Complete Docker Beginner's Guide: From Installation to Production Orchestration
This comprehensive Docker tutorial covers container fundamentals, installation on CentOS, image and container management, Dockerfile creation, data volumes, networking, Docker Compose orchestration, registry setup, and production best practices with hands-on command examples.
1.1 Container Introduction
1.1.1 What Are Linux Containers
Linux containers are isolated processes running from a distinct image that provides all necessary files. Containers package application dependencies, ensuring portability and consistency from development through testing to production.
The article illustrates with a scenario: developing on a laptop with specific configuration while the enterprise has standardized test and production environments. Containers ensure the application runs across these environments without re-creating server environments or rewriting code.
1.1.2 Containers vs Virtualization
Virtualization runs multiple OS instances on a single system via a hypervisor. Containers share the host OS kernel while isolating application processes. This makes containers more lightweight, enabling dense deployment on limited resources.
1.1.3 Container History
Concept originated in 2000 as FreeBSD jail for partitioning systems into secure subsystems. Jail used a modified chroot environment virtualizing filesystem, network, and user access. In 2001, Jacques Gélinas' VServer project brought isolation to Linux, enabling multiple controlled user spaces.
1.2 What Is Docker?
Docker refers to the open-source community project, tools from the project, Docker Inc. (the company), and officially supported tools. Docker lets you treat containers as lightweight, modular VMs with high flexibility for creation, deployment, replication, and migration across environments.
1.2.1 How Docker Works
Docker uses Linux kernel features Cgroups and namespaces to isolate processes. It provides image-based deployment, making it easy to share applications with dependencies across environments. Docker automates application deployment within containers.
1.2.2 Docker vs Traditional Linux Containers (LXC)
Docker initially used LXC but later moved away. LXC uses an init system to manage multiple processes as a single unit. Docker encourages each application to run its own process independently, providing tools for this granular approach.
1.2.3 Docker Goals
Build, Ship, and Run Any App, Anywhere : Build a Docker image, Ship via docker pull, Run by starting a container. Each container has its own filesystem rootfs.
1.3 Installing Docker
Environment: two CentOS 7.2 nodes (kernel 3.10.0-327.el7.x86_64) with IPs 10.0.0.100/101 and 172.16.1.100/101.
On both nodes:
wget -O /etc/yum.repos.d/docker-ce.repo https://mirrors.ustc.edu.cn/docker-ce/linux/centos/docker-ce.repo
sed -i 's#download.docker.com#mirrors.ustc.edu.cn/docker-ce#g' /etc/yum.repos.d/docker-ce.repo
yum install docker-ce -yOn docker01, modify /usr/lib/systemd/system/docker.service to listen on remote port:
ExecStart=/usr/bin/dockerd -H unix:///var/run/docker.sock -H tcp://10.0.0.100:2375
systemctl daemon-reload
systemctl enable docker.service
systemctl restart docker.serviceTest from docker02: docker -H 10.0.0.100 info shows Server Version 17.12.0-ce, Storage Driver devicemapper.
1.3.1 Basic Commands
docker versionshows client/server version 17.12.0-ce, API 1.35, Go 1.9.2.
Configure registry mirror in /etc/docker/daemon.json:
{
"registry-mirrors": ["https://registry.docker-cn.com"]
}1.3.2 First Container
docker run -d -p 80:80 nginxpulls nginx:latest, downloads layers, starts container. Parameters: run create+run, -d detach, -p port mapping, nginx image name.
1.3.3 Image Lifecycle
Diagram shows image layers: base image, software layers, container writable layer.
1.4 Image Operations
1.4.1 Search Official Repository
docker search centosreturns columns: NAME, DESCRIPTION, STARS, OFFICIAL, AUTOMATED.
1.4.2 Pull Images
docker pull centosdownloads latest tag (207MB). docker image list shows REPOSITORY, TAG, IMAGE ID, CREATED, SIZE. Third-party pull: docker pull index.tenxcloud.com/tenxcloud/httpd.
1.4.3 Export Image
docker image save centos > docker-centos.tar.gzexports to tar.gz.
1.4.4 Remove Image
docker image rm centos:latestremoves image.
1.4.5 Import Image
docker image load -i docker-centos.tar.gzloads image back.
1.4.6 Inspect Image
docker image inspect centosshows detailed metadata.
1.5 Container Daily Management
1.5.1 Start/Stop
Simple run: docker run nginx. Two-step create+start (rare): docker create centos:latest /bin/bash then docker start <name>. Quick run with command: docker run centos:latest /usr/bin/sleep 20. Key rule: the first process inside container must keep running, otherwise container exits.
List running: docker container ls or docker ps. Inspect: docker container inspect <name/id>. List all: docker ps -a. Stop: docker stop <name/id> or docker container kill <name/id>.
1.5.2 Enter Container
At start: docker run -it nginx:latest /bin/bash ( -it interactive TTY). Exit with ctrl+p & ctrl+q to detach.
After start: docker attach <id> attaches to existing terminal (shared view). Recommended: docker exec -it <name> /bin/bash creates new terminal session (isolated). Example shows separate PTS terminals.
1.5.3 Remove All Containers
docker rm -f `docker ps -a -q`( -f force).
1.5.4 Port Mapping
Formats: -p hostPort:containerPort, -p ip:hostPort:containerPort, -p ip::containerPort (random host port), -p hostPort:containerPort:udp, multiple -p flags. Random mapping: docker run -P (capital P, requires image support).
1.6 Data Volume Management
1.6.1 Create Volume at Mount
docker run -d -p 80:80 -v /data:/usr/share/nginx/html nginx:latestmounts host /data to container /usr/share/nginx/html. Writing echo "http://www.nmtui.com" >/data/index.html on host reflects in container via curl 10.0.0.100. Shared volume: second container with same -v sees same content. docker volume ls lists volumes (DRIVER, VOLUME NAME).
1.6.2 Create Volume Then Mount
docker volume creategenerates random name. Named volume: docker volume create clsn. Inspect: docker volume inspect clsn shows Mountpoint /var/lib/docker/volumes/clsn/_data. Use:
docker run -d -p 9000:80 -v clsn:/usr/share/nginx/html nginx:latest. Write to mountpoint on host, verify via curl. --volumes-from shares volumes from another container.
1.6.3 Manual Image Creation from Container
Start centos:6.8, install openssh-server, set root password, start sshd. Commit: docker commit <container> centos6-ssh. Run new image:
docker run -d -p 1122:22 centos6-ssh:latest /usr/sbin/sshd -D. Install httpd, create init.sh starting httpd and sshd, commit again: docker commit <id> centos6-httpd. Run with ports 1222:22 and 80:80.
1.7 Dockerfile Automated Builds
Reference: https://github.com/CentOS/CentOS-Dockerfiles
1.7.1 Dockerfile Instructions
Core parts: FROM base image, RUN build commands, CMD startup command. Common instructions explained mnemonically: FROM (mother), MAINTAINER (caretaker), RUN (what to do), ADD (funding, auto-extract), WORKDIR (cd), VOLUME (luggage storage), EXPOSE (open doors), CMD (run!). Others: COPY, ENV, ENTRYPOINT.
1.7.2 Create a Dockerfile
Directory /opt/base, file Dockerfile:
FROM centos:6.8
RUN yum install openssh-server -y
RUN echo "root:123456" |chpasswd
RUN /etc/init.d/sshd start
CMD ["/usr/sbin/sshd","-D"]Build: docker image build -t centos6.8-ssh . ( -t tag, . current path). Run: docker run -d -p 2022:22 centos6.8-ssh-b.
1.7.3 Dockerfile for kodexplorer
FROM centos:6.8
RUN yum install wget unzip php php-gd php-mbstring -y && yum clean all
WORKDIR /var/www/html/
RUN wget -c http://static.kodcloud.com/update/download/kodexplorer4.25.zip
RUN unzip kodexplorer4.25.zip && rm -f kodexplorer4.25.zip
RUN chown -R apache.apache .
CMD ["/usr/sbin/apachectl","-D","FOREGROUND"]1.8 Docker Image Layers
Reference: http://www.maiziedu.com/wiki/cloud/dockerimage/. 99% of Docker Hub images extend a base image by installing/configuring software. Each installation adds a layer.
1.8.1 Why Layering
Resource sharing: multiple images from same base store/load base once. Copy-on-Write: when container modifies base file (e.g., /etc), change is isolated to that container's writable layer.
1.8.2 Writable Container Layer
On container start, a new writable layer ("container layer") is added atop read-only image layers. All changes (add, delete, modify) occur only in container layer.
1.8.3 Container Layer Details
Layers unite into single filesystem. Upper layer file /a overrides lower /a. File operations:
Add file : Created in container layer.
Read file : Search top-down, copy to container layer on first find, then read.
Modify file : Search top-down, copy to container layer on first find, then modify.
Delete file : Search top-down, record deletion in container layer (file not actually removed from lower layers).
This Copy-on-Write ensures image layers remain read-only and shareable.
1.9 Running Zabbix Server with Docker
1.9.1 Container Linking
Create nginx container, then link centos-ssh container with --link quirky_brown:web01. Inside linked container, ping web01 resolves to nginx container IP. Example with httpd and busybox shows same mechanism.
1.9.2 Start Zabbix Stack
1) MySQL:
docker run --name mysql-server -t -e MYSQL_DATABASE="zabbix" -e MYSQL_USER="zabbix" -e MYSQL_PASSWORD="zabbix_pwd" -e MYSQL_ROOT_PASSWORD="root_pwd" -d mysql:5.7 --character-set-server=utf8 --collation-server=utf8_bin2) Java gateway:
docker run --name zabbix-java-gateway -t -d zabbix/zabbix-java-gateway:latest3) Zabbix server: links mysql and java-gateway, sets DB env vars, --link mysql-server:mysql, --link zabbix-java-gateway:zabbix-java-gateway, port 10051.
4) Zabbix web: links mysql and zabbix-server, port 80.
1.9.3 Zabbix API
Get token via curl POST to /api_jsonrpc.php with JSON-RPC user.login. Returns auth token.
1.10 Docker Registry
1.10.1 Basic Registry
Run registry:
docker run -d -p 5000:5000 --restart=always --name registry -v /opt/myregistry:/var/lib/registry registry. Configure daemon for insecure registry: "insecure-registries": ["10.0.0.100:5000"] in /etc/docker/daemon.json, restart docker. Tag image: docker tag busybox:latest 10.0.0.100:5000/clsn/busybox:1.0. Push: docker push 10.0.0.100:5000/clsn/busybox.
1.10.2 Registry with Basic Auth
Install httpd-tools, create htpasswd:
htpasswd -Bbn clsn 123456 > /opt/registry-var/auth/htpasswd. Run registry with auth env vars: REGISTRY_AUTH=htpasswd, REGISTRY_AUTH_HTPASSWD_PATH=/auth/htpasswd. Login: docker login 10.0.0.100:5000, push. Credentials stored in ~/.docker/config.json as base64 auth strings.
1.11 Docker Compose Orchestration
1.11.1 Install
yum install -y python2-pip, pip install docker-compose. Configure pip mirror: index-url = https://mirrors.aliyun.com/pypi/simple/ in ~/.pip/pip.conf.
1.11.2 Compose WordPress
Directory /opt/my_wordpress, docker-compose.yml version '3' with services db (mysql:5.7, volume /data/db_data:/var/lib/mysql, env vars) and wordpress (depends_on db, volume /data/web_data:/var/www/html, ports "8000:80", env vars). Start: docker-compose up -d. Access http://10.0.0.100:8000.
1.11.3 HAProxy Load Balancing
Modify compose: remove fixed port mapping on wordpress ( ports: - "80"). Scale: docker-compose scale wordpress=2 (deprecated, use up --scale). Install HAProxy, configure /etc/haproxy/haproxy.cfg with frontend on 10.0.0.100:8000, backend roundrobin to two wordpress nodes (ports 32768, 32769 from docker-proxy). Enable stats on port 8888 with auth admin:123456. Start HAProxy.
1.11.4 Socat for HAProxy Socket Control
Install socat. Commands: echo "help"|socat stdio /var/lib/haproxy/stats, disable/enable servers via socket. PHP test page check.php shows server address/name.
1.12 Container Restart on Docker Restart
1.12.1 Per-Container Restart Policy
docker run --restart=always.
1.12.2 Daemon Live-Restore
Add "live-restore": true to /etc/docker/daemon.json. Example daemon.json includes registry-mirrors, graph (data dir), insecure-registries, live-restore. Restart docker; applies to containers started after change.
1.13 Docker Network Types
1.13.1 Network Types
None : No network config, --net=none Container : Share network namespace with another container, --net=container:containerID Host : Share host network namespace, --net=host Bridge : Docker NAT model (default)
Bridge: each container gets network namespace, IP bridged to host virtual bridge.
1.13.2 None Network
docker run -it --network none busybox:latest /bin/shshows only loopback interface.
1.13.3 Container Network
docker run -it --network container:mywordpress_db_1 busybox:latest /bin/shshows same IP (172.18.0.3) as target container; processes remain isolated.
1.13.4 Host Network
docker run -it --network host busybox:latest /bin/shshares host IP/ports; considered less secure.
1.13.5 List Networks
docker network listshows bridge, host, none, and compose-created networks.
1.13.6 Pipework for Static IP
Install pipework from GitHub (https://github.com/jpetazzo/pipework). Configure host bridge br0 via ifcfg-eth0 (BRIDGE=br0) and ifcfg-br0 with static IP. Restart network. Assign IP to container:
pipework br0 $(docker run -d -it -p 6880:80 --name httpd_pw httpd) 10.0.0.220/[email protected]. Test curl/ping from other host. Works with --net=none containers too. Note: IP must be reassigned after container restart.
1.13.7 Macvlan Cross-Host
Create network:
docker network create --driver macvlan --subnet 10.1.0.0/24 --gateway 10.1.0.254 -o parent=eth0 macvlan_1. Set ip link set eth0 promisc on. Run container:
docker run -it --network macvlan_1 --ip=10.1.0.222 busybox /bin/sh.
1.14 Harbor Enterprise Registry
Install docker-compose, download harbor-offline-installer-v1.3.0.tgz, extract. Edit harbor.cfg: hostname = 10.0.0.100, harbor_admin_password = Harbor12345. Run ./install.sh. Access web UI, create project. Tag image: docker tag centos:6.8 10.0.0.100/clsn/centos6.8:1.0. Login: docker login 10.0.0.100 (admin/Harbor12345). Push: docker push 10.0.0.100/clsn/centos6.8. Verify in web UI.
1.14.1 Container Best Practices
Don't split application deployment.
Don't create large images.
Don't run multiple processes in one container.
Don't store credentials in images; don't rely on IP addresses.
Run processes as non-root user.
Don't use "latest" tag.
Don't create images from running containers.
Don't use single-layer images.
Don't store data inside containers.
1.14.2 Container Monitoring
Monitor: basic info (count, ID, name, image, command, ports), running state (running, paused, stopped, exited), resource usage (CPU, memory, block I/O, network).
Signed-in readers can open the original source through BestHub's protected redirect.
This article has been distilled and summarized from source material, then republished for learning and reference. If you believe it infringes your rights, please contactand we will review it promptly.
Linux Tech Enthusiast
Focused on sharing practical Linux technology content, covering Linux fundamentals, applications, tools, as well as databases, operating systems, network security, and other technical knowledge.
How this landed with the community
Was this worth your time?
0 Comments
Thoughtful readers leave field notes, pushback, and hard-won operational detail here.
