Glossary

Docker

Docker is a platform for packaging an application together with its dependencies, libraries, and runtime into a single portable unit called a container, so it runs the same way on a developer's laptop, a CI server, and production. Unlike a virtual machine, a container doesn't bundle a full guest operating system — it shares the host machine's kernel while isolating the process using Linux kernel features (namespaces for isolation, cgroups for resource limits).

How it works

A Dockerfile describes how to build an image — a read-only, layered filesystem snapshot — as a sequence of instructions (FROM, COPY, RUN, CMD):

FROM node:20-alpine
WORKDIR /app
COPY package.json .
RUN npm install
COPY . .
CMD ["node", "server.js"]

Each instruction adds a cached, reusable layer, which is why reordering a Dockerfile (installing dependencies before copying application code, as above) speeds up rebuilds — Docker can reuse the cached dependency-install layer when only the application code changes. A running instance of an image is a container; the same image can run as many independent containers as needed. Images and their runtime format are standardized by the OCI (Open Container Initiative), which is why images built by Docker can also run under other compatible runtimes like Podman or containerd.

Common pitfalls

  • A container is isolated but not fully secure by default — running as root inside a container, or mounting sensitive host paths, can still expose the host if the container is compromised.
  • Images can grow unnecessarily large by including build tools or caches that aren't needed at runtime — multi-stage builds (building in one stage, copying only the final artifact to a slim final image) fix this.
  • Container filesystem changes are ephemeral by default and disappear when the container is removed — data that needs to persist requires an explicit volume.
  • "It works on my machine but not in the container" is almost always a difference in base image, environment variables, or file paths that weren't made explicit in the Dockerfile.

Related terms

  • YAML — the format used by Docker Compose files (and container orchestration tools generally) to describe multi-container setups declaratively.
  • DNS — containers on the same network typically resolve each other by service name through an internal DNS layer rather than hardcoded IPs.

See also