---
tags:
- containers
- l1
- flashcard-deck
- docker-basics
---
<!-- wiki:breadcrumb:start -->
[Portal](../../../../library/portal/index.md) | **Level:** [L1: Foundations](../../../../library/portal/levels.md) | **Topics:** [Docker / Containers](../../../../library/portal/topics.md) | **Domain:** containers
<!-- wiki:breadcrumb:end -->

id	category	difficulty	tags	question	answer	source_path
docker-basics/002ae05052cc	docker-basics	hard	docker-basics, containers, fundamentals, configuration	How can you pass environment variables to a Docker container?	Environment variables can be passed to a Docker container using the -e (or --env) option in the docker run command. \nExample:\n```docker run -e MY_VARIABLE=value my_image``` \nThis command sets the environment variable MY_VARIABLE with the value value inside the running container. \nAlternatively, you can use a file containing environment variables and pass it to the container using the --env-file option:\n```docker run --env-file my_env_file my_image``` \nThis is useful for managing multiple environment variables in a file. The file should contain variable assignments, one per line. \nPassing environment variables to containers is crucial for configuring applications and services within the containerized environment.	projects/knowledge/interview/docker/194-how-can-you-pass-environment-variables-to-a-docker.txt
docker-basics/00a400f25487	docker-basics	medium	docker-basics, images, fundamentals	How to list the container images on certain host?	`podman images` or `docker images` lists all local images. Add `--format '{{.Repository}}:{{.Tag}} {{.Size}}'` for cleaner output. Use `--filter dangling=true` to find untagged images wasting disk space.	projects/knowledge/interview/docker/023-how-to-list-the-container-images-on-certain-host.txt
docker-basics/0113a4a29242	docker-basics	easy	docker-basics, images, fundamentals	True or False? It's not possible to remove an image if a certain container is using it	True. You should stop and remove the container before trying to remove the image it uses.\n\nExample: docker rmi nginx fails if any container (even stopped) uses that image. Fix: docker rm <container> first, then docker rmi nginx.\n\nGotcha: docker rmi -f can force-remove, but running containers will keep using the image layers via their mount. The image tag disappears but the data stays until the container is removed.	projects/knowledge/interview/docker/025-true-or-false-its-not-possible-to-remove-an-image-.txt
docker-basics/0df046a9a708	docker-basics	medium	docker-basics, fundamentals, comparison	What are some of the advantages in using containers? you can compare to other options like VMs	* Reusable: container can be used by multiple different users for different usages - production vs. staging, development, testing, etc.\n* Lightweight: containers are fairly lightweight which means deployments can be done quickly since you don't need to install a full OS (as in VMs for example)\n* Isolation: Containers are isolated environments, usually changes made to the OS won't affect the containers and vice-versa	projects/knowledge/interview/docker/007-what-are-some-of-the-advantages-in-using-container.txt
docker-basics/172e66c55392	docker-basics	hard	docker-basics, compose, orchestration	What is the significance of Docker Compose in the context of orchestration?	Docker Compose is a tool for defining and running multi-container Docker applications. While Docker Compose is not a full orchestration solution like Docker Swarm or Kubernetes, it plays a crucial role in simplifying the definition and deployment of multi-container applications, especially in development and testing environments. \n**The significance of Docker Compose includes:**	projects/knowledge/interview/docker/186-what-is-the-significance-of-docker-compose-in-the-.txt
docker-basics/1b89b230cb32	docker-basics	hard	docker-basics, containers, fundamentals	Describe the lifecycle of a Docker container.	The lifecycle of a Docker container involves several stages:\n* Creation: A container is created from a Docker image using the docker run command. The image is pulled from a registry if not available locally.\n* Execution: The container is started, and the application inside the container begins to run. The container runs in isolation with its own filesystem, network, and processes.\n* Monitoring and Logging: Docker provides tools for monitoring container logs and resource usage.	projects/knowledge/interview/docker/134-describe-the-lifecycle-of-a-docker-container.txt
docker-basics/1cb178e559bb	docker-basics	easy	docker-basics, images, fundamentals	How to retrieve the latest ubuntu image?	`podman image pull ubuntu:latest`\n\nGotcha: 'latest' tag is just a convention — it is not guaranteed to be the newest version. Always use explicit version tags (ubuntu:22.04) in production.	projects/knowledge/interview/docker/058-how-to-retrieve-the-latest-ubuntu-image.txt
docker-basics/1d96036cf743	docker-basics	medium	docker-basics, containers, fundamentals	What is a Docker container?	A container is a runtime instance of a Docker image. It's a lightweight, isolated process running the application packaged in the image, with its own filesystem, network interface, etc., but sharing the host kernel.	projects/knowledge/interview/docker/199-what-is-docker-container.txt
docker-basics/1dc4f25731ef	docker-basics	medium	docker-basics, dockerfile, build	What is the difference between CMD and ENTRYPOINT in a Dockerfile?	Both define the startup command for a container. ENTRYPOINT is the fixed main command (and can't be overridden by default), while CMD provides default arguments to that command (or a fallback command). If you provide arguments to docker run, it replaces the CMD but adds to the ENTRYPOINT. Essentially, use ENTRYPOINT for the primary command (e.g., the executable) and CMD for default options or command if none is provided.	projects/knowledge/interview/docker/207-cmd-vs-entrypoint.txt
docker-basics/1e4567d668f1	docker-basics	easy	docker-basics, fundamentals, comparison	How is a container different from a VM?	Containers share the host kernel; VMs have their own OS.\n\nUnder the hood: containers share the host kernel and use namespaces/cgroups for isolation. VMs run separate kernels on a hypervisor. Containers start in milliseconds; VMs take seconds to minutes.\n\nAnalogy: VMs are separate houses (each with its own foundation). Containers are apartments in a building (shared foundation/kernel, separate living spaces).\n\nNumber anchor: container startup: ~100ms. VM startup: 30-90 seconds. Container image: 5-500MB. VM image: 1-20GB.	projects/knowledge/interview/docker/199-container-vs-vm.txt
docker-basics/1eee01995f06	docker-basics	hard	docker-basics, containers, runtime	Explain the significance of the "--rm" option when running a container.	The --rm option in the docker run command is used to automatically remove the container when it exits. By default, when a container stops, it remains on the host machine, and you need to explicitly remove it using the docker rm command. However, if you use the --rm option, the container is automatically removed upon termination, saving disk space and simplifying container management. \nExample:\n```docker run --rm image_name``` \nThis is particularly useful for short-lived or disposable containers, such as those used for testing or one-time tasks.	projects/knowledge/interview/docker/153-explain-the-significance-of-the-rm-option-when-run.txt
docker-basics/216532f7940e	docker-basics	easy	docker-basics, containers, lifecycle	How to stop and remove a container?	`podman container stop <container id/name> && podman container rm <container id/name>`\n\nGotcha: docker rm -f combines stop + remove. docker container prune batch-removes ALL stopped containers.	projects/knowledge/interview/docker/013-how-to-stop-and-remove-a-container.txt
docker-basics/218789b189d1	docker-basics	hard	docker-basics, images, fundamentals	How are Docker images different from Docker containers?	Docker images and containers are related but distinct concepts:\n* Docker Image: It is a static, immutable snapshot of a file system and application configuration. It serves as a template for creating containers. Images are created using Dockerfiles and can be versioned and stored in repositories like Docker Hub.\n* Docker Container: It is a running instance of a Docker image. Containers are dynamic and can be started, stopped, and moved between different environments. They encapsulate the application and its dependencies, providing a lightweight and portable execution environment. \nIn summary, an image is a blueprint, and a container is an instantiated and running execution of that blueprint.	projects/knowledge/interview/docker/133-how-are-docker-images-different-from-docker-contai.txt
docker-basics/24161c0dcb67	docker-basics	medium	docker-basics, fundamentals, concepts	What does docker ps do?	It lists running containers (add -a to list all containers, including stopped ones). It shows container IDs, names, images, status, and port mappings.\n\nExample: docker ps shows running containers. docker ps -a shows all (including stopped). docker ps -q returns only IDs (useful for scripting: docker stop $(docker ps -q)).	projects/knowledge/interview/docker/203-docker-ps.txt
docker-basics/255428f91026	docker-basics	easy	docker-basics, images, fundamentals	How to download/pull a container image without actually running a container?	`podman pull <image>` or `docker pull <image>` downloads an image without running it. Pull downloads layers in parallel and skips layers already present locally. Each layer is content-addressed by SHA256, so identical layers are shared across images.	projects/knowledge/interview/docker/024-how-to-downloadpull-a-container-image-without-actu.txt
docker-basics/29aeb91f11b4	docker-basics	hard	docker-basics, images, fundamentals	Explain the concept of layers in a Docker image.	Docker images are composed of multiple layers, and each layer represents a set of filesystem changes or instructions in the Dockerfile. Layers are created during the image build process, and they contribute to the final image. The layering concept provides several benefits: \n* Caching: Docker caches layers, so if a layer hasn't changed, it can be reused in subsequent builds. This improves build efficiency by only rebuilding the changed layers.\n* Reusability: Layers are shared among images.	projects/knowledge/interview/docker/141-explain-the-concept-of-layers-in-a-docker-image.txt
docker-basics/325734a5fd80	docker-basics	hard	docker-basics, fundamentals, comparison	How are containers different from virtual machines (VMs)?	The primary difference between containers and VMs is that containers allow you to virtualize\nmultiple workloads on a single operating system while in the case of VMs, the hardware is being virtualized to run multiple machines each with its own guest OS.\nYou can also think about it as containers are for OS-level virtualization while VMs are for hardware virtualization.	projects/knowledge/interview/docker/004-how-are-containers-different-from-virtual-machines.txt
docker-basics/3cf6ce29ccd5	docker-basics	medium	docker-basics, images, fundamentals	True or False? If image httpd-service has an entry point for running the httpd service then, the following will run the container and eventually the httpd service podman run httpd-service ls	False. Running that command will override the entry point so the httpd service won't run and instead podman will run the `ls` command.	projects/knowledge/interview/docker/016-true-or-false-if-image-httpd-service-has-an-entry-.txt
docker-basics/470e8ad053e7	docker-basics	medium	docker-basics, images, fundamentals	How to remove an image from the host?	`podman rmi IMAGE`\n\nIt will fail if some containers are using it. You can then use `--force` flag for that but generally, it's better if you inspect the containers using the image before doing so.\n\nTo delete all images: `podman rmi -a`	projects/knowledge/interview/docker/046-how-to-remove-an-image-from-the-host.txt
docker-basics/48a01e4042fb	docker-basics	medium	docker-basics, images, fundamentals	What is a container image?	* An image of a container contains the application, its dependencies and the operating system where the application is executed. \n* It's a collection of read-only layers. These layers are loosely coupled\n * Each layer is assembled out of one or more files	projects/knowledge/interview/docker/003-what-is-a-container-image.txt
docker-basics/4a840ecfc93e	docker-basics	hard	docker-basics, containers, lifecycle	How do you stop and remove a Docker container?	To stop a running container, you use the docker stop command: \n```docker stop container_id\n```\n`container_id` is the ID or name of the running container. \nTo remove a stopped container, you use the docker rm command: \n```docker rm container_id``` \n`container_id` is the ID or name of the stopped container. \nYou can combine these commands into a single line to stop and remove a container: \n```docker rm -f container_id``` \nThe -f flag forcefully removes the container, even if it's still running.	projects/knowledge/interview/docker/152-how-do-you-stop-and-remove-a-docker-container.txt
docker-basics/4b963626cf8b	docker-basics	medium	docker-basics, fundamentals, concepts	What does docker pull ubuntu:20.04 do?	It downloads the Ubuntu 20.04 image from Docker Hub (or another registry) to your local machine, so you can run containers from it.\n\nUnder the hood: pull resolves the tag to a manifest, downloads each layer in parallel, verifies SHA256 digests, and unpacks into the local storage driver (overlay2).\n\nRemember: docker pull only downloads. docker run will auto-pull if the image is not local. Explicit pull is useful for pre-caching images in CI or air-gapped environments.	projects/knowledge/interview/docker/211-docker-pull.txt
docker-basics/4cffcc21391c	docker-basics	medium	docker-basics, compose, orchestration	What is Docker Compose?	Docker Compose is a tool for defining and running multi-container Docker applications using a YAML file (docker-compose.yml or compose.yaml). It allows you to spin up a stack of interconnected services with one command (`docker compose up`), simplifying orchestration for development or testing.	projects/knowledge/interview/docker/210-what-is-docker-compose.txt
docker-basics/4e6b584f785b	docker-basics	hard	docker-basics, compose, orchestration	Explain the purpose of Docker Compose.	Docker Compose is a tool for defining and running multi-container Docker applications. It allows users to define an entire application stack, including services, networks, and volumes, in a single file called docker-compose.yml. This file specifies the configuration for each service, their dependencies, and how they should interact. Docker Compose simplifies the process of managing complex applications with multiple interconnected containers. It facilitates the orchestration of containers, making it easier to start, stop, and scale multi-container applications with a single command. Docker Compose is particularly useful for development and testing environments where multiple services need to work together.	projects/knowledge/interview/docker/136-explain-the-purpose-of-docker-compose.txt
docker-basics/55c67ea2fd53	docker-basics	hard	docker-basics, containers, fundamentals	What is a container and how does it differ from a virtual machine?	This can be tricky to answer since there are many ways to create a containers:\n\n  - Docker\n  - systemd-nspawn\n  - LXC\n\nIf to focus on OCI (Open Container Initiative) based containers, it offers the following [definition](https://github.com/opencontainers/runtime-spec/blob/master/glossary.md#container): "An environment for executing processes with configurable isolation and resource limitations. For example, namespaces, resource limits, and mounts are all part of the container environment."	projects/knowledge/interview/docker/001-what-is-a-container.txt
docker-basics/5750c40e8f22	docker-basics	hard	docker-basics, compose, orchestration	Explain what is Docker compose and what is it used for	Compose is a tool for defining and running multi-container Docker applications. With Compose, you use a YAML file to configure your application’s services. Then, with a single command, you create and start all the services from your configuration.\n\nFor example, you can use it to set up ELK stack where the services are: elasticsearch, logstash and kibana. Each running in its own container. \nIn general, it's useful for running applications which composed out of several different services. It let's you manage it as one deployed app, instead of different multiple separate services.	projects/knowledge/interview/docker/104-explain-what-is-docker-compose-and-what-is-it-used.txt
docker-basics/5dca45408a0a	docker-basics	medium	docker-basics, images, fundamentals	What's the difference between an image and a container?	An image is the static definition (the blueprint), while a container is the live, running instance of that image. You can have many containers from the same image.\n\nUnder the hood: an image is a stack of read-only filesystem layers. A container adds a writable layer on top. Multiple containers can share the same image layers.	projects/knowledge/interview/docker/200-image-vs-container.txt
docker-basics/66c002324176	docker-basics	easy	docker-basics, containers, fundamentals	How to list all the containers on the local host?	`podman container ls`\n\nGotcha: only shows running containers. Add -a for all (including stopped). Use -q for IDs only — great for scripting.	projects/knowledge/interview/docker/010-how-to-list-all-the-containers-on-the-local-host.txt
docker-basics/6a89f9d477a9	docker-basics	medium	docker-basics, images, fundamentals	True or False? Once a container is stopped and removed, its image removed as well from the host	False. The image will still be available for use by potential containers in the future. \nTo remove the image, run `podman rmi IMAGE`	projects/knowledge/interview/docker/050-true-or-false-once-a-container-is-stopped-and-remo.txt
docker-basics/6c85f08b261b	docker-basics	medium	docker-basics, containers, runtime	True or False? Running podman restart CONTAINER_NAME kills the main process inside the container and runs it again from scratch	False. `podman restart` creates an entirely new container with the same ID while reusing the filesystem and state of the original container.	projects/knowledge/interview/docker/017-true-or-false-running-podman-restart-containername.txt
docker-basics/6f7f353db2e3	docker-basics	hard	docker-basics, dockerfile, build	Explain the difference between COPY and ADD commands in a Dockerfile.	Both COPY and ADD commands in a Dockerfile are used to copy files from the host machine into the container, but there are differences: \n**COPY:** \nSyntax: ```COPY <src> <dest>``` \n* Copies files or directories from the host to the container.'\n* Designed for copying local files, and it does not extract compressed files.\n* Recommended for copying only essential files during image building.\n**ADD:** \nSyntax: ```ADD <src> <dest>```\n* Similar to COPY but with additional features.	projects/knowledge/interview/docker/146-explain-the-difference-between-copy-and-add-comman.txt
docker-basics/7184285a2d3f	docker-basics	hard	docker-basics, dockerfile, build	What is a Dockerfile, and how is it used in creating images?	A Dockerfile is a script that contains a set of instructions for building a Docker image. It specifies the base image, sets up the environment, installs dependencies, and defines how the application should run. Dockerfiles are used to automate the process of creating reproducible and consistent images. \n**Key components of a Dockerfile include:**\n* Base Image: Specifies the base image on which the new image will be built.	projects/knowledge/interview/docker/140-what-is-a-dockerfile-and-how-is-it-used-in-creatin.txt
docker-basics/72e132a29614	docker-basics	easy	docker-basics, containers, fundamentals	What is a "container"?	An isolated environment holding an app and its dependencies.\n\nUnder the hood: containers use Linux namespaces (PID, network, mount) for isolation and cgroups for resource limits. They share the host kernel — not a VM.	projects/knowledge/interview/docker/198-what-is-container.txt
docker-basics/779b61e79481	docker-basics	medium	docker-basics, images, fundamentals	Where pulled images are stored?	Depends on the container runtime. Docker stores images in `/var/lib/docker/` (overlay2 driver by default). Podman uses `/var/lib/containers/storage/` for root and `~/.local/share/containers/storage/` for rootless. Check with `podman info | grep -i root`.	projects/knowledge/interview/docker/027-where-pulled-images-are-stored.txt
docker-basics/7eeda53625c2	docker-basics	medium	docker-basics, images, fundamentals	True or False? Using the 'latest' tag when pulling an image means, you are pulling the most recently published image	False. While this might be true in some cases, it's not guaranteed that you'll pull the latest published image when using the 'latest' tag. \nFor example, in some images, 'edge' tag is used for the most recently published images.	projects/knowledge/interview/docker/026-true-or-false-using-the-latest-tag-when-pulling-an.txt
docker-basics/8051f36f8dc6	docker-basics	hard	docker-basics, containers, runtime	How do you attach and detach from a running container?	To attach to a running container and interact with its console, you can use the docker attach command: \n```docker attach container_id``` \n`container_id` is the ID or name of the running container. \nTo detach from the container without stopping it, press Ctrl + P followed by Ctrl + Q. This allows you to return to the host terminal while leaving the container running.\nAlternatively, you can use the docker exec command to execute commands inside a running container without attaching to its console: \n```docker exec -it container_id /bin/bash``` \nThis opens a new shell session within the running container. To exit the session without stopping the container, use the exit command.	projects/knowledge/interview/docker/156-how-do-you-attach-and-detach-from-a-running-contai.txt
docker-basics/80ee6112773b	docker-basics	medium	docker-basics, containers, runtime	How can you access logs from a running container?	To access logs from a running container, you can use the docker logs command. Here's an example: \n```docker logs container_id``` \n`container_id` is the ID or name of the running container. \nThis command prints the container's logs to the terminal. The -f option can be added to follow the log output in real-time.	projects/knowledge/interview/docker/151-how-can-you-access-logs-from-a-running-container.txt
docker-basics/8658b7d1eae8	docker-basics	medium	docker-basics, fundamentals, comparison	In which scenarios would you use containers and in which you would prefer to use VMs?	You should choose VMs when:\n  * You need run an application which requires all the resources and functionalities of an OS\n  * You need full isolation and security\n\nYou should choose containers when:\n  * You need a lightweight solution\n  * Running multiple versions or instances of a single application	projects/knowledge/interview/docker/005-in-which-scenarios-would-you-use-containers-and-in.txt
docker-basics/86d117cc8af1	docker-basics	easy	docker-basics, dockerfile, build	Containerfile/Dockerfile can contain more than one ENTRYPOINT instruction and one CMD instruction	True, a Dockerfile can contain multiple ENTRYPOINT and CMD instructions, but only the last of each takes effect. This is useful in multi-stage builds where each stage can have its own ENTRYPOINT. \nGotcha: if you override ENTRYPOINT at runtime with --entrypoint, CMD is also reset.	projects/knowledge/interview/docker/078-containerfiledockerfile-can-contain-more-than-one-.txt
docker-basics/86e643775550	docker-basics	medium	docker-basics, containers, runtime	What is the significance of the "-d" flag when running a container?	The -d flag in the docker run command stands for "detached" mode. When you run a container with this flag, the container runs in the background, and the terminal is immediately returned to you. This allows you to continue using the terminal for other commands while the container runs separately. \n```docker run -d image_name``` \nYou'll receive the container ID, and the container continues to run in the background. You can use commands like docker logs to view the container's output.	projects/knowledge/interview/docker/150-what-is-the-significance-of-the-d-flag-when-runnin.txt
docker-basics/87fd3c636796	docker-basics	medium	docker-basics, images, build	How docker image build works?	1. Docker spins up a temporary container\n2. Runs a single instruction in the temporary container\n3. Stores the result as a new image layer\n4. Remove the temporary container\n5. Repeat for every instruction	projects/knowledge/interview/docker/044-how-docker-image-build-works.txt
docker-basics/89a6c888ba83	docker-basics	medium	docker-basics, images, fundamentals	What is a Docker image?	A Docker image is a lightweight, standalone, and executable package that includes everything needed to run a piece of software, including the code, runtime, libraries, and system tools. It is a snapshot of a file system and parameters needed for running a container. Docker images are built from a set of instructions called a Dockerfile, and they can be versioned, stored in repositories, and shared with others. Images serve as the blueprint for creating containers, and they encapsulate the application and its dependencies in a consistent and reproducible manner.	projects/knowledge/interview/docker/132-what-is-a-docker-image.txt
docker-basics/8a14e4cd27d5	docker-basics	easy	docker-basics, dockerfile, build	Which instructions in Containerfile/Dockerfile create new layers?	Instructions such as FROM, COPY and RUN, create new image layers instead of just adding metadata.\n\nRemember: FROM, RUN, COPY, ADD create layers. ENV, EXPOSE, CMD create metadata only. Fewer RUN = smaller images.	projects/knowledge/interview/docker/075-which-instructions-in-containerfiledockerfile-crea.txt
docker-basics/8b31eab43d76	docker-basics	hard	docker-basics, images, fundamentals	What is the difference between a Docker image and a container?	An image is a read-only template containing application code, runtime,\nlibraries, and dependencies. A container is a running instance of an image.\n\nImage:\n- Immutable, versioned, shareable\n- Built from Dockerfile\n- Stored in registries (Docker Hub, ECR, etc.)\n- Composed of layered filesystem\n\nContainer:\n- Running process isolated from host\n- Has writable layer on top of image\n- Ephemeral by default (data lost when removed)\n- Can have multiple containers from same image\n\nAnalogy:\n- Image = Class definition\n- Container = Object instance\n\nCommands:\n- `docker build` → creates image\n- `docker run` → creates container from image\n- `docker images` → list images\n- `docker ps` → list running containers	projects/knowledge/interview/docker/221-image-vs-container.txt
docker-basics/8f73de895b8d	docker-basics	hard	docker-basics, images, build	How do you create a Docker image?	To create a Docker image, you typically follow these steps:\n* Create a Dockerfile:\nWrite a Dockerfile, which is a plain text file containing instructions for building the image. The Dockerfile specifies the base image, adds dependencies, defines environment variables, and sets up the application.\n* Build the Image:\nUse the docker build command to build the image based on the Dockerfile. Provide the path to the directory containing the Dockerfile.\n```docker build -t image_name:tag path/to/dockerfile_directory```\n* Verify the Image:\nOnce the build is complete, you can use the docker images command to verify that the new image is listed.	projects/knowledge/interview/docker/139-how-do-you-create-a-docker-image.txt
docker-basics/90877a0ddfdc	docker-basics	easy	docker-basics, containers, runtime	How do you run a container from an image?	`docker run <image>` (or `podman run <image>`). Examples: `docker run ubuntu` (runs and exits), `docker run -it ubuntu bash` (interactive shell), `docker run -d -p 8080:80 nginx` (detached with port mapping). Key flags: `-d` (detached/background), `-it` (interactive TTY), `-p` (port mapping), `--name` (assign name), `--rm` (auto-remove on exit).	projects/knowledge/interview/docker/008-how-to-run-a-container.txt
docker-basics/92e0ce14939f	docker-basics	hard	docker-basics, dockerfile, build	What is the difference between ENTRYPOINT and CMD in a Dockerfile?	Both specify what runs when a container starts, but they behave differently:\n\nCMD:\n- Provides default command and/or arguments\n- Easily overridden by `docker run` arguments\n- Only the last CMD takes effect\n\nENTRYPOINT:\n- Defines the executable that always runs\n- Arguments from `docker run` are appended to it\n- Harder to override (requires --entrypoint flag)\n\nCombination patterns:\n\n1. CMD only (flexible):\n   CMD ["python", "app.py"]\n   # docker run myimage → runs python app.py\n   # docker run myimage bash → runs bash instead\n\n2. ENTRYPOINT only (fixed command):\n   ENTRYPOINT ["python", "app.py"]\n   # docker run myimage → runs python app.py\n   # docker run myimage --debug → runs python app.py --debug\n\n3. Both (best practice for CLI tools):\n   ENTRYPOINT ["python", "app.py"]\n   CMD ["--help"]\n   # docker run myimage → runs python app.py --help\n   # docker run myimage --version → runs python app.py --version	projects/knowledge/interview/docker/223-entrypoint-vs-cmd.txt
docker-basics/9506db416e69	docker-basics	hard	docker-basics, fundamentals, concepts	Explain the difference between "docker run" and "docker create."	\n**docker run:**\n* Combines the creation and start of a container in a single command.\n* Syntax: docker run [options] image_name [command] [args]\n* Creates a new container from the specified image and starts it.\n* Example: ```docker run -d -p 8080:80 my_web_app``` \n**docker create:**\n* Creates a new container but does not start it.\n* Syntax: docker create [options] image_name [command] [args]\n* Returns the container ID but doesn't run the specified command.\n* Example: docker create -v /data my_data_container \nOnce you use docker create to create a container, you can start it later using docker start and stop it with docker stop.	projects/knowledge/interview/docker/149-explain-the-difference-between-docker-run-and-dock.txt
docker-basics/9564bdfa8445	docker-basics	medium	docker-basics, dockerfile, build	What is a Containerfile/Dockerfile?	Different container engines (e.g. Docker, Podman) can build images automatically by reading the instructions from a Containerfile/Dockerfile. A Containerfile/Dockerfile is a text file that contains all the instructions for building an image which containers can use.	projects/knowledge/interview/docker/066-what-is-a-containerfiledockerfile.txt
docker-basics/965870027331	docker-basics	medium	docker-basics, containers, runtime	Why after running podman container run ubuntu the output of podman container ls is empty?	Because the container immediately exits after running the ubuntu image. This is completely normal and expected as containers designed to run a service or a app and exit when they are done running it. To see the container you can run `podman ps -a`\n\nIf you want the container to keep running, you can run a command like `sleep 100` which will run for 100 seconds or you can attach to terminal of the container with a command similar: `podman container run -it ubuntu /bin/bash`	projects/knowledge/interview/docker/009-why-after-running-podman-container-run-ubuntu-the-.txt
docker-basics/97cd2ab4a459	docker-basics	medium	docker-basics, containers, runtime	How to attach your shell to a terminal of a running container?	`podman container exec -it [container id/name] bash`\n\nThis can be done in advance while running the container: `podman container run -it [image:tag] /bin/bash`	projects/knowledge/interview/docker/011-how-to-attach-your-shell-to-a-terminal-of-a-runnin.txt
docker-basics/9ab77cbd9504	docker-basics	medium	docker-basics, dockerfile, build	What is the difference between CMD and RUN in Containerfile/Dockerfile?	RUN lets you execute commands inside of your Docker image. These commands get executed once at build time and get written into your Docker image as a new layer.\nCMD is the command the container executes by default when you launch the built image. A Containerfile/Dockerfile can only have one CMD.\nYou could say that CMD is a Docker run-time operation, meaning it’s not something that gets executed at build time. It happens when you run an image. A running image is called a container.	projects/knowledge/interview/docker/072-what-is-the-difference-between-cmd-and-run-in-cont.txt
docker-basics/9d16795aca1e	docker-basics	medium	docker-basics, fundamentals, concepts	What's your experience with Docker?	I've built images, managed registries, debugged containers, and run large-scale containerized workloads through Kubernetes, Docker CE, and CoreOS environments. I'm comfortable writing Dockerfiles, optimizing layers, and understanding how images, tags, and volumes interact.	projects/knowledge/interview/docker/195-whats-your-experience-with-docker.txt
docker-basics/a1b36fc81231	docker-basics	hard	docker-basics, images, fundamentals	What are Docker image layers and how do they work?	A Docker image is built up from a series of layers. Each layer represents an instruction in the image’s Containerfile/Dockerfile. Each layer except the very last one is read-only.\nEach layer is only a set of differences from the layer before it. The layers are stacked on top of each other. When you create a new container, you add a new writable layer on top of the underlying layers. This layer is often called the “container layer”.	projects/knowledge/interview/docker/103-explain-image-layers.txt
docker-basics/a21587d9fc3b	docker-basics	medium	docker-basics, compose, orchestration	Describe the process of using Docker Compose	* Define the services you would like to run together in a docker-compose.yml file\n* Run `docker compose up` to run the services	projects/knowledge/interview/docker/105-describe-the-process-of-using-docker-compose.txt
docker-basics/a4bf0745fd8c	docker-basics	medium	docker-basics, containers, runtime	How to run a container in the background?	With the -d flag. It will run in the background and will not attach it to the terminal.\n\n`docker container run -d httpd` or `podman container run -d httpd`	projects/knowledge/interview/docker/015-how-to-run-a-container-in-the-background.txt
docker-basics/a529e8eb9ec5	docker-basics	easy	docker-basics, containers, runtime	True or False? You can remove a running container if it doesn't running anything	False. You have to stop the container before removing it.\n\nUnder the hood: docker stop sends SIGTERM, waits 10s, then SIGKILL. docker rm -f sends SIGKILL immediately.	projects/knowledge/interview/docker/012-true-or-false-you-can-remove-a-running-container-i.txt
docker-basics/a85c36fb84cc	docker-basics	medium	docker-basics, containers, runtime	How do you run a Docker container?	To run a Docker container, you use the docker run command. Here's a basic example:\n```docker run image_name``` \n* `image_name` is the name of the Docker image you want to run. \nThis command will start a new container based on the specified image. Additional options can be used to customize the container's behavior, such as exposing ports, mounting volumes, setting environment variables, and more.	projects/knowledge/interview/docker/148-how-do-you-run-a-docker-container.txt
docker-basics/a8e9d239c2e6	docker-basics	medium	docker-basics, fundamentals, concepts, configuration	Explain the use of the "--env" option in the "docker run" command.	The --env option in the docker run command is used to set environment variables within the container. Environment variables are key-value pairs that provide configuration information to applications running inside the container. \n```docker run --env MYSQL_ROOT_PASSWORD=secret -d mysql:latest``` \nIn this example, the MYSQL_ROOT_PASSWORD environment variable is set to "secret" for a MySQL container. Multiple --env options can be used to set multiple environment variables.	projects/knowledge/interview/docker/157-explain-the-use-of-the-env-option-in-the-docker-ru.txt
docker-basics/aeedc3b17d44	docker-basics	medium	docker-basics, images, build	How do you build a Docker image?	By writing a Dockerfile with instructions (base image, operations like copying files, installing packages, setting entrypoint, etc.) and running docker build . -t name:tag. Docker will execute the Dockerfile steps to produce an image.	projects/knowledge/interview/docker/201-build-docker-image.txt
docker-basics/b2454c9ca32b	docker-basics	hard	docker-basics, dockerfile, build	What is the purpose of the ENTRYPOINT and CMD directives in a Dockerfile?	Both ENTRYPOINT and CMD are instructions in a Dockerfile used to define the default command that will be executed when a container starts: \n**ENTRYPOINT:**\nSpecifies the executable that will run when the container starts. It is often used for defining the primary application or process within the container.\nExample: ENTRYPOINT ["nginx", "-g", "daemon off;"] \n**CMD:**\nDefines default arguments for the ENTRYPOINT or sets the default command when the container starts if no ENTRYPOINT is specified.\nCMD can be overridden at	projects/knowledge/interview/docker/142-what-is-the-purpose-of-the-entrypoint-and-cmd-dire.txt
docker-basics/b3adb84ed325	docker-basics	medium	docker-basics, containers, runtime	How can you restart a stopped container?	To restart a stopped container, you can use the docker start command:\n```docker start container_id``` \n`container_id` is the ID or name of the stopped container. \nThis command restarts the container using its existing configuration and state. If you want to restart a container with different settings, you can use the docker create and docker start combination.	projects/knowledge/interview/docker/154-how-can-you-restart-a-stopped-container.txt
docker-basics/bda83053f479	docker-basics	medium	docker-basics, images, fundamentals	Can you explain the layered filesystem concept in Docker images?	Docker images are composed of layers. Each instruction in a Dockerfile (like RUN, COPY) creates a new immutable layer. Layers are cached and reused – if two images share some layers, Docker stores those layers only once. When running a container, these image layers are combined with a thin writable layer on top.	projects/knowledge/interview/docker/212-layered-filesystem.txt
docker-basics/c020741593f2	docker-basics	medium	docker-basics, fundamentals, concepts	What's the difference between these two forms:	The first form is also referred as "Exec form" and the second one is referred as "Shell form". \nThe second one (Shell form) wraps the commands in `/bin/sh -c` hence creates a shell process for it.\n\nWhile using either Exec form or Shell form might be fine, it's the mixing that can lead to unexpected results. \nConsider:\n\n```\nENTRYPOINT ["ls"]\nCMD /tmp\n```\n\nThat would results in running `ls /bin/sh -c /tmp`	projects/knowledge/interview/docker/077-whats-the-difference-between-these-two-forms-entry.txt
docker-basics/c28ed0e8cb47	docker-basics	easy	docker-basics, fundamentals, concepts	What is Docker and what problem does containerization solve?	Docker is a platform for containerization. It allows you to package applications and their dependencies into containers – lightweight, portable units that run uniformly across environments (from development to production).	projects/knowledge/interview/docker/197-what-is-docker.txt
docker-basics/c461b085bbd4	docker-basics	medium	docker-basics, dockerfile, build	List five different instructions that are available for use in a Containerfile/Dockerfile	* WORKDIR: sets the working directory inside the image filesystems for all the instructions following it\n  * EXPOSE: exposes the specified port (it doesn't adds a new layer, rather documented as image metadata)\n  * ENTRYPOINT: specifies the startup commands to run when a container is started from the image\n  * ENV: sets an environment variable to the given value\n  * USER: sets the user (and optionally the user group) to use while running the image	projects/knowledge/interview/docker/068-list-five-different-instructions-that-are-availabl.txt
docker-basics/c4f01143f448	docker-basics	medium	docker-basics, dockerfile, build	How to create a new image using a Containerfile/Dockerfile?	The following command is executed from within the directory where Dockefile resides:\n\n`docker image build -t some_app:latest .`\n`podman image build -t some_app:latest .`	projects/knowledge/interview/docker/073-how-to-create-a-new-image-using-a-containerfiledoc.txt
docker-basics/c5201e6129c7	docker-basics	easy	docker-basics, containers, runtime	After running a container, it stopped. podman ps shows nothing. How can you show its details?	`podman ps -a` shows all containers including stopped ones. Without `-a`, only running containers appear. Add `--filter status=exited` to see only stopped containers, or `--format` for custom output columns.	projects/knowledge/interview/docker/019-after-running-a-container-it-stopped-podman-ps-sho.txt
docker-basics/c72a8ff842bc	docker-basics	easy	docker-basics, images, fundamentals	How to check what a certain container image will execute once we'll run a container based on that image?	Look for the `Cmd` or `Entrypoint` fields in the output of `docker image inspect <image>`. \nExample: `docker image inspect nginx | jq '.[0].Config.Cmd'` returns the default command. \nGotcha: if both ENTRYPOINT and CMD are set, the effective command is ENTRYPOINT + CMD concatenated.	projects/knowledge/interview/docker/042-how-to-check-what-a-certain-container-image-will-e.txt
docker-basics/c74cee87cbf7	docker-basics	medium	docker-basics, images, fundamentals	Explain container image layers	- The layers of an image is where all the content is stored - code, files, etc.\n  - Each layer is independent\n  - Each layer has an ID that is an hash based on its content\n  - The layers (as the image) are immutable which means a change to one of the layers can be easily identified	projects/knowledge/interview/docker/028-explain-container-image-layers.txt
docker-basics/c76d0497e6be	docker-basics	medium	docker-basics, images, fundamentals	Why container images are relatively small?	* Most of the images don't contain Kernel. They share and access the one used by the host on which they are running\n* Containers intended to run specific application in most cases. This means they hold only what the application needs in order to run	projects/knowledge/interview/docker/021-why-container-images-are-relatively-small.txt
docker-basics/cc8899c19baf	docker-basics	medium	docker-basics, images, fundamentals	True or False? Multiple images can share layers	True. \nOne evidence for that can be found in pulling images. Sometimes when you pull an image, you'll see a line similar to the following: \n`fa20momervif17: already exists`\n\nThis is because it recognizes such layer already exists on the host, so there is no need to pull the same layer twice.	projects/knowledge/interview/docker/036-true-or-false-multiple-images-can-share-layers.txt
docker-basics/cd3ad9ded797	docker-basics	hard	docker-basics, fundamentals, concepts	What is Docker, and how does it differ from traditional virtualization?	Docker is a containerization platform that enables developers to package applications and their dependencies into standardized units called containers. These containers can run consistently across various environments, providing a lightweight and portable solution. Unlike traditional virtualization, where each application runs on a separate operating system (OS) with its own kernel, Docker containers share the host OS kernel, making them more efficient and faster to deploy. Virtualization involves running multiple virtual machines (VMs) on a hypervisor, each with its own OS instance, which can consume more resources compared to Docker containers.	projects/knowledge/interview/docker/129-what-is-docker-and-how-does-it-differ-from-traditi.txt
docker-basics/cd6da28d8f4d	docker-basics	medium	docker-basics, containers, fundamentals	Describe the process of containerizing an application	1. Write a Containerfile/Dockerfile that includes your app (including the commands to run it) and its dependencies\n2. Build the image using the Containerfile/Dockefile you wrote\n3. You might want to push the image to a registry\n4. Run the container using the image you've built	projects/knowledge/interview/docker/006-describe-the-process-of-containerizing-an-applicat.txt
docker-basics/d0d7c91db285	docker-basics	medium	docker-basics, dockerfile, build	Which instructions in Containerfile/Dockerfile create image metadata and don't create new layers?	Instructions such as ENTRYPOINT, ENV, EXPOSE, create image metadata and they don't create new layers.\n\nRemember: FROM, RUN, COPY, ADD create layers. ENV, EXPOSE, CMD create metadata only. Fewer RUN = smaller images.	projects/knowledge/interview/docker/076-which-instructions-in-containerfiledockerfile-crea.txt
docker-basics/d4424515af25	docker-basics	medium	docker-basics, dockerfile, build	What is the difference between ADD and COPY in Containerfile/Dockerfile?	COPY takes in a source and destination. It lets you copy in a file or directory from the build context into the Docker image itself. \nADD lets you do the same, but it also supports two other sources. You can use a URL instead of a file or directory from the build context. In addition, you can extract a tar file from the source directly into the destination.	projects/knowledge/interview/docker/071-what-is-the-difference-between-add-and-copy-in-con.txt
docker-basics/d48cfbadc64b	docker-basics	medium	docker-basics, dockerfile, build	What instruction exists in every Containerfile/Dockefile and what does it do?	In every Containerfile/Dockerfile, you can find the instruction `FROM <image name>` which is also the first instruction (at least most of the time. You can put ARG before). \nIt specifies the base layer of the image to be used. Every other instruction is a layer on top of that base image.	projects/knowledge/interview/docker/067-what-instruction-exists-in-every-containerfiledock.txt
docker-basics/d775f8783b46	docker-basics	hard	docker-basics, containers, fundamentals	Why containers are needed? What is their goal?	OCI provides a good [explanation](https://github.com/opencontainers/runtime-spec/blob/master/principles.md#the-5-principles-of-standard-containers): "Define a unit of software delivery called a Standard Container. The goal of a Standard Container is to encapsulate a software component and all its dependencies in a format that is self-describing and portable, so that any compliant runtime can run it without extra dependencies, regardless of the underlying machine and the contents of the container."	projects/knowledge/interview/docker/002-why-containers-are-needed-what-is-their-goal.txt
docker-basics/d8b6c8647fef	docker-basics	easy	docker-basics, fundamentals, concepts	What is the "build context"?	The build context is the set of files located at the PATH or URL passed to `docker build`. Docker sends the entire context to the daemon, so a large context slows builds. Use `.dockerignore` to exclude unnecessary files like `.git/`, `node_modules/`, and test data.	projects/knowledge/interview/docker/070-what-is-the-build-context.txt
docker-basics/dbb3429dbcbf	docker-basics	easy	docker-basics, images, fundamentals	True or False? In most cases, container images contain their own kernel	False. They share and access the one used by the host on which they are running.\n\nUnder the hood: sharing the host kernel is why images are small — only userspace needed. But kernel exploits affect all containers.	projects/knowledge/interview/docker/031-true-or-false-in-most-cases-container-images-conta.txt
docker-basics/de0ccbbf750f	docker-basics	easy	docker-basics, images, fundamentals	How to list all the image tags for a given container image?	`podman search --list-tags IMAGE_NAME` or use the registry API directly. For Docker Hub: `curl -s 'https://hub.docker.com/v2/repositories/library/nginx/tags/?page_size=100' | jq '.results[].name'`. \nGotcha: some registries limit tag listing or require authentication.	projects/knowledge/interview/docker/020-how-to-list-all-the-image-tags-for-a-given-contain.txt
docker-basics/e1ccbbf66c90	docker-basics	easy	docker-basics, dockerfile, build	What is a "Dockerfile"?	A script with instructions to build a Docker image.\n\nGotcha: each RUN creates a new layer. Combine related commands with && to reduce image size and layer count.\n\nExample: FROM python:3.11-slim / WORKDIR /app / COPY . . / RUN pip install -r requirements.txt / CMD ["python", "main.py"]	projects/knowledge/interview/docker/201-dockerfile.txt
docker-basics/e6c2daf10b81	docker-basics	hard	docker-basics, images, fundamentals	You are interested in running a container with snake game application. How can you search for such image and check if it exists?	`podman search snake-game` queries configured registries for matching images. Add `--limit 10` to control result count. Results show INDEX, NAME, DESCRIPTION, and STARS columns. \nGotcha: search only queries registries in `registries.search` config — private registries need explicit configuration.	projects/knowledge/interview/docker/022-you-are-interested-in-running-a-container-with-sna.txt
docker-basics/e6e322d5dfcd	docker-basics	medium	docker-basics, images, fundamentals	What ways are there for creating new images?	1. Create a Containerfile/Dockerfile and build an image out of it\n2. Using `podman commit` on a running container after making changes to it	projects/knowledge/interview/docker/061-what-ways-are-there-for-creating-new-images.txt
docker-basics/e9b16c5619e0	docker-basics	easy	docker-basics, dockerfile, build	What happens when CMD instruction is defined but not an ENTRYPOINT instruction in a Containerfile/Dockerfile?	When CMD is defined but ENTRYPOINT is not, the ENTRYPOINT from the base image is used. If the base image also has no ENTRYPOINT (rare), CMD runs as the main process via `/bin/sh -c`. \nGotcha: if you later add ENTRYPOINT, the existing CMD becomes arguments to it, which may break the container.	projects/knowledge/interview/docker/079-what-happens-when-cmd-instruction-is-defined-but-n.txt
docker-basics/f7d67044b345	docker-basics	medium	docker-basics, images, fundamentals	True or False? Changing the content of any of the image layers will cause the hash content of the image to change	True. These hashes are content based and since images (and their layers) are immutable, any change will cause the hashes to change.	projects/knowledge/interview/docker/029-true-or-false-changing-the-content-of-any-of-the-i.txt
docker-basics/z5e6f7a8b9c0	docker-basics	medium	docker-basics, containers, runtime	Do containers run their own kernel?	No. Containers share the host kernel. This is fundamentally different from VMs. A container escape is a kernel or runtime vulnerability, not a VM boundary problem.\n\nUnder the hood: this is the fundamental difference from VMs. Because containers share the host kernel, a kernel exploit in one container affects all. This is why container runtimes add seccomp, AppArmor, and capabilities restrictions.	zines/how.containers.work.cleaned.notes
docker-basics/z6f7a8b9c0d1	docker-basics	easy	docker-basics, images, fundamentals	What is the relationship between a container image and a running container?	An image is a reusable filesystem template (read-only layers). A container is a running process with its own writable layer on top. Multiple containers can share the same image.	zines/how.containers.work.cleaned.notes
docker-basics/257bc752d39d	docker-basics	medium	miscellaneous, containers, control-flow, dns	How do you scale resources horizontally and vertically to meet increasing demand?	• Vertical Scaling: Vertical scaling involves increasing the capacity of individual servers by adding more CPU, RAM, or storage. This is suitable for applications that benefit from increased resources on a single server. • Horizontal Scaling: Horizontal scaling involves adding more servers to distribute the workload. This is effective for applications designed to run in a distributed environment, and it improves redundancy and fault tolerance.	
docker-basics/accc735fe31e	docker-basics	medium	miscellaneous, containers, control-flow, debugging	Discuss your experience with containerization technologies such as Docker or Kubernetes.	• Experience with Docker: I have extensive experience with Docker, including containerizing applications, creating Docker images, and managing containerized environments. • Container Orchestration with Kubernetes: I am proficient in Kubernetes for container orchestration, managing containerized applications at scale, and automating deployment, scaling, and operations. • Microservices Architecture: I have implemented microservices architectures using Docker containers, enabling modular and scalable application development.	

<!-- wiki:related:start -->
---

## Wiki Navigation

### Related Content

- [AWS ECS](../../../../library/topics/aws-ecs/index.md) (Topic Pack, L2) — Docker / Containers
- [Case Study: CI Pipeline Fails — Docker Layer Cache Corruption](../../../../library/case-studies/cross-domain/ci-pipeline-docker-cache-registry/README.md) (Case Study, L2) — Docker / Containers
- [Case Study: Container Vuln Scanner False Positive Blocks Deploy](../../../../library/case-studies/cross-domain/container-vuln-scanner-false-positive/README.md) (Case Study, L2) — Docker / Containers
- [Case Study: ImagePullBackOff Registry Auth](../../../../library/case-studies/kubernetes_ops/imagepullbackoff-registry-auth/README.md) (Case Study, L1) — Docker / Containers
- [Container Images](../../../../library/topics/container-images/index.md) (Topic Pack, L1) — Docker / Containers
- [Containers Deep Dive](../../../../library/topics/containers-deep-dive/index.md) (Topic Pack, L1) — Docker / Containers
- [Deep Dive: Containers How They Really Work](../../../../library/deep-dives/containers.how.they.really.work.md) (deep_dive, L2) — Docker / Containers
- [Deep Dive: Docker Image Internals](../../../../library/deep-dives/docker.image.internals.md) (deep_dive, L2) — Docker / Containers
- [Docker](../../../../library/topics/docker/index.md) (Topic Pack, L1) — Docker / Containers
- [Docker Drills](../../../../library/drills/docker_drills.md) (Drill, L1) — Docker / Containers

<!-- wiki:related:end -->
