Docker & Podman Basics
Everyday Container Commands
Docker popularized the container workflow; Podman is a newer, largely command-compatible alternative built specifically to avoid Docker's requirement of a single, always-running privileged background daemon (Podman runs each container as its own process directly, which is also what makes it comfortable running fully rootless). The command-line experience is close enough that alias docker=podman often just works unmodified.
| Command | Action |
|---|---|
docker run -d -p 8080:80 nginx | Run detached, map port |
docker ps / docker ps -a | Running / all containers |
docker images | Local images |
docker exec -it <id> bash | Shell into a container |
docker logs <id> | Container output |
docker stop / rm | Stop / remove |
docker build -t app . | Build from a Dockerfile |
docker pull / push | Registry transfer |
An image is a read-only template - a filesystem snapshot plus instructions on how to run it - and a container is a running (or stopped) instance created from that image, the same relationship as a program on disk versus a running process from the Process Management module. docker run creates and starts a new container from an image; docker exec instead reaches into an already-running one to run an additional command inside it (commonly a shell, for debugging).
Dockerfile essentials: FROM (the base image to build on top of), RUN (execute a command while building the image, baking its result into a new layer), COPY (bring files from your machine into the image), WORKDIR (set the working directory for subsequent instructions), EXPOSE (document which port the container listens on), CMD/ENTRYPOINT (what command actually runs when a container starts from this image).
Tip: These four flags ondocker runcover the overwhelming majority of everyday container usage, and are worth knowing cold:-p host:containermaps a port on the host machine to a port inside the container (traffic hitting the host port gets forwarded in);-v host:containermounts a host directory or named volume into the container's filesystem, so data written there survives even if the container itself is later removed;-e KEY=valsets an environment variable visible inside the container;-druns it detached, in the background, handing your terminal back immediately; and-it(interactive + a pseudo-TTY) is what you want when you need to actually type into the container's console, such as duringdocker exec -it <id> bash.