Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Docker packages an application and its dependencies into an image, then runs that image as one or more containers. To get started, install Docker for your operating system, run a container, learn where its data lives, and use Compose when your application needs multiple services. The key distinction to keep in mind is that a container is a runnable instance—not a complete virtual machine—and data in its writable layer is not automatically durable.

What is Docker, and how do I get started?

Docker is a platform for packaging and running applications in a consistent way across development, testing, and deployment environments. An image is a read-only template; a container is an instance created from that template, with runtime settings and a writable layer for changes made while it runs. Containers share the host machine’s operating-system kernel rather than each carrying a separate full operating system. Docker’s overview and documentation explain these concepts in more detail.

  • Image: the application package and filesystem template you can build, store, and distribute.
  • Container: a process running from an image, with its own runtime configuration and writable layer.
  • Docker Engine: the system that manages images, containers, networks, and volumes. Its long-running daemon, dockerd, receives API requests from clients such as the docker command-line interface.
  • Dockerfile: a text file of instructions for building an image.
  • Compose file: configuration for an application made up of services and related resources, such as networks and volumes.

Installation depends on the host. Docker Desktop is a desktop application that bundles Docker Engine components and developer tooling; on Linux servers, Docker Engine installation instructions are organized by distribution. Choose the appropriate current path rather than copying a command intended for another operating system: Docker Engine, Docker Engine installation. Supported platforms and terms can change.

Docker states that commercial use of Docker Engine obtained through Docker Desktop in an organization exceeding 250 employees or $10 million in annual revenue requires a paid subscription. Check Docker’s current product and licensing terms before choosing an installation route, since those terms can change. The open-source Engine is supported by Moby maintainers and the community; Docker supports its products, including Desktop. Docker Engine documentation

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Run your first container and understand its lifecycle

This example from Docker’s overview starts an interactive Bash session in Ubuntu. Run it in a terminal with Docker available:

docker run -i -t ubuntu /bin/bash

If the image is not available locally, Docker can pull it from a configured registry. The command then creates a container, adds a writable layer, sets up networking, and starts the requested process. The flags -i and -t keep input open and provide a terminal. Type exit to end the shell: the container stops, but exiting alone does not remove it. Docker’s container lifecycle overview

For routine work, this small set of commands covers the basic lifecycle. Replace <name-or-id> with a container name or ID shown by Docker:

docker pull ubuntu                 # Fetch an image explicitly
docker run -d --name demo ubuntu sleep infinity
docker ps                          # List running containers
docker ps -a                       # Include stopped containers
docker logs demo                   # Read the container's output
docker stop demo                   # Stop it
docker rm demo                     # Remove the stopped container

The detached example keeps a process running so the container can be inspected and stopped from another prompt. A stopped container can be started again; removing it deletes that container instance. Consult the official Docker Engine documentation for current CLI syntax and command options.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Build an image from a Dockerfile

A Dockerfile turns application setup into a repeatable build recipe. Instructions such as choosing a base image, copying files, installing dependencies, and selecting a startup command are used to construct the image. The directory supplied to docker build is the build context: files in it may be sent to the builder, so keep it focused.

docker build -t my-app:dev .

Here, . is the current directory and my-app:dev is the local image name and tag. Add a .dockerignore file beside the Dockerfile to exclude files the build does not need—such as local dependency folders, build outputs, or secrets. This reduces unnecessary context and helps avoid copying unintended files into an image. Build caching can speed up repeated builds, so arrange instructions with frequently changing files later where practical. Docker’s building best practices

Keep build tools out of the runtime image when possible

Multi-stage builds let one stage compile or package an application and a later stage copy only the required output into the final image. That can keep compilers and other build-only tools out of the runtime environment. Use a trusted base image, avoid installing packages the application does not need, and run the application as a non-root user when its requirements allow it.

Choose between a moving tag and a pinned digest

An image tag is a readable label, but a publisher can later make the same tag refer to a different image. A digest identifies a specific image version, which makes a build more repeatable. The tradeoff is operational: a pinned digest will not adopt a publisher’s later security fixes until someone reviews and updates the pin. Use a deliberate update process rather than assuming either mutable tags or permanent pins are always safer. Docker recommends rebuilding images regularly and discusses these tradeoffs in its image-building guidance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Keep important data outside the container

Files written into a container’s writable layer belong to that container. If you remove the container, those changes disappear unless the data is stored separately. Mount a volume for data that must outlive a particular container instance. A named volume is managed by Docker; a bind mount connects a host path to a container path and therefore couples the container to a location on the host. Docker’s overview explains why container-local changes are not a substitute for persistent storage.

Storage choice What it connects Useful when Tradeoff to consider
Container writable layer Changes made inside one container Temporary files that can be recreated Removing the container removes its layer and its data.
Named volume A Docker-managed storage location to a container path Application data that should survive replacing a container It is separate from the container lifecycle, so manage backups and cleanup deliberately.
Bind mount A specific host path to a container path Local development files or a deliberately shared host directory It exposes a host location to the container and can introduce host-path, permissions, and security concerns.

For example, this creates a named volume, writes a file through one temporary container, removes that container, then reads the file through another:

docker volume create app-data
docker run --name writer -v app-data:/data ubuntu sh -c 'echo saved > /data/message.txt'
docker rm writer
docker run --rm -v app-data:/data ubuntu cat /data/message.txt

The final command should print saved: the container was replaced, but the named volume remained. Removing a container is not the same as deleting its volume. Check the current Docker storage and Engine documentation for storage commands and platform-specific mount details.

Run a multi-service application with Compose

Use a Dockerfile to describe how to build an individual service image; use a Compose file to describe how application services fit together. Compose can create and run the services as a group, along with their configured networks and storage. A Compose project gets a default network where services can discover one another by service name, so an application service can address a service named cache using that name rather than a changing container IP. Docker’s Compose networking guide

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

This illustrative compose.yaml starts an Nginx web server and a Redis service. It demonstrates service configuration and name-based networking; Nginx is not configured here to use Redis.

services:
  web:
    image: nginx:alpine
    ports:
      - "8080:80"
    depends_on:
      - cache
  cache:
    image: redis:alpine

Save the file as compose.yaml, then run these commands from the same directory:

  1. docker compose up -d creates and starts the services in the background. Open http://localhost:8080 to reach the published web port.
  2. docker compose ps shows service status, and docker compose logs -f follows service output.
  3. docker compose down stops and removes the project’s containers and default network. Review the file and command options before adding volume cleanup or other destructive operations.

The example uses image tags for readability; those tags can move as publishers update images. For a release that needs a fixed image identity, apply the tag-versus-digest decision described above. Add custom or external networks only when the application’s architecture needs them. Compose networking documentation

Default bridge networking or host networking?

Choice How it behaves Use it when
Compose default network Services join a project network and can discover one another by service name. You want service-to-service communication with the usual Compose network model.
Host networking The container shares the host network stack; it does not use the default Compose service-name discovery model. A specific workload requires direct access to the host network stack and you have assessed the consequences.

Host networking is not a general performance or connectivity shortcut: it changes the network boundary and bypasses the normal service-name setup. Use it only for a concrete requirement. Compose networking documentation

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Docker Container Linux Devops Programming Coding T-Shirt
  • Docker, Docker Swarm, Docker Compose, Programmer, Developer, Coding, Programming, Software Engineer, Code, DevOps, Deploy, Deployment, Kubernetes, Salt, Puppet, Chef, Terraform, Container, AWS, Azure, Cloud, Geek, Funny, Computer, Software, Tech, IT
  • Integration, Scrum, Compile, Compilation, Science, Bug, Debug, Python, Linux, Java, Javascript, Scala, Dotnet, Kotlin
  • Lightweight, Classic fit, Double-needle sleeve and bottom hem
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Secure Docker by treating access and configuration as powerful

Containers provide useful isolation through Linux kernel features such as namespaces and control groups, but they are not a guarantee that an application is harmless to its host. Security depends on the host kernel, Docker daemon access, the image, and the privileges, mounts, and network configuration granted to each workload.

  • Restrict daemon access. A user who controls the Docker daemon can request host directory mounts and potentially gain broad access to host files. Do not expose the Docker API to untrusted networks, and limit who can control the daemon. Docker Engine security guidance
  • Inspect Compose files before running them. Compose applies requested host mounts, privileges, and other settings as written. Treat unfamiliar or downloaded Compose projects as executable configuration; review them before using docker compose up. Compose trust model
  • Reduce container privileges. Run the application as a non-root user where possible, grant only the capabilities it needs, and avoid unnecessary host mounts or elevated privileges. Docker build recommendations
  • Consider rootless mode when it suits the workload. Rootless mode runs both the daemon and containers as a non-root user. It has prerequisites and feature constraints, so check the current setup instructions and confirm the features your application needs are supported. Rootless mode documentation

No one setting makes every workload safe. In particular, trust in an image does not make a broad host mount harmless, and running a container as non-root does not remove the need to control daemon access or inspect its configuration.

Choose the right way to learn and operate Docker

If you want a guided desktop learning environment, start with Docker Desktop’s current setup route for your platform. If you are installing on a Linux server, select the instructions for that distribution and the stable channel when you want a generally available release. Verify the current platform requirements before installation. Engine installation instructions and Engine documentation

Docker’s free Docker 101 tutorial covers images, containers, volumes, Compose, networking, and build practices. A printed Docker book can be a useful optional reference, but it is not a prerequisite for learning or using Docker.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.