Operations 46 min read

Complete Docker Beginner's Guide: From Installation to Production Orchestration

This comprehensive Docker tutorial covers container fundamentals, installation on CentOS, image and container management, Dockerfile creation, data volumes, networking, Docker Compose orchestration, registry setup, and production best practices with hands-on command examples.

Linux Tech Enthusiast
Linux Tech Enthusiast
Linux Tech Enthusiast
Complete Docker Beginner's Guide: From Installation to Production Orchestration

1.1 Container Introduction

1.1.1 What Are Linux Containers

Linux containers are isolated processes running from a distinct image that provides all necessary files. Containers package application dependencies, ensuring portability and consistency from development through testing to production.

The article illustrates with a scenario: developing on a laptop with specific configuration while the enterprise has standardized test and production environments. Containers ensure the application runs across these environments without re-creating server environments or rewriting code.

1.1.2 Containers vs Virtualization

Virtualization runs multiple OS instances on a single system via a hypervisor. Containers share the host OS kernel while isolating application processes. This makes containers more lightweight, enabling dense deployment on limited resources.

1.1.3 Container History

Concept originated in 2000 as FreeBSD jail for partitioning systems into secure subsystems. Jail used a modified chroot environment virtualizing filesystem, network, and user access. In 2001, Jacques Gélinas' VServer project brought isolation to Linux, enabling multiple controlled user spaces.

1.2 What Is Docker?

Docker refers to the open-source community project, tools from the project, Docker Inc. (the company), and officially supported tools. Docker lets you treat containers as lightweight, modular VMs with high flexibility for creation, deployment, replication, and migration across environments.

1.2.1 How Docker Works

Docker uses Linux kernel features Cgroups and namespaces to isolate processes. It provides image-based deployment, making it easy to share applications with dependencies across environments. Docker automates application deployment within containers.

1.2.2 Docker vs Traditional Linux Containers (LXC)

Docker initially used LXC but later moved away. LXC uses an init system to manage multiple processes as a single unit. Docker encourages each application to run its own process independently, providing tools for this granular approach.

1.2.3 Docker Goals

Build, Ship, and Run Any App, Anywhere : Build a Docker image, Ship via docker pull, Run by starting a container. Each container has its own filesystem rootfs.

1.3 Installing Docker

Environment: two CentOS 7.2 nodes (kernel 3.10.0-327.el7.x86_64) with IPs 10.0.0.100/101 and 172.16.1.100/101.

On both nodes:

wget -O /etc/yum.repos.d/docker-ce.repo https://mirrors.ustc.edu.cn/docker-ce/linux/centos/docker-ce.repo
sed -i 's#download.docker.com#mirrors.ustc.edu.cn/docker-ce#g' /etc/yum.repos.d/docker-ce.repo
yum install docker-ce -y

On docker01, modify /usr/lib/systemd/system/docker.service to listen on remote port:

ExecStart=/usr/bin/dockerd -H unix:///var/run/docker.sock -H tcp://10.0.0.100:2375
systemctl daemon-reload
systemctl enable docker.service
systemctl restart docker.service

Test from docker02: docker -H 10.0.0.100 info shows Server Version 17.12.0-ce, Storage Driver devicemapper.

1.3.1 Basic Commands

docker version

shows client/server version 17.12.0-ce, API 1.35, Go 1.9.2.

Configure registry mirror in /etc/docker/daemon.json:

{
  "registry-mirrors": ["https://registry.docker-cn.com"]
}

1.3.2 First Container

docker run -d -p 80:80 nginx

pulls nginx:latest, downloads layers, starts container. Parameters: run create+run, -d detach, -p port mapping, nginx image name.

1.3.3 Image Lifecycle

Diagram shows image layers: base image, software layers, container writable layer.

1.4 Image Operations

1.4.1 Search Official Repository

docker search centos

returns columns: NAME, DESCRIPTION, STARS, OFFICIAL, AUTOMATED.

1.4.2 Pull Images

docker pull centos

downloads latest tag (207MB). docker image list shows REPOSITORY, TAG, IMAGE ID, CREATED, SIZE. Third-party pull: docker pull index.tenxcloud.com/tenxcloud/httpd.

1.4.3 Export Image

docker image save centos > docker-centos.tar.gz

exports to tar.gz.

1.4.4 Remove Image

docker image rm centos:latest

removes image.

1.4.5 Import Image

docker image load -i docker-centos.tar.gz

loads image back.

1.4.6 Inspect Image

docker image inspect centos

shows detailed metadata.

1.5 Container Daily Management

1.5.1 Start/Stop

Simple run: docker run nginx. Two-step create+start (rare): docker create centos:latest /bin/bash then docker start <name>. Quick run with command: docker run centos:latest /usr/bin/sleep 20. Key rule: the first process inside container must keep running, otherwise container exits.

List running: docker container ls or docker ps. Inspect: docker container inspect <name/id>. List all: docker ps -a. Stop: docker stop <name/id> or docker container kill <name/id>.

1.5.2 Enter Container

At start: docker run -it nginx:latest /bin/bash ( -it interactive TTY). Exit with ctrl+p & ctrl+q to detach.

After start: docker attach <id> attaches to existing terminal (shared view). Recommended: docker exec -it <name> /bin/bash creates new terminal session (isolated). Example shows separate PTS terminals.

1.5.3 Remove All Containers

docker rm -f `docker ps -a -q`

( -f force).

1.5.4 Port Mapping

Formats: -p hostPort:containerPort, -p ip:hostPort:containerPort, -p ip::containerPort (random host port), -p hostPort:containerPort:udp, multiple -p flags. Random mapping: docker run -P (capital P, requires image support).

1.6 Data Volume Management

1.6.1 Create Volume at Mount

docker run -d -p 80:80 -v /data:/usr/share/nginx/html nginx:latest

mounts host /data to container /usr/share/nginx/html. Writing echo "http://www.nmtui.com" >/data/index.html on host reflects in container via curl 10.0.0.100. Shared volume: second container with same -v sees same content. docker volume ls lists volumes (DRIVER, VOLUME NAME).

1.6.2 Create Volume Then Mount

docker volume create

generates random name. Named volume: docker volume create clsn. Inspect: docker volume inspect clsn shows Mountpoint /var/lib/docker/volumes/clsn/_data. Use:

docker run -d -p 9000:80 -v clsn:/usr/share/nginx/html nginx:latest

. Write to mountpoint on host, verify via curl. --volumes-from shares volumes from another container.

1.6.3 Manual Image Creation from Container

Start centos:6.8, install openssh-server, set root password, start sshd. Commit: docker commit <container> centos6-ssh. Run new image:

docker run -d -p 1122:22 centos6-ssh:latest /usr/sbin/sshd -D

. Install httpd, create init.sh starting httpd and sshd, commit again: docker commit <id> centos6-httpd. Run with ports 1222:22 and 80:80.

1.7 Dockerfile Automated Builds

Reference: https://github.com/CentOS/CentOS-Dockerfiles

1.7.1 Dockerfile Instructions

Core parts: FROM base image, RUN build commands, CMD startup command. Common instructions explained mnemonically: FROM (mother), MAINTAINER (caretaker), RUN (what to do), ADD (funding, auto-extract), WORKDIR (cd), VOLUME (luggage storage), EXPOSE (open doors), CMD (run!). Others: COPY, ENV, ENTRYPOINT.

1.7.2 Create a Dockerfile

Directory /opt/base, file Dockerfile:

FROM centos:6.8
RUN yum install openssh-server -y
RUN echo "root:123456" |chpasswd
RUN /etc/init.d/sshd start
CMD ["/usr/sbin/sshd","-D"]

Build: docker image build -t centos6.8-ssh . ( -t tag, . current path). Run: docker run -d -p 2022:22 centos6.8-ssh-b.

1.7.3 Dockerfile for kodexplorer

FROM centos:6.8
RUN yum install wget unzip php php-gd php-mbstring -y && yum clean all
WORKDIR /var/www/html/
RUN wget -c http://static.kodcloud.com/update/download/kodexplorer4.25.zip
RUN unzip kodexplorer4.25.zip && rm -f kodexplorer4.25.zip
RUN chown -R apache.apache .
CMD ["/usr/sbin/apachectl","-D","FOREGROUND"]

1.8 Docker Image Layers

Reference: http://www.maiziedu.com/wiki/cloud/dockerimage/. 99% of Docker Hub images extend a base image by installing/configuring software. Each installation adds a layer.

1.8.1 Why Layering

Resource sharing: multiple images from same base store/load base once. Copy-on-Write: when container modifies base file (e.g., /etc), change is isolated to that container's writable layer.

1.8.2 Writable Container Layer

On container start, a new writable layer ("container layer") is added atop read-only image layers. All changes (add, delete, modify) occur only in container layer.

1.8.3 Container Layer Details

Layers unite into single filesystem. Upper layer file /a overrides lower /a. File operations:

Add file : Created in container layer.

Read file : Search top-down, copy to container layer on first find, then read.

Modify file : Search top-down, copy to container layer on first find, then modify.

Delete file : Search top-down, record deletion in container layer (file not actually removed from lower layers).

This Copy-on-Write ensures image layers remain read-only and shareable.

1.9 Running Zabbix Server with Docker

1.9.1 Container Linking

Create nginx container, then link centos-ssh container with --link quirky_brown:web01. Inside linked container, ping web01 resolves to nginx container IP. Example with httpd and busybox shows same mechanism.

1.9.2 Start Zabbix Stack

1) MySQL:

docker run --name mysql-server -t -e MYSQL_DATABASE="zabbix" -e MYSQL_USER="zabbix" -e MYSQL_PASSWORD="zabbix_pwd" -e MYSQL_ROOT_PASSWORD="root_pwd" -d mysql:5.7 --character-set-server=utf8 --collation-server=utf8_bin

2) Java gateway:

docker run --name zabbix-java-gateway -t -d zabbix/zabbix-java-gateway:latest

3) Zabbix server: links mysql and java-gateway, sets DB env vars, --link mysql-server:mysql, --link zabbix-java-gateway:zabbix-java-gateway, port 10051.

4) Zabbix web: links mysql and zabbix-server, port 80.

1.9.3 Zabbix API

Get token via curl POST to /api_jsonrpc.php with JSON-RPC user.login. Returns auth token.

1.10 Docker Registry

1.10.1 Basic Registry

Run registry:

docker run -d -p 5000:5000 --restart=always --name registry -v /opt/myregistry:/var/lib/registry registry

. Configure daemon for insecure registry: "insecure-registries": ["10.0.0.100:5000"] in /etc/docker/daemon.json, restart docker. Tag image: docker tag busybox:latest 10.0.0.100:5000/clsn/busybox:1.0. Push: docker push 10.0.0.100:5000/clsn/busybox.

1.10.2 Registry with Basic Auth

Install httpd-tools, create htpasswd:

htpasswd -Bbn clsn 123456 > /opt/registry-var/auth/htpasswd

. Run registry with auth env vars: REGISTRY_AUTH=htpasswd, REGISTRY_AUTH_HTPASSWD_PATH=/auth/htpasswd. Login: docker login 10.0.0.100:5000, push. Credentials stored in ~/.docker/config.json as base64 auth strings.

1.11 Docker Compose Orchestration

1.11.1 Install

yum install -y python2-pip

, pip install docker-compose. Configure pip mirror: index-url = https://mirrors.aliyun.com/pypi/simple/ in ~/.pip/pip.conf.

1.11.2 Compose WordPress

Directory /opt/my_wordpress, docker-compose.yml version '3' with services db (mysql:5.7, volume /data/db_data:/var/lib/mysql, env vars) and wordpress (depends_on db, volume /data/web_data:/var/www/html, ports "8000:80", env vars). Start: docker-compose up -d. Access http://10.0.0.100:8000.

1.11.3 HAProxy Load Balancing

Modify compose: remove fixed port mapping on wordpress ( ports: - "80"). Scale: docker-compose scale wordpress=2 (deprecated, use up --scale). Install HAProxy, configure /etc/haproxy/haproxy.cfg with frontend on 10.0.0.100:8000, backend roundrobin to two wordpress nodes (ports 32768, 32769 from docker-proxy). Enable stats on port 8888 with auth admin:123456. Start HAProxy.

1.11.4 Socat for HAProxy Socket Control

Install socat. Commands: echo "help"|socat stdio /var/lib/haproxy/stats, disable/enable servers via socket. PHP test page check.php shows server address/name.

1.12 Container Restart on Docker Restart

1.12.1 Per-Container Restart Policy

docker run --restart=always

.

1.12.2 Daemon Live-Restore

Add "live-restore": true to /etc/docker/daemon.json. Example daemon.json includes registry-mirrors, graph (data dir), insecure-registries, live-restore. Restart docker; applies to containers started after change.

1.13 Docker Network Types

1.13.1 Network Types

None : No network config, --net=none Container : Share network namespace with another container, --net=container:containerID Host : Share host network namespace, --net=host Bridge : Docker NAT model (default)

Bridge: each container gets network namespace, IP bridged to host virtual bridge.

1.13.2 None Network

docker run -it --network none busybox:latest /bin/sh

shows only loopback interface.

1.13.3 Container Network

docker run -it --network container:mywordpress_db_1 busybox:latest /bin/sh

shows same IP (172.18.0.3) as target container; processes remain isolated.

1.13.4 Host Network

docker run -it --network host busybox:latest /bin/sh

shares host IP/ports; considered less secure.

1.13.5 List Networks

docker network list

shows bridge, host, none, and compose-created networks.

1.13.6 Pipework for Static IP

Install pipework from GitHub (https://github.com/jpetazzo/pipework). Configure host bridge br0 via ifcfg-eth0 (BRIDGE=br0) and ifcfg-br0 with static IP. Restart network. Assign IP to container:

pipework br0 $(docker run -d -it -p 6880:80 --name httpd_pw httpd) 10.0.0.220/[email protected]

. Test curl/ping from other host. Works with --net=none containers too. Note: IP must be reassigned after container restart.

1.13.7 Macvlan Cross-Host

Create network:

docker network create --driver macvlan --subnet 10.1.0.0/24 --gateway 10.1.0.254 -o parent=eth0 macvlan_1

. Set ip link set eth0 promisc on. Run container:

docker run -it --network macvlan_1 --ip=10.1.0.222 busybox /bin/sh

.

1.14 Harbor Enterprise Registry

Install docker-compose, download harbor-offline-installer-v1.3.0.tgz, extract. Edit harbor.cfg: hostname = 10.0.0.100, harbor_admin_password = Harbor12345. Run ./install.sh. Access web UI, create project. Tag image: docker tag centos:6.8 10.0.0.100/clsn/centos6.8:1.0. Login: docker login 10.0.0.100 (admin/Harbor12345). Push: docker push 10.0.0.100/clsn/centos6.8. Verify in web UI.

1.14.1 Container Best Practices

Don't split application deployment.

Don't create large images.

Don't run multiple processes in one container.

Don't store credentials in images; don't rely on IP addresses.

Run processes as non-root user.

Don't use "latest" tag.

Don't create images from running containers.

Don't use single-layer images.

Don't store data inside containers.

1.14.2 Container Monitoring

Monitor: basic info (count, ID, name, image, command, ports), running state (running, paused, stopped, exited), resource usage (CPU, memory, block I/O, network).

Original Source

Signed-in readers can open the original source through BestHub's protected redirect.

Sign in to view source
Republication Notice

This article has been distilled and summarized from source material, then republished for learning and reference. If you believe it infringes your rights, please contactadmin@besthub.devand we will review it promptly.

Dockercontainerizationbest-practicesnetworkingdockerfiledocker-composevolumesregistry
Linux Tech Enthusiast
Written by

Linux Tech Enthusiast

Focused on sharing practical Linux technology content, covering Linux fundamentals, applications, tools, as well as databases, operating systems, network security, and other technical knowledge.

0 followers
Reader feedback

How this landed with the community

Sign in to like

Rate this article

Was this worth your time?

Sign in to rate
Discussion

0 Comments

Thoughtful readers leave field notes, pushback, and hard-won operational detail here.