Skip to content
Bill Liao
Go back

100 Docker interview Questions and Answers

Edit page

100 Most Frequently Asked Docker Interview Questions & Answers

Below is a practical Docker interview guide, progressing from fundamentals to advanced topics, with an emphasis on what is commonly asked for Senior Java / Spring Boot / Microservices / Cloud / DevOps roles.


1. Docker Fundamentals

1. What is Docker?

Docker is a platform for building, packaging, distributing, and running applications in lightweight, isolated environments called containers.

A Docker container packages:

This helps ensure that an application behaves consistently across development, testing, and production.


2. What is a Docker container?

A container is a running instance of a Docker image.

For example:

Bash

docker run nginx

Docker creates a container from the nginx image and starts it.

Image = blueprint
Container = running instance


3. What is a Docker image?

A Docker image is an immutable template used to create containers.

An image consists of multiple filesystem layers and contains everything required to run an application.

Example:

Spring Boot Application
        ↓
Docker Image
        ↓
Docker Container

4. What is the difference between Docker image and container?

ImageContainer
Read-only templateRunning instance
ImmutableHas writable layer
Used to create containersExecutes the application
Stored in registry/local cacheExists on Docker host

Example:

docker pull nginx
docker run nginx

nginx is the image; the resulting running process is the container.


5. What is Docker Engine?

Docker Engine is the core technology responsible for building and running containers.

It includes:


6. What is Docker daemon?

The Docker daemon (dockerd) is the background service that manages:

The Docker CLI communicates with the daemon through the Docker API.


7. What is Docker CLI?

Docker CLI is the command-line interface used to interact with Docker.

Examples:

docker ps
docker images
docker build
docker run
docker stop
docker logs

8. What is Docker Hub?

Docker Hub is a public container image registry.

It provides:

Examples include:

nginx
redis
postgres
mysql

9. What is a container registry?

A container registry stores and distributes container images.

Examples include:

Typical workflow:

Developer
   ↓
docker build
   ↓
Docker Image
   ↓
docker push
   ↓
Container Registry
   ↓
docker pull
   ↓
Production

10. What are the main advantages of Docker?

Major advantages include:


2. Docker Architecture

11. Explain Docker architecture.

Docker uses a client-server architecture.

Docker CLI
    |
    | Docker API
    ↓
Docker Daemon
    |
    +---- Images
    |
    +---- Containers
    |
    +---- Networks
    |
    +---- Volumes

The CLI sends commands to the Docker daemon, which performs the actual operations.


12. What is the Docker client?

The Docker client is the command-line interface used to send commands to the Docker daemon.

For example:

Bash

docker run redis

The CLI sends the request to dockerd.


13. What is containerd?

containerd is a container runtime component responsible for managing the container lifecycle.

Docker Engine uses containerd underneath.

A simplified architecture is:

Docker CLI
    ↓
Docker Daemon
    ↓
containerd
    ↓
runc
    ↓
Linux Container

14. What is runc?

runc is a low-level container runtime that implements the OCI runtime specification.

It is responsible for creating and starting containers using Linux kernel features.


15. What is OCI?

OCI stands for Open Container Initiative.

It defines standards for:

OCI helps ensure interoperability between container technologies.


16. How does Docker differ from a virtual machine?

The key difference is the operating system kernel.

Virtual Machines

Application
Guest OS
Hypervisor
Host OS
Hardware

Docker containers:

Application
Libraries
Container
Docker
Host OS Kernel
Hardware

Containers generally start faster and consume fewer resources because they share the host kernel.


17. Are Docker containers virtual machines?

No.

Containers provide OS-level process isolation, while virtual machines virtualize hardware and run their own operating systems.


18. Why are containers lightweight?

Containers share the host operating system kernel instead of running a complete guest OS.

Therefore, they generally require:


19. What happens when you execute docker run?

For example:

Bash

docker run nginx

Docker generally:

  1. Checks whether the image exists locally.
  2. Pulls it if necessary.
  3. Creates a container.
  4. Creates its filesystem.
  5. Configures networking.
  6. Applies namespaces/cgroups.
  7. Starts the container process.

20. What are Linux namespaces?

Namespaces provide process isolation.

Docker uses namespaces to isolate things such as:

For example, a process inside a container may see only the processes belonging to its namespace.


3. Dockerfile

21. What is a Dockerfile?

A Dockerfile is a text file containing instructions used to build a Docker image.

Example:

FROM eclipse-temurin:21-jre

WORKDIR /app

COPY app.jar app.jar

ENTRYPOINT ["java", "-jar", "app.jar"]

22. What is the FROM instruction?

FROM specifies the base image.

Example:

dockerfile

FROM eclipse-temurin:21-jre

It should normally be the first instruction in a Dockerfile.


23. What is RUN?

RUN executes commands while building the image.

Example:

dockerfile

RUN apt-get update && apt-get install -y curl

The result becomes part of an image layer.


24. What is CMD?

CMD specifies the default command or arguments executed when a container starts.

Example:

dockerfile

CMD ["java", "-jar", "app.jar"]

CMD can be overridden when running the container.


25. What is ENTRYPOINT?

ENTRYPOINT defines the primary executable for a container.

Example:

dockerfile

ENTRYPOINT ["java", "-jar", "app.jar"]

It is commonly used when the container is intended to behave like a specific executable.


26. What is the difference between CMD and ENTRYPOINT?

CMDENTRYPOINT
Default command/argumentsMain executable
Easily overriddenUsually preserved
Often used for defaultsOften used for fixed application

Example:

ENTRYPOINT ["java", "-jar"]
CMD ["app.jar"]

Then:

Bash

docker run myapp

runs:

java -jar app.jar

27. What is COPY?

COPY copies files from the build context into the image.

dockerfile

COPY target/app.jar /app/app.jar

28. What is ADD?

ADD can copy files like COPY, but it has additional functionality such as archive extraction and URL support in certain contexts.

For most Dockerfiles, prefer:

dockerfile

COPY

because its behavior is simpler and more explicit.


29. What is WORKDIR?

WORKDIR sets the working directory for subsequent Dockerfile instructions and the container’s default working directory.

Example:

dockerfile

WORKDIR /app

30. What is EXPOSE?

EXPOSE documents the port that the application listens on.

Example:

dockerfile

EXPOSE 8080

Important:

EXPOSE does not publish the port to the host.

You still need:

Bash

docker run -p 8080:8080 myapp

31. What is .dockerignore?

.dockerignore specifies files that should not be included in the Docker build context.

Example:

.git
target
node_modules
*.log
.env

This can reduce build time and prevent unnecessary or sensitive files from being copied.


32. What is Docker build context?

The build context is the set of files sent to Docker during a build.

For:

Bash

docker build -t myapp .

. is the build context.

A large context can make builds slower.


33. What is Docker image layering?

Docker images are constructed from layers.

For example:

FROM ubuntu
RUN apt-get update
COPY app.jar /app

Each filesystem-changing instruction can create a layer.

Layers can be cached and reused, improving build performance.


34. How does Docker build cache work?

Docker checks whether previous build steps can be reused.

For example:

COPY pom.xml .
RUN mvn dependency:go-offline

COPY src ./src
RUN mvn package

Changing source code doesn’t necessarily invalidate the dependency layer.

This can make builds much faster.


35. How can you optimize Docker build performance?

Common techniques:


4. Docker Commands

36. How do you list running containers?

Bash

docker ps

All containers:

Bash

docker ps -a

37. How do you start a container?

Bash

docker start <container>

38. How do you stop a container?

Bash

docker stop <container>

39. How do you restart a container?

Bash

docker restart <container>

40. How do you remove a container?

Bash

docker rm <container>

Force removal:

Bash

docker rm -f <container>

41. How do you remove an image?

Bash

docker rmi <image>

42. How do you see container logs?

Bash

docker logs <container>

Follow logs:

Bash

docker logs -f <container>

43. How do you execute a command inside a running container?

Bash

docker exec -it <container> /bin/bash

For lightweight images:

Bash

docker exec -it <container> /bin/sh

44. How do you inspect a container?

Bash

docker inspect <container>

It provides information about:


45. How do you check resource usage?

Bash

docker stats

It displays CPU, memory, network and block I/O statistics.


46. How do you see Docker images?

Bash

docker images

or:

Bash

docker image ls

47. How do you remove unused Docker resources?

Bash

docker system prune

For more aggressive cleanup:

Bash

docker system prune -a

Be careful because this can remove unused images and other resources.


48. What is the difference between docker stop and docker kill?

docker stop gracefully stops a container.

Bash

docker stop app

Docker sends a termination signal and allows the application time to shut down.

docker kill immediately sends a kill signal by default.

Bash

docker kill app

49. What is the difference between docker exec and docker run?

docker run creates and starts a new container.

Bash

docker run nginx

docker exec executes a command inside an existing running container.

Bash

docker exec -it nginx sh

50. How do you rename a container?

Bash

docker rename old-name new-name

5. Docker Networking

51. What is Docker networking?

Docker networking allows containers to communicate with:

Docker provides several network drivers.


52. What is the default Docker network?

Docker normally provides several default networks, including:

The default network used by containers is typically the bridge network.


53. What is a bridge network?

A bridge network allows containers on the same Docker host to communicate.

Create one:

Bash

docker network create my-network

Run containers on it:

docker run --network my-network redis
docker run --network my-network myapp

54. How can containers communicate with each other?

Containers connected to the same user-defined Docker network can communicate using container/service names.

For example:

Spring Boot → postgres:5432
Spring Boot → redis:6379

Docker’s embedded DNS resolves service/container names.


55. What is host networking?

With:

Bash

docker run --network host nginx

the container shares the host’s network namespace rather than getting a separate container network stack.

This can reduce network overhead but reduces network isolation.


56. What is the none network?

The none network provides a container with essentially no external network connectivity.

It is useful for workloads that do not need networking.


57. What is port mapping?

Port mapping connects a host port to a container port.

Example:

Bash

docker run -p 8080:8080 myapp

This means:

Host:8080 → Container:8080

58. What is the difference between EXPOSE and -p?

EXPOSE documents the intended container port:

dockerfile

EXPOSE 8080

-p publishes the port:

Bash

docker run -p 8080:8080 myapp

59. What is a Docker network driver?

A network driver determines how container networking works.

Common drivers include:


60. What is an overlay network?

An overlay network allows containers running across multiple Docker hosts to communicate as though they are on the same logical network.

It is commonly associated with multi-host/container orchestration environments such as Docker Swarm.


6. Docker Volumes and Storage

61. How does Docker handle persistent data?

Containers are generally considered ephemeral.

For persistent data, Docker provides:


62. What is a Docker volume?

A volume is Docker-managed persistent storage.

Create:

Bash

docker volume create postgres-data

Use:

Bash

docker run -v postgres-data:/var/lib/postgresql/data postgres

63. What is a bind mount?

A bind mount maps a host filesystem path into a container.

Example:

Bash

docker run -v $(pwd):/app myapp

64. Volume vs bind mount?

VolumeBind Mount
Managed by DockerManaged by user
Docker-controlled locationExplicit host path
Good for persistent application dataUseful for development
More portableMore host-dependent

65. What happens to container data when a container is deleted?

Data stored only in the container’s writable layer is normally lost when the container is removed.

Data stored in a volume survives container deletion.


66. How do you list volumes?

Bash

docker volume ls

67. How do you inspect a volume?

Bash

docker volume inspect my-volume

68. What is tmpfs?

A tmpfs mount stores data in memory rather than persistent disk storage.

Example:

Bash

docker run --tmpfs /tmp myapp

It is useful for temporary sensitive data or high-speed temporary files.


7. Docker Compose

69. What is Docker Compose?

Docker Compose is a tool for defining and running multi-container applications using a YAML configuration.

Example architecture:

Spring Boot
    |
PostgreSQL
    |
Redis

70. What is docker-compose.yml?

It is a YAML file describing application services, networks, volumes, and configuration.

Example:

services:
  app:
    image: myapp
    ports:
      - "8080:8080"

  postgres:
    image: postgres:16
    environment:
      POSTGRES_PASSWORD: secret

71. How do you start Docker Compose?

Modern Docker:

Bash

docker compose up

Background:

Bash

docker compose up -d

72. How do you stop Compose services?

Bash

docker compose down

73. What is the difference between docker compose stop and docker compose down?

stop stops containers but generally keeps the resources.

Bash

docker compose stop

down stops and removes the Compose-created containers and networks.

Bash

docker compose down

74. How does service discovery work in Docker Compose?

Compose creates a network and provides DNS-based service discovery.

For example:

services:
  app:
    ...
  postgres:
    ...

The application can connect to:

postgres:5432

rather than using an IP address.


75. How do you configure environment variables in Compose?

Example:

services:
  app:
    environment:
      SPRING_PROFILES_ACTIVE: prod
      DB_HOST: postgres

You can also use an .env file.


76. How do you persist PostgreSQL data with Compose?

Example:

services:
  postgres:
    image: postgres:16
    volumes:
      - postgres-data:/var/lib/postgresql/data

volumes:
  postgres-data:

77. What is depends_on?

depends_on defines service startup dependencies.

Example:

services:
  app:
    depends_on:
      - postgres

  postgres:
    image: postgres:16

Important interview point:

depends_on does not necessarily mean the dependency is fully ready to accept connections.

Health checks may be required.


78. How would you ensure a Spring Boot application waits for PostgreSQL?

Use:

A robust production system should not rely solely on container startup order.


8. Docker Security

79. Is Docker secure?

Docker provides isolation mechanisms, but containers are not an absolute security boundary.

Security should include:


80. Why should containers avoid running as root?

Running as root increases the impact of a container compromise.

Example Dockerfile:

RUN adduser --disabled-password appuser
USER appuser

The application then runs without root privileges.


81. How do you reduce Docker image vulnerabilities?

Use:


82. What is Docker image scanning?

Image scanning identifies known vulnerabilities in:

This can be integrated into CI/CD pipelines.


83. What are Docker secrets?

Secrets are sensitive values such as:

They should not normally be hardcoded into Dockerfiles or committed into Git.

In production, secrets are often managed by dedicated systems such as cloud secret managers or orchestrator-native secret mechanisms.


84. Why should you avoid putting secrets in Dockerfile?

For example, this is dangerous:

dockerfile

ENV DB_PASSWORD=secret123

The value can become part of image metadata or layers and potentially be exposed.

Instead, inject secrets at runtime using an appropriate secret-management mechanism.


85. What is a read-only container filesystem?

You can make the container filesystem read-only:

Bash

docker run --read-only myapp

The application must then use explicit writable volumes/tmpfs locations where necessary.

This can reduce the impact of certain attacks.


9. Docker Resource Management

86. How do you limit container memory?

Example:

Bash

docker run --memory=512m myapp

This limits the container’s memory usage.


87. How do you limit CPU?

Example:

Bash

docker run --cpus="1.5" myapp

This limits CPU allocation.


88. What are cgroups?

Linux control groups, or cgroups, allow resource usage to be controlled and measured.

Docker uses them to manage resources such as:


89. What happens if a container exceeds its memory limit?

Depending on the configuration and workload, the container’s processes can be killed by the kernel’s out-of-memory mechanisms.

This is why memory limits and application JVM settings need to be considered together for Java applications.


90. How should you configure JVM memory inside Docker?

Modern JVMs are container-aware, but you should still configure memory deliberately.

For example:

Bash

-XX:MaxRAMPercentage=75

You need to leave room for:


10. Advanced Docker / Senior-Level Questions

91. What is a multi-stage Docker build?

A multi-stage build uses multiple FROM instructions to separate build and runtime environments.

Example:

FROM maven:3.9-eclipse-temurin-21 AS build

WORKDIR /app
COPY pom.xml .
COPY src ./src

RUN mvn clean package -DskipTests

FROM eclipse-temurin:21-jre

WORKDIR /app
COPY --from=build /app/target/app.jar app.jar

ENTRYPOINT ["java", "-jar", "app.jar"]

The final image contains the runtime rather than the Maven build environment.

Benefits:


92. How would you Dockerize a Spring Boot application?

A common production approach:

Source Code
    ↓
Maven/Gradle Build
    ↓
JAR
    ↓
Docker Multi-stage Build
    ↓
Minimal JRE Image
    ↓
Container

Example:

FROM eclipse-temurin:21-jre

WORKDIR /app

COPY target/application.jar application.jar

USER 1001

EXPOSE 8080

ENTRYPOINT ["java", "-jar", "application.jar"]

93. What is BuildKit?

BuildKit is Docker’s modern build engine.

It provides features such as:


94. What is a multi-architecture Docker image?

A multi-architecture image supports multiple CPU architectures using the same image reference.

For example:

linux/amd64
linux/arm64

This is particularly important when deploying applications across:


95. What is Docker image digest?

An image tag such as:

myapp:latest

can point to different image versions over time.

A digest identifies a specific immutable image content:

myapp@sha256:...

For production deployments, digest pinning can improve reproducibility.


96. What is the difference between latest and a versioned image tag?

latest is simply a tag. It does not necessarily mean the newest or safest version.

For example:

myapp:latest

versus:

myapp:1.4.2

Production deployments should generally use explicit versions or immutable digests rather than relying on latest.


97. How would you troubleshoot a container that immediately exits?

Start with:

Bash

docker ps -a

Then inspect logs:

Bash

docker logs <container>

Inspect configuration:

Bash

docker inspect <container>

Check the configured command:

Bash

docker inspect <container>

Potential causes include:


98. How would you troubleshoot a Dockerized Spring Boot application that cannot connect to PostgreSQL?

Check:

1. Container status

Bash

docker ps

2. PostgreSQL logs

Bash

docker logs postgres

3. Network

Bash

docker network inspect <network>

4. Connection hostname

Inside Compose, use:

postgres

not:

localhost

because localhost inside the Spring Boot container refers to the Spring Boot container itself.

5. Port

Container-to-container communication normally uses the PostgreSQL container port:

5432

rather than the host-mapped port.

This is one of the most common Docker interview troubleshooting questions.


99. How would you design a production Docker environment for microservices?

A strong architecture might look like:

                    Container Registry
                           |
                    CI/CD Pipeline
                           |
              +------------+------------+
              |                         |
         Service A                  Service B
         Container                 Container
              |                         |
              +-----------+-------------+
                          |
                    Message Broker
                       Kafka
                          |
             +------------+------------+
             |                         |
         PostgreSQL                 Redis

Key considerations:

For larger production environments, Docker containers are commonly managed by an orchestrator such as Kubernetes or a cloud container service.


100. Docker vs Kubernetes — what is the difference?

This is one of the most important senior-level questions.

Docker is primarily a containerization platform and tooling ecosystem.

Kubernetes is a container orchestration platform.

Docker helps you:

Build → Package → Run → Distribute containers

Kubernetes helps you:

Deploy → Scale → Network → Heal → Roll out → Manage containers

A typical enterprise architecture is:

Developer
   ↓
Dockerfile
   ↓
Docker Image
   ↓
Container Registry
   ↓
Kubernetes
   ↓
Pods
   ↓
Services
   ↓
Ingress

Edit page
Share this post:

Previous Post
100 Kubernetes interview Questions and Answers
Next Post
100 Microsoft Azure interview Questions and Answers