Running Containers, Lifecycle and Resources
Know how `docker run` builds the command, how containers start, stop, restart and die, how to limit resources, and how to debug a container that misbehaves.
Key points
- 1
Arguments after the image name replace CMD and are appended to ENTRYPOINT;
--entrypointreplaces ENTRYPOINT and clears the image CMD. - 2
docker stopsends SIGTERM (or STOPSIGNAL), waits 10 s on Linux, then SIGKILL. Exit codes above 128 mean a signal: 137 = SIGKILL, 143 = SIGTERM. - 3
PID 1 ignores signals it has no handler for, and shell-form CMD makes
/bin/shPID 1. Use exec form,execin entrypoint scripts, or--initto reap zombies and forward signals. - 4
Restart policies:
on-failure[:n]only on non-zero exits;alwaysrestarts after a daemon restart even if stopped manually;unless-stoppeddoes not. Unhealthy containers are not restarted by the standalone engine. - 5
--memoryis a hard cap enforced by the OOM killer (checkState.OOMKilled);--memory-swapis memory plus swap;--cpuscaps CPU while--cpu-sharesonly weights it under contention;--pids-limitstops fork bombs. - 6
The writable layer survives stop and restart but not
docker rm;docker cpworks on stopped containers anddocker commitnever includes volumes. - 7
Only stdout and stderr reach
docker logs. json-file does not rotate by default;localdoes; dual logging keepsdocker logsworking with remote drivers.
Common traps
Ctrl-C after
docker attachsends SIGINT to PID 1 and can stop a production container; detach with Ctrl-P Ctrl-Q.freeand/proc/meminfoinside a container show host memory, not the--memorylimit.Environment variables are fixed at creation;
docker restartanddocker updatecannot change them.
Test yourself on Running Containers, Lifecycle and Resources
Ten questions, with the answer and explanation after each one.