---
tags:
- containers
- l1
- flashcard-deck
- docker-ops
---
<!-- wiki:breadcrumb:start -->
[Portal](../../../../library/portal/index.md) | **Level:** [L1: Foundations](../../../../library/portal/levels.md) | **Topics:** [Docker / Containers](../../../../library/portal/topics.md) | **Domain:** containers
<!-- wiki:breadcrumb:end -->

id	category	difficulty	tags	question	answer	source_path
docker-ops/056ea44dc660	docker-ops	medium	docker-ops, architecture, distribution	How multi-architecture images work? Explain by describing what happens when an image is pulled	1. A client makes a call to the registry to use a specific image (using an image name and optionally a tag)\n2. A manifest list is parsed (assuming it exists) to check if the architecture of the client is supported and available as a manifest\n3. If it is supported (a manifest for the architecture is available) the relevant manifest is parsed to obtain the IDs of the layers\n4. Each layer is then pulled using the obtained IDs from the previous step	projects/knowledge/interview/docker/040-how-multi-architecture-images-work-explain-by-desc.txt
docker-ops/05f3c3af9fd9	docker-ops	easy	docker-ops, registry	A registry contains one or more ____ which in turn contain one or more ____	A registry contains one or more repositories which in turn contain one or more images.\n\nAnalogy: registry = library, repository = bookshelf (one per project), image = specific edition of a book (tagged by version).\n\nExample: Docker Hub (registry) > library/nginx (repository) > nginx:1.25, nginx:1.24, nginx:alpine (images/tags).\n\nRemember: a repository groups all versions of one image. A registry hosts many repositories.	projects/knowledge/interview/docker/055-a-registry-contains-one-or-more-which-in-turn-cont.txt
docker-ops/0f173e7a339d	docker-ops	medium	docker-ops, tagging	How do you tag and version Docker images?	Tagging and versioning Docker images help identify and manage different versions of an image. The basic syntax for tagging is repository:tag. Here's how you can tag and version a Docker image:\n```\n# Tagging an image with a specific version\ndocker tag image_name:latest image_name:1.0\n# Pushing the tagged image to a registry (optional)\ndocker push image_name:1.0\n```\n`image_name` is the name of your Docker image. \n`latest` is the default tag, but it's a good practice to use version tags like 1.0.	projects/knowledge/interview/docker/145-how-do-you-tag-and-version-docker-images.txt
docker-ops/10a0b8ae08ff	docker-ops	medium	docker-ops, operations, troubleshooting	Describe in detail what happens when you run `podman/docker run hello-world`?	Docker/Podman CLI passes your request to Docker daemon.\nDocker/Podman daemon downloads the image from Docker Hub\nDocker/Podman daemon creates a new container by using the image it downloaded\nDocker/Podman daemon redirects output from container to Docker CLI which redirects it to the standard output	projects/knowledge/interview/docker/087-describe-in-detail-what-happens-when-you-run-podma.txt
docker-ops/16c0fd485472	docker-ops	medium	docker-ops, operations, troubleshooting	How to configure registries with the containers engine you are using?	For podman, registries can be configured in `/etc/containers/registries.conf` this way:\n\n```\n[registries.search]\nregistries = ["quay.io"]\n```\n\nFor Docker, registries are configured in /etc/docker/daemon.json or ~/.docker/config.json.\n\nGotcha: Docker defaults to docker.io. Podman defaults to searching multiple registries. Misconfigured search order can pull the wrong image from the wrong registry.\n\nExample: docker login ghcr.io stores credentials in ~/.docker/config.json for GitHub Container Registry.	projects/knowledge/interview/docker/057-how-to-configure-registries-with-the-containers-en.txt
docker-ops/1a5bbd162848	docker-ops	easy	docker-ops, architecture	How to check which architectures a certain container image supports?	`docker manifest inspect <name>`\n\nExample: docker manifest inspect nginx:latest shows a manifest list with entries for linux/amd64, linux/arm64, linux/arm/v7, etc.\n\nUnder the hood: multi-arch images use a manifest list (also called an OCI image index) that maps each platform to a platform-specific image manifest.\n\nRemember: crane (from go-containerregistry) is a faster alternative: crane manifest nginx:latest | jq '.manifests[].platform'	projects/knowledge/interview/docker/041-how-to-check-which-architectures-a-certain-contain.txt
docker-ops/1e7a24ee61b1	docker-ops	medium	docker-ops, operations, troubleshooting	You and your team work on the same project, but different versions of it. For each version, the team creates a new, separate image. What would you suggest the team to change in such case?	Use tags. You can distinguish between different releases of a project using image tags. There is no need to create an entire separate image for version/release of a project.	projects/knowledge/interview/docker/128-you-and-your-team-work-on-the-same-project-but-dif.txt
docker-ops/20e65b899ed7	docker-ops	hard	docker-ops, layer-caching	What is the role of cache in image builds?	When you build an image for the first time, the different layers are being cached. So, while the first build of the image might take time, any other build of the same image (given that Containerfile/Dockerfile didn't change or the content used by the instructions) will be instant thanks to the caching mechanism used.\n\nIn little bit more details, it works this way:\n1. The first instruction (FROM) will check if base image already exists on the host before pulling it \n2.	projects/knowledge/interview/docker/045-what-is-the-role-of-cache-in-image-builds.txt
docker-ops/21a02c3fbe5f	docker-ops	medium	docker-ops, image-verification	What is the digest of an image? What problem does it solves?	Tags are mutable. This is mean that we can have two different images with the same name and the same tag. It can be very confusing to see two images with the same name and the same tag in your environment. How would you know if they are truly the same or are they different? \n\nThis is where "digests` come handy. A digest is a content-addressable identifier. It isn't mutable as tags. Its value is predictable and this is how you can tell if two images are the same content wise and not merely by looking at the name and the tag of the images.	projects/knowledge/interview/docker/037-what-is-the-digest-of-an-image-what-problem-does-i.txt
docker-ops/24977fc078cc	docker-ops	medium	docker-ops, image-verification	What is a distribution hash in regards to layers?	- Layers are compressed when pushed or pulled\n  - distribution hash is the hash of the compressed layer\n  - the distribution hash used when pulling or pushing images for verification (making sure no one tempered with image or layers)\n  - It's also used for avoiding ID collisions (a case where two images have exactly the same generated ID)	projects/knowledge/interview/docker/039-what-is-a-distribution-hash-in-regards-to-layers.txt
docker-ops/27b258b28bd5	docker-ops	easy	docker-ops, operations, troubleshooting	How to list the layers of an image?	In case of Docker, you can use `docker image inspect <name>` and look at the RootFS.Layers field. For a more readable view: docker history <name> shows each layer with its command, size, and creation date.\n\nExample: docker history nginx:latest --no-trunc shows the full Dockerfile instruction that created each layer.\n\nRemember: dive is a third-party tool that lets you interactively browse layers and see exactly what files each layer adds or removes.	projects/knowledge/interview/docker/030-how-to-list-the-layers-of-an-image.txt
docker-ops/29850ee600f9	docker-ops	easy	docker-ops, reliability	What forms of self-healing options available for Docker containers?	Restart Policies. It allows you to automatically restart containers after certain events.\n\nExample: docker run --restart=always nginx restarts the container on crash, daemon restart, or host reboot. Other policies: no (default), on-failure[:max-retries], unless-stopped.\n\nRemember: restart policies provide basic self-healing. For production, Kubernetes provides richer self-healing: liveness probes, readiness probes, and deployment controllers that recreate failed pods.	projects/knowledge/interview/docker/118-what-forms-of-self-healing-options-available-for-d.txt
docker-ops/335cc6aa0dd6	docker-ops	easy	docker-ops, cleanup, tagging	True or False? Once created, it's impossible to remove a tag for a certain image	False. You can run `podman rmi IMAGE:TAG`.\n\nUnder the hood: removing a tag removes only the pointer. Underlying layers remain until garbage collected.	projects/knowledge/interview/docker/064-true-or-false-once-created-its-impossible-to-remov.txt
docker-ops/37b3bb86fd9d	docker-ops	medium	docker-ops, cleanup	What is a dangling image?	It's an image without tags attached to it.\nOne way to reach this situation is by building an image with exact same name and tag as another already existing image. It can be still referenced by using its full SHA.	projects/knowledge/interview/docker/033-what-is-a-dangling-image.txt
docker-ops/38a8a14b64db	docker-ops	medium	docker-ops, swarm	How do you initialize a Docker Swarm?	To initialize a Docker Swarm and make the current node a manager: \n```docker swarm init --advertise-addr <manager-node-IP>``` \nThis command generates a join token that other nodes can use to join the swarm.\nTo join a worker or manager node to the swarm: \n```docker swarm join --token <token> <manager-node-IP>:<manager-port>```	projects/knowledge/interview/docker/182-how-do-you-initialize-a-docker-swarm.txt
docker-ops/3a7ba0822414	docker-ops	medium	docker-ops, registry	What is a container registry and how is it used?	- A registry is a service which stores container images and allows users to pull specified images to run containers.\n- There are public registries (everyone can access them) and private (accessed only internally in the organization or specific network)	projects/knowledge/interview/docker/054-what-is-a-registry.txt
docker-ops/3adb070d7101	docker-ops	medium	docker-ops, registry	How to find out which registry do you use by default from your environment?	Depends on the containers technology you are using. For example, in case of Docker, it can be done with `docker info`\n\n```\n> docker info\nRegistry: https://index.docker.io/v1\n```	projects/knowledge/interview/docker/056-how-to-find-out-which-registry-do-you-use-by-defau.txt
docker-ops/4140725ace97	docker-ops	hard	docker-ops, operations, troubleshooting	Describe in detail what happens when you run a container	1. The Docker client converts the run command into an API payload\n2. It then POST the payload to the API endpoint exposed by the Docker daemon\n3. When the daemon receives the command to create a new container, it makes a call to containerd via gRPC\n4. containerd converts the required image into an OCI bundle and tells runc to use that bundle for creating the container\n5. runc interfaces with the OS kernel to pull together the different constructs (namespace, cgroups, etc.) used for creating the container\n6. Container process is started as a child-process of runc\n7. Once it starts, runc exists	projects/knowledge/interview/docker/097-describe-in-detail-what-happens-when-you-run-a-con.txt
docker-ops/450a9f7c2ddf	docker-ops	hard	docker-ops, tagging, distribution	Describe in detail what happens when you run `docker pull image:tag`?	Docker CLI passes your request to Docker daemon. Dockerd Logs shows the process\n\ndocker.io/library/busybox:latest resolved to a manifestList object with 9 entries; looking for a unknown/amd64 match\n\nfound match for linux/amd64 with media type application/vnd.docker.distribution.manifest.v2+json, digest sha256:400ee2ed939df769d4681023810d2e4fb9479b8401d97003c710d0e20f7c49c6	projects/knowledge/interview/docker/096-describe-in-detail-what-happens-when-you-run-docke.txt
docker-ops/47a56a5a26ef	docker-ops	medium	docker-ops, operations, troubleshooting	There is a running container that has a certain issue. You would like to share an image of that container with your team members, with certain environment variables set for debugging purposes. How would you do it?	`podman commit` can be a good choice for that. You can create a new image of the running container (with the issue) and share that new image with your team members. \n\nWhat you probably want to avoid using:\n - Using something as `podman save/load` as it applies on an image, not a running container (so you'll share the image but the issue might not be reproduced when your team members run a container using it)\n - Modifying Containerfile/Dockerfile as you don't really want to add environment variables meant for debugging to the source from which you usually build images	projects/knowledge/interview/docker/127-there-is-a-running-container-that-has-a-certain-is.txt
docker-ops/4f15c3c473e2	docker-ops	medium	docker-ops, internals	What is shim in regards to Docker?	shim is the process that becomes the container's parent when runc process exists. It's responsible for:\n\n  - Reporting exit code back to the Docker daemon\n  - Making sure the container doesn't terminate if the daemon is being restarted. It does so by keeping the stdout and stdin open	projects/knowledge/interview/docker/100-what-is-shim-in-regards-to-docker.txt
docker-ops/4fe4e5c6c22c	docker-ops	easy	docker-ops, multi-stage, tagging	True or False? In multi-stage builds, artifacts can be copied between stages	True. In multi-stage builds, `COPY --from=builder /app/binary /app/binary` copies artifacts between stages. This lets you compile in a full SDK image but ship only the binary in a minimal runtime image (e.g., distroless or alpine), dramatically reducing final image size and attack surface.	projects/knowledge/interview/docker/107-true-or-false-in-multi-stage-builds-artifacts-can-.txt
docker-ops/5066575b164d	docker-ops	hard	docker-ops, operations, troubleshooting	What happens when you run docker container run ubuntu?	1. Docker client posts the command to the API server running as part of the Docker daemon\n2. Docker daemon checks if a local image exists\n  1. If it exists, it will use it\n  2. If doesn't exists, it will go to the remote registry (Docker Hub by default) and pull the image locally\n3. containerd and runc are instructed (by the daemon) to create and start the container	projects/knowledge/interview/docker/014-what-happens-when-you-run-docker-container-run-ubu.txt
docker-ops/50aecc44fd6e	docker-ops	medium	docker-ops, registry	What is Docker Hub and how is it used in container workflows?	Docker Hub is a cloud registry for Docker images. It allows you to push images to share them and pull images (like "nginx" or "ubuntu") for use. It contains official images and user-contributed repositories.	projects/knowledge/interview/docker/205-what-is-docker-hub.txt
docker-ops/5a7eb2129842	docker-ops	medium	docker-ops, swarm	What is Docker Swarm, and how does it facilitate orchestration?	Docker Swarm is a native clustering and orchestration solution for Docker. It allows you to create and manage a swarm of Docker nodes, turning them into a single, virtual Docker host. Swarm provides built-in orchestration features for deploying, scaling, and managing containerized applications across a cluster of machines. \n**Swarm facilitates orchestration by:**\n* Service Management: Defining and deploying services across the swarm.\n* Scaling: Scaling services up or down based on demand.\n* Load Balancing: Distributing traffic to services among available nodes.\n* Rolling Updates: Performing rolling updates to services with minimal downtime.\n* Secrets and Configs: Managing sensitive information and configurations securely.	projects/knowledge/interview/docker/180-what-is-docker-swarm-and-how-does-it-facilitate-or.txt
docker-ops/5e055aa3675d	docker-ops	medium	docker-ops, internals	True or False? Running a dozen of containers will result in having a dozen of runc processes	False. Once a container is created, the parent runc process exists.\n\nUnder the hood: runc creates namespaces/cgroups, starts the process, then exits. The shim becomes container's parent.	projects/knowledge/interview/docker/099-true-or-false-running-a-dozen-of-containers-will-r.txt
docker-ops/5ea83b13a747	docker-ops	medium	docker-ops, best-practices	What are some best practices in regards to Container Images?	- Use tags. Using `latest` is quite common (which can mean latest build or latest release)\n  - tag like `3.1` can be used to reference the latest release/tag of the image like `3.1.6`\n- Don't use `commit` for creating new official images as they include the overhead of logs and processes and usually end up with bigger images\n- For sharing the image, use a registry (either a public or a private one, depends on your needs)	projects/knowledge/interview/docker/060-what-are-some-best-practices-in-regards-to-contain.txt
docker-ops/600813e6274f	docker-ops	easy	docker-ops, operations, troubleshooting	How to view the instructions that were used to build image?	`docker image history <image name>:<tag>`\n\nUnder the hood: docker history shows each layer's command and size. Helps identify bloated RUN instructions.	projects/knowledge/interview/docker/043-how-to-view-the-instructions-that-were-used-to-bui.txt
docker-ops/615e333424fb	docker-ops	easy	docker-ops, tagging	True or False? A single container image can have multiple tags	True. When listing images, you might be able to see two images with the same ID but different tags.\n\nExample: tag same image as v1.2.3, v1.2, v1, latest — all pointing to one digest. Standard versioning strategy.	projects/knowledge/interview/docker/032-true-or-false-a-single-container-image-can-have-mu.txt
docker-ops/62a197e8fb58	docker-ops	medium	docker-ops, operations, troubleshooting	What components are part of the Docker engine?	The Docker engine has three core components: the Docker daemon (dockerd) handles high-level tasks like image management and networking; containerd manages container lifecycle (start, stop, pause); and runc is the low-level OCI runtime that actually creates and runs containers using Linux namespaces and cgroups.	projects/knowledge/interview/docker/092-what-components-are-part-of-the-docker-engine.txt
docker-ops/6926e9a2594d	docker-ops	easy	docker-ops, registry	What is "Docker Hub"?	Docker Hub is a public registry for storing and sharing Docker images. It hosts official images (nginx, postgres, ubuntu) maintained by Docker and verified publishers. Free accounts get one private repo; paid plans add more. Alternatives include Quay.io, GitHub Container Registry (ghcr.io), and self-hosted registries.	projects/knowledge/interview/docker/202-docker-hub.txt
docker-ops/6ae5f4a2a0c6	docker-ops	medium	docker-ops, swarm	Explain the concept of Docker Swarm stacks.	To perform rolling updates in Docker Swarm, use the docker service update command with the --update-delay option: \n```docker service update --image new_image:tag --update-delay 10s my_service``` \nThis example updates the my_service service to use the new image with a 10-second delay between updating each container. This ensures a controlled and gradual rollout of the new version, minimizing downtime. \nRolling updates help maintain service availability while introducing changes to the running containers.	projects/knowledge/interview/docker/185-explain-the-concept-of-docker-swarm-stacks.txt
docker-ops/6c4f208bd2d8	docker-ops	medium	docker-ops, registry	You would like to share an image with another developer, but without using a registry. How would you do it?	Use `podman save -o image.tar IMAGE` to export, transfer with rsync/scp, then `podman load -i image.tar` on the remote host. This is useful for air-gapped environments without registry access. \nGotcha: the tarball includes all layers, so large images produce large files — consider compressing with gzip.	projects/knowledge/interview/docker/049-you-would-like-to-share-an-image-with-another-deve.txt
docker-ops/770298bbec97	docker-ops	hard	docker-ops, optimization	How do you optimize Docker images for size?	Optimizing Docker images for size is crucial for efficient image distribution and faster deployment. Here are some strategies:\n* Use Minimal Base Images:\nChoose lightweight base images, such as Alpine Linux, to minimize the size of the initial image layer.\n* Reduce the Number of Layers:\nMinimize the number of layers in the Dockerfile to reduce image complexity and improve caching.\n* Combine RUN Commands:\nCombine multiple RUN commands into a single command to reduce the number of layers.	projects/knowledge/interview/docker/143-how-do-you-optimize-docker-images-for-size.txt
docker-ops/770f7bd5a383	docker-ops	hard	docker-ops, internals	What is the significance of the Docker daemon?	The Docker daemon (dockerd) is a background process responsible for managing Docker objects on the host system. It serves as the central component of the Docker architecture and performs key functions, including:\n* Image and Container Management: The daemon manages Docker images, containers, networks, and volumes.	projects/knowledge/interview/docker/138-what-is-the-significance-of-the-docker-daemon.txt
docker-ops/79eb611ec5c3	docker-ops	medium	docker-ops, tagging	What are image tags? Why is it recommended to use tags when supporting multiple releases/versions of a project?	Image tags are used to distinguish between multiple versions of the same software or project. Let's say you developed a project called "FluffyUnicorn" and the current release is `1.0`. You are about to release `1.1` but you still want to keep `1.0` as stable release for anyone who is interested in it. What would you do? If your answer is create another, separate new image, then you probably want to rethink the idea and just create a new image tag for the new release.\n\nContainer registries also support tags. So when pulling an image, you can specify a specific tag of that image.	projects/knowledge/interview/docker/062-what-are-image-tags-why-is-it-recommended-to-use-t.txt
docker-ops/7e7cbbbc86bb	docker-ops	hard	docker-ops, multi-stage, tagging	Explain Multi-stage builds	Multi-stages builds allow you to produce smaller container images by splitting the build process into multiple stages.\n\nAs an example, imagine you have one Containerfile/Dockerfile where you first build the application and then run it. The whole build process of the application might be using packages and libraries you don't really need for running the application later. Moreover, the build process might produce different artifacts which not all are needed for running the application.	projects/knowledge/interview/docker/106-explain-multi-stage-builds.txt
docker-ops/80e3746bdd99	docker-ops	medium	docker-ops, operations, troubleshooting	Do you perform any checks or testing on your Containerfiles/Dockerfiles?	Use [hadolint](https://github.com/hadolint/hadolint), a Dockerfile linter based on best practices. Run it with `hadolint Dockerfile` or integrate into CI. It checks for issues like missing version pinning in apt-get install, running as root, and using COPY instead of ADD. Also consider `docker scout` for vulnerability scanning of built images.	projects/knowledge/interview/docker/074-do-you-perform-any-checks-or-testing-on-your-conta.txt
docker-ops/88f474275225	docker-ops	hard	docker-ops, operations, troubleshooting	How do you uninstall Docker from a system?	The process of uninstalling Docker varies depending on the operating system. Here are instructions for some common platforms: \n**Linux (Ubuntu/Debian):**\n* sudo apt-get purge docker-ce docker-ce-cli containerd.io\n**Linux (CentOS/RHEL):**\n* sudo yum remove docker-ce docker-ce-cli containerd.io\n**Mac:**\nUse the Docker Desktop application to stop Docker.\n* Remove the Docker application from the "Applications" folder.\n**Windows:**\n* Use the "Add or Remove Programs" feature to uninstall Docker Desktop.	projects/knowledge/interview/docker/137-how-do-you-uninstall-docker-from-a-system.txt
docker-ops/8ce65639dfc4	docker-ops	easy	docker-ops, operations, troubleshooting	How to see changes done to a given image over time?	`docker history <image>` shows each layer's creation command, size, and timestamp. This helps identify which Dockerfile instructions added the most size. Add `--no-trunc` to see full commands. \nGotcha: squashed images or images built with BuildKit may show truncated history.	projects/knowledge/interview/docker/034-how-to-see-changes-done-to-a-given-image-over-time.txt
docker-ops/8e6086328970	docker-ops	hard	docker-ops, architecture	Explain the architecture of Docker.	Docker follows a client-server architecture. The key components include:\n* Docker Daemon: This is a background process that manages Docker objects like images, containers, networks, and volumes on the host system.\n* Docker Client: It is the primary interface through which users interact with Docker. Users issue commands to the Docker client, and the client communicates with the Docker daemon to execute those commands.\n* Docker Registry: It is a repository for Docker images. Docker Hub is the default public registry, but private registries can also be used.\n* Docker Objects: These include images, containers, networks, and volumes. Images are the blueprints for containers, and containers are the running instances of those images.	projects/knowledge/interview/docker/130-explain-the-architecture-of-docker.txt
docker-ops/8ee0eaf1647d	docker-ops	hard	docker-ops, internals	True or False? Killing the Docker daemon will kill all the running containers	False. While this was true at some point, today the container runtime isn't part of the daemon (it's part of containerd and runc) so stopping or killing the daemon will not affect running containers.	projects/knowledge/interview/docker/098-true-or-false-killing-the-docker-daemon-will-kill-.txt
docker-ops/8f2cb3d6c696	docker-ops	easy	docker-ops, cleanup	What does docker system prune -a do?	Deletes all unused images, containers, and data.\n\nUnder the hood: removes stopped containers, unused networks, dangling images, and build cache. Add -a for ALL unused images, --volumes for volumes.\n\nGotcha: prune is permanent. In production, schedule carefully — it can remove images that stopped containers need for restart.	projects/knowledge/interview/docker/206-docker-prune.txt
docker-ops/906008838d12	docker-ops	hard	docker-ops, multi-stage, tagging	What is a multi-stage Docker build and why would you use it?	Multi-stage builds allow you to use multiple FROM statements in a Dockerfile,\ncreating separate build stages. Only the final stage becomes the output image.\n\nBenefits:\n- Smaller final images (no build tools, source code)\n- Improved security (fewer components to attack)\n- Cleaner Dockerfiles (no complex cleanup commands)\n- Faster deployments (smaller images to transfer)\n\nExample:\n```dockerfile\n# Build stage\nFROM golang:1.21 AS builder\nWORKDIR /app\nCOPY . .\nRUN go build -o myapp\n\n# Final stage\nFROM alpine:3.19\nCOPY --from=builder /app/myapp /usr/local/bin/\nCMD ["myapp"]\n```\n\nResult: Final image only contains Alpine + binary, not the Go compiler\nand all source code.\n\nCommon pattern: Build in full SDK image, run in minimal runtime image.	projects/knowledge/interview/docker/222-multi-stage-build.txt
docker-ops/916259905d16	docker-ops	easy	docker-ops, tagging	How do you tag a Docker image and what are tagging best practices?	`podman tag IMAGE:TAG` or `docker tag SOURCE_IMAGE:TAG TARGET_IMAGE:TAG`. \nExample: `docker tag myapp:latest myregistry.com/myapp:v1.2.3`. \nBest practice: use semantic versioning (v1.2.3) rather than 'latest', which is mutable and makes rollbacks ambiguous. Also tag with the git SHA for traceability.	projects/knowledge/interview/docker/063-how-to-tag-an-image.txt
docker-ops/951a99ea9fc2	docker-ops	hard	docker-ops, operations, troubleshooting	Explain the concept of Docker context.	Docker context is a feature introduced to simplify the management of Docker environments. A Docker context represents a point of interaction with a Docker daemon, which can be local or remote. It includes information about the Docker host, authentication details, and other settings. \n**Key aspects of Docker context:**\n* Switching Contexts: Users can switch between different Docker contexts using the docker context use command.	projects/knowledge/interview/docker/189-explain-the-concept-of-docker-context.txt
docker-ops/974233550a28	docker-ops	medium	docker-ops, operations, troubleshooting	Which components/layers compose the Docker technology?	1. Runtime - responsible for starting and stopping containers\n2. Daemon - implements the Docker API and takes care of managing images (including builds), authentication, security, networking, etc.\n3. Orchestrator	projects/knowledge/interview/docker/091-which-componentslayers-compose-the-docker-technolo.txt
docker-ops/a34e3a7192b3	docker-ops	medium	docker-ops, optimization	How do you keep Docker images small?	Use smaller base images, minimize layers, clean package caches, and copy only what's required. Multi-stage builds help keep production images clean.	projects/knowledge/interview/docker/196-how-do-you-keep-docker-images-small.txt
docker-ops/a7338353f915	docker-ops	medium	docker-ops, operations, troubleshooting	What `podman commit` does?. When will you use it?	Creates a new image from a running container. Users can apply extra changes to be saved in the new image version.\n\nMost of the time the user case for using `podman commit` would be to apply changes allowing to better debug the container. Not so much for creating a new image since commit adds additional overhead of potential logs and processes, not required for running the application in the container. This eventually makes images created by `podman commit` bigger due to the additional data stored there.	projects/knowledge/interview/docker/035-what-podman-commit-does-when-will-you-use-it.txt
docker-ops/afc172b04375	docker-ops	medium	docker-ops, best-practices	What are some best practices you following in regards to using containers in production?	Images:\n  * Use images from official repositories\n  * Include only the packages you are going to use. Nothing else.\n  * Specify a tag in FROM instruction. Not using a tag means you'll always pull the latest, which changes over time and might result in unexpected result.\n  * Do not use environment variables to share secrets\n  * Keep images small! - you want them only to include what is required for the application to run successfully. Nothing else.\nComponents:\n  * Secured connection between components (e.g. client and server)	projects/knowledge/interview/docker/116-what-are-some-best-practices-you-following-in-rega.txt
docker-ops/afe8285ff81c	docker-ops	hard	docker-ops, operations, troubleshooting	What is Docker Machine, and how is it used?	Docker Machine is a tool for creating and managing Docker hosts (virtual machines) on local or remote systems. It simplifies the process of setting up Docker on different platforms, allowing users to create and manage Docker-enabled machines with minimal effort. \n**Key features and usage of Docker Machine:**\n* Provisioning: Docker Machine can create Docker hosts on various platforms, including local VirtualBox, AWS, Azure, and others.\n* Management: Docker Machine provides commands for starting, stopping, and managing Docker hosts.	projects/knowledge/interview/docker/188-what-is-docker-machine-and-how-is-it-used.txt
docker-ops/b0be49419ed9	docker-ops	hard	docker-ops, operations, troubleshooting	What is the purpose of Docker plugins?	Docker plugins extend Docker's functionality by providing additional features, functionalities, or integrations. Plugins allow users to customize and enhance Docker according to specific requirements. \n**Key aspects of Docker plugins:**\n* Storage Plugins: Extend Docker's storage capabilities, allowing integration with various storage solutions.\n* Network Plugins: Enhance Docker's networking features, enabling integration with different network infrastructures.	projects/knowledge/interview/docker/191-what-is-the-purpose-of-docker-plugins.txt
docker-ops/b0eae13509cb	docker-ops	medium	docker-ops, optimization	What are the pros and cons of squashing images?	Pros:\n  * Smaller image\n  * Reducing number of layers (especially if the image has lot of layers)\nCons:\n  * No sharing of the image layers\n  * Push and pull can take more time (because no matching layers found on target)	projects/knowledge/interview/docker/048-what-are-the-pros-and-cons-of-squashing-images.txt
docker-ops/bc0369cd1579	docker-ops	medium	docker-ops, operations, troubleshooting	What is the low-level runtime?	- The low level runtime is called runc\n  - It manages every container running on Docker host\n  - Its purpose is to interact with the underlying OS to start and stop containers\n  - Its reference implementation is of the OCI (Open Containers Initiative) container-runtime-spec\n  - It's a small CLI wrapper for libcontainer	projects/knowledge/interview/docker/093-what-is-the-low-level-runtime.txt
docker-ops/bca7430daafc	docker-ops	easy	docker-ops, registry, distribution	How to push an image to a registry?	`podman push IMAGE`\n\nYou can specify a specific registry: `podman push IMAGE REGISTRY_ADDRESS`\n\nUnder the hood: push uploads only new layers. Content-addressable storage deduplicates — shared layers never re-uploaded.	projects/knowledge/interview/docker/059-how-to-push-an-image-to-a-registry.txt
docker-ops/c69ec03fdb55	docker-ops	medium	docker-ops, registry	What is Docker Hub, and how is it used?	Docker Hub is a cloud-based registry service provided by Docker that allows users to store and share Docker images. It serves as a central repository for Docker images, and users can pull images from Docker Hub to their local systems. Docker Hub provides both public and private repositories. Public repositories are accessible to anyone, while private repositories require authentication to access. Users can also push their own Docker images to Docker Hub, making them available to the Docker community. It is a convenient platform for collaborating, distributing, and versioning Docker images.	projects/knowledge/interview/docker/135-what-is-docker-hub-and-how-is-it-used.txt
docker-ops/cc3dad31ab78	docker-ops	easy	docker-ops, tagging	True or False? Multiple tags can reference the same image	True. Multiple tags can point to the same Docker image (same digest). For example, 'latest', 'v1.2', and 'stable' can all reference the same image layers.	projects/knowledge/interview/docker/065-true-or-false-multiple-tags-can-reference-the-same.txt
docker-ops/cd72448eb854	docker-ops	medium	docker-ops, internals	True or False? The docker daemon (dockerd) performs lower-level tasks compared to containerd	False. The Docker daemon (dockerd) performs higher-level tasks like image management, networking, and volume orchestration. containerd handles the lower-level container lifecycle (start, stop, pause, delete). Below containerd, runc does the actual Linux kernel work (namespaces, cgroups). The hierarchy is: dockerd -> containerd -> runc.	projects/knowledge/interview/docker/095-true-or-false-the-docker-daemon-dockerd-performs-l.txt
docker-ops/cf34605fdae9	docker-ops	medium	docker-ops, best-practices	What are some of the best practices regarding Containerfiles/Dockerfiles that you are following?	* Include only the packages you are going to use. Nothing else.\n  * Specify a tag in FROM instruction. Not using a tag means you'll always pull the latest, which changes over time and might result in unexpected result.\n  * Do not use environment variables to share secrets\n  * Use images from official repositories\n  * Keep images small! - you want them only to include what is required for the application to run successfully. Nothing else.\n  * If are using the apt package manager, you might want to use 'no-install-recommends' with `apt-get install` to install only main dependencies (instead of suggested, recommended packages)	projects/knowledge/interview/docker/069-what-are-some-of-the-best-practices-regarding-cont.txt
docker-ops/d286ab062532	docker-ops	easy	docker-ops, oci	Which operations OCI based containers must support?	OCI containers must support five operations: Create, Kill, Delete, Start, and Query State. Mnemonic: CKDSQ — 'Containers Keep Delivering Software Quickly.' These operations define the minimum interface any OCI-compliant runtime (runc, crun, kata) must implement.	projects/knowledge/interview/docker/126-which-operations-oci-based-containers-must-support.txt
docker-ops/d44e73fc09b7	docker-ops	easy	docker-ops, operations, troubleshooting	How the centralized location, where images are stored, is called?	A Registry. Docker Hub is the default public registry. You can run a private registry with `docker run -d -p 5000:5000 registry:2`. Images are pushed/pulled by their registry path.	projects/knowledge/interview/docker/053-how-the-centralized-location-where-images-are-stor.txt
docker-ops/d47fae9aad9b	docker-ops	easy	docker-ops, internals	How the Docker client communicates with the daemon?	Via the local socket at `/var/run/docker.sock`\n\nGotcha: docker.sock = full root on the host. Mounting it into containers is equivalent to giving them root access.	projects/knowledge/interview/docker/102-how-the-docker-client-communicates-with-the-daemon.txt
docker-ops/da5febe4694d	docker-ops	medium	docker-ops, cleanup	How do you remove old, non running, containers?	1. To remove one or more Docker images use the docker container rm command followed by the ID of the containers you want to remove.\n2. The docker system prune command will remove all stopped containers, all dangling images, and all unused networks\n3. docker rm $(docker ps -a -q) - This command will delete all stopped containers. The command docker ps -a -q will return all existing container IDs and pass them to the rm command which will delete them. Any running containers will not be deleted.	projects/knowledge/interview/docker/101-how-do-you-remove-old-non-running-containers.txt
docker-ops/defcce3bc090	docker-ops	hard	docker-ops, multi-stage, tagging	What is multi-stage Docker builds, and when would you use them?	Multi-stage builds in Docker allow you to use multiple FROM statements in a single Dockerfile, creating a series of intermediate images. Each stage is used for a specific purpose, such as building dependencies or compiling code, and the final stage produces the optimized runtime image.	projects/knowledge/interview/docker/144-what-is-multi-stage-docker-builds-and-when-would-y.txt
docker-ops/e10260cd4cde	docker-ops	medium	docker-ops, swarm	What is the purpose of Docker services in Swarm mode?	Docker services in Swarm mode are the primary abstraction for deploying and managing containers. A service defines the desired state for a group of tasks (containers) and ensures that the specified number of replicas are running across the swarm. \n**Key aspects of Docker services:** \n* Replicas: The number of identical containers running the service.\n* Load Balancing: Services distribute incoming traffic across all running containers.\n* Desired State: The service maintains the desired number of replicas, auto-healing if necessary.\n* Scaling: Services can be scaled up or down dynamically.	projects/knowledge/interview/docker/183-what-is-the-purpose-of-docker-services-in-swarm-mo.txt
docker-ops/e30a9ea1dc0e	docker-ops	easy	docker-ops, operations, troubleshooting	How to find out which files were added to the container image filesystem?	`podman diff IMAGE_NAME` shows filesystem changes: A=added, C=changed, D=deleted files in the container's writable layer versus the base image. This is useful for debugging unexpected file modifications or verifying that a container only changed what you intended. Works on both running and stopped containers.	projects/knowledge/interview/docker/051-how-to-find-out-which-files-were-added-to-the-cont.txt
docker-ops/e6b3351850bc	docker-ops	medium	docker-ops, build-optimization	What .dockerignore is used for?	By default, Docker uses everything (all the files and directories) in the directory you use as build context. \n`.dockerignore` used for excluding files and directories from the build context	projects/knowledge/interview/docker/108-what-dockerignore-is-used-for.txt
docker-ops/e83f20610c90	docker-ops	medium	docker-ops, swarm	How can you scale services in Docker Swarm?	To scale a service in Docker Swarm, use the docker service scale command: \n```docker service scale my_service=5``` \nThis command scales the service named my_service to have five replicas. Docker Swarm will automatically distribute the replicas across available worker nodes.	projects/knowledge/interview/docker/184-how-can-you-scale-services-in-docker-swarm.txt
docker-ops/e96819484227	docker-ops	medium	docker-ops, cleanup	How can you remove intermediate images in the Docker build process?	Docker automatically creates intermediate images during the build process, and these images can accumulate, consuming disk space. To remove intermediate images, you can use the docker image prune command:\n```\n# Remove all dangling (untagged) images and unused build cache\ndocker image prune\n# Remove all unused images, not just dangling ones\ndocker image prune -a\n```\nThe -a option in the second command removes all unused images, including those with tags.	projects/knowledge/interview/docker/147-how-can-you-remove-intermediate-images-in-the-dock.txt
docker-ops/eab19bbe24ce	docker-ops	medium	docker-ops, reliability	What restart policies are you familiar with?	* always: restart the container when it's stopped (not with `docker container stop`)\n  * unless-stopped: restart the container unless it was in stopped status\n  * no: don't restart the container at any point (default policy)\n  * on-failure: restart the container when it exists due to an error (= exit code different than zero)	projects/knowledge/interview/docker/119-what-restart-policies-are-you-familiar-with.txt
docker-ops/eadae977743f	docker-ops	medium	docker-ops, oci	What is the OCI (Open Container Initiative) and what standards does it define?	OCI (Open Container Initiative) is an open governance established in 2015 to standardize container creation - mostly image format and runtime. At that time there were a number of parties involved and the most prominent one was Docker.\n\nSpecifications published by OCI:\n\n  - [image-spec](https://github.com/opencontainers/image-spec)\n  - [runtime-spec](https://github.com/opencontainers/runtime-spec)	projects/knowledge/interview/docker/125-what-is-the-oci.txt
docker-ops/f2801b20e17d	docker-ops	hard	docker-ops, optimization	What ways are there to reduce container images size?	* Reduce number of instructions - in some case you may be able to join layers by installing multiple packages with one instructions for example or using `&&` to concatenate RUN instructions\n  * Using smaller images - in some cases you might be using images that contain more than what is needed for your application to run. It is good to get overview of some images and see whether you can use smaller images that you are usually using.\n  * Cleanup after running commands - some commands, like packages installation, create some metadata or cache that you might not need for running the application. It's important to clean up after such commands to reduce the image size\n  * For Docker images, you can use multi-stage builds	projects/knowledge/interview/docker/047-what-ways-are-there-to-reduce-container-images-siz.txt
docker-ops/f369856de76f	docker-ops	hard	docker-ops, inspection	Explain the significance of the "docker inspect" command.	The docker inspect command is used to obtain detailed information about Docker objects, including containers, images, volumes, networks, and more. It provides a JSON-formatted output containing extensive details about the specified object. \n**Key uses and significance of docker inspect:**\n* Container Details: View container configurations, networking information, mounted volumes, and more.\n* Image Details: Retrieve information about image layers, labels, and other metadata.	projects/knowledge/interview/docker/193-explain-the-significance-of-the-docker-inspect-com.txt
docker-ops/f4b0a6e53451	docker-ops	hard	docker-ops, operations, troubleshooting	What is the high-level runtime?	- The high level runtime is called containerd\n  - It was developed by Docker Inc and at some point donated to CNCF\n  - It manages the whole lifecycle of a container - start, stop, remove and pause\n  - It take care of setting up network interfaces, volume, pushing and pulling images, ...\n  - It manages the lower level runtime (runc) instances\n  - It's used both by Docker and Kubernetes as a container runtime\n  - It sits between Docker daemon and runc at the OCI layer\n\nNote: running `ps -ef | grep -i containerd` on a system with Docker installed and running, you should see a process of containerd	projects/knowledge/interview/docker/094-what-is-the-high-level-runtime.txt
docker-ops/f4d9ac8d1c50	docker-ops	hard	docker-ops, swarm, architecture	Describe the architecture of Docker Swarm.	Docker Swarm follows a decentralized and agent-based architecture. Key components include: \n**Manager Nodes:**\n* Control the swarm and orchestrate deployments.\n* Maintain the desired state of services.\n* Serve as the entry point for CLI and API commands. \n**Worker Nodes:**\n* Execute containerized tasks and services.\n* Receive workloads from manager nodes. \n**Tokens:**\n* Used for node join operations.\n* Managers and workers join the swarm using tokens. \n**Raft Consensus Algorithm:**	projects/knowledge/interview/docker/181-describe-the-architecture-of-docker-swarm.txt
docker-ops/fd48595349b8	docker-ops	easy	docker-ops, architecture	True or False? A single image can support multiple architectures (Linux x64, Windows x64, ...)	True. Docker supports multi-architecture images via manifest lists. A single image tag can resolve to different platform-specific images (linux/amd64, linux/arm64, windows/amd64).	projects/knowledge/interview/docker/038-true-or-false-a-single-image-can-support-multiple-.txt

<!-- wiki:related:start -->
---

## Wiki Navigation

### Related Content

- [AWS ECS](../../../../library/topics/aws-ecs/index.md) (Topic Pack, L2) — Docker / Containers
- [Case Study: CI Pipeline Fails — Docker Layer Cache Corruption](../../../../library/case-studies/cross-domain/ci-pipeline-docker-cache-registry/README.md) (Case Study, L2) — Docker / Containers
- [Case Study: Container Vuln Scanner False Positive Blocks Deploy](../../../../library/case-studies/cross-domain/container-vuln-scanner-false-positive/README.md) (Case Study, L2) — Docker / Containers
- [Case Study: ImagePullBackOff Registry Auth](../../../../library/case-studies/kubernetes_ops/imagepullbackoff-registry-auth/README.md) (Case Study, L1) — Docker / Containers
- [Container Images](../../../../library/topics/container-images/index.md) (Topic Pack, L1) — Docker / Containers
- [Containers Deep Dive](../../../../library/topics/containers-deep-dive/index.md) (Topic Pack, L1) — Docker / Containers
- [Deep Dive: Containers How They Really Work](../../../../library/deep-dives/containers.how.they.really.work.md) (deep_dive, L2) — Docker / Containers
- [Deep Dive: Docker Image Internals](../../../../library/deep-dives/docker.image.internals.md) (deep_dive, L2) — Docker / Containers
- [Docker](../../../../library/topics/docker/index.md) (Topic Pack, L1) — Docker / Containers
- Docker Basics Flashcards *(CLI)* (flashcard_deck, L1) — Docker / Containers

<!-- wiki:related:end -->
