Unit content
Docker
Docker is a container platform built around images, containers and a workflow for describing reproducible runtime environments.
Images and containers
An image is a read-only template containing a filesystem and metadata needed to start a container. A container is a running or stopped instance created from an image.
Several containers can be created from the same image while maintaining separate writable runtime state.
Dockerfiles and builds
A Dockerfile describes how to build an image in ordered steps. A simple example is
FROM python:3
WORKDIR /app
COPY . .
CMD ["python", "app.py"]
Building the file produces an image whose environment can be reused on another Docker installation with the same relevant architecture and dependencies.
Files and persistent data
Container writable layers are normally treated as disposable. Bind mounts and volumes let selected data exist outside that disposable layer so that source files or persistent application data can survive container replacement.
Runtime configuration
Containers can receive environment variables, resource limits and mappings that expose selected service endpoints to the host. Detailed network protocols are separate concepts; Docker fundamentals do not depend on knowing TCP or UDP internals.
Images are not virtual machines
A Docker container normally runs processes sharing the host kernel. Its image provides a userspace filesystem and runtime environment rather than an entire guest operating system kernel.
Docker packages process environments reproducibly; it does not remove the need to understand the application, its data or the security implications of how the container is configured.