How Docker containers work
Docker packages an app with everything it needs into an image, then runs that image as isolated containers on any machine with Docker.
- 1
Write a Dockerfile
A Dockerfile lists the steps to build your app's environment: a base image, files to copy and commands to run.
- 2
Build an image in layers
Each step that changes files becomes a read-only layer stacked on the one below. The image is that stack.
- 3
Layers are cached
When you change your code, only the layers from that step up are rebuilt. Put steps that rarely change first and builds stay fast.
- 4
Run containers
A container is a running instance of an image with its own writable layer. Several share one host kernel, isolated by namespaces and limited by cgroups.
- 5
Ship the same image anywhere
Push the image to a registry and pull it on a laptop, in CI or on a server. It runs the same way in all of them.
Write a Dockerfile
A Dockerfile lists the steps to build your app's environment: a base image, files to copy and commands to run.
Build an image in layers
Each step that changes files becomes a read-only layer stacked on the one below. The image is that stack.
Layers are cached
When you change your code, only the layers from that step up are rebuilt. Put steps that rarely change first and builds stay fast.
Run containers
A container is a running instance of an image with its own writable layer. Several share one host kernel, isolated by namespaces and limited by cgroups.
Ship the same image anywhere
Push the image to a registry and pull it on a laptop, in CI or on a server. It runs the same way in all of them.
In short
- Containers share the host's kernel, so they start in seconds and use far less memory than virtual machines.
- Copy dependency files and install them before copying your code, so code changes don't reinstall everything.
- Keep images small: slim base images and multi-stage builds cut size and attack surface.
- The layer sizes in the animation are illustrative.