Skip to main content
PacketMentor logo
Open menu
← All topics
Automation & Programmability Foundational

Docker: Pull, Run, Manage Images and Containers

The 7 docker commands you use every day: pull, images, run, ps, logs, exec, rm. The difference between an image and a container, and the common flags you need.

Quick summary
  • Image = snapshot (nginx:latest). Container = running instance of an image (one or many per image).
  • docker pull <image> downloads. docker run <image> starts a container from it. docker ps lists running; -a adds stopped.
  • docker exec enters a running container. docker logs reads its stdout. docker stop + rm cleans up.

Mental model

Cisco objective 4.7 says “Utilize Docker images in local developer environment”. Seven commands cover the daily workflow.

Two concepts to pin down:

  • Image = a filesystem snapshot plus metadata. nginx:latest, python:3.11-slim, ubuntu:22.04.
  • Container = a running (or stopped) process started from an image. You can run many containers from one image.

The 7 commands

1. docker pull <image>

Download an image from a registry (Docker Hub by default).

docker pull nginx
docker pull python:3.11-slim

If no tag is given, :latest is assumed.

2. docker images

List images you have.

REPOSITORY   TAG      IMAGE ID       CREATED        SIZE
nginx        latest   a2abf6c4d29d   2 weeks ago    142MB
python       3.11     bf7c3d2e8a01   3 weeks ago    1.02GB

3. docker run <image>

Start a container.

docker run nginx                              # foreground, interrupts stop it
docker run -d nginx                           # -d detaches (runs in background)
docker run -d --name web nginx                # --name assigns a readable name
docker run -d -p 8080:80 nginx                # -p HOST:CONTAINER maps a port
docker run -d -e DEBUG=true myapp             # -e sets an env var
docker run --rm busybox echo hi               # --rm removes container when it exits
docker run -it ubuntu bash                    # -it keeps stdin open with a TTY

If the image is not local, docker run auto-pulls it first.

4. docker ps

List containers.

docker ps                 # only running
docker ps -a              # all (including Exited)
docker ps -q              # IDs only; good for scripting (docker rm $(docker ps -aq))

Output:

CONTAINER ID   IMAGE   COMMAND                  CREATED         STATUS         NAMES
7c2e1f0abc12   nginx   "/docker-entrypoint..."  2 minutes ago   Up 2 minutes   web

5. docker logs <container>

Dump the container’s stdout + stderr. Use the name or short ID.

docker logs web
docker logs -f web            # -f = follow (tail -f style)
docker logs --tail 50 web     # last 50 lines

6. docker exec -it <container> <command>

Run a command inside an already-running container.

docker exec -it web bash           # open an interactive shell
docker exec web ls /etc/nginx      # one-shot command
docker exec web nginx -s reload    # reload nginx config inside the container

7. docker stop / docker rm / docker rmi

Clean up.

docker stop web          # send SIGTERM, then SIGKILL after a grace period
docker rm web            # remove the stopped container (frees name)
docker rm -f web         # stop and remove in one go
docker rmi nginx         # remove the image too

Common first-run gotchas

  • Port not reachable from host? You forgot -p 80:80.
  • Container exits immediately? docker logs <name> — usually the main process crashed.
  • “Permission denied” talking to Docker daemon? On Linux: add your user to the docker group (sudo usermod -aG docker $USER) and log out+in.
  • “Container name already in use”? docker rm <name> first; or use --rm to auto-cleanup.
  • Volume disappears after run? You did not mount it with -v HOST:CONTAINER — anything inside the container’s filesystem is ephemeral.

Volumes (persisting data)

Containers are disposable; data inside dies with them. Mount a host directory to keep data:

docker run -d -v /var/lib/mydata:/data myapp     # host:container

Or use a named volume (Docker-managed storage):

docker volume create mydata
docker run -d -v mydata:/data myapp

Networking in two sentences

By default each container gets its own IP on a bridge network. You reach it from the host via -p HOST:CONTAINER port mapping. To let two containers talk to each other, put them on the same user-defined network (docker network create mynet, then --network mynet on each run).

Hands-on lab · 6 minute walkthrough

Pull, run, ps, logs, exec, stop, rm

12 steps against a real engine. State persists across commands: images list grows, container list grows, stop/rm actually frees names.

Open the lab →
docker-basics · lab
you@laptop:~$ docker run -d --name web nginx
0000f87df337
you@laptop:~$ docker exec web whoami
root
you@laptop:~$

FAQ

Image vs container, in one sentence? Image is the recipe + ingredients. Container is the cooked meal.

What is a tag? A label attached to an image (nginx:1.25, nginx:latest, nginx:alpine). Tags are mutable — the maintainer can repoint nginx:latest tomorrow.

Where do images get downloaded from by default? docker.io/library/<name> (Docker Hub). Private registries use registry.example.com/path/name:tag.

Is Docker required for CCNA Automation? Yes, lightly. 4.6 (interpret Dockerfile) and 4.7 (use images locally) are explicit objectives. You will not design a Kubernetes cluster for the exam; you will read a Dockerfile and name what each line does.

Master this on a real network

Want this drilled into reflex?

1:1 weekly sessions, live feedback on your labs, and US interview prep: built around the CCNA Automation® exam blueprint. Free first session. No card on file until you decide.

Claim my free session →

Get the free CCNA 12-week roadmap

You're already reading up on Docker: Pull, Run, Manage Images and Containers. The roadmap is the order I recommend studying every CCNA topic in: with what to lab each week and where Docker: Pull, Run, Manage Images and Containers fits. A written personal reply, not an autoresponder. Expect it within one business day.

Personal reply from a senior network engineer. No third-party tracking. Unsubscribe any time.