Docker: containerization platform packaging applications with dependencies. Containers are lightweight, isolated, portable. Benefits: consistency (dev = production), easy scaling, resource efficiency, fast startup. Docker vs VMs: containers share OS kernel, VMs have separate OS. Ideal for microservices.
Dockerfile: text file with instructions to build Docker image. Commands: FROM (base image), RUN (execute), COPY (add files), WORKDIR (set directory), EXPOSE (port), CMD (default command), ENTRYPOINT. Build: docker build -t image:tag . Result: reusable image.
Image: blueprint (immutable) containing application and dependencies. Container: running instance of image (mutable). Image layers stack on top of each other. Containers are isolated processes. Push images to registries (Docker Hub, ECR). Build once, run anywhere.
Docker Compose: tool for defining multi-container applications. docker-compose.yml: define services (containers), networks, volumes, environment. Single command: docker-compose up starts all containers. Great for development and testing. Manages container orchestration locally.
Use minimal base images (alpine, distroless). Multi-stage builds: build in one stage, copy artifacts to final. Combine RUN commands. Remove unnecessary files. Use .dockerignore. Cache layers efficiently. Smaller images: faster transfer, less storage, better security.
Volumes: persistent storage outside container. Attach to containers, survive container deletion. Types: named volumes, bind mounts, tmpfs. Networking: containers connect to networks. Default bridge network, custom networks. Containers can communicate by name.
Docker Hub: cloud-based registry where Docker images are stored and shared. Largest repository of Docker images. Push images: docker push username/image:tag. Pull images: docker pull username/image:tag. Public and private repositories. Official images: verified, well-maintained. Use for sharing images with team or public.
Git: version control system used to track changes in code and manage source code history locally. Enables collaboration, branching, merging. Commands: git add, git commit, git push, git pull. GitHub: cloud platform used to host Git repositories and collaborate with other developers. Provides pull requests, code review, issue tracking, CI/CD integration.
Tag image: docker tag image:tag registry/image:tag. Login: docker login. Push: docker push registry/image:tag. Pull: docker pull registry/image:tag. Registry: Docker Hub (default), private registry. Organize with namespaces.
Run as non-root user. Scan images for vulnerabilities. Use read-only filesystem when possible. Limit resources (CPU, memory). Use secrets for sensitive data. Keep base images updated. Minimize attack surface. Monitor containers.
docker ps: list containers. docker logs: view output. docker exec -it container bash: enter container. docker inspect: view configuration. docker stats: monitor resources. Use logging drivers (json-file, splunk). Implement health checks.
Bridge (default): containers on private network. Host: container shares host network. Overlay: multi-host networking (Swarm/Kubernetes). Macvlan: containers get MAC addresses. None: no networking. Choose based on needs. Custom bridge networks enable DNS name resolution.