Docker · Cheat sheet

Docker CLI cheat sheet

Docker CLI cheat sheet: images, containers, Compose, Dockerfile, BuildKit, and runtime hardening — with example commands.

79 commands·9 sections·Updated ·By SecOpsLog

Rows marked Destructive State operation Caution Exposes secrets can remove data, change authoritative state, affect a running system, or print secrets. Read the note before running them against anything that matters.

Images

Beginner
docker build -t app:1.0 .
Build and tag from ./Dockerfile.
docker build -f prod.Dockerfile -t app:prod .
Build from a named Dockerfile.
docker images
List local images and sizes.Example output
IMAGE        ID             DISK USAGE   CONTENT SIZE   EXTRA
app:1.0      9c1e...             142MB         48.2MB
nginx:1.30   a3e0...             187MB         59.8MB    U
docker pull nginx:1.30
Fetch a pinned image tag.
docker tag app:1.0 reg.io/team/app:1.0
Add a registry-qualified tag to push.
docker push reg.io/team/app:1.0
Upload an image to a registry.
docker history app:1.0
See layers and the instruction that made each.
docker rmi app:1.0Caution
Remove an image.Caution: Untags or deletes the image; a local build you never pushed is gone.
docker save app:1.0 | gzip > app.tgz
Export an image as a tarball (air-gap).
docker load < app.tgz
Import an image from a tarball.

Run containers

Beginner
docker run -d -p 8080:80 --name web nginx
Run detached, publish a port, name it.
docker run -it ubuntu bash
Interactive shell in a throwaway container.
docker run --rm alpine echo hi
Auto-remove the container when it exits.
docker run -e KEY=val app
Pass an environment variable.
docker run -v $(pwd):/app app
Bind-mount the current directory.
docker run --network mynet app
Attach to a user-defined network (DNS by name).
docker ps
Running containers.Example output
CONTAINER ID   IMAGE   STATUS         PORTS                  NAMES
b1e2...        nginx   Up 3 minutes   0.0.0.0:8080->80/tcp   web
docker ps -a
All containers, including stopped.
docker stop web && docker rm webDestructive
Stop then remove a container.Destructive: Removes the container and its writable layer; named volumes survive.
docker restart web
Restart a container.

Interact & inspect

Beginner
docker exec -it web sh
Shell into a running container.
docker logs -f web
Follow a container’s stdout/stderr.
docker logs --tail 50 web
Last 50 log lines.
docker inspect webExposes secrets
Full JSON config (mounts, env, network, state).Exposes secrets: Prints Config.Env, which often holds passwords and tokens.
docker inspect -f '{{.State.Health.Status}}' web
Extract one field with a Go template.Example output
healthy
docker stats
Live CPU/mem/net per container.
docker top web
Processes running inside a container.
docker cp web:/etc/nginx/nginx.conf .
Copy a file out of a container.
docker diff web
Files changed vs the image (A/C/D).

Volumes & networks

Intermediate
docker volume create data
Create a named, Docker-managed volume.
docker run -d -v data:/data redis:8
Named volume at the image’s data path (/data); survives docker rm.
docker volume ls
List volumes.
docker volume inspect data
Where a volume lives on the host.
docker network create --driver bridge mynet
User-defined bridge (name-based DNS).
docker network ls
List networks.
docker network connect mynet web
Attach a running container to a network.
docker network inspect mynet
Subnet, gateway and attached containers.

System & cleanup

Intermediate
docker system df
Disk used by images/containers/volumes/cache.Example output
TYPE            TOTAL   ACTIVE   RECLAIMABLE
Images          12      3        4.1GB (61%)
Build Cache     40      0        2.2GB
docker image prune -aDestructive
Delete all images not used by a container.Destructive: Deletes every image without a container, including unpushed local builds.
docker container pruneDestructive
Remove all stopped containers.Destructive: Deletes every stopped container and its writable layer.
docker volume pruneDestructive
Remove unused anonymous volumes (-a adds unused named ones).Destructive: Permanently deletes unused anonymous volumes and their data.
docker builder prune
Remove dangling build cache (-a for all unused cache).
docker system prune -af --volumesDestructive
Remove stopped containers, unused images/networks/cache and anonymous volumes.Destructive: Deletes stopped containers, unused images, build cache and anonymous volumes.

Compose

Intermediate
docker compose up -d
Start the whole stack in the background.
docker compose ps
Services and their state.
docker compose logs -f web
Tail one service’s logs.
docker compose exec web sh
Shell into a service container.
docker compose build --no-cache
Rebuild images from scratch.
docker compose up -d --scale worker=4
Run N replicas of a service.
docker compose config
Render the fully-resolved merged config.
docker compose down -vDestructive
Stop and delete containers + named volumes.Destructive: Deletes the stack's named and anonymous volumes, including database data.

Dockerfile directives

Intermediate
FROM node:24-alpine
Base image — pin a small, specific tag.
WORKDIR /app
Set (and create) the working directory.
COPY package*.json ./
Copy files; order layers for cache reuse.
RUN npm ci --omit=dev
Execute a build step in a new layer.
ENV NODE_ENV=production
Set an environment variable in the image.
ARG VERSION=1.0
Build-time variable (not kept at runtime).
EXPOSE 3000
Document the listening port (metadata only).
USER 10001
Drop to a non-root UID for runtime.
HEALTHCHECK CMD curl -f http://localhost:3000/ || exit 1
Health status (healthy/unhealthy); Docker records it but restarts nothing.
ENTRYPOINT ["node"]
Fixed executable.
CMD ["server.js"]
Default args (overridable at run).

BuildKit & multi-stage

Advanced
FROM golang:1.27 AS build
Name a build stage to copy artifacts from later.
COPY --from=build /out/app /app
Pull only the binary into a tiny final image.
docker build --target build -t app:dev .
Build just one stage (e.g. for tests).
docker build --build-arg VERSION=2.1 .
Pass a value to an ARG.
docker build --no-cache .
Ignore layer cache for a clean build.
docker build --secret id=npm,src=$HOME/.npmrc .
Mount a secret at build time (never layered).
docker buildx build --platform linux/amd64,linux/arm64 --push -t reg/app:1.0 .
Multi-arch build and push in one step.
docker buildx create --name ci --driver docker-container --bootstrap --use
Builder for multi-arch + registry cache without the containerd store.
docker build --cache-to type=registry,ref=reg/app:cache --cache-from type=registry,ref=reg/app:cache .
Share the layer cache across CI runners.

Registry & hardening

Advanced
docker login reg.io
Authenticate to a registry.
docker scout cves app:1.0
Scan an image for known CVEs.
docker run --read-only --tmpfs /tmp app
Immutable root FS; writable /tmp only.
docker run --user 10001:10001 app
Run as a non-root user.
docker run --cap-drop ALL --cap-add NET_BIND_SERVICE app
Drop all Linux capabilities, add back one.
docker run --security-opt no-new-privileges app
Block privilege escalation (setuid).
docker run --memory=256m --cpus=0.5 --pids-limit=100 app
Cap memory, CPU and process count.
docker run --network none app
Fully isolate a container from the network.

Primary references

Found a technical issue on this page? Report it with the tool version you used and the behavior you saw. How resources are maintained.

Go deeper
Hands-on courses for Docker