Complete container reference — images · containers · compose · networks · volumes
docker create — creates but doesn't start
docker start — starts a stopped container
docker pause / unpause — freeze/resume
docker stop — graceful stop (SIGTERM → SIGKILL)
docker kill — immediate SIGKILL
docker rm — remove stopped container
["cmd"] doesn't spawn a shell — signals work correctly..dockerignore — keeps images lean and avoids leaking secrets!package*.json first, then run npm install, then copy source
Each RUN creates a new layer — chain commands with &&
Clean up in the same RUN command to avoid layer bloat
--network host is Linux-only. Not supported on Docker Desktop (Mac/Win).depends_on doesn't wait for app readiness — use healthchecks!--memory-swap equal to --memory disables swap entirely.-p.
CMD vs ENTRYPOINT — CMD is overridable; ENTRYPOINT is fixed. Use both together for defaults.
Layer caching — any change to a line invalidates all layers below it. Put COPY source last.
Default bridge network has no DNS. Create a custom network for service discovery.
depends_on waits for container to start, not for the app inside to be ready.
Anonymous volumes in docker run take priority over bind mounts — great for node_modules.
ENV in Dockerfile persists into the container — use ARG for build-only secrets.
docker stop sends SIGTERM then waits 10s before SIGKILL — ensure your app handles SIGTERM.
Multi-stage only copies what you COPY from previous stages — everything else is discarded.
--rm flag removes container on exit — great for one-off tasks, bad for debugging crashes.
USER node in Dockerfile
Use read-only filesystems with --read-only + --tmpfs for writable paths
Always .dockerignore your .env and credentials
Use BuildKit secrets for tokens during build — never ARG for secrets
Scan images with docker scout or Trivy
Pin base image versions — avoid :latest in production
Drop capabilities with --cap-drop ALL and add back only what's needed