- Docker networking and storage
- Best practices and real-world projects
The goal is not merely to install Docker but to understand how to package, ship, and run applications consistently across any environment.
Chapter 1: Introduction to Docker
1.1 What Is Docker
Docker is an open-source platform that enables developers and IT teams to build, package, deploy, and run applications within containers. Containers are lightweight, portable, and self-sufficient environments that include everything needed to run an application: code, runtime, system tools, libraries, and settings.
Examples of what Docker can do:
- Package a web application with its dependencies
- Run a database in an isolated environment
- Create reproducible development environments
- Deploy microservices consistently
- Build and test applications in CI/CD pipelines
Example: Running a Simple Container
docker run hello-world
Output:
Hello from Docker!
This message shows that your installation appears to be working correctly.
The Docker client contacted the Docker daemon, which pulled the “hello-world” image from the Docker Hub, created a container, and ran it.
1.2 History of Docker
The history of Docker is closely tied to the evolution of containerization and modern DevOps practices.
Timeline:
- 2008 – Linux Containers (LXC) were introduced, providing OS-level virtualization. They were powerful but complex to use.
- 2010 – dotCloud, a platform-as-a-service company, began working on internal containerization tools. This work eventually became Docker.
- 2013 – Docker was released as open-source by dotCloud. It introduced a simple, user-friendly interface for containers, making containerization accessible to developers worldwide.
- 2014 – Docker 1.0 was released. Docker Hub was launched as a public registry for sharing container images. Docker became the standard for containerization.
- 2015 – The Open Container Initiative (OCI) was founded to create open standards for containers. Docker donated its container runtime (runc) to the OCI.
- 2017 – Docker introduced Docker Swarm for container orchestration. Kubernetes emerged as the dominant orchestration platform.
- 2019 – Docker Enterprise was acquired by Mirantis. Docker continued as an open-source project.
- 2020+ – Docker remains the most popular container platform. Modern builds leverage BuildKit for parallelized builds, advanced caching, and multi-architecture support.
1.3 Containerization vs Virtualization
Understanding the difference between containers and virtual machines is essential.
| Feature | Virtual Machines | Containers |
|---|---|---|
| Hardware | Emulates hardware | Uses host OS kernel |
| OS | Full guest OS | Shared host OS |
| Startup Time | Minutes | Seconds |
| Resource Usage | High | Low |
| Isolation | Strong | Moderate |
| Portability | Moderate | Excellent |
Virtual Machines:
- Each VM includes a full operating system
- Uses hardware virtualization (hypervisor)
- Heavy resource consumption
- Slower startup
Containers:
- Share the host operating system kernel
- Lightweight and fast
- Isolated at the process level
- Quick startup and shutdown
Analogy:
- Virtual machines are like separate houses (each with its own foundation, walls, and roof)
- Containers are like apartments in the same building (sharing the same foundation and structure but with separate rooms)
1.4 Docker Architecture
Docker uses a client-server architecture. The main components are the Docker client, Docker daemon, and Docker registry.
Docker Client
│
│ CLI Commands (docker build, docker run, docker pull)
▼
Docker Daemon (dockerd)
│
│ Manages images, containers, networks, volumes
▼
Docker Registry (Docker Hub, private registry)
│
│ Pulls/Pushes images over HTTP/HTTPS
▼
Containers (Running instances of images)
Docker Daemon (dockerd):
The background service that runs on the host machine and manages images, containers, networks, and volumes. The daemon:
- Builds and runs containers
- Manages images and networks
- Brokers communication with registries
- Enforces access and keeps state
Docker Client (docker):
The command-line interface that users interact with. The client sends commands to the daemon via a REST API.
Docker Registry:
A storage and distribution system for Docker images. Docker Hub is the default public registry.
1.5 Docker Components
Docker Engine:
The core of the Docker platform. It consists of:
dockerd– The daemon that manages containerscontainerd– A container runtime that manages container lifecyclerunc– The low-level OCI runtime that creates containers
Docker Images:
The building blocks of containers. Images are read-only templates that contain the application and its dependencies.
Docker Containers:
Running instances of Docker images. Containers are isolated, lightweight, and portable.
Docker Hub:
A cloud-based registry service for sharing and storing Docker images.
1.6 Use Cases of Docker
Development Environments:
- Consistent development environments across teams
- Eliminate “works on my machine” problems
- Quick setup for new developers
Application Packaging:
- Package applications with all dependencies
- Portable across environments (dev, test, production)
- Simplified deployment
Microservices:
- Package each service in its own container
- Independent deployment and scaling
- Technology flexibility (different languages per service)
CI/CD Pipelines:
- Consistent build environments
- Isolated testing environments
- Reproducible builds
Cloud-Native Applications:
- Scalable deployments
- Integration with orchestrators (Kubernetes)
- Multi-cloud portability
Chapter 2: Detailed Setup and First Application
2.1 Prerequisites for Environment Setup
Linux (Ubuntu 22.04 LTS or newer):
- 64-bit system
- 4 GB RAM (recommended)
- 20 GB free storage
- Stable internet connection
Windows (10/11):
- Windows 10/11 64-bit
- Windows 10/11 Pro, Enterprise, or Education (for WSL2)
- Virtualization enabled in BIOS
- Hyper-V or WSL2 enabled
- 8 GB RAM (recommended)
macOS (Monterey or newer):
- macOS 11+ with Apple Silicon or Intel
- 4 GB+ RAM
2.2 Linux Command-Line Environment
Step 1: Update System Packages
sudo apt update
sudo apt upgrade -y
Step 2: Install Required Dependencies
sudo apt install -y apt-transport-https ca-certificates curl software-properties-common
Step 3: Add Docker’s Official GPG Key
curl -fsSL https://download.docker.com/linux/ubuntu/gpg | sudo gpg --dearmor -o /usr/share/keyrings/docker-archive-keyring.gpg
Step 4: Add Docker Repository
echo "deb [arch=$(dpkg --print-architecture) signed-by=/usr/share/keyrings/docker-archive-keyring.gpg] https://download.docker.com/linux/ubuntu $(lsb_release -cs) stable" | sudo tee /etc/apt/sources.list.d/docker.list > /dev/null
Step 5: Install Docker Engine
sudo apt update
sudo apt install -y docker-ce docker-ce-cli containerd.io docker-buildx-plugin docker-compose-plugin
Step 6: Verify Installation
docker --version
Expected Output:
Docker version 26.1.0, build 1234567
Step 7: Start Docker Service
sudo systemctl start docker
sudo systemctl enable docker
Step 8: Verify Docker is Running
sudo systemctl status docker
Step 9: Run Your First Container
docker run hello-world
Expected Output:
Hello from Docker!
This message shows that your installation appears to be working correctly.
Step 10: Add User to Docker Group (Optional, Avoids sudo)
sudo usermod -aG docker $USER
newgrp docker
2.3 Linux GUI/IDE Environment
Installing VS Code
sudo snap install --classic code
Installing Docker Extension for VS Code
- Open VS Code
- Go to Extensions (Ctrl+Shift+X)
- Search for “Docker”
- Install the official Docker extension
Docker Extension Features
- Container management from VS Code
- Dockerfile syntax highlighting and autocomplete
- Docker Compose support
- Image management
- Log viewing
Installing Portainer (Web-Based Docker Management)
docker volume create portainer_data
docker run -d -p 8000:8000 -p 9443:9443 --name portainer \
--restart=always \
-v /var/run/docker.sock:/var/run/docker.sock \
-v portainer_data:/data \
portainer/portainer-ce:latest
Access Portainer at https://localhost:9443
2.4 Linux AI-Integrated Workflow
GitHub Copilot with Docker
- Install GitHub Copilot extension in VS Code
- Sign in with your GitHub account
- Use Copilot for Dockerfile generation and command suggestions
Example AI Prompt
“Generate a Dockerfile for a Python Flask application.”
AI Response:
FROM python:3.9-slim
WORKDIR /app
COPY requirements.txt .
RUN pip install --no-cache-dir -r requirements.txt
COPY . .
EXPOSE 5000
CMD ["python", "app.py"]
AI for Troubleshooting
Example AI Prompt:
“My Docker container is exiting immediately. How can I debug this?”
AI Response:
- Check container logs:
docker logs <container_name> - Verify the CMD/ENTRYPOINT is correct
- Ensure the application doesn’t exit immediately
- Use interactive mode:
docker run -it <image> /bin/bash
2.5 Windows Command-Line Environment
Prerequisites for Windows
- Enable WSL2 (Windows Subsystem for Linux 2)
- Enable virtualization in BIOS
- Install Windows Terminal (recommended)
Step 1: Download Docker Desktop
Go to https://www.docker.com/products/docker-desktop and download Docker Desktop for Windows.
Step 2: Run the Installer
- Double-click
Docker Desktop Installer.exe - Follow the installation wizard
- Ensure WSL2 option is selected
Step 3: Start Docker Desktop
- Launch Docker Desktop from the Start menu
- Wait for the Docker engine to start
- The whale icon in the system tray indicates Docker is running
Step 4: Verify Installation
Open PowerShell or Command Prompt:
docker --version
docker run hello-world
Step 5: Using Docker with WSL2
wsl --install
wsl --set-default-version 2
Docker Desktop integrates with WSL2, allowing Linux containers to run natively on Windows.
2.6 Windows GUI/IDE Environment
Installing VS Code on Windows
- Visit https://code.visualstudio.com/
- Download and run the installer
- Check “Add to PATH” during installation
Installing Docker Extension
- Open VS Code
- Go to Extensions (Ctrl+Shift+X)
- Search for “Docker”
- Install the official Docker extension
Using Docker with PowerShell
# List containers
docker ps -a
# Pull an image
docker pull nginx:latest
# Run a container
docker run -d -p 8080:80 --name webserver nginx
# Access the website at http://localhost:8080
2.7 Windows AI-Integrated Workflow
GitHub Copilot for Windows
- Install GitHub Copilot extension in VS Code
- Sign in with your GitHub account
Example AI Prompt
“Create a Dockerfile for a Node.js application.”
AI Response:
FROM node:18-alpine
WORKDIR /app
COPY package*.json ./
RUN npm install
COPY . .
EXPOSE 3000
CMD ["npm", "start"]
AI-Powered Troubleshooting
Example AI Prompt:
“Docker Desktop on Windows is not starting. What should I check?”
AI Response:
- Check if virtualization is enabled in BIOS
- Ensure WSL2 is installed and enabled
- Check Docker logs at
%AppData%\Docker\log.txt - Try resetting Docker Desktop
- Restart the Docker service
2.8 macOS Command-Line Environment
Step 1: Install Homebrew
/bin/bash -c "$(curl -fsSL https://raw.githubusercontent.com/Homebrew/install/HEAD/install.sh)"
Step 2: Install Docker Desktop via Homebrew
brew install --cask docker
Step 3: Start Docker Desktop
- Open Docker from the Applications folder
- You will see a whale icon in the top menu bar
- Wait for Docker to start (the icon will stop animating)
Step 4: Verify Installation
docker --version
docker run hello-world
Alternative: Install Using the DMG
- Download Docker Desktop for macOS from the Docker website
- Choose the correct version: Apple Silicon (M1/M2) or Intel Chip
- Open the downloaded
.dmgfile - Drag the Docker icon to the Applications folder
- Launch Docker from the Applications folder
2.9 macOS GUI/IDE Environment
Installing VS Code on macOS
brew install --cask visual-studio-code
Installing Docker Extension
- Open VS Code
- Go to Extensions
- Search for “Docker”
- Install the official Docker extension
Using Docker from Terminal
# Pull an image
docker pull nginx:latest
# Run a container
docker run -d -p 8080:80 --name webserver nginx
# View running containers
docker ps
2.10 macOS AI-Integrated Workflow
GitHub Copilot for macOS
- Install GitHub Copilot extension in VS Code
- Sign in with your GitHub account
Example AI Prompt
“Write a Docker Compose file for a web application with PostgreSQL.”
AI Response:
version: '3.8'
services:
web:
build: .
ports:
- "5000:5000"
environment:
- DATABASE_URL=postgresql://postgres:password@db:5432/app
depends_on:
- db
db:
image: postgres:15
environment:
- POSTGRES_USER=postgres
- POSTGRES_PASSWORD=password
- POSTGRES_DB=app
volumes:
- postgres_data:/var/lib/postgresql/data
volumes:
postgres_data:
AI-Powered Troubleshooting
Example AI Prompt:
“Docker on macOS is using too much disk space. How can I clean it?”
AI Response:
# Remove unused containers
docker container prune
# Remove unused images
docker image prune
# Remove unused volumes
docker volume prune
# Remove everything unused
docker system prune -a
2.11 Software Execution Lifecycle
Understanding how Docker processes a command from start to finish is essential.
Developer Writes Dockerfile
│
▼
docker build Command
│
▼
Docker Client Sends Request to Daemon
│
▼
Daemon Reads Dockerfile
│
▼
Daemon Creates Image Layers
│
▼
Each Instruction Executed (RUN, COPY, etc.)
│
▼
Image Created and Stored Locally
│
▼
docker run Command
│
▼
Daemon Creates Container from Image
│
▼
Container Started (Isolated Process)
│
▼
Application Runs Inside Container
│
▼
docker push Command (Optional)
│
▼
Image Uploaded to Registry
Docker Run Lifecycle
docker run <image>
│
▼
Daemon Checks if Image Exists Locally
│
├── Yes → Uses Local Image
│
└── No → Pulls from Registry
│
▼
Daemon Creates Container Filesystem
│
▼
Daemon Creates Network Interface
│
▼
Daemon Allocates IP Address
│
▼
Daemon Starts the Container Process
│
▼
Application Runs Inside Container
│
▼
Container Output Streamed to Client
Chapter 3: AI Integration with Docker
3.1 AI-Assisted Learning
Example AI Prompts:
- “Explain Docker containers with a simple example”
- “What’s the difference between a Docker image and a container?”
- “Show me how to write a Dockerfile for a Python application”
- “Explain Docker volumes with examples”
3.2 AI-Based Troubleshooting
Example AI Prompt:
“My Docker container exits immediately after starting. Here’s my Dockerfile: [paste]. What’s wrong?”
AI Response:
- Identifies the issue (e.g., missing CMD or ENTRYPOINT)
- Suggests using
docker logsto see error messages - Recommends running in interactive mode for debugging
- Provides corrected Dockerfile
3.3 AI-Driven Dockerfile Generation
Example AI Prompt:
“Generate a Dockerfile for a React application with Nginx.”
AI Response:
# Build stage
FROM node:18-alpine AS build
WORKDIR /app
COPY package*.json ./
RUN npm install
COPY . .
RUN npm run build
# Production stage
FROM nginx:alpine
COPY --from=build /app/build /usr/share/nginx/html
EXPOSE 80
CMD ["nginx", "-g", "daemon off;"]
3.4 AI Security Analysis
Example AI Prompt:
“Analyze this Dockerfile for security issues: [paste]”
AI Response:
- Identifies running as root (recommends using a non-root user)
- Checks for exposed secrets
- Suggests using specific image tags instead of
latest - Recommends adding
--no-cacheto package installations - Suggests using multi-stage builds to reduce attack surface
3.5 AI Log Analysis
Example AI Prompt:
“Analyze these Docker container logs for errors: [paste]”
AI Response:
- Identifies error patterns
- Suggests specific fixes
- Points to configuration issues
- Recommends additional logging
3.6 AI Performance Optimization
Example AI Prompt:
“How can I optimize this Dockerfile for faster builds and smaller image size? [paste]”
AI Response:
- Order layers correctly – Put frequently changing instructions last
- Use multi-stage builds – Separate build and runtime
- Minimize layers – Combine RUN commands
- Use specific base images – Alpine for smaller size
- Clean up – Remove temporary files
- Use buildkit – For parallelized builds
Chapter 4: Docker Fundamentals
4.1 Images and Containers
Docker Images:
- Read-only templates
- Contain the application and its dependencies
- Built from Dockerfiles
- Stored in registries
Docker Containers:
- Running instances of images
- Isolated from the host system
- Can be started, stopped, moved, and deleted
- Have their own filesystem, network, and process space
Relationship:
Image (Template) → Container (Running Instance)
4.2 Docker Registries
A Docker registry stores and distributes Docker images.
Public Registries:
- Docker Hub – Default public registry
- Google Container Registry (GCR) – Google’s registry
- Amazon Elastic Container Registry (ECR) – AWS registry
- Azure Container Registry (ACR) – Azure registry
Private Registries:
- Organizations can host their own registries
- Secure and controlled access
Registry Commands:
# Pull an image from registry
docker pull nginx:latest
# Push an image to registry
docker push username/image:tag
# Login to a registry
docker login
# Logout from a registry
docker logout
4.3 Docker Hub
Docker Hub is the default public registry for Docker images.
Key Features:
- Official Images – Maintained by Docker and trusted vendors
- Verified Publisher Images – Published by software vendors
- Community Images – Published by the Docker community
Searching Docker Hub:
# Search for images
docker search nginx
# Pull an image
docker pull nginx:latest
# Pull from a specific user
docker pull username/repository:tag
4.4 Dockerfile Basics
A Dockerfile is a text file that contains instructions for building a Docker image.
Basic Dockerfile Structure:
# Base image
FROM ubuntu:22.04
# Metadata
LABEL maintainer="user@example.com"
# Environment variables
ENV APP_HOME=/app
# Create working directory
WORKDIR $APP_HOME
# Copy files
COPY . .
# Run commands
RUN apt-get update && apt-get install -y python3
# Expose port
EXPOSE 8080
# Default command
CMD ["python3", "app.py"]
4.5 Docker Commands
Image Commands:
# List images
docker images
docker image ls
# Pull an image
docker pull nginx:latest
# Build an image
docker build -t myapp:latest .
# Remove an image
docker rmi image_name
# Remove unused images
docker image prune
Container Commands:
# Run a container
docker run nginx:latest
# Run in detached mode
docker run -d nginx:latest
# Run with a name
docker run --name webserver nginx:latest
# List running containers
docker ps
# List all containers
docker ps -a
# Stop a container
docker stop container_name
# Start a container
docker start container_name
# Restart a container
docker restart container_name
# Remove a container
docker rm container_name
# Remove all stopped containers
docker container prune
Chapter 5: Docker Images and Dockerfiles
5.1 Understanding Docker Images
Image Layers:
Docker images are built from layers. Each instruction in a Dockerfile creates a layer. Layers are cached, making builds faster.
Base Image:
The foundation of a Docker image. Common base images include:
ubuntu:22.04– Ubuntu Linuxalpine:latest– Minimal Alpine Linuxnode:18-alpine– Node.js on Alpinepython:3.11-slim– Python on slim Debian
Image Tags:
Tags identify different versions of an image.
# Format: repository:tag
docker pull nginx:latest
docker pull nginx:1.25
docker pull username/app:v1.0
5.2 Dockerfile Instructions
| Instruction | Purpose |
|---|---|
FROM | Set base image |
RUN | Execute commands during build |
COPY | Copy files from host to image |
ADD | Copy with additional features (URLs, tar extraction) |
WORKDIR | Set working directory |
ENV | Set environment variables |
EXPOSE | Document ports |
CMD | Default command |
ENTRYPOINT | Main executable |
ARG | Build-time variables |
LABEL | Metadata |
VOLUME | Mount point for volumes |
CMD vs ENTRYPOINT:
ENTRYPOINTspecifies the executable that will always runCMDprovides default arguments to the entrypoint
Example:
ENTRYPOINT ["python3"]
CMD ["app.py"]
When the container runs, it executes python3 app.py.
5.3 Building Images
# Build an image from Dockerfile in current directory
docker build -t myapp:latest .
# Build with a specific Dockerfile
docker build -f Dockerfile.prod -t myapp:prod .
# Build with build arguments
docker build --build-arg VERSION=1.0 -t myapp:v1.0 .
# Build using BuildKit (faster, parallel builds)
DOCKER_BUILDKIT=1 docker build -t myapp:latest .
Build Output:
[1/5] FROM ubuntu:22.04
[2/5] WORKDIR /app
[3/5] COPY . .
[4/5] RUN apt-get update && apt-get install -y python3
[5/5] CMD ["python3", "app.py"]
Successfully built 1234567
Successfully tagged myapp:latest
5.4 Image Layering and Caching
How Layering Works:
Each instruction in a Dockerfile creates a new layer. Layers are cached and reused.
Layer Caching:
- If a layer hasn’t changed, Docker reuses the cached version
- Changing a layer invalidates all subsequent layers
Best Practices for Caching:
- Order instructions from least to most frequently changing
- Copy dependency files before source code
- Use specific package versions
Example (Optimized for Caching):
FROM node:18-alpine
WORKDIR /app
# Copy package files first (changes less frequently)
COPY package*.json ./
RUN npm install
# Copy source code last (changes frequently)
COPY . .
CMD ["npm", "start"]
5.5 Multi-Stage Builds
Multi-stage builds reduce image size by separating build and runtime environments.
Example:
# Build stage
FROM golang:1.20 AS builder
WORKDIR /app
COPY go.mod go.sum ./
RUN go mod download
COPY . .
RUN go build -o myapp .
# Runtime stage
FROM alpine:latest
RUN apk --no-cache add ca-certificates
WORKDIR /root/
COPY --from=builder /app/myapp .
EXPOSE 8080
CMD ["./myapp"]
Benefits:
- Smaller final images
- No build tools in production
- Cleaner separation of concerns
5.6 Image Optimization
Use Alpine Base Images:
Alpine Linux is minimal (5MB) and secure.
FROM alpine:latest
Minimize Layers:
Combine RUN commands to reduce layers.
# Bad (multiple layers)
RUN apt-get update
RUN apt-get install -y python3
RUN apt-get clean
# Good (single layer)
RUN apt-get update && apt-get install -y python3 && apt-get clean
Remove Temporary Files:
RUN apt-get update && apt-get install -y python3 \
&& apt-get clean \
&& rm -rf /var/lib/apt/lists/*
Use .dockerignore:
Create a .dockerignore file to exclude unnecessary files.
node_modules
.git
*.log
.DS_Store
Chapter 6: Docker Containers
6.1 Running Containers
# Run a container
docker run nginx:latest
# Run in background (detached mode)
docker run -d nginx:latest
# Run with a name
docker run --name webserver nginx:latest
# Run with port mapping
docker run -p 8080:80 nginx:latest
# Run with environment variables
docker run -e MY_ENV=value nginx:latest
# Run with volume mount
docker run -v /host/path:/container/path nginx:latest
# Run interactively
docker run -it ubuntu:22.04 /bin/bash
# Run and remove after exit
docker run --rm nginx:latest
6.2 Container Lifecycle
Created → Running → Paused → Stopped → Deleted
States:
- Created – Container has been created but not started
- Running – Container is running
- Paused – Container processes are paused
- Stopped – Container has been stopped
- Deleted – Container has been removed
Commands:
# Create a container (without starting)
docker create nginx:latest
# Start a container
docker start container_name
# Stop a container
docker stop container_name
# Pause a container
docker pause container_name
# Unpause a container
docker unpause container_name
# Restart a container
docker restart container_name
# Remove a container
docker rm container_name
6.3 Container Management
# List running containers
docker ps
# List all containers
docker ps -a
# List containers by image
docker ps -a --filter ancestor=nginx
# List containers by status
docker ps -a --filter status=exited
# Inspect a container
docker inspect container_name
# View container stats
docker stats container_name
# View container processes
docker top container_name
# View container logs
docker logs container_name
# Follow logs in real-time
docker logs -f container_name
# View recent logs
docker logs --tail 100 container_name
6.4 Executing Commands in Containers
# Execute a command in a running container
docker exec container_name ls -la
# Execute interactively
docker exec -it container_name /bin/bash
# Execute as a specific user
docker exec -u root container_name /bin/bash
# Execute with environment variables
docker exec -e MY_VAR=value container_name /bin/bash
# Execute in a specific working directory
docker exec -w /app container_name /bin/bash
6.5 Container Logs and Debugging
# View container logs
docker logs container_name
# Follow logs
docker logs -f container_name
# View only recent logs
docker logs --tail 50 container_name
# View logs with timestamps
docker logs -t container_name
# View logs with details
docker logs --details container_name
Debugging Tips:
- Check logs:
docker logs container_name - Inspect container:
docker inspect container_name - Execute interactive shell:
docker exec -it container_name /bin/bash - Check processes:
docker top container_name - Check resource usage:
docker stats container_name
Chapter 7: Docker Networking
7.1 Network Drivers
| Driver | Purpose |
|---|---|
bridge | Default network for containers on the same host |
host | Shares the host’s network |
overlay | Connects containers across multiple hosts |
macvlan | Assigns MAC addresses to containers |
none | No network |
7.2 Bridge Networks
Bridge networks allow containers on the same host to communicate.
Default Bridge Network:
# Containers can communicate by IP address
docker run --name container1 nginx
docker run --name container2 nginx
# container1 IP: 172.17.0.2
# container2 IP: 172.17.0.3
User-Defined Bridge Network:
# Create a custom bridge network
docker network create mynetwork
# Run containers on the custom network
docker run --network mynetwork --name app1 nginx
docker run --network mynetwork --name app2 nginx
# Containers can communicate by name
docker exec app1 ping app2
Benefits of User-Defined Networks:
- Automatic service discovery via DNS
- Better isolation
- Customizable IP ranges
- Ability to connect and disconnect containers
7.3 Host Networks
Host networks remove network isolation, using the host’s network directly.
docker run --network host nginx
Use Cases:
- Performance-sensitive applications
- Applications that need to bind to specific ports
- When network isolation is not required
7.4 Overlay Networks
Overlay networks connect containers across multiple Docker hosts. They require Docker Swarm or Kubernetes.
# Initialize Swarm
docker swarm init
# Create an overlay network
docker network create -d overlay myoverlay
# Run services on the overlay network
docker service create --network myoverlay --name app nginx
7.5 Container Communication
Container-to-Container Communication:
# On the same bridge network (by container name)
docker exec container1 ping container2
# By IP address
docker exec container1 ping 172.17.0.3
# By container ID
docker exec container1 ping container_id
Container-to-Host Communication:
# Access host from container (Linux)
docker exec container_name ping host.docker.internal
# Access host from container (Windows/macOS)
docker exec container_name ping host.docker.internal
Chapter 8: Docker Storage
8.1 Volumes
Volumes are persistent storage mechanisms managed by the Docker daemon. They retain data even after containers are removed.
Create a Volume:
# Create a named volume
docker volume create myvolume
# List volumes
docker volume ls
# Inspect a volume
docker volume inspect myvolume
Mount a Volume:
# Mount a named volume
docker run -v myvolume:/app/data nginx
# Mount with read-only
docker run -v myvolume:/app/data:ro nginx
Volume Features:
- Managed by Docker
- Easier to back up and migrate than bind mounts
- Can be shared between containers
- Persistent across container restarts
8.2 Bind Mounts
Bind mounts map a specific file or directory from the host directly into the container.
# Bind mount a host directory
docker run -v /host/path:/container/path nginx
# Bind mount a single file
docker run -v /host/file.txt:/container/file.txt nginx
# Bind mount with read-only
docker run -v /host/path:/container/path:ro nginx
When to Use Bind Mounts:
- Development (live code sync)
- Sharing configuration files
- Working with host data
Limitations:
- Dependent on host directory structure
- Not portable across different hosts
- Cannot be easily backed up or migrated
8.3 tmpfs Mounts
tmpfs mounts store data in memory (RAM), not on disk. Data is lost when the container stops.
docker run --tmpfs /app/temp nginx
Use Cases:
- Temporary files
- Caches
- Session data
8.4 Managing Volumes
# List volumes
docker volume ls
# Create a volume
docker volume create myvolume
# Inspect a volume
docker volume inspect myvolume
# Remove a volume
docker volume rm myvolume
# Remove unused volumes
docker volume prune
# Remove all volumes
docker volume prune -a
Backup a Volume:
# Create a backup container
docker run --rm -v myvolume:/source -v $(pwd):/backup alpine \
tar czf /backup/myvolume-backup.tar.gz -C /source .
Restore a Volume:
# Restore from backup
docker run --rm -v myvolume:/target -v $(pwd):/backup alpine \
tar xzf /backup/myvolume-backup.tar.gz -C /target
Chapter 9: Docker Compose
9.1 What Is Docker Compose
Docker Compose is a tool for defining and running multi-container Docker applications. With a single configuration file (docker-compose.yml), you can define all services, networks, and volumes for your application.
Benefits:
- Single command to start/stop all services
- Consistent configuration across environments
- Service dependency management
- Simplified multi-container workflows
9.2 Docker Compose File Structure
A docker-compose.yml file has three main sections:
version: '3.8'
services:
# Define services (containers)
web:
build: .
ports:
- "5000:5000"
environment:
- DEBUG=true
db:
image: postgres:15
environment:
- POSTGRES_PASSWORD=secret
volumes:
- db_data:/var/lib/postgresql/data
volumes:
db_data:
networks:
frontend:
backend:
9.3 Services, Networks, and Volumes
Services:
Each service represents a container configuration.
services:
web:
build: ./web
ports:
- "80:80"
environment:
- NODE_ENV=production
depends_on:
- api
api:
build: ./api
ports:
- "3000:3000"
environment:
- DB_HOST=db
- DB_USER=postgres
db:
image: postgres:15
environment:
- POSTGRES_PASSWORD=secret
volumes:
- postgres_data:/var/lib/postgresql/data
Networks:
Define custom networks for service communication.
networks:
frontend:
backend:
internal:
Volumes:
Define persistent storage volumes.
volumes:
postgres_data:
redis_data:
uploads:
9.4 Managing Multi-Container Applications
# Start all services (detached mode)
docker-compose up -d
# Start specific services
docker-compose up -d web api
# View logs
docker-compose logs -f
# View logs for specific service
docker-compose logs -f web
# Stop all services
docker-compose down
# Stop and remove volumes
docker-compose down -v
# Rebuild and start
docker-compose up -d --build
# Scale a service
docker-compose up -d --scale web=3
# Execute command in a service
docker-compose exec web /bin/bash
# List services
docker-compose ps
9.5 Real-World Compose Examples
Example 1: Web Application with Database
version: '3.8'
services:
web:
build: .
ports:
- "5000:5000"
environment:
- DATABASE_URL=postgresql://postgres:password@db:5432/app
depends_on:
- db
volumes:
- .:/app
db:
image: postgres:15
environment:
- POSTGRES_USER=postgres
- POSTGRES_PASSWORD=password
- POSTGRES_DB=app
volumes:
- postgres_data:/var/lib/postgresql/data
redis:
image: redis:alpine
ports:
- "6379:6379"
volumes:
postgres_data:
Example 2: Full Stack Application
version: '3.8'
services:
nginx:
image: nginx:alpine
ports:
- "80:80"
volumes:
- ./nginx.conf:/etc/nginx/nginx.conf
depends_on:
- web
- api
web:
build: ./frontend
ports:
- "3000:3000"
api:
build: ./backend
ports:
- "8000:8000"
environment:
- DB_HOST=db
- REDIS_HOST=redis
db:
image: postgres:15
environment:
- POSTGRES_PASSWORD=secret
volumes:
- postgres_data:/var/lib/postgresql/data
redis:
image: redis:alpine
volumes:
postgres_data:
Chapter 10: Docker in Production
10.1 Container Orchestration
Container orchestration automates the deployment, scaling, and management of containers.
Orchestration Features:
- Scheduling containers on hosts
- Scaling services up or down
- Load balancing traffic
- Health checking and self-healing
- Rolling updates and rollbacks
- Service discovery
Popular Orchestrators:
- Kubernetes – Industry standard
- Docker Swarm – Docker’s built-in orchestration
- Amazon ECS – AWS container orchestration
- Azure Container Apps – Azure’s serverless containers
10.2 Docker Swarm
Docker Swarm is Docker’s built-in orchestration solution. It uses a manager/worker model.
# Initialize Swarm
docker swarm init
# Join as a worker
docker swarm join --token <token> <manager-ip>:2377
# Deploy a service
docker service create --name web --replicas 3 -p 80:80 nginx
# Scale a service
docker service scale web=5
# Update a service
docker service update --image nginx:latest web
# Rollback a service
docker service rollback web
# Remove a service
docker service rm web
10.3 Kubernetes
Kubernetes is the industry standard for container orchestration.
Key Concepts:
- Pod – Smallest deployable unit, one or more containers
- Deployment – Manages replicas and updates
- Service – Stable network endpoint for pods
- Ingress – External access to services
- ConfigMap – Configuration data
- Secret – Sensitive data
Example Deployment:
apiVersion: apps/v1
kind: Deployment
metadata:
name: nginx-deployment
spec:
replicas: 3
selector:
matchLabels:
app: nginx
template:
metadata:
labels:
app: nginx
spec:
containers:
- name: nginx
image: nginx:latest
ports:
- containerPort: 80
10.4 CI/CD with Docker
CI/CD Pipeline with Docker:
Code Commit → Build Docker Image → Push to Registry → Deploy to Environment
Example GitHub Actions Workflow:
name: Build and Deploy Docker Image
on:
push:
branches: [ main ]
jobs:
build:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v2
- name: Login to Docker Hub
uses: docker/login-action@v2
with:
username: ${{ secrets.DOCKER_USERNAME }}
password: ${{ secrets.DOCKER_PASSWORD }}
- name: Build and push
uses: docker/build-push-action@v4
with:
push: true
tags: user/app:latest
10.5 Monitoring and Logging
Container Monitoring:
# View container stats
docker stats
# View container logs
docker logs container_name
# Monitor with Prometheus
# Run Prometheus container
docker run -d -p 9090:9090 prom/prometheus
# Monitor with Grafana
docker run -d -p 3000:3000 grafana/grafana
Logging Drivers:
# Use JSON file logging (default)
docker run --log-driver json-file nginx
# Use syslog
docker run --log-driver syslog nginx
# Use journald
docker run --log-driver journald nginx
Chapter 11: Security
11.1 Container Isolation
Containers provide isolation at the process level using Linux kernel features:
- Namespaces – Isolate processes, network, filesystem
- Cgroups – Limit resource usage
- Seccomp – Restrict system calls
- Capabilities – Limit root privileges
Best Practices:
- Run containers as non-root users
- Drop unnecessary capabilities
- Use read-only filesystems
- Enable seccomp profiles
Non-Root User in Dockerfile:
FROM ubuntu:22.04
# Create a non-root user
RUN useradd -m appuser
# Switch to non-root user
USER appuser
WORKDIR /app
COPY . .
CMD ["python3", "app.py"]
11.2 Image Security
Best Practices:
- Use official and verified images
- Scan images for vulnerabilities
- Use specific image tags (not
latest) - Minimize image size
- Remove unnecessary packages
Image Scanning:
# Scan image for vulnerabilities
docker scan myapp:latest
# Use Trivy for scanning
docker run --rm aquasec/trivy image myapp:latest
11.3 Secrets Management
Docker Secrets (Swarm):
# Create a secret
echo "mysecretpassword" | docker secret create db_password -
# Use secret in service
docker service create --secret db_password --name db postgres
Using Environment Variables (Not Recommended for Secrets):
# Not secure - secrets visible in inspect
docker run -e DB_PASSWORD=secret postgres
Using Docker Secrets in Compose:
services:
db:
image: postgres:15
secrets:
- db_password
secrets:
db_password:
file: ./secrets/db_password.txt
11.4 Security Best Practices
Dockerfile Best Practices:
- Use specific base image tags
- Run as non-root user
- Use multi-stage builds
- Remove package caches
- Avoid storing secrets in images
Runtime Best Practices:
- Use read-only filesystem where possible
- Limit container resources (CPU, memory)
- Use user-defined networks
- Enable logging and monitoring
- Regularly update images
- Scan images for vulnerabilities
Network Security:
- Use TLS for registry communication
- Restrict container network access
- Use network segmentation
Chapter 12: Real-World Projects
12.1 Web Application Containerization
Project: Containerize a Python Flask application.
Project Structure:
flask-app/
├── app.py
├── requirements.txt
├── Dockerfile
└── .dockerignore
app.py:
from flask import Flask
app = Flask(__name__)
@app.route('/')
def hello():
return 'Hello, Docker!'
if __name__ == '__main__':
app.run(host='0.0.0.0', port=5000)
requirements.txt:
Flask==2.3.0
Dockerfile:
FROM python:3.11-slim
WORKDIR /app
COPY requirements.txt .
RUN pip install --no-cache-dir -r requirements.txt
COPY . .
EXPOSE 5000
CMD ["python", "app.py"]
Build and Run:
docker build -t flask-app .
docker run -d -p 5000:5000 --name flask-app flask-app
12.2 Multi-Container Application
Project: Deploy a web application with PostgreSQL and Redis.
Project Structure:
app/
├── docker-compose.yml
├── web/
│ ├── Dockerfile
│ └── app.py
└── nginx/
└── nginx.conf
docker-compose.yml:
version: '3.8'
services:
web:
build: ./web
ports:
- "5000:5000"
environment:
- DB_HOST=db
- REDIS_HOST=redis
depends_on:
- db
- redis
db:
image: postgres:15
environment:
- POSTGRES_USER=postgres
- POSTGRES_PASSWORD=password
- POSTGRES_DB=app
volumes:
- postgres_data:/var/lib/postgresql/data
redis:
image: redis:alpine
volumes:
postgres_data:
12.3 Microservices Deployment
Project: Deploy a microservices architecture with API Gateway.
Services:
- API Gateway – Routes requests
- User Service – Manages users
- Product Service – Manages products
- Order Service – Manages orders
docker-compose.yml:
version: '3.8'
services:
gateway:
image: nginx:alpine
ports:
- "80:80"
volumes:
- ./nginx.conf:/etc/nginx/nginx.conf
depends_on:
- user-service
- product-service
- order-service
user-service:
build: ./user-service
environment:
- DB_HOST=db
depends_on:
- db
product-service:
build: ./product-service
environment:
- DB_HOST=db
depends_on:
- db
order-service:
build: ./order-service
environment:
- DB_HOST=db
- REDIS_HOST=redis
depends_on:
- db
- redis
db:
image: postgres:15
environment:
- POSTGRES_PASSWORD=secret
volumes:
- postgres_data:/var/lib/postgresql/data
redis:
image: redis:alpine
volumes:
postgres_data:
12.4 CI/CD Pipeline with Docker
Project: Set up a CI/CD pipeline using GitHub Actions.
GitHub Actions Workflow:
name: CI/CD Pipeline
on:
push:
branches: [ main ]
pull_request:
branches: [ main ]
jobs:
build-and-test:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- name: Build Docker image
run: docker build -t myapp .
- name: Run tests
run: docker run --rm myapp npm test
deploy:
needs: build-and-test
runs-on: ubuntu-latest
if: github.ref == 'refs/heads/main'
steps:
- uses: actions/checkout@v3
- name: Login to Docker Hub
uses: docker/login-action@v2
with:
username: ${{ secrets.DOCKER_USERNAME }}
password: ${{ secrets.DOCKER_PASSWORD }}
- name: Build and push
uses: docker/build-push-action@v4
with:
push: true
tags: username/myapp:latest
- name: Deploy to server
uses: appleboy/ssh-action@v0.1.5
with:
host: ${{ secrets.SERVER_HOST }}
username: ${{ secrets.SERVER_USER }}
key: ${{ secrets.SERVER_SSH_KEY }}
script: |
docker pull username/myapp:latest
docker stop myapp || true
docker rm myapp || true
docker run -d -p 80:80 --name myapp username/myapp:latest
Docker Master Roadmap — Complete Learning Path
Phase 1: Foundations (Weeks 1-2)
- What is Docker and containerization
- Docker vs Virtual Machines
- Docker architecture (client, daemon, registry)
- Installing Docker on Linux, Windows, macOS
- Running your first container
- Basic Docker commands
Phase 2: Images and Dockerfiles (Weeks 3-4)
- Understanding Docker images and layers
- Writing Dockerfiles (FROM, RUN, COPY, CMD, ENTRYPOINT)
- Building images
- Multi-stage builds
- Image optimization
- Pushing and pulling images
Phase 3: Containers (Weeks 5-6)
- Container lifecycle
- Running containers with options
- Container management (start, stop, restart)
- Executing commands in containers
- Container logs and debugging
- Container resource limits
Phase 4: Networking (Weeks 7-8)
- Network drivers (bridge, host, overlay)
- User-defined bridge networks
- Container-to-container communication
- Exposing ports
- Network troubleshooting
Phase 5: Storage (Weeks 9-10)
- Volumes (named, anonymous)
- Bind mounts
- tmpfs mounts
- Managing volumes (create, inspect, prune)
- Backup and restore volumes
Phase 6: Docker Compose (Weeks 11-12)
- What is Docker Compose
- docker-compose.yml structure
- Services, networks, and volumes
- Multi-container applications
- Compose commands (up, down, logs, exec)
- Real-world compose examples
Phase 7: Production and Orchestration (Weeks 13-14)
- Docker Swarm
- Kubernetes basics
- CI/CD with Docker
- Monitoring and logging
- Security best practices
- Image scanning
Phase 8: Real-World Projects (Weeks 15-16)
- Web application containerization
- Multi-container application
- Microservices deployment
- CI/CD pipeline with Docker
- Production deployment
Common Errors and Troubleshooting
Container Exits Immediately
Error:
docker run myapp
# Container exits immediately
Solutions:
# View logs
docker logs container_name
# Run interactively
docker run -it myapp /bin/bash
# Check CMD/ENTRYPOINT
docker inspect container_name | grep -A 5 "Cmd"
Port Already In Use
Error:
Error response from daemon: port is already allocated
Solution:
# Find process using port
sudo lsof -i :8080
# Stop the container using the port
docker stop container_name
# Or use a different port
docker run -p 8081:80 nginx
Permission Denied
Error:
Got permission denied while trying to connect to the Docker daemon socket
Solution:
# Add user to docker group
sudo usermod -aG docker $USER
# Logout and login again
newgrp docker
# Or use sudo
sudo docker run hello-world
Image Build Fails
Error:
failed to solve: ...
Solutions:
# Check Dockerfile syntax
docker build --no-cache -t myapp .
# Check each instruction
# Use --progress=plain for detailed output
docker build --progress=plain -t myapp .
# Check network connectivity
# Verify package sources are accessible
Docker Daemon Not Running
Error:
Cannot connect to the Docker daemon
Solution:
# Linux
sudo systemctl start docker
# Windows/macOS
# Start Docker Desktop from applications
# Check status
docker info
Final Thoughts
To a child starting out:
Imagine you have a magical lunchbox. You can put any food inside, and wherever you go, the lunchbox keeps your food fresh, warm, and safe. Docker is like that magical lunchbox for software. You put your application and everything it needs inside, and it runs the same way on any computer.
Your journey:
- Understand what containers are
- Install Docker on your computer
- Run your first container (hello-world)
- Build a Docker image for your application
- Run multiple containers together
- Use Docker Compose for multi-container apps
- Deploy to production
- Scale with orchestration (Swarm/Kubernetes)
- Implement CI/CD pipelines
- Master security best practices
Remember: Every major company in the world uses containers. Every cloud platform supports them. By learning Docker, you are learning the foundation of modern deployment.
Keep building. Keep shipping. Keep scaling.