CONTAINERS / A CONCEPT NOTE

Docker

package apps with their entire runtime into lightweight boxes

~80 sec read

Overview · mechanism
pitfall · examples

01 / THE SHORT VERSION

The idea in a few sentences.

A Dockerfile describes each layer — OS base, dependencies, app code, start command. docker build creates a cached image; docker run launches a container from it. Each container is an isolated process with its own filesystem, network, and PID namespace.

02 / FOLLOW THE MECHANISM

How a container starts

  1. Docker client

    sends a run command to the Docker daemon (dockerd).

  2. Daemon

    checks if the image is cached locally; if not, pulls layers from a registry.

  3. Daemon

    creates a new writable container layer on top of the image layers (copy-on-write).

  4. containerd + runc

    set up cgroups (CPU/memory limits), namespaces (isolation), and the root filesystem, then execute the entrypoint.

  5. Process

    runs inside the container. When it exits, the container stops (unless --restart is set).

04 / COMMAND NOTES

Read the command, then the result.

Inspect the flags and arguments before trying an example. Snippets can need local setup, replacement values, or resources in your own environment.

EXAMPLE 01 · REFERENCE

list all containers, including stopped

docker ps -a

EXAMPLE 02 · REFERENCE

get a shell inside a running container

docker exec -it CONTAINER sh

Explore command anatomy in the CLI lab