docker inspect & Go Templates

Everything Is in inspect

By now you've used docker ps and docker logs to look at a container's status and output. But those only show a small slice of what Docker actually knows about a container. Every fact - its IP address, what's mounted into it, its environment variables, its resource limits, its health status, its exit code - lives in one big JSON document (JSON is just a structured, nested text format for storing named values - the same format most web APIs return) that you can pull with one command:

$ docker inspect web                 # the whole JSON (hundreds of lines)
$ docker inspect -f '{{.State.Status}}' web
running
$ docker inspect -f '{{range .NetworkSettings.Networks}}{{.IPAddress}}{{end}}' web
172.17.0.2
$ docker inspect -f '{{.HostConfig.Memory}}' web
268435456

Typing docker inspect web alone dumps the entire JSON document - often hundreds of lines - which is unwieldy when you just want one fact. The -f flag lets you extract a single value using Go templates, a small text-substitution syntax (borrowed from the Go programming language Docker is written in) for picking one field out of nested JSON. You don't need to know Go itself - just these three patterns, which cover 95% of real use:

PatternUse
{{.Path.To.Field}}one value
{{range .Mounts}}{{.Destination}} {{end}}iterate a list
{{index .Config.Labels "my.label"}}keys with dots/dashes
Tip: When you don't know the path, dump the full JSON and search it (docker inspect web | grep -i memory). Then codify the path with -f for scripts and checks.
Scenario: Audits, monitoring scripts, CI gates and every lab checker you've run in this track are built on inspect -f. It's the read API of Docker operations.