Docker Cheatsheet
Cheatsheet · 28 Sep 2026
AI-generated Written with AI, solely for personal reference.
Docker packages an app with everything it needs to run, so it behaves the same on any machine.
- Image: a read-only template (your app, its runtime and its dependencies). Built from a
Dockerfile. - Container: a running instance of an image. You can run many containers from one image.
- Volume: storage that outlives containers, for databases and other data you want to keep.
- Network: lets containers talk to each other by name.
Images
| Command | What it does |
|---|---|
docker pull nginx:latest |
Download an image |
docker images |
List local images |
docker build -t myapp:1.0 . |
Build an image from the Dockerfile in this folder |
docker tag myapp:1.0 user/myapp:1.0 |
Give an image another name, e.g. for a registry |
docker login |
Sign in to a registry (Docker Hub by default) |
docker push user/myapp:1.0 |
Upload an image to a registry |
docker history myapp:1.0 |
Show the layers an image was built from |
docker rmi myapp:1.0 |
Remove an image |
Running containers
docker run -d --name web -p 8080:80 nginx
| Flag | What it does |
|---|---|
-d |
Run in the background (detached) |
--name web |
Name the container, so you can refer to it as web |
-p 8080:80 |
Publish a port: host 8080 → container 80 |
-e KEY=value |
Set an environment variable |
--env-file .env |
Load environment variables from a file |
-v data:/app/data |
Mount a volume or folder (see Storage) |
-it |
Interactive terminal, for shells: docker run -it ubuntu bash |
--rm |
Delete the container when it stops |
--network mynet |
Join a network |
-w /app |
Set the working directory inside the container |
--restart unless-stopped |
Restart automatically, e.g. after a reboot |
Managing containers
| Command | What it does |
|---|---|
docker ps |
List running containers |
docker ps -a |
List all containers, including stopped ones |
docker stop web / docker start web |
Stop / start a container |
docker restart web |
Restart a container |
docker rm web |
Remove a stopped container (-f to force a running one) |
docker logs -f web |
Follow a container’s output (-n 100 for the last 100 lines) |
docker exec -it web sh |
Open a shell inside a running container |
docker cp web:/etc/nginx/nginx.conf . |
Copy a file out of a container (or in, reversed) |
docker inspect web |
Full details: IP address, mounts, settings |
docker stats |
Live CPU and memory use |
If an image has no bash, use sh.
A starter Dockerfile
# Start from an official Python image
FROM python:3.13-slim
# Work in /app inside the image
WORKDIR /app
# Install dependencies first, so Docker can cache this step
COPY requirements.txt .
RUN pip install --no-cache-dir -r requirements.txt
# Then copy the rest of the code
COPY . .
# Document the port and set the start command
EXPOSE 8000
CMD ["python", "app.py"]
Build and run it:
docker build -t myapp .
docker run -d --name myapp -p 8000:8000 myapp
Add a .dockerignore next to it to keep junk out of the image:
.git
__pycache__/
.venv/
.env
Why this order? Each instruction makes a cached layer. Copying requirements.txt and installing before copying the code means a code change doesn’t reinstall every dependency.
Storage: volumes and bind mounts
| Command | What it does |
|---|---|
docker volume create pgdata |
Create a named volume |
docker volume ls |
List volumes |
docker volume rm pgdata |
Remove a volume (deletes its data) |
docker run -v pgdata:/var/lib/postgresql/data postgres |
Volume: Docker-managed storage that survives the container |
docker run -v "$(pwd)":/app myapp |
Bind mount: share a folder from your machine, handy for live code edits |
Networks
Containers on the same user-created network can reach each other by container name.
docker network create mynet
docker run -d --name db --network mynet -e POSTGRES_PASSWORD=secret postgres
docker run -d --name api --network mynet myapp # the app connects to host "db"
| Command | What it does |
|---|---|
docker network ls |
List networks |
docker network connect mynet web |
Add a running container to a network |
docker network rm mynet |
Remove a network |
Docker Compose
Compose runs a multi-container app from one file, compose.yaml:
services:
api:
build: .
ports:
- "8000:8000"
environment:
DATABASE_URL: postgres://postgres:secret@db:5432/postgres
depends_on:
- db
db:
image: postgres:17
environment:
POSTGRES_PASSWORD: secret
volumes:
- pgdata:/var/lib/postgresql/data
volumes:
pgdata:
Services share a network automatically, so api reaches the database at host db.
| Command | What it does |
|---|---|
docker compose up -d |
Start everything in the background |
docker compose up -d --build |
Rebuild images first, then start |
docker compose ps |
List the app’s containers |
docker compose logs -f api |
Follow one service’s logs |
docker compose exec api sh |
Open a shell in a running service |
docker compose restart api |
Restart one service |
docker compose down |
Stop and remove the containers and network |
docker compose down -v |
Also delete the named volumes (deletes data) |
Cleaning up
| Command | What it removes |
|---|---|
docker system df |
Nothing: shows how much space Docker uses |
docker container prune |
Stopped containers |
docker image prune |
Dangling images (untagged leftovers from builds) |
docker image prune -a |
All images not used by a container |
docker volume prune |
Unused anonymous volumes (-a for all unused volumes, deletes data) |
docker system prune |
Stopped containers, unused networks, dangling images and build cache |
docker system prune -a --volumes |
All of the above plus unused images and anonymous volumes |
Every prune command asks for confirmation first; add -f to skip it.