Docker
Docker
Beginner
Q1: What is Docker?
Docker is a platform for building, shipping, and running applications in containers.
Q2: What is a container?
A lightweight isolated process with its own filesystem, network, and runtime settings.
Q3: Container vs virtual machine?
Containers share host kernel; VMs emulate full OS with separate kernels.
Q4: Why are containers popular?
Fast startup, portability, efficient resource usage, and consistent environments.
Q5: What is a Docker image?
Immutable template containing app code, runtime, libraries, and metadata.
Q6: What is a Docker container instance?
A running (or stopped) instantiation of an image.
Q7: What is Docker Engine?
Core runtime (daemon + APIs) managing images, containers, networks, and volumes.
Q8: What is Docker daemon?
Background service (dockerd) handling container lifecycle operations.
Q9: What is Docker CLI?
Command-line client that talks to Docker daemon API.
Q10: What is Dockerfile?
Text file with instructions to build a Docker image.
Q11: What does FROM do in Dockerfile?
Sets base image for subsequent build steps.
Q12: What does RUN do?
Executes commands at build time, creating image layers.
Q13: What does COPY do?
Copies files from build context into image.
Q14: What does ADD do?
Like COPY plus extra features (URL/tar auto-extract), used more cautiously.
Q15: COPY vs ADD?
Prefer COPY unless ADD-specific behavior is truly needed.
Q16: What does WORKDIR do?
Sets working directory for subsequent instructions.
Q17: What does CMD do?
Defines default command/args when container starts (overridable).
Q18: What does ENTRYPOINT do?
Defines main executable for container (harder to override semantics).
Q19: CMD + ENTRYPOINT together?
ENTRYPOINT sets executable; CMD provides default arguments.
Q20: What does EXPOSE do?
Documents intended listening ports (does not publish by itself).
Q21: What does ENV do?
Sets environment variables in image/container.
Q22: What does ARG do?
Defines build-time variables available during image build.
Q23: ARG vs ENV?
ARG build-time only (unless copied into ENV); ENV available at runtime.
Q24: What is image layer?
Read-only filesystem delta created by each Dockerfile instruction.
Q25: Why layers matter?
Enable caching, reuse, and smaller incremental image transfers.
Q26: What is build context?
Directory/files sent to daemon for image build.
Q27: Why keep build context small?
Faster builds and less accidental file leakage.
Q28: What is .dockerignore?
File listing paths excluded from build context.
Q29: What is Docker Hub?
Public registry for hosting and distributing container images.
Q30: What is a container registry?
Repository service storing versioned container images.
Q31: What is image tag?
Human-friendly image version label (e.g., myapp:1.2.0).
Q32: What does latest tag mean?
Just a tag name, not guaranteed newest unless maintained that way.
Q33: What is docker pull?
Downloads image from registry.
Q34: What is docker run?
Creates and starts a new container from image.
Q35: What is docker ps?
Lists running containers (= -a= includes stopped).
Q36: What is docker stop?
Gracefully stops running container.
Q37: What is docker kill?
Forcibly terminates container process.
Q38: What is docker rm?
Removes stopped container.
Q39: What is docker rmi?
Removes image from local cache.
Q40: What is port mapping?
Publishing container port to host port (e.g., -p 8080:80).
Q41: What is docker logs?
Shows container stdout/stderr logs.
Q42: What is docker exec?
Runs command inside running container.
Q43: What is detached mode (-d)?
Runs container in background.
Q44: What is interactive mode (-it)?
Attaches terminal input/output for interactive sessions.
Q45: What is named container (–name)?
Assigns stable container name for easier management.
Q46: What is restart policy?
Rules for auto-restarting containers (e.g., unless-stopped).
Q47: What is bind mount?
Mount host path into container.
Q48: What is Docker volume?
Managed persistent storage independent from container lifecycle.
Q49: Bind mount vs volume?
Bind uses explicit host path; volume managed by Docker abstraction.
Q50: Why persistent storage needed?
Container writable layer is ephemeral and removed with container.
Q51: What is default Docker network?
Bridge network for local container connectivity.
Q52: Can containers talk by name?
Yes, on user-defined bridge networks via embedded DNS.
Q53: What is docker-compose (Compose)?
Tool for defining/running multi-container applications declaratively.
Q54: What is compose file?
YAML describing services, networks, volumes, env, and dependencies.
Q55: Why use Compose in development?
Reproducible local stacks with one command.
Q56: Common beginner Docker anti-pattern?
Running everything as root with oversized images.
Q57: Another beginner anti-pattern?
Hardcoding secrets directly in Dockerfile/image.
Q58: Beginner security baseline?
Minimal base image, non-root user, trusted image sources.
Q59: Beginner performance baseline?
Use build cache, .dockerignore, and multi-stage builds.
Q60: Beginner best practice?
Keep images small, explicit, versioned, and reproducible.
Intermediate
Q61: What is multi-stage build?
Dockerfile pattern using multiple FROM stages to separate build/runtime artifacts.
Q62: Why multi-stage builds?
Smaller final images and reduced attack surface.
Q63: What is BuildKit?
Modern Docker build backend with advanced caching and features.
Q64: BuildKit benefits?
Faster builds, better cache control, secret mounts, parallelism.
Q65: What is layer cache invalidation?
Changing one step invalidates cache for subsequent dependent layers.
Q66: How optimize cache usage?
Place rarely changed steps (deps install) before frequently changed code copy.
Q67: Why pin image versions/digests?
Reproducibility and supply-chain safety.
Q68: Tag pinning vs digest pinning?
Tags can move; digests are immutable content addresses.
Q69: What is image provenance/signing concept?
Cryptographically verifying image origin/integrity.
Q70: What is SBOM?
Software Bill of Materials listing components in image.
Q71: Why SBOM important?
Vulnerability management and compliance visibility.
Q72: What is container image scanning?
Checking image layers/dependencies for known vulnerabilities.
Q73: Can scanning eliminate all risk?
No, but it significantly reduces known exposure.
Q74: What is CVE?
Common Vulnerabilities and Exposures identifier for disclosed security flaws.
Q75: Distroless image concept?
Minimal runtime image without package manager/shell.
Q76: Distroless tradeoff?
Better security/smaller size but harder interactive debugging.
Q77: Alpine image tradeoff?
Small size, but musl-based environment may cause compatibility/perf differences for some apps.
Q78: What is healthcheck in Dockerfile?
Command Docker runs to determine container health.
Q79: Why health checks matter?
Enable orchestrators/scripts to detect unhealthy instances.
Q80: What is ENTRYPOINT exec form?
JSON-array syntax preferred for signal handling and argument safety.
Q81: Shell form vs exec form?
Shell form runs through shell; exec form runs process directly.
Q82: Why PID 1 behavior matters in containers?
PID 1 has special signal/reaping responsibilities.
Q83: What is init process need in containers?
Small init helps forward signals and reap zombies.
Q84: What is TTY allocation pitfall in production?
Can alter buffering/signal behavior unexpectedly.
Q85: What is container exit code?
Process return code indicating success/failure cause.
Q86: What is tmpfs mount?
In-memory filesystem mount for ephemeral sensitive/temp data.
Q87: What is read-only root filesystem?
Security hardening by preventing writes to image filesystem.
Q88: How allow writes with read-only root?
Use writable volumes/tmpfs for required paths.
Q89: What are Linux capabilities in Docker?
Fine-grained kernel privileges assignable to containers.
Q90: Why drop capabilities?
Principle of least privilege reduces exploit impact.
Q91: What is seccomp profile?
Syscall filtering policy for container processes.
Q92: What is AppArmor/SELinux role?
Mandatory access control policies restricting container actions.
Q93: What is user namespace remapping?
Maps container root to non-root host UID range.
Q94: What is rootless Docker?
Running Docker daemon/containers without root privileges.
Q95: Rootless tradeoff?
Improved security with some networking/storage feature constraints.
Q96: What is cgroups in Docker context?
Kernel mechanism limiting CPU, memory, I/O resources.
Q97: What is memory limit flag use?
Prevents container from exhausting host memory.
Q98: What happens on OOM?
Kernel may kill process/container (OOMKill).
Q99: What is CPU quota/share configuration?
Controls CPU time allocation across containers.
Q100: What is Docker bridge network?
NATed local network for containers on single host.
Q101: What is host network mode?
Container shares host network namespace (less isolation).
Q102: What is overlay network?
Multi-host network abstraction (commonly with orchestrators).
Q103: What is MACVLAN/IPVLAN use case?
Assign near-native network identity to containers in specific environments.
Q104: What is DNS behavior in containers?
Docker provides embedded DNS for service/container name resolution on user-defined networks.
Q105: What is volume driver?
Plugin/system enabling different volume backends.
Q106: What is named volume lifecycle?
Persists beyond container deletion until explicitly removed.
Q107: What is anonymous volume?
Unnamed volume created automatically (harder to manage).
Q108: Why avoid anonymous volumes in prod?
Can accumulate orphaned storage.
Q109: What is docker system prune?
Removes unused resources (images/containers/networks/build cache, optionally volumes).
Q110: Prune risk?
Accidental deletion of needed cache/data if used carelessly.
Q111: What is log driver in Docker?
Mechanism for routing container logs (json-file, journald, fluentd, etc.).
Q112: Why configure log rotation?
Prevent disks filling from unbounded logs.
Q113: What is docker stats?
Live resource usage metrics per container.
Q114: What is docker inspect?
Low-level JSON metadata for container/image/network/volume.
Q115: What is compose override file?
Environment-specific extension to base compose config.
Q116: What is dependson limitation in Compose?
Controls startup order, not full service readiness by itself.
Q117: What is wait-for-it/readiness pattern?
Explicitly wait for dependent service availability before start logic.
Q118: What is intermediate anti-pattern?
Using one giant mutable “pet” container instead of immutable rebuilds.
Q119: Better release pattern?
Immutable versioned images + recreate containers from new image.
Q120: What is CI/CD Docker baseline?
Build, scan, test, sign, push, deploy with rollback path.
Q121: Why avoid docker commit for releases?
Non-reproducible image creation outside source-controlled Dockerfile.
Q122: What is multi-arch image?
Single image tag supporting multiple CPU architectures.
Q123: How build multi-arch images?
Buildx with platform targets and manifest lists.
Q124: Intermediate maturity signal?
Team can explain image hardening, cache strategy, and runtime limits.
Q125: Intermediate debugging baseline?
Logs + inspect + exec + metrics + reproducible local compose.
Q126: What is intermediate reliability principle?
Assume containers are ephemeral and design statelessly where possible.
Q127: What is intermediate security principle?
Trust but verify images via scanning, signatures, and least privilege.
Q128: What is intermediate cost principle?
Optimize image size, build time, and host density.
Q129: What is intermediate operations principle?
Standardize Dockerfiles and runtime policies across services.
Q130: Intermediate best practice?
Balance developer speed with strong supply-chain and runtime controls.
Advanced
Q131: What is container supply-chain security?
Protecting build sources, dependencies, images, registries, and deployment artifacts.
Q132: What is SLSA/in-toto style provenance concept?
Attestable build provenance proving how/where artifact was produced.
Q133: Why reproducible builds matter?
Same source should yield same artifact for trust and debugging.
Q134: What is hermetic build concept?
Build isolated from uncontrolled external network/state dependencies.
Q135: What is cache poisoning risk?
Untrusted cache layers introducing compromised artifacts.
Q136: How mitigate cache poisoning?
Trusted builders, signed caches, isolated CI, provenance verification.
Q137: What is image promotion pipeline?
Move same tested digest through envs (dev→staging→prod) without rebuild.
Q138: Why promote by digest not tag?
Avoid tag drift and ensure exact artifact parity.
Q139: What is runtime drift?
Running container config/image diverges from declared desired state.
Q140: How detect runtime drift?
Continuous reconciliation and policy/audit checks.
Q141: What is policy-as-code for containers?
Automated enforcement of security/compliance rules on Dockerfiles/images/runtime specs.
Q142: Example policy checks?
No root user, pinned base image, no latest tag, resource limits required.
Q143: What is secret zero problem?
Securely bootstrapping first credential needed to fetch other secrets.
Q144: Why environment variables for secrets can be risky?
May leak via logs, process listings, crash dumps, or debug endpoints.
Q145: Better secret handling pattern?
External secret manager + short-lived credentials + mounted files/tokens.
Q146: What is egress control for containers?
Restrict outbound network to necessary destinations only.
Q147: Why egress control matters?
Limits data exfiltration and command-and-control channels.
Q148: What is syscall attack surface minimization?
Use hardened seccomp/capability profiles and minimal binaries.
Q149: What is immutable infrastructure principle with containers?
Never patch running containers; rebuild and redeploy new images.
Q150: What is golden base image strategy?
Curated hardened base images reused organization-wide.
Q151: Golden image downside?
Centralized updates can create broad coordinated upgrade needs.
Q152: What is noisy-neighbor issue on container hosts?
One workload consumes disproportionate resources affecting others.
Q153: Mitigation for noisy neighbors?
Resource quotas, isolation classes, scheduling policies, autoscaling.
Q154: What is container density tradeoff?
Higher density improves cost efficiency but may reduce isolation headroom.
Q155: What is cold start optimization for containers?
Smaller images, lazy loading, pre-pulled layers, fast init paths.
Q156: What is union filesystem overhead consideration?
Layered FS adds abstraction costs; workload-dependent performance impact.
Q157: What is I/O amplification in copy-on-write layers?
Small writes can trigger larger underlying operations.
Q158: How optimize write-heavy workloads?
Use volumes for data paths rather than container writable layer.
Q159: What is advanced logging strategy?
Structured logs, centralized aggregation, correlation IDs, retention controls.
Q160: What is metrics/tracing role in container ops?
Visibility into resource saturation, latency, and dependency behavior.
Q161: What is “pets vs cattle” in container operations?
Treat containers as replaceable units, not manually curated long-lived pets.
Q162: What is disaster recovery concern for container platforms?
Image registry availability, backup of persistent volumes/config/secrets.
Q163: What is registry mirror/caching use?
Improve pull speed and resilience against upstream outages.
Q164: What is air-gapped Docker workflow?
Offline image import/sign/scan/deploy pipelines for restricted environments.
Q165: What is multi-tenant host hardening baseline?
Strong isolation, rootless where possible, strict policies, continuous auditing.
Q166: What is compliance evidence for containerized systems?
SBOMs, scan reports, signed artifacts, deployment attestations, audit logs.
Q167: What is chaos testing for container workloads?
Inject container crashes/network faults/resource pressure to test resilience.
Q168: Why test OOM and disk-full scenarios?
Common real-world failure modes for container hosts.
Q169: What is blue/green deployment with containers?
Run old/new versions concurrently and switch traffic safely.
Q170: What is canary deployment with containers?
Gradually route traffic to new version while monitoring risk indicators.
Q171: What is rollback best practice?
Fast revert to previous known-good image digest and config.
Q172: What is orchestration relationship to Docker?
Orchestrators (Kubernetes/Swarm/etc.) manage container fleets at scale.
Q173: Is Docker alone enough for large production clusters?
Usually orchestration is needed for scheduling, self-healing, and scaling.
Q174: What is advanced anti-pattern?
Using privileged containers broadly to “make things work.”
Q175: Why avoid privileged mode?
It effectively removes many isolation boundaries and increases host compromise risk.
Q176: What is final reliability principle?
Design for container replacement, failure, and rapid recovery.
Q177: What is final security principle?
Harden every stage: build, registry, runtime, and operations.
Q178: What is final performance principle?
Benchmark real workloads; tune images, limits, and storage/network paths empirically.
Q179: What is final governance principle?
Standardize policies/templates and enforce continuously in CI/CD.
Q180: Final maturity principle?
Docker excellence is reproducible, secure, observable, and operable container delivery at scale.
# Build stage FROM eclipse-temurin:21-jdk AS build WORKDIR /app COPY . . RUN ./mvnw -q -DskipTests package # Runtime stage FROM eclipse-temurin:21-jre WORKDIR /app # Create non-root user RUN useradd -r -u 10001 appuser USER 10001 COPY --from=build /app/target/*.jar app.jar EXPOSE 8080 ENTRYPOINT ["java", "-jar", "/app/app.jar"]