Docker is a containerization platform that allows developers and DevOps engineers to package applications with all their dependencies into isolated, lightweight environments called containers.
Containers ensure consistency across environments — whether you’re deploying locally, on AWS, or in Kubernetes.
They boot fast, use fewer resources than virtual machines, and are the foundation for modern DevOps, CI/CD, and microservices architectures.
Answer:
Docker is a platform that automates deploying applications inside lightweight, portable containers.
In DevOps, Docker helps to:
Example:
Running a Node.js app on any machine:
docker run -d -p 3000:3000 node:18
Answer:
Think of an image as a “class” and a container as an “object” created from that class.
Example:
docker pull nginx # downloads the image
docker run -d nginx # creates a running container
Answer:
A Dockerfile is a text document that defines how to build a Docker image step-by-step.
Example:
FROM node:18
WORKDIR /app
COPY . .
RUN npm install
CMD ["npm", "start"]
In DevOps:
Dockerfiles make application builds automated and reproducible. They’re essential for CI/CD pipelines where each build creates an image version tagged by commit or release.
Answer:
Docker consists of:
dockerd) – runs in the background and manages images, containers, networks, etc.docker) – CLI tool to communicate with the daemon.Answer:
docker ps
(Add -a to show all containers, including stopped ones.)
docker images
In real-world DevOps pipelines, these are used to verify what’s running before deploying updates or performing cleanups.
EXPOSE instruction do in a Dockerfile?Answer:
EXPOSE tells Docker which port the container listens on at runtime.
Example:
EXPOSE 8080
Note: It doesn’t publish the port automatically — it’s just documentation.
To expose externally:
docker run -p 8080:8080 myapp
Answer:
By using volumes or bind mounts.
Example:
docker run -v /host/data:/container/data nginx
Why it matters:
Persistent storage is key when containers need to retain data (e.g., databases, logs, uploaded files).
Answer:
docker logs <container_id>
To follow logs in real-time:
docker logs -f <container_id>
Use case:
When debugging a failed deployment or checking microservice interactions in a CI/CD pipeline.
Answer:
docker stop <container_id>
docker rm <container_id>
docker rmi <image_id>
To clean up all unused resources:
docker system prune -af
Answer:
| Feature | Docker | Virtual Machine |
|---|---|---|
| Isolation | OS-level | Hardware-level |
| Boot Time | Seconds | Minutes |
| Size | MBs | GBs |
| Performance | Lightweight | Heavy |
| Use Case | Microservices, CI/CD | Legacy workloads |
In DevOps:
Docker replaces most VM use cases for speed and efficiency.
Answer:
docker build -t myapp:1.0 .
This command builds an image using the Dockerfile in the current directory and tags it myapp:1.0.
In CI/CD, tags often correspond to build versions or Git commit hashes for traceability:
docker build -t myapp:${BUILD_NUMBER} .
Answer:
docker tag myapp:1.0 username/myapp:1.0
docker push username/myapp:1.0
For AWS ECR:
aws ecr get-login-password | docker login --username AWS --password-stdin <ECR_URL>
docker push <ECR_URL>/myapp:latest
Why it matters:
This process automates artifact storage, which is central to CI/CD pipelines.
Answer:
Docker Compose is a tool for defining and running multi-container applications using a YAML file.
Example docker-compose.yml:
version: "3"
services:
web:
image: nginx
ports:
- "80:80"
db:
image: mongo
volumes:
- db_data:/data/db
volumes:
db_data:
Use case:
Developers can start a full app stack (frontend + backend + database) with one command:
docker-compose up -d
Answer:
Modern Docker uses user-defined networks instead of legacy --link.
Example:
docker network create mynetwork
docker run -d --network mynetwork --name db mongo
docker run -d --network mynetwork --name app myapp
Containers can now communicate using names (e.g., mongodb://db:27017).
COPY and ADD in Dockerfile?Answer:
COPY: Copies files/folders from host to image.ADD: Does the same but can also handle remote URLs and auto-extract archives.Example:
COPY . /app
Best Practice:
Use COPY for predictable behavior — ADD can unintentionally extract files.
Answer:
alpine.RUN apt-get update && apt-get install -y curl && rm -rf /var/lib/apt/lists/*
Impact:
Smaller images = faster builds, deployments, and cost savings on registries.
Answer:
docker stats
Displays real-time CPU, memory, and network metrics for containers.
In production, these stats are exported to monitoring tools like Prometheus, Grafana, or AWS CloudWatch.
Answer:
docker logs <container_id>
docker inspect <container_id>
docker run -it <image> /bin/bash
Common causes:
Answer:
Bind mount a host directory to store logs:
docker run -d -v /host/logs:/var/log/app myapp
Or configure logging drivers:
docker run --log-driver json-file --log-opt max-size=10m myapp
In production, logs are centralized with Fluentd, ELK, or CloudWatch Logs.
Answer:
docker pull myapp:latest
DevOps practice:
This pattern is known as blue-green deployment — used for zero-downtime rollouts.
Answer:
Avoid hardcoding sensitive data in Dockerfiles. Use:
.env files (for local dev)docker run -e DB_USER=admin -e DB_PASS=$PASSWORD myapp
In production, secrets should come from AWS Secrets Manager or HashiCorp Vault.
Answer:
| Directive | Purpose |
|---|---|
| ENTRYPOINT | Defines the main executable for the container. |
| CMD | Provides default arguments to ENTRYPOINT or acts as fallback. |
Example:
ENTRYPOINT ["python3", "app.py"]
CMD ["--debug"]
You can override CMD at runtime:
docker run myapp --prod
Answer:
Use the HEALTHCHECK instruction in Dockerfile:
HEALTHCHECK CMD curl -f http://localhost:3000/health || exit 1
Why it matters:
Ensures container orchestration tools (like ECS or Kubernetes) can detect unhealthy containers and replace them automatically.
Answer:
FROM node:18 AS builder
WORKDIR /app
COPY . .
RUN npm install && npm run buildFROM nginx:alpinedocker build --build-arg ENV=prod -t app:prod .
Result:
Faster build times, smaller images, and optimized pipelines.
Answer:
docker network ls
docker inspect -f '{{range.NetworkSettings.Networks}}{{.IPAddress}}{{end}}' container_name
docker exec -it app ping db
curl or netstat to test endpoints.In production:
Networking issues often arise when microservices cannot communicate — these checks isolate problems fast.
Answer:
Use centralized log management:
fluentd, gelf, awslogs)docker run --log-driver awslogs --log-opt awslogs-group=myapp myapp
Why it matters:
In microservices, container-level logs must be aggregated for traceability and compliance.
Answer:
USER appuser
--cap-drop.DevOps Impact:
Security breaches in containers can compromise entire clusters — prevention is key.
Answer:
Example Jenkins pipeline:
pipeline {
agent any
stages {
stage('Build') {
steps {
sh 'docker build -t myapp:${BUILD_NUMBER} .'
}
}
stage('Test') {
steps {
sh 'docker run myapp:${BUILD_NUMBER} npm test'
}
}
stage('Push') {
steps {
sh 'docker push myapp:${BUILD_NUMBER}'
}
}
}
}
Why it’s important:
Automating Docker image builds ensures every deployment is versioned and reproducible.
Q: A Dockerized web app crashed during deployment because “port already in use” errors appeared. How did you handle it?
Answer (STAR):
docker ps to find the container using port 80.docker stop <container_id>.netstat -tuln | grep 80.Q: You noticed Docker images in your registry have become too large, slowing deployments. What did you do?
Answer (STAR):
ubuntu to alpine.app:slim).