Docker Q1: A container exits immediately after starting How do you debug it [L1]
docker logs <container-id> — read why it exited. Use docker run -it <image> sh to start interactively. Check the entrypoint/cmd. Common c......
Master 105+ battle-tested scenario-based Docker & Containers interview questions for Senior DevOps, Cloud, and SRE engineers. Includes incident runbooks, STAR talking points, and CLI commands.
docker logs <container-id> — read why it exited. Use docker run -it <image> sh to start interactively. Check the entrypoint/cmd. Common c......
Clean up: docker system prune -af removes unused images, containers, volumes, build cache. docker images | grep '<none>' finds dangling i......
By default, containers are isolated. They need to be on the same Docker network. Create a network: docker network create app-net. Run bot......
Multi-stage build (build artifact in fat builder image, copy only artifact to slim runtime). Use alpine-based images. Clean up package ma......
Same pod: share network namespace → communicate via localhost. Different pods: need a Kubernetes Service. Direct pod IP works but is ephe......
Install NVIDIA Container Toolkit on the host. Run with --gpus all or --gpus '"device=0"'. In Docker Compose: deploy: resources: reservati......
docker update --cpus="1.5" <container> — limit to 1.5 CPU cores. Also --memory="512m" for memory limit. For Kubernetes, update the res...
COPY: copies files from build context to image. Simple and explicit. ADD: same as COPY but also supports URLs and auto-extracts tar archi......
dockerfile...
ENTRYPOINT defines the main command that always runs. CMD provides default arguments. If ENTRYPOINT is ["nginx"] and CMD is ["-g", "dae...
Bind mount: docker run -v /host/path:/container/path. Volume: docker run -v myvolume:/container/path (Docker manages storage location). U......
Docker Compose. Define all services in docker-compose.yml. docker-compose up starts everything. Auto-creates networks, manages startup or......
The container's PID 1 (init process) is still running but the app process (a child) crashed. If using shell scripts as entrypoint, the sh......
docker stats — live stream of CPU%, memory, network I/O, block I/O per container. docker stats --no-stream for a one-time snapshot. For h......
depends_on only waits for container start, not for the service inside to be ready....
BuildKit is the modern Docker build backend. Benefits: parallel layer building (faster), better caching, secret mounts (pass secrets to b......
BuildKit secret mounts:...
docker stop sends SIGTERM, waits 10 seconds (configurable), then SIGKILL. App can handle SIGTERM for graceful shutdown. docker kill sends......
docker inspect <container> — full JSON config including environment variables, mounts, network, etc. docker exec <container> env — shows ......
- bridge (default) — container gets its own IP on a virtual network. Containers talk via bridge or by name (user-defined networks)....
docker exec -it <container> bash or sh if bash isn't available....
Image = read-only template (blueprint). Container = running instance of an image....
docker cp <container>:/path/to/file /host/path....
Stale package lists or network issue. Add --no-cache to Docker build or restructure to always apt-get update && apt-get install in the sa......
Multiple FROM statements in one Dockerfile. Build artifacts in a heavy build stage, copy only what's needed to a slim runtime stage. Fina......
docker run -e DB_HOST=localhost or docker run --env-file .env. For Compose: environment: key or env_file: key....
Mount a volume and use a log shipper sidecar to read and forward the file. Or configure the app to write to stdout. Containers should wri......
trivy image <image> — scans OS packages and app libraries for CVEs. Integrate in CI: fail the pipeline on HIGH/CRITICAL findings. Also: d......
Excludes files from the Docker build context. Smaller context = faster builds. Prevents accidentally copying secrets, .git, node_modules ......
In Dockerfile: HEALTHCHECK --interval=30s --timeout=3s CMD curl -f http://localhost/health || exit 1. Docker marks container as healthy o......
Docker Buildx with QEMU emulation: docker buildx build --platform linux/amd64,linux/arm64 -t myimage:latest --push . Creates a multi-arch......
docker login <registry>. docker tag myimage:latest <registry>/myimage:latest. docker push <registry>/myimage:latest....
Documents which port the container listens on. Doesn't actually publish the port. To publish: docker run -p 8080:3000 myimage. EXPOSE is ......
Docker Compose is not recommended for production at scale. For production: Kubernetes (EKS/GKE/AKS), ECS, or Docker Swarm (simpler than K......
Add arguments after the image name: docker run myimage custom-command --flag. This replaces CMD. To override ENTRYPOINT: docker run --ent......
docker run --init runs a tiny init process (tini) as PID 1. This properly handles zombie process reaping and signal forwarding. Without i......
Override the entrypoint to sleep: docker run --entrypoint sleep myimage 300. Then exec in and investigate. Or: docker run --entrypoint /b......
Docker reuses unchanged layers from cache. Layers that change early in the Dockerfile invalidate all subsequent layers. Put slow-changing......
docker top <container> — shows running processes. docker exec <container> ps aux for more detail....
DCT allows image publishers to sign images and consumers to verify signatures. DOCKER_CONTENT_TRUST=1 enforces that only signed images ca......
An untagged image (shows as <none>:<none>). Created when you build a new image with the same tag — the old layers lose their tag. Clean u......
Under deploy.resources.limits: cpus: '0.5' and memory: 512M. Note: deploy key is only respected by Swarm mode; for regular Compose use me......
Each container gets a network namespace. A virtual ethernet pair (veth) connects the container's namespace to a Linux bridge (docker0). i......
docker-compose build <service> then docker-compose up -d <service>. Compose won't rebuild services that haven't changed unless you add --....
up starts all services defined in the compose file as long-running services. run runs a one-off command in a service container: docker-co......
Mounting the Docker socket (/var/run/docker.sock) gives the container full control over the Docker daemon — effectively root on the host.......
Update the image tag in the deployment to the previous version's tag. kubectl set image deployment/app container=registry/app:v1.2.3. Or ......
Docker Swarm is Docker's built-in orchestration. Simpler to set up and use than Kubernetes. Less features (no Ingress, limited scheduling......
Use BuildKit's --build-context to pass multiple directories as build context. Use cache mounts for shared dependencies. Or extract shared......
docker run --restart=unless-stopped — restarts always except when manually stopped. Or --restart=always. Docker Compose: restart: unless-......
Creates a new image from a running container's current state. Rarely used in production (not reproducible). Use it for: quick debugging s......
ARG VERSION=latest in Dockerfile. Build: docker build --build-arg VERSION=1.2.3 .. ARG values are available only at build time, not at ru......
ECR lifecycle policies: keep only last N images, delete untagged images after X days. aws ecr put-lifecycle-policy --lifecycle-policy-tex......
docker save myimage > image.tar — exports image to a tar file. docker load < image.tar — imports it. Use for air-gapped environments (no ......
Drop all capabilities, add only needed ones:...
docker history <image> — shows each layer, its size, and the command that created it. Use --no-trunc to see full commands. dive <image> f......
VOLUME /data in Dockerfile tells Docker this path should be a volume. Docker auto-creates an anonymous volume at that path if none is pro......
Docker Compose in CI (all services started via compose). Or CI service containers (GitHub Actions services, GitLab CI services). Or testc......
docker network inspect <network> — see which containers are on the network. From one container: ping <other-container-name> (if on same u......
Privileged containers can access all devices, modify kernel parameters, and escape the container namespace. They have near-root access to......
If they bind-mounted a single file (e.g., -v /path/to/app.py:/app/app.py) instead of a directory, the issue is how modern text editors (l......
Docker bypasses UFW by design....
Exit code 137 specifically means the container received a SIGKILL (signal 9) and was abruptly terminated ($128 + 9 = 137$)....
You cannot exec a shell if the shell binary literally doesn't exist inside the container. You must inject tools from the outside using Li......
The container is exhausting its Shared Memory (/dev/shm) limit....
Dockerfile instructions like COPY, RUN, and ADD create immutable, read-only layers....
Using standard Docker Storage Drivers (like overlay2) or traversing file-system boundaries for massive, high-IOPS write-heavy database wo......
A Docker container strictly lives only as long as its primary PID 1 process is running....
Using the latest tag makes it a mutable tag. ...
Passing secrets via Environment Variables (-e) is insecure because:...
Containers do not automatically inherit the ulimit settings from the user space of the host operating system. The Docker daemon manages i......
You would use the docker inspect command to query the detailed metadata json....
You need to use a BuildKit persistent cache mount for the dependency directory. This allows the compiler to share an explicit cache folde......
By default, processes inside the container execute as the root user (UID 0). ...
The default docker0 bridge network utilizes the 172.17.0.0/16 subnet, which provides approximately 65,534 IP addresses. ...
This brutally violates the principle of Immutable Infrastructure and destroys startup agility....
A Dangling Volume is an orphaned Docker volume that is no longer attached to any active or stopped container....
No, Docker containers natively are not Virtual Machines....
This is historically managed by Docker Content Trust (DCT), effectively backed by the Notary service. By enabling export DOCKER_CONTENT_T......
Docker Desktop on Windows heavily masks the truth. To run Linux containers, it actually boots a hidden Linux VM deeply in the background ......
By default, every Docker container gets its own isolated PID namespace, meaning each container can only see its own processes (its PID 1 ......
The container is likely running out of inodes, not disk space. The overlay2 filesystem has a finite number of inodes, and millions of sma......
Docker stores credentials per registry in ~/.docker/config.json, and you do NOT need to log out of one registry to use another. Each dock......
Docker containers on user-defined networks use Docker's embedded DNS server (127.0.0.11). On the default bridge network, containers inher......
docker system prune only removes objects tracked by the Docker daemon (images, containers, volumes, build cache). If the Docker daemon cr......
Use Rootless Docker, which runs the Docker daemon and all containers entirely within a user's namespace without requiring root privileges......
Use the --target flag to build only up to the test stage, and structure the Dockerfile so the test report is generated before the asserti......
The application or its runtime is writing files to the container's writable layer (the thin read-write layer on top of the image layers).......
Mounting the Docker socket gives the inner container full root-equivalent access to the host. Secure alternatives:...
Docker's default json-file logging driver stores container stdout/stderr as JSON files under /var/lib/docker/containers/<id>/. Without li......
Use the --read-only flag to make the entire root filesystem read-only:...
Docker has experimental support for checkpoint and restore using CRIU (Checkpoint/Restore In Userspace). CRIU freezes a running process, ......
Before executing any Dockerfile instruction, Docker packages the entire build context (the directory passed to docker build) and transfer......
Use Compose Profiles (introduced in Docker Compose v1.28):...
Inside a container, localhost refers to the container's own loopback interface, not the host's. The container and host have separate netw......
Docker Hub enforces pull rate limits: anonymous users get 100 pulls per 6 hours per IP, authenticated free users get 200. CI servers shar......
Use docker manifest inspect to query the registry's manifest list without downloading any image layers:...
When Docker sends SIGTERM via docker stop, it delivers the signal to PID 1 inside the container. If PID 1 is a shell script (/bin/sh or /......
Use docker diff <container> to inspect the container's writable layer against its base image:...
Use network aliases to assign additional DNS names to a container on a specific network:...
How to architect and operate Docker workloads across multiple clouds (AWS, Azure, GCP): multi-architecture image builds (buildx), centralized artifact registrie...
Layered observability architecture for container performance in production: diagnosing cgroup CPU throttling, memory working sets, cAdvisor and Prometheus metri...
How to write a production-ready, highly secure multi-stage Dockerfile during a live screen-sharing interview: separate dependency caching, compilation, unprivil...
Business and architectural value realization of Docker in production: transitioning from brittle snowflake servers to immutable container artifacts, eliminating...
Comprehensive container image security and repository governance: automated CI vulnerability scanning with Trivy, image signing via Cosign, AWS ECR scan-on-push...