Docker CLI Cheatsheet - Run, Build & Compose Commands
A Docker command reference for app developers and SREs, covering image build, container lifecycle, networks & volumes, Compose orchestration, and resource cleanup. Unlike OS-level container tools, Docker layered images and isolation are what matter when you must debug startup failures, mapping mistakes, or image bloat. By the end you can bring a service up from an image and troubleshoot the three most frequent problems: startup, networking, and disk usage.
Typical Use Case
For app developers and SREs: run a local service from an image, build reproducible images, orchestrate multi-container stacks with Compose, and independently diagnose startup failures, port-mapping mistakes, image bloat, and disk-full conditions.
Image 8
docker imagesdocker pull nginx:alpinedocker build -t app:1.0 .docker rmi <image>docker tag app:1.0 reg/app:1.0docker save -o app.tar app:1.0docker load -i app.tardocker pull alpine:3.20 --platform=linux/amd64Container 9
docker ps -adocker run -d -p 8080:80 --name web nginxdocker exec -it web shdocker logs -f --tail 100 webdocker stop web && docker rm webdocker inspect webdocker start web && docker restart webdocker statsdocker top webNetwork & Volume 8
docker network lsdocker network create appnetdocker network connect appnet webdocker volume lsdocker run -v data:/var/lib/app appdocker run -v $(pwd):/app appdocker volume create appdatadocker volume pruneRegistry 6
docker logindocker login registry.example.comdocker push app:1.0docker pull ubuntu:22.04docker search nginxdocker logoutBuild & Debug 7
docker build -t app:1.0 --no-cache .docker build -t app:1.0 --target=dev .docker history app:1.0docker diff <container>docker cp app.conf web:/etc/nginx/conf.d/docker cp web:/var/log/nginx/access.log ./docker events --since 5mCompose & Cleanup 9
docker compose up -ddocker compose logs -f svcdocker compose downdocker compose psdocker compose restartdocker system dfdocker system prune -adocker container prunedocker image prune -aFAQ 5
Q: How to clean up all unused Docker resources?Q: How to view container logs?Q: How to enter a running container?Q: How to copy files between host and container?Q: What restart policies are available?Parameter matrix
| 参数 | Effect | Example |
|---|---|---|
-d | 后台(detached)运行容器 | docker run -d -p 8080:80 nginx |
-p | 端口映射,格式 主机端口:容器端口 | docker run -d -p 8080:80 nginx |
--name | 为容器指定可读名字,便于后续操作 | docker run -d --name web nginx |
-v | 挂载数据卷或绑定目录,持久化数据 | docker run -v /data:/app/data nginx |
--rm | 容器退出后自动删除,避免残留 | docker run --rm alpine echo hi |
-e | 向容器内注入环境变量 | docker run -e NODE_ENV=prod app |
--network | 加入指定网络,容器间可用名字互访 | docker run --network appnet web |
-it | 分配交互式终端,用于进入容器 shell | docker exec -it web sh |
--restart | 退出后的重启策略(no/on-failure/always) | docker run -d --restart unless-stopped web |
--platform | 指定目标架构(ARM Mac 拉 amd64) | docker pull --platform=linux/amd64 nginx |
--no-cache | 构建时忽略层缓存,强制重跑所有层 | docker build --no-cache -t app . |
-f | 指定 Dockerfile 路径 | docker build -f Dockerfile.prod -t app . |
Common pitfalls
Symptom端口映射后仍无法从宿主机其他进程或外网访问容器服务。
Cause把 主机:容器 写反,或容器内进程只监听 127.0.0.1 而非 0.0.0.0。
Fix确认 -p 8080:80 是「宿主机端口:容器端口」;容器应用需监听 0.0.0.0 才能被外部访问。
Symptomdocker exec 进入容器报 OCI runtime exec failed: exec: "bash": not found。
Cause镜像基于 alpine/scratch 等精简镜像,没有内置 bash。
Fix改用 sh:docker exec -it web sh;或在 Dockerfile 中 apk add bash 后再用 bash。
Symptomdocker build 每次都重新拉取基础镜像、层缓存不命中。
Cause基础镜像用 latest 标签,或把易变的文件(源码)COPY 在不变的文件之前。
Fix固定基础镜像版本(如 node:20-alpine);把不常变的依赖安装层放在前面,源码 COPY 放最后。
Symptom构建或运行报 No space left on device,宿主机磁盘被占满。
Cause大量已停止容器、悬空镜像(<none>)、未清理的数据卷长期累积。
Fix先 docker system df 看占用,再 docker system prune -a --volumes 清理;生产机设定期清理任务。
Symptom容器被强制退出,docker inspect 看到 ExitCode 137。
Cause内存超限被 OOM Killer 杀掉(137 = SIGKILL)。
Fix用 docker stats 看实时内存;为容器设合理 --memory 上限,或优化应用内存占用。
Symptom在 ARM Mac 上拉取的镜像放到 x86 服务器上跑报错 exec format error。
Cause镜像架构与运行环境不一致(arm64 vs amd64)。
Fix构建/拉取时显式指定目标平台:docker build --platform=linux/amd64 -t app . 并推送对应架构镜像。
Symptom在容器内修改了配置文件,重建镜像后改动全部丢失。
Cause容器文件系统是临时的,未挂载持久卷。
Fix用 -v 挂载命名卷或绑定目录(-v /host/path:/container/path)保存需要保留的状态。
Troubleshooting
1容器起不来或闪退,先看日志
docker logs --tail 50 web从日志末尾定位启动失败的报错(配置错误、依赖缺失、端口占用)。
2确认容器退出状态与原因
docker inspect -f '{{.State}}' webExitCode 0=正常退出,137=OOM,139=段错误等,结合 Reason 判断。
3端口冲突或映射异常时列出所有容器端口
docker ps --format '{{.Names}}\t{{.Ports}}'核对 0.0.0.0:8080->80/tcp 是否如预期,避免端口被其他容器占用。
4磁盘被占满时先看各对象占用
docker system df区分 Images / Containers / Volumes 占用,再针对性清理。
5进入容器排查网络连通性
docker exec -it web sh -c "cat /etc/resolv.conf; ping -c1 8.8.8.8"分别验证 DNS 解析与出网连通,定位是网络配置还是镜像问题。
Command Examples
Run nginx in the background with a port mapping
docker run -d --name web -p 8080:80 nginx:alpine-p 8080:80 表示宿主机 8080 转发到容器 80,访问 http://localhost:8080 即可看到 nginx 欢迎页;-d 让容器后台运行,--name 便于后续用名字管理。
Output
b3f2c1a9d8e4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b
Bind-mount the current directory and enter an interactive shell
docker run -it --rm -v "$(pwd)":/app -w /app node:18-alpine sh-v 把当前目录挂载到容器 /app,-w 设为工作目录,--rm 退出时自动删除容器,-it 提供交互终端,适合本地调试 Node 应用而无需本地安装 Node。
Follow the last 100 lines of a container log
docker logs -f --tail 100 web-f 实时跟踪后续日志,--tail 100 只从最后 100 行开始输出,排查启动崩溃或请求异常时第一命令。
Prune unused images to free disk space
docker system df先 docker system df 看占用,再决定是否 docker image prune -a 清理所有未被容器引用的镜像;删镜像前务必确认没有需要保留的版本。
Output
TYPE TOTAL ACTIVE SIZE RECLAIMABLE Images 12 5 1.4GB 621.5MB (43%) Containers 8 3 5.6MB 5.6MB (100%)
Common Pitfalls
- docker run -p is host_port:container_port — reversed means external access never works, and it fails silently, the hardest thing to debug.
- prune -a removes every image no container is using, including freshly built but not-yet-run versions. Run docker images first on production.
- An "executable file not found" error usually means the image lacks that shell; Alpine ships only sh, so use docker exec -it <c> sh.
- Flags like -e env vars and port mappings cannot be changed after the container starts; you must stop, remove, and re-run.
- A permission denied on bind mounts often comes from a mismatch between the host directory owner and the container user.
Tips
- In docker run -p, it's host_port:container_port — reversing them blocks external access.
- If exec says "executable file not found", switch to sh: Alpine images usually lack bash.
- prune -a removes all images not used by any container — verify with docker images first on production.
- docker system df quickly shows disk usage — run it periodically to avoid /var/lib/docker filling up.
- docker compose restart is faster than down/up and does not rebuild networks or volumes — best for nginx config changes.
FAQ
What is the difference between docker run and docker start?
docker run creates and starts a new container from an image (first launch); docker start restarts an existing but stopped container without creating a new instance. Use start to debug existing state, run to deploy new services.
How do I free up disk space used by Docker?
Use docker system prune to remove stopped containers, dangling images, and build cache; add -a to also remove all images not referenced by any container. Use cautiously in production to avoid deleting valuable images.
What is the relationship between a container and an image?
An image is a read-only template containing the code, dependencies, and config needed to run an app; a container is a running instance of that image with a writable layer on top. One image can launch multiple isolated containers.
Why does my container exit immediately with status Exited (0)?
Check the exit code with docker ps -a: Exited (0) usually means the foreground process did not stay alive (the command finished and exited), so use -it or switch to a foreground command in the Dockerfile (e.g. CMD ["nginx","-g","daemon off;"]). For non-zero codes, run docker logs <id> to read the real error, usually a missing dependency, permission, or wrong config path.
Why can I not reach localhost from inside a container?
Inside a container, localhost refers to the container itself, not the host, so host services are unreachable via localhost. To reach a host service, use the default bridge gateway IP (host.docker.internal on macOS/Windows, --network host or the host LAN IP on Linux). To make containers talk to each other, join them to a custom network and address them by container name.
Official References
Each command links to its official documentation below, so you can verify the latest usage and read deeper.
Maintained by LaoHand
Publicly updated on Sep 10, 2026, continuously proofread against official docs.
Contact Us
Wrong command or description? Send us corrections, business inquiries or product feedback by email.
Contact Us