CONTAINERS / A CONCEPT NOTE
Docker
package apps with their entire runtime into lightweight boxes
Overview · mechanism
pitfall · examples
01 / THE SHORT VERSION
The idea in a few sentences.
A Dockerfile describes each layer — OS base, dependencies, app code, start command. docker build creates a cached image; docker run launches a container from it. Each container is an isolated process with its own filesystem, network, and PID namespace.
02 / FOLLOW THE MECHANISM
How a container starts
Docker client
sends a
runcommand to the Docker daemon (dockerd).Daemon
checks if the image is cached locally; if not, pulls layers from a registry.
Daemon
creates a new writable container layer on top of the image layers (copy-on-write).
containerd + runc
set up cgroups (CPU/memory limits), namespaces (isolation), and the root filesystem, then execute the entrypoint.
Process
runs inside the container. When it exits, the container stops (unless
--restartis set).
04 / COMMAND NOTES
Read the command, then the result.
Inspect the flags and arguments before trying an example. Snippets can need local setup, replacement values, or resources in your own environment.
list all containers, including stopped
docker ps -aget a shell inside a running container
docker exec -it CONTAINER sh05 / CHECK YOURSELF
Could you explain Docker to a teammate?
Try it out loud in two sentences: what it is, and the one detail that changes the picture. If you stall, the gap is the part to reread.
Up next in Containers & KubernetesKubernetesorchestrating containers at scale