# docker - daemon must be running (`systemctl start docker`) - use `sudo` or add user to group `docker` (`sudo usermod -aG docker user`) - [docs](https://docs.docker.com/) - there are lots of flavours and tools upon tools, each w/ their own name, currently (sept 2018) "docker" usually means "docker ce (community edition)" - images are built, containers are running images, aka images w/ command (like class vs instance) (not sure if this is correct, but get the idea) ## hello world ```sh docker version docker info docker pull hello-world docker image ls -a docker container ls -a docker run hello-world docker ps # list running container docker top # pipes internal top docker rm docker rmi docker rm -f $(docker ps -a -q) # stop and remove all docker run -it ubuntu bash # start image docker exec -it sh # give interacive shell in running container docker logs # show stdout/stderr (?) of running processes docker system prune -a # `--all` includes images ``` ## dockerfile - order sensitive - every line is some delta-foo - gets images from [hub](https://hub.docker.com/), or local repository - minimal image is named "scratch" (`FROM scratch`) - minimal userland image is "alpine", which is a minimal linux distro - naming convention for images: -- - `ENTRYPOINT`: hard-coded command and args to run, sometimes empty, overwrite w/ `--entrypoint` - `CMD`: default args, overwritten by args passed to `docker run` file lives in own dir, build w/: ```sh docker build docker build -t : docker history ``` ## docker compose configures one or more docker containers and one or more networks. images are usually referenced by their `name:tag` given on build w/ `-t`. can handle multiple containers in multiple networks and up/down them all in one go. all before `:` is host, all after is in docker. ```sh docker-compose up docker-compose down # all data inside container will be lost docker-compose pause # data will be retained, will be resumed on host reboot docker-compose unpause docker-compose ps # like `docker ps`, but with grouping docker-compose logs docker-compose run bash # interactive shell using docker-compose settings ``` ## storage julian says: also check named volumes in [gitea doc](https://docs.gitea.io/en-us/). - volumes: are stored in docker-managed part of fs, e.g. `/var/lib/docker/volumes/`, see `docker volume create/ls/prune/...` - bind mounts: anywhere on fs, may be modified by anyone at anytime - tmpfs mounts # history / buzzwording - kernel namespaces - cgroups, `grep "docker\|lxc" /proc/1/cgroup` - sdn, software defined network (maybe not `lxc`), can alias names - `lxc`, first container implementation by kernel devs - `docker`, pimped `lxc`