100 Most Frequently Asked Docker Interview Questions & Answers
Below is a practical Docker interview guide, progressing from fundamentals to advanced topics, with an emphasis on what is commonly asked for Senior Java / Spring Boot / Microservices / Cloud / DevOps roles.
1. Docker Fundamentals
1. What is Docker?
Docker is a platform for building, packaging, distributing, and running applications in lightweight, isolated environments called containers.
A Docker container packages:
- Application code
- Runtime
- Libraries
- Dependencies
- Configuration
This helps ensure that an application behaves consistently across development, testing, and production.
2. What is a Docker container?
A container is a running instance of a Docker image.
For example:
Bash
docker run nginx
Docker creates a container from the nginx image and starts it.
Image = blueprint
Container = running instance
3. What is a Docker image?
A Docker image is an immutable template used to create containers.
An image consists of multiple filesystem layers and contains everything required to run an application.
Example:
Spring Boot Application
↓
Docker Image
↓
Docker Container
4. What is the difference between Docker image and container?
| Image | Container |
|---|---|
| Read-only template | Running instance |
| Immutable | Has writable layer |
| Used to create containers | Executes the application |
| Stored in registry/local cache | Exists on Docker host |
Example:
docker pull nginx
docker run nginx
nginx is the image; the resulting running process is the container.
5. What is Docker Engine?
Docker Engine is the core technology responsible for building and running containers.
It includes:
- Docker CLI
- Docker daemon
- Container runtime
- Image management
- Networking
- Storage management
6. What is Docker daemon?
The Docker daemon (dockerd) is the background service that manages:
- Containers
- Images
- Networks
- Volumes
- Container lifecycle
The Docker CLI communicates with the daemon through the Docker API.
7. What is Docker CLI?
Docker CLI is the command-line interface used to interact with Docker.
Examples:
docker ps
docker images
docker build
docker run
docker stop
docker logs
8. What is Docker Hub?
Docker Hub is a public container image registry.
It provides:
- Public images
- Private repositories
- Image distribution
- Automated builds
- Official images
Examples include:
nginx
redis
postgres
mysql
9. What is a container registry?
A container registry stores and distributes container images.
Examples include:
- Docker Hub
- Amazon ECR
- Azure Container Registry
- Google Artifact Registry
- GitHub Container Registry
Typical workflow:
Developer
↓
docker build
↓
Docker Image
↓
docker push
↓
Container Registry
↓
docker pull
↓
Production
10. What are the main advantages of Docker?
Major advantages include:
- Consistent environments
- Fast startup
- Lightweight isolation
- Easy deployment
- Reproducible builds
- Efficient resource utilization
- Easy scaling
- CI/CD integration
- Microservices support
2. Docker Architecture
11. Explain Docker architecture.
Docker uses a client-server architecture.
Docker CLI
|
| Docker API
↓
Docker Daemon
|
+---- Images
|
+---- Containers
|
+---- Networks
|
+---- Volumes
The CLI sends commands to the Docker daemon, which performs the actual operations.
12. What is the Docker client?
The Docker client is the command-line interface used to send commands to the Docker daemon.
For example:
Bash
docker run redis
The CLI sends the request to dockerd.
13. What is containerd?
containerd is a container runtime component responsible for managing the container lifecycle.
Docker Engine uses containerd underneath.
A simplified architecture is:
Docker CLI
↓
Docker Daemon
↓
containerd
↓
runc
↓
Linux Container
14. What is runc?
runc is a low-level container runtime that implements the OCI runtime specification.
It is responsible for creating and starting containers using Linux kernel features.
15. What is OCI?
OCI stands for Open Container Initiative.
It defines standards for:
- Container images
- Container runtimes
OCI helps ensure interoperability between container technologies.
16. How does Docker differ from a virtual machine?
The key difference is the operating system kernel.
Virtual Machines
Application
Guest OS
Hypervisor
Host OS
Hardware
Docker containers:
Application
Libraries
Container
Docker
Host OS Kernel
Hardware
Containers generally start faster and consume fewer resources because they share the host kernel.
17. Are Docker containers virtual machines?
No.
Containers provide OS-level process isolation, while virtual machines virtualize hardware and run their own operating systems.
18. Why are containers lightweight?
Containers share the host operating system kernel instead of running a complete guest OS.
Therefore, they generally require:
- Less memory
- Less CPU
- Less disk space
- Faster startup
19. What happens when you execute docker run?
For example:
Bash
docker run nginx
Docker generally:
- Checks whether the image exists locally.
- Pulls it if necessary.
- Creates a container.
- Creates its filesystem.
- Configures networking.
- Applies namespaces/cgroups.
- Starts the container process.
20. What are Linux namespaces?
Namespaces provide process isolation.
Docker uses namespaces to isolate things such as:
- Processes
- Network interfaces
- Mount points
- Hostnames
- Users
For example, a process inside a container may see only the processes belonging to its namespace.
3. Dockerfile
21. What is a Dockerfile?
A Dockerfile is a text file containing instructions used to build a Docker image.
Example:
FROM eclipse-temurin:21-jre
WORKDIR /app
COPY app.jar app.jar
ENTRYPOINT ["java", "-jar", "app.jar"]
22. What is the FROM instruction?
FROM specifies the base image.
Example:
dockerfile
FROM eclipse-temurin:21-jre
It should normally be the first instruction in a Dockerfile.
23. What is RUN?
RUN executes commands while building the image.
Example:
dockerfile
RUN apt-get update && apt-get install -y curl
The result becomes part of an image layer.
24. What is CMD?
CMD specifies the default command or arguments executed when a container starts.
Example:
dockerfile
CMD ["java", "-jar", "app.jar"]
CMD can be overridden when running the container.
25. What is ENTRYPOINT?
ENTRYPOINT defines the primary executable for a container.
Example:
dockerfile
ENTRYPOINT ["java", "-jar", "app.jar"]
It is commonly used when the container is intended to behave like a specific executable.
26. What is the difference between CMD and ENTRYPOINT?
| CMD | ENTRYPOINT |
|---|---|
| Default command/arguments | Main executable |
| Easily overridden | Usually preserved |
| Often used for defaults | Often used for fixed application |
Example:
ENTRYPOINT ["java", "-jar"]
CMD ["app.jar"]
Then:
Bash
docker run myapp
runs:
java -jar app.jar
27. What is COPY?
COPY copies files from the build context into the image.
dockerfile
COPY target/app.jar /app/app.jar
28. What is ADD?
ADD can copy files like COPY, but it has additional functionality such as archive extraction and URL support in certain contexts.
For most Dockerfiles, prefer:
dockerfile
COPY
because its behavior is simpler and more explicit.
29. What is WORKDIR?
WORKDIR sets the working directory for subsequent Dockerfile instructions and the container’s default working directory.
Example:
dockerfile
WORKDIR /app
30. What is EXPOSE?
EXPOSE documents the port that the application listens on.
Example:
dockerfile
EXPOSE 8080
Important:
EXPOSE does not publish the port to the host.
You still need:
Bash
docker run -p 8080:8080 myapp
31. What is .dockerignore?
.dockerignore specifies files that should not be included in the Docker build context.
Example:
.git
target
node_modules
*.log
.env
This can reduce build time and prevent unnecessary or sensitive files from being copied.
32. What is Docker build context?
The build context is the set of files sent to Docker during a build.
For:
Bash
docker build -t myapp .
. is the build context.
A large context can make builds slower.
33. What is Docker image layering?
Docker images are constructed from layers.
For example:
FROM ubuntu
RUN apt-get update
COPY app.jar /app
Each filesystem-changing instruction can create a layer.
Layers can be cached and reused, improving build performance.
34. How does Docker build cache work?
Docker checks whether previous build steps can be reused.
For example:
COPY pom.xml .
RUN mvn dependency:go-offline
COPY src ./src
RUN mvn package
Changing source code doesn’t necessarily invalidate the dependency layer.
This can make builds much faster.
35. How can you optimize Docker build performance?
Common techniques:
- Use
.dockerignore - Minimize build context
- Order stable instructions first
- Use multi-stage builds
- Use appropriate base images
- Avoid unnecessary packages
- Use BuildKit
- Cache dependencies
4. Docker Commands
36. How do you list running containers?
Bash
docker ps
All containers:
Bash
docker ps -a
37. How do you start a container?
Bash
docker start <container>
38. How do you stop a container?
Bash
docker stop <container>
39. How do you restart a container?
Bash
docker restart <container>
40. How do you remove a container?
Bash
docker rm <container>
Force removal:
Bash
docker rm -f <container>
41. How do you remove an image?
Bash
docker rmi <image>
42. How do you see container logs?
Bash
docker logs <container>
Follow logs:
Bash
docker logs -f <container>
43. How do you execute a command inside a running container?
Bash
docker exec -it <container> /bin/bash
For lightweight images:
Bash
docker exec -it <container> /bin/sh
44. How do you inspect a container?
Bash
docker inspect <container>
It provides information about:
- Network
- Mounts
- Environment
- Configuration
- IP addresses
- Runtime settings
45. How do you check resource usage?
Bash
docker stats
It displays CPU, memory, network and block I/O statistics.
46. How do you see Docker images?
Bash
docker images
or:
Bash
docker image ls
47. How do you remove unused Docker resources?
Bash
docker system prune
For more aggressive cleanup:
Bash
docker system prune -a
Be careful because this can remove unused images and other resources.
48. What is the difference between docker stop and docker kill?
docker stop gracefully stops a container.
Bash
docker stop app
Docker sends a termination signal and allows the application time to shut down.
docker kill immediately sends a kill signal by default.
Bash
docker kill app
49. What is the difference between docker exec and docker run?
docker run creates and starts a new container.
Bash
docker run nginx
docker exec executes a command inside an existing running container.
Bash
docker exec -it nginx sh
50. How do you rename a container?
Bash
docker rename old-name new-name
5. Docker Networking
51. What is Docker networking?
Docker networking allows containers to communicate with:
- Other containers
- The host
- External systems
Docker provides several network drivers.
52. What is the default Docker network?
Docker normally provides several default networks, including:
bridgehostnone
The default network used by containers is typically the bridge network.
53. What is a bridge network?
A bridge network allows containers on the same Docker host to communicate.
Create one:
Bash
docker network create my-network
Run containers on it:
docker run --network my-network redis
docker run --network my-network myapp
54. How can containers communicate with each other?
Containers connected to the same user-defined Docker network can communicate using container/service names.
For example:
Spring Boot → postgres:5432
Spring Boot → redis:6379
Docker’s embedded DNS resolves service/container names.
55. What is host networking?
With:
Bash
docker run --network host nginx
the container shares the host’s network namespace rather than getting a separate container network stack.
This can reduce network overhead but reduces network isolation.
56. What is the none network?
The none network provides a container with essentially no external network connectivity.
It is useful for workloads that do not need networking.
57. What is port mapping?
Port mapping connects a host port to a container port.
Example:
Bash
docker run -p 8080:8080 myapp
This means:
Host:8080 → Container:8080
58. What is the difference between EXPOSE and -p?
EXPOSE documents the intended container port:
dockerfile
EXPOSE 8080
-p publishes the port:
Bash
docker run -p 8080:8080 myapp
59. What is a Docker network driver?
A network driver determines how container networking works.
Common drivers include:
- bridge
- host
- none
- overlay
- macvlan
60. What is an overlay network?
An overlay network allows containers running across multiple Docker hosts to communicate as though they are on the same logical network.
It is commonly associated with multi-host/container orchestration environments such as Docker Swarm.
6. Docker Volumes and Storage
61. How does Docker handle persistent data?
Containers are generally considered ephemeral.
For persistent data, Docker provides:
- Volumes
- Bind mounts
- tmpfs mounts
62. What is a Docker volume?
A volume is Docker-managed persistent storage.
Create:
Bash
docker volume create postgres-data
Use:
Bash
docker run -v postgres-data:/var/lib/postgresql/data postgres
63. What is a bind mount?
A bind mount maps a host filesystem path into a container.
Example:
Bash
docker run -v $(pwd):/app myapp
64. Volume vs bind mount?
| Volume | Bind Mount |
|---|---|
| Managed by Docker | Managed by user |
| Docker-controlled location | Explicit host path |
| Good for persistent application data | Useful for development |
| More portable | More host-dependent |
65. What happens to container data when a container is deleted?
Data stored only in the container’s writable layer is normally lost when the container is removed.
Data stored in a volume survives container deletion.
66. How do you list volumes?
Bash
docker volume ls
67. How do you inspect a volume?
Bash
docker volume inspect my-volume
68. What is tmpfs?
A tmpfs mount stores data in memory rather than persistent disk storage.
Example:
Bash
docker run --tmpfs /tmp myapp
It is useful for temporary sensitive data or high-speed temporary files.
7. Docker Compose
69. What is Docker Compose?
Docker Compose is a tool for defining and running multi-container applications using a YAML configuration.
Example architecture:
Spring Boot
|
PostgreSQL
|
Redis
70. What is docker-compose.yml?
It is a YAML file describing application services, networks, volumes, and configuration.
Example:
services:
app:
image: myapp
ports:
- "8080:8080"
postgres:
image: postgres:16
environment:
POSTGRES_PASSWORD: secret
71. How do you start Docker Compose?
Modern Docker:
Bash
docker compose up
Background:
Bash
docker compose up -d
72. How do you stop Compose services?
Bash
docker compose down
73. What is the difference between docker compose stop and docker compose down?
stop stops containers but generally keeps the resources.
Bash
docker compose stop
down stops and removes the Compose-created containers and networks.
Bash
docker compose down
74. How does service discovery work in Docker Compose?
Compose creates a network and provides DNS-based service discovery.
For example:
services:
app:
...
postgres:
...
The application can connect to:
postgres:5432
rather than using an IP address.
75. How do you configure environment variables in Compose?
Example:
services:
app:
environment:
SPRING_PROFILES_ACTIVE: prod
DB_HOST: postgres
You can also use an .env file.
76. How do you persist PostgreSQL data with Compose?
Example:
services:
postgres:
image: postgres:16
volumes:
- postgres-data:/var/lib/postgresql/data
volumes:
postgres-data:
77. What is depends_on?
depends_on defines service startup dependencies.
Example:
services:
app:
depends_on:
- postgres
postgres:
image: postgres:16
Important interview point:
depends_on does not necessarily mean the dependency is fully ready to accept connections.
Health checks may be required.
78. How would you ensure a Spring Boot application waits for PostgreSQL?
Use:
- PostgreSQL health check
depends_onwith health conditions where supported- Application-level retry
- Connection retry configuration
A robust production system should not rely solely on container startup order.
8. Docker Security
79. Is Docker secure?
Docker provides isolation mechanisms, but containers are not an absolute security boundary.
Security should include:
- Minimal images
- Non-root users
- Image scanning
- Read-only filesystems where appropriate
- Resource limits
- Secrets management
- Network restrictions
- Least privilege
80. Why should containers avoid running as root?
Running as root increases the impact of a container compromise.
Example Dockerfile:
RUN adduser --disabled-password appuser
USER appuser
The application then runs without root privileges.
81. How do you reduce Docker image vulnerabilities?
Use:
- Minimal base images
- Regular updates
- Dependency scanning
- Multi-stage builds
- SBOM generation
- Image vulnerability scanners
- Trusted base images
82. What is Docker image scanning?
Image scanning identifies known vulnerabilities in:
- OS packages
- Libraries
- Application dependencies
This can be integrated into CI/CD pipelines.
83. What are Docker secrets?
Secrets are sensitive values such as:
- Passwords
- API keys
- Certificates
- Tokens
They should not normally be hardcoded into Dockerfiles or committed into Git.
In production, secrets are often managed by dedicated systems such as cloud secret managers or orchestrator-native secret mechanisms.
84. Why should you avoid putting secrets in Dockerfile?
For example, this is dangerous:
dockerfile
ENV DB_PASSWORD=secret123
The value can become part of image metadata or layers and potentially be exposed.
Instead, inject secrets at runtime using an appropriate secret-management mechanism.
85. What is a read-only container filesystem?
You can make the container filesystem read-only:
Bash
docker run --read-only myapp
The application must then use explicit writable volumes/tmpfs locations where necessary.
This can reduce the impact of certain attacks.
9. Docker Resource Management
86. How do you limit container memory?
Example:
Bash
docker run --memory=512m myapp
This limits the container’s memory usage.
87. How do you limit CPU?
Example:
Bash
docker run --cpus="1.5" myapp
This limits CPU allocation.
88. What are cgroups?
Linux control groups, or cgroups, allow resource usage to be controlled and measured.
Docker uses them to manage resources such as:
- CPU
- Memory
- PIDs
- Block I/O
89. What happens if a container exceeds its memory limit?
Depending on the configuration and workload, the container’s processes can be killed by the kernel’s out-of-memory mechanisms.
This is why memory limits and application JVM settings need to be considered together for Java applications.
90. How should you configure JVM memory inside Docker?
Modern JVMs are container-aware, but you should still configure memory deliberately.
For example:
Bash
-XX:MaxRAMPercentage=75
You need to leave room for:
- JVM heap
- Metaspace
- Native memory
- Threads
- Direct buffers
- Other processes
10. Advanced Docker / Senior-Level Questions
91. What is a multi-stage Docker build?
A multi-stage build uses multiple FROM instructions to separate build and runtime environments.
Example:
FROM maven:3.9-eclipse-temurin-21 AS build
WORKDIR /app
COPY pom.xml .
COPY src ./src
RUN mvn clean package -DskipTests
FROM eclipse-temurin:21-jre
WORKDIR /app
COPY --from=build /app/target/app.jar app.jar
ENTRYPOINT ["java", "-jar", "app.jar"]
The final image contains the runtime rather than the Maven build environment.
Benefits:
- Smaller image
- Reduced attack surface
- Cleaner production image
92. How would you Dockerize a Spring Boot application?
A common production approach:
Source Code
↓
Maven/Gradle Build
↓
JAR
↓
Docker Multi-stage Build
↓
Minimal JRE Image
↓
Container
Example:
FROM eclipse-temurin:21-jre
WORKDIR /app
COPY target/application.jar application.jar
USER 1001
EXPOSE 8080
ENTRYPOINT ["java", "-jar", "application.jar"]
93. What is BuildKit?
BuildKit is Docker’s modern build engine.
It provides features such as:
- Better build performance
- Parallel execution
- Improved caching
- Advanced build features
- More efficient builds
94. What is a multi-architecture Docker image?
A multi-architecture image supports multiple CPU architectures using the same image reference.
For example:
linux/amd64
linux/arm64
This is particularly important when deploying applications across:
- Intel/AMD servers
- ARM servers
- Apple Silicon development machines
95. What is Docker image digest?
An image tag such as:
myapp:latest
can point to different image versions over time.
A digest identifies a specific immutable image content:
myapp@sha256:...
For production deployments, digest pinning can improve reproducibility.
96. What is the difference between latest and a versioned image tag?
latest is simply a tag. It does not necessarily mean the newest or safest version.
For example:
myapp:latest
versus:
myapp:1.4.2
Production deployments should generally use explicit versions or immutable digests rather than relying on latest.
97. How would you troubleshoot a container that immediately exits?
Start with:
Bash
docker ps -a
Then inspect logs:
Bash
docker logs <container>
Inspect configuration:
Bash
docker inspect <container>
Check the configured command:
Bash
docker inspect <container>
Potential causes include:
- Application startup failure
- Incorrect
ENTRYPOINT - Incorrect
CMD - Missing environment variables
- Missing configuration
- Port/configuration problems
- Permission issues
- Dependency unavailable
98. How would you troubleshoot a Dockerized Spring Boot application that cannot connect to PostgreSQL?
Check:
1. Container status
Bash
docker ps
2. PostgreSQL logs
Bash
docker logs postgres
3. Network
Bash
docker network inspect <network>
4. Connection hostname
Inside Compose, use:
postgres
not:
localhost
because localhost inside the Spring Boot container refers to the Spring Boot container itself.
5. Port
Container-to-container communication normally uses the PostgreSQL container port:
5432
rather than the host-mapped port.
This is one of the most common Docker interview troubleshooting questions.
99. How would you design a production Docker environment for microservices?
A strong architecture might look like:
Container Registry
|
CI/CD Pipeline
|
+------------+------------+
| |
Service A Service B
Container Container
| |
+-----------+-------------+
|
Message Broker
Kafka
|
+------------+------------+
| |
PostgreSQL Redis
Key considerations:
- Immutable images
- Versioned images
- Health checks
- Resource limits
- Centralized logging
- Metrics
- Distributed tracing
- Secret management
- Network segmentation
- Vulnerability scanning
- Automated deployment
- Horizontal scaling
- Graceful shutdown
For larger production environments, Docker containers are commonly managed by an orchestrator such as Kubernetes or a cloud container service.
100. Docker vs Kubernetes — what is the difference?
This is one of the most important senior-level questions.
Docker is primarily a containerization platform and tooling ecosystem.
Kubernetes is a container orchestration platform.
Docker helps you:
Build → Package → Run → Distribute containers
Kubernetes helps you:
Deploy → Scale → Network → Heal → Roll out → Manage containers
A typical enterprise architecture is:
Developer
↓
Dockerfile
↓
Docker Image
↓
Container Registry
↓
Kubernetes
↓
Pods
↓
Services
↓
Ingress