Study notes · 10% of the exam

Running Containers, Lifecycle and Resources

Know how `docker run` builds the command, how containers start, stop, restart and die, how to limit resources, and how to debug a container that misbehaves.

Key points

  1. 1

    Arguments after the image name replace CMD and are appended to ENTRYPOINT; --entrypoint replaces ENTRYPOINT and clears the image CMD.

  2. 2

    docker stop sends SIGTERM (or STOPSIGNAL), waits 10 s on Linux, then SIGKILL. Exit codes above 128 mean a signal: 137 = SIGKILL, 143 = SIGTERM.

  3. 3

    PID 1 ignores signals it has no handler for, and shell-form CMD makes /bin/sh PID 1. Use exec form, exec in entrypoint scripts, or --init to reap zombies and forward signals.

  4. 4

    Restart policies: on-failure[:n] only on non-zero exits; always restarts after a daemon restart even if stopped manually; unless-stopped does not. Unhealthy containers are not restarted by the standalone engine.

  5. 5

    --memory is a hard cap enforced by the OOM killer (check State.OOMKilled); --memory-swap is memory plus swap; --cpus caps CPU while --cpu-shares only weights it under contention; --pids-limit stops fork bombs.

  6. 6

    The writable layer survives stop and restart but not docker rm; docker cp works on stopped containers and docker commit never includes volumes.

  7. 7

    Only stdout and stderr reach docker logs. json-file does not rotate by default; local does; dual logging keeps docker logs working with remote drivers.

Common traps

  • Ctrl-C after docker attach sends SIGINT to PID 1 and can stop a production container; detach with Ctrl-P Ctrl-Q.

  • free and /proc/meminfo inside a container show host memory, not the --memory limit.

  • Environment variables are fixed at creation; docker restart and docker update cannot change them.

Test yourself on Running Containers, Lifecycle and Resources

Ten questions, with the answer and explanation after each one.