Docker & Podman Basics

Everyday Container Commands

Docker popularized the container workflow; Podman is a newer, largely command-compatible alternative built specifically to avoid Docker's requirement of a single, always-running privileged background daemon (Podman runs each container as its own process directly, which is also what makes it comfortable running fully rootless). The command-line experience is close enough that alias docker=podman often just works unmodified.

CommandAction
docker run -d -p 8080:80 nginxRun detached, map port
docker ps / docker ps -aRunning / all containers
docker imagesLocal images
docker exec -it <id> bashShell into a container
docker logs <id>Container output
docker stop / rmStop / remove
docker build -t app .Build from a Dockerfile
docker pull / pushRegistry transfer

An image is a read-only template - a filesystem snapshot plus instructions on how to run it - and a container is a running (or stopped) instance created from that image, the same relationship as a program on disk versus a running process from the Process Management module. docker run creates and starts a new container from an image; docker exec instead reaches into an already-running one to run an additional command inside it (commonly a shell, for debugging).

Dockerfile essentials: FROM (the base image to build on top of), RUN (execute a command while building the image, baking its result into a new layer), COPY (bring files from your machine into the image), WORKDIR (set the working directory for subsequent instructions), EXPOSE (document which port the container listens on), CMD/ENTRYPOINT (what command actually runs when a container starts from this image).

Tip: These four flags on docker run cover the overwhelming majority of everyday container usage, and are worth knowing cold: -p host:container maps a port on the host machine to a port inside the container (traffic hitting the host port gets forwarded in); -v host:container mounts a host directory or named volume into the container's filesystem, so data written there survives even if the container itself is later removed; -e KEY=val sets an environment variable visible inside the container; -d runs it detached, in the background, handing your terminal back immediately; and -it (interactive + a pseudo-TTY) is what you want when you need to actually type into the container's console, such as during docker exec -it <id> bash.