Click to Contract/Expend
- Docker Client (Docker CLI): Tool that we are going to issue commands to
- Docker Server (Docker Deamon): Tool that is responsible for creating images, running, containers, etc
- Docker Machine
- Docker Image
- Docker Container
- Docker Hub
- Docker Compose
docker version
docker run hello-world- Kernel: opens endpoints to allocate hardware resources such as HD, memory and network
- Namespacing: Isolating resources per process (or group of processes)
- Control Groups(cgroups): Limit amount of resources used per process
namespacing and cgroups belong to linux system
Docker Server is based on linux virtual machine
So it would have several containers and they communicate via Linux Kernel
docker run hello-worlddocker run busybox echo hi there
docker run busybox ls
docker run busybox ls binwhy busybox, not hello-world?
-> hello-world doesn't contain all of them, but only one single file for hello-world
docker ps
docker run busybox ping google.com
docker ps
docker ps --alldocker run = docker create + docker start
docker create hello-world
# 345e9a72706489ad455541d2d2c55991d28f85b63233a847dee307fec4e3a9be
docker start -a 345e9a72706489ad455541d2d2c55991d28f85b63233a847dee307fec4e3a9bedocker ps -a
# | CONTAINER ID | IMAGE | COMMAND | CREATED | STATUS | PORTS | NAMES |
# | :----------: | :-----: | :------: | :------------: | :-----------------------: | :------------: | :---: |
# | 71e182459e15 | busybox | "ls bin" | 13 minutes ago | Exited (0) 33 seconds ago | stoic_meninsky | |
docker start -a 71e182459e15
docker start -a stoic_meninskydocker system prune
# WARNING! This will remove:
# - all stopped containers
# - all networks not used by at least one container
# - all dangling images
# - all dangling build cache
docker container prunedocker create busybox echo hi there
# 5307aeeb3432e854ed7eb2a6884e4336cb71bea8be64e50076f8870beb7c5e35
docker ps -a
# | CONTAINER ID | IMAGE | COMMAND | CREATED | STATUS | PORTS | NAMES |
# | :----------: | :-----: | :-------------: | :------------: | :-----: | :---: | :-----------: |
# | 5307aeeb3432 | busybox | "echo hi there" | 28 seconds ago | Created | | peaceful_benz |
docker start 5307aeeb3432e854ed7eb2a6884e4336cb71bea8be64e50076f8870beb7c5e35
docker container ls -a
# | CONTAINER ID | IMAGE | COMMAND | CREATED | STATUS | PORTS | NAMES |
# | :----------: | :-----: | :-------------: | :------------: | :----------------------: | :---: | :-----------: |
# | 5307aeeb3432 | busybox | "echo hi there" | 53 seconds ago | Exited (0) 2 seconds ago | | peaceful_benz |
docker logs 5307aeeb3432
# hi theredocker create busybox ping google.com
# 0547fcddf48255831fc4695fba2c49426237b229746edb94fb4c7620ef186bcf
docker start 0547fcddf48255831fc4695fba2c49426237b229746edb94fb4c7620ef186bcf
docker logs 0547fcddf48255831fc4695fba2c49426237b229746edb94fb4c7620ef186bcf
docker ps- Stop a Container:
docker stop <container id>- stop ->
SIGTERM-> give a little bit of time to shut it down and clean up - The SIGTERM signal is a generic signal used to cause program termination. Unlike SIGKILL, this signal can be blocked, handled, and ignored. It is the normal way to politely ask a program to terminate.
- with
docker stopcommand, if the container is not automatically stopped in 10 seconds,docker killwill be executed.
- stop ->
- Kill a Container:
docker kill <container id>- kill ->
SIGKILL-> shutdown immediately - The SIGKILL signal is used to cause immediate program termination. It cannot be handled or ignored, and is therefore always fatal. It is also not possible to block this signal.
- kill ->
Termination Signals (The GNU C Library)
docker stop 0547fcddf482
# ping command doesn't really react to stop(SIGTERM) command
# so kill will be executed
docker start 0547fcddf482
docker kill 0547fcddf482# already installed redis via brew
redis-server
redis-cli
set mynumber 5
get mynumber
# 5docker run redisdocker exec -it <container id> <command>
docker run redis
docker ps
docker exec -it 73b7e60d4626 redis-cli
# [127.0.0.1:6379>- STDIN
- STDOUT
- STDERR
-i, --interactive Keep STDIN open even if not attached
--privileged Give extended privileges to the command
-t, --tty Allocate a pseudo-TTY
docker exec -i 73b7e60d4626 redis-cli
# it's attached but it doens't have pretty/helping terminal supportdocker exec -it 73b7e60d4626 sh
cd /
ls
# bin boot data dev etc home lib lib64 media mnt opt proc root run sbin srv sys tmp usr var
echo hi there
# hi there
export b=5
echo $b
redis-cli
# [127.0.0.1:6379>
Ctrl + D (to exit)- bash
- powershell
- zsh
- sh
Traditionally most containers have
shincluded, but some havebash
docker run -it busybox sh
ping google.com
docker run -it busybox sh
# In a new tab
docker run -it busybox sh
touch hithere
lsIf I run two containers and I create a new file on one, basically they don't share file system.
- Build images with BuildKit
- Specifying external cache sources
- Advanced Dockerfiles: Faster Builds and Smaller Images Using BuildKit and Multistage Builds
# 24-docker/01-redis-image
docker build .
docker run 62d17fb20f2136049f12adbefc57552b347a96849cd918d4e7b78ec9bfcca00d# Use an existing docker image as a base
FROM alpine
# Download and install a dependency
RUN apk add --update redis
# Tell the image what to do when it starts as a container
CMD ["redis-server"]- alpine: A minimal Docker image based on Alpine Linux with a complete package index and only 5 MB in size
- apk: Alpine Linux package manager
docker build .: give me docker image out of docker cli
the build result between option "buildkit": true and "buildkit": false are different.
# "buildkit": true
noah@Noahs-MacBook-Pro 01-redis-image % docker build .
[+] Building 13.2s (7/7) FINISHED
=> [internal] load build definition from Dockerfile 0.1s
=> => transferring dockerfile: 240B 0.0s
=> [internal] load .dockerignore 0.0s
=> => transferring context: 2B 0.0s
=> [internal] load metadata for docker.io/library/alpine:latest 7.4s
=> [auth] library/alpine:pull token for registry-1.docker.io 0.0s
=> [1/2] FROM docker.io/library/alpine@sha256:21a3deaa0d32a8057914f36584b5288d2e5ecc984380bc0118285c70fa8c9300 1.2s
=> => resolve docker.io/library/alpine@sha256:21a3deaa0d32a8057914f36584b5288d2e5ecc984380bc0118285c70fa8c9300 0.0s
=> => sha256:59bf1c3509f33515622619af21ed55bbe26d24913cedbca106468a5fb37a50c3 2.82MB / 2.82MB 0.8s
=> => sha256:21a3deaa0d32a8057914f36584b5288d2e5ecc984380bc0118285c70fa8c9300 1.64kB / 1.64kB 0.0s
=> => sha256:e7d88de73db3d3fd9b2d63aa7f447a10fd0220b7cbf39803c803f2af9ba256b3 528B / 528B 0.0s
=> => sha256:c059bfaa849c4d8e4aecaeb3a10c2d9b3d85f5165c66ad3a4d937758128c4d18 1.47kB / 1.47kB 0.0s
=> => extracting sha256:59bf1c3509f33515622619af21ed55bbe26d24913cedbca106468a5fb37a50c3 0.3s
=> [2/2] RUN apk add --update redis 3.7s
=> exporting to image 0.5s
=> => exporting layers 0.5s
=> => writing image sha256:62d17fb20f2136049f12adbefc57552b347a96849cd918d4e7b78ec9bfcca00d 0.0s# "buildkit": false
noah@Noahs-MacBook-Pro 01-redis-image % docker build .
Sending build context to Docker daemon 2.048kB
Step 1/3 : FROM alpine
latest: Pulling from library/alpine
59bf1c3509f3: Already exists
Digest: sha256:21a3deaa0d32a8057914f36584b5288d2e5ecc984380bc0118285c70fa8c9300
Status: Downloaded newer image for alpine:latest
---> c059bfaa849c
Step 2/3 : RUN apk add --update redis
---> Running in 041ffef007ff
fetch https://dl-cdn.alpinelinux.org/alpine/v3.15/main/x86_64/APKINDEX.tar.gz
fetch https://dl-cdn.alpinelinux.org/alpine/v3.15/community/x86_64/APKINDEX.tar.gz
(1/1) Installing redis (6.2.6-r0)
Executing redis-6.2.6-r0.pre-install
Executing redis-6.2.6-r0.post-install
Executing busybox-1.34.1-r3.trigger
OK: 8 MiB in 15 packages
Removing intermediate container 041ffef007ff
---> 505677ae7f28
Step 3/3 : CMD ["redis-server"]
---> Running in 59d6409a9a32
Removing intermediate container 59d6409a9a32
---> bc5303779113
Successfully built bc5303779113- Each step except step 1, follows this process
- Create a new temporary container based on an image from the previous step
- Execute command
- Remove the temporary container
- Create a new image based on the result
RUN apk add --update gcc
noah@Noahs-MacBook-Pro 01-redis-image % docker build .
Sending build context to Docker daemon 2.048kB
Step 1/4 : FROM alpine
---> c059bfaa849c
Step 2/4 : RUN apk add --update redis
---> Using cache
---> 505677ae7f28
Step 3/4 : RUN apk add --update gcc
---> Running in 4063e9253202
fetch https://dl-cdn.alpinelinux.org/alpine/v3.15/main/x86_64/APKINDEX.tar.gz
fetch https://dl-cdn.alpinelinux.org/alpine/v3.15/community/x86_64/APKINDEX.tar.gz
(1/11) Installing libgcc (10.3.1_git20211027-r0)
(2/11) Installing libstdc++ (10.3.1_git20211027-r0)
(3/11) Installing binutils (2.37-r3)
(4/11) Installing libgomp (10.3.1_git20211027-r0)
(5/11) Installing libatomic (10.3.1_git20211027-r0)
(6/11) Installing libgphobos (10.3.1_git20211027-r0)
(7/11) Installing gmp (6.2.1-r0)
(8/11) Installing isl22 (0.22-r0)
(9/11) Installing mpfr4 (4.1.0-r0)
(10/11) Installing mpc1 (1.2.1-r0)
(11/11) Installing gcc (10.3.1_git20211027-r0)
Executing busybox-1.34.1-r3.trigger
OK: 118 MiB in 26 packages
Removing intermediate container 4063e9253202
---> 83fc43ba34a6
Step 4/4 : CMD ["redis-server"]
---> Running in e36ad7baea5f
Removing intermediate container e36ad7baea5f
---> 44f7d19aff95
Successfully built 44f7d19aff95RUN apk add --update redis
RUN apk add --update gcc
⬇️
RUN apk add --update gcc
RUN apk add --update redis
if the series of order changes, we cannot use cache and it will build all again
docker build -t pcsmomo/redis:latest .
pcsmomo/redis:latest- pcsmomo: my docker id
- redis: repo/project name
- latest: version
docker build -t pcsmomo/redis:latest .
docker run pcsmomo/redisJust for Practice Manual Image generation
docker run -it alpine sh
apk add --update redis
# new tab
docker ps
# | CONTAINER ID | IMAGE | COMMAND | CREATED | STATUS | PORTS | NAMES |
# | :----------: | :-----: | :-------------: | :----------------: | :----------------------: | :---: | :-----------: |
# | 5f943d0f3d3a | alpine | "sh" | About a minute ago | Up About a minute | | sweet_pascal |
docker commit -c 'CMD ["redis-server"]' 5f943d0f3d3a
# sha256:c01e6d5982bc36560e9d6e65d6cf5ca1758418e06a04eb7b343b899a4fd9d178
docker run c01e6d5982bc3we don't have to copy all the full sha256 strings. Just unique enough is fine
mkdir 02-simpleweb
cd 02-simpleweb
touch package.jsondocker build .
# /bin/sh: npm: not foundnode:alpine- alpine : small and compact version
docker build .
# npm ERR! Tracker "idealTree" already existscopy source dest (source: my side side first)
copy ./ ./
docker build -t pcsmomo/simpleweb .
docker run pcsmomo/simpleweb
# navigate localhost:8080 -> This site can’t be reacheddocker run -p 8080:8080 pcsmomo/simpleweb
# 8080:8080, first my side:container side later
docker run -p 5000:8080 pcsmomo/simplewebWORKDIR /usr/app- if not specifying this, it will do all the instructions such as copy/install on the 'root' directory
# working on shell when running
docker run -it pcsmomo/simpleweb sh# "exec", working on shell if the app is running
docker run -p 8080:8080 pcsmomo/simpleweb
docker ps
docker exec -it 81f2ed1aebd7 sh# Install some dependencies
COPY ./package.json ./
RUN npm install
COPY ./ ./