Mental model
Cisco objective 4.7 says “Utilize Docker images in local developer environment”. Seven commands cover the daily workflow.
Two concepts to pin down:
- Image = a filesystem snapshot plus metadata.
nginx:latest,python:3.11-slim,ubuntu:22.04. - Container = a running (or stopped) process started from an image. You can run many containers from one image.
The 7 commands
1. docker pull <image>
Download an image from a registry (Docker Hub by default).
docker pull nginx
docker pull python:3.11-slim
If no tag is given, :latest is assumed.
2. docker images
List images you have.
REPOSITORY TAG IMAGE ID CREATED SIZE
nginx latest a2abf6c4d29d 2 weeks ago 142MB
python 3.11 bf7c3d2e8a01 3 weeks ago 1.02GB
3. docker run <image>
Start a container.
docker run nginx # foreground, interrupts stop it
docker run -d nginx # -d detaches (runs in background)
docker run -d --name web nginx # --name assigns a readable name
docker run -d -p 8080:80 nginx # -p HOST:CONTAINER maps a port
docker run -d -e DEBUG=true myapp # -e sets an env var
docker run --rm busybox echo hi # --rm removes container when it exits
docker run -it ubuntu bash # -it keeps stdin open with a TTY
If the image is not local, docker run auto-pulls it first.
4. docker ps
List containers.
docker ps # only running
docker ps -a # all (including Exited)
docker ps -q # IDs only; good for scripting (docker rm $(docker ps -aq))
Output:
CONTAINER ID IMAGE COMMAND CREATED STATUS NAMES
7c2e1f0abc12 nginx "/docker-entrypoint..." 2 minutes ago Up 2 minutes web
5. docker logs <container>
Dump the container’s stdout + stderr. Use the name or short ID.
docker logs web
docker logs -f web # -f = follow (tail -f style)
docker logs --tail 50 web # last 50 lines
6. docker exec -it <container> <command>
Run a command inside an already-running container.
docker exec -it web bash # open an interactive shell
docker exec web ls /etc/nginx # one-shot command
docker exec web nginx -s reload # reload nginx config inside the container
7. docker stop / docker rm / docker rmi
Clean up.
docker stop web # send SIGTERM, then SIGKILL after a grace period
docker rm web # remove the stopped container (frees name)
docker rm -f web # stop and remove in one go
docker rmi nginx # remove the image too
Common first-run gotchas
- Port not reachable from host? You forgot
-p 80:80. - Container exits immediately?
docker logs <name>— usually the main process crashed. - “Permission denied” talking to Docker daemon? On Linux: add your user to the
dockergroup (sudo usermod -aG docker $USER) and log out+in. - “Container name already in use”?
docker rm <name>first; or use--rmto auto-cleanup. - Volume disappears after run? You did not mount it with
-v HOST:CONTAINER— anything inside the container’s filesystem is ephemeral.
Volumes (persisting data)
Containers are disposable; data inside dies with them. Mount a host directory to keep data:
docker run -d -v /var/lib/mydata:/data myapp # host:container
Or use a named volume (Docker-managed storage):
docker volume create mydata
docker run -d -v mydata:/data myapp
Networking in two sentences
By default each container gets its own IP on a bridge network. You reach it from the host via -p HOST:CONTAINER port mapping. To let two containers talk to each other, put them on the same user-defined network (docker network create mynet, then --network mynet on each run).
Pull, run, ps, logs, exec, stop, rm
12 steps against a real engine. State persists across commands: images list grows, container list grows, stop/rm actually frees names.
Open the lab →FAQ
Image vs container, in one sentence? Image is the recipe + ingredients. Container is the cooked meal.
What is a tag? A label attached to an image (nginx:1.25, nginx:latest, nginx:alpine). Tags are mutable — the maintainer can repoint nginx:latest tomorrow.
Where do images get downloaded from by default? docker.io/library/<name> (Docker Hub). Private registries use registry.example.com/path/name:tag.
Is Docker required for CCNA Automation? Yes, lightly. 4.6 (interpret Dockerfile) and 4.7 (use images locally) are explicit objectives. You will not design a Kubernetes cluster for the exam; you will read a Dockerfile and name what each line does.
