Docker — Conteneurisation et DevOps
Status: Basic Tags: Docker DevOps Containers Cloud Created: 2026-08-09 Related: Ubuntu, Kubernetes, CD
Introduction
Docker is a platform for developing, shipping, and running applications in lightweight, portable containers. Containers package an application with all its dependencies into a standardized unit for software development.
Installation
Install Docker on Ubuntu
# Install Docker
curl -fsSL https://get.docker.com | sh
# Add user to docker group
sudo usermod -aG docker $USER
newgrp docker
# Verify installation
docker --version
docker run hello-worldCore Concepts
Images
- Definition: Read-only template used to create containers
- Layers: Composed of multiple layers (base image, dependencies, code)
- Tags: Version identifiers (e.g., python:3.12-slim)
- Registry: Centralized storage (Docker Hub, private registries)
Containers
- Definition: Running instances of images
- Isolation: Each container runs in its own namespace
- Lifecycle: Created, started, stopped, removed
- State: Can be saved as new images
Volumes and Networks
- Volumes: Persistent storage for containers
- Bind Mounts: Link host directories to containers
- Networks: Isolate container communication
- Bridge: Default network driver
Dockerfile
Structure
# Use base image
FROM python:3.12-slim
# Set working directory
WORKDIR /app
# Copy requirements and install dependencies
COPY requirements.txt .
RUN pip install --no-cache-dir -r requirements.txt
# Copy application code
COPY . .
# Set environment variables
ENV PORT=8080
ENV DEBUG=false
# Expose port
EXPOSE 8080
# Run application
CMD ["python", "app.py"]Best Practices
- Use slim images: Smaller attack surface, faster builds
- Multi-stage builds: Separate build and runtime environments
- Layer caching: Order instructions by frequency of change
- Security: Run as non-root user
- Health checks: Define health checks for monitoring
Multi-stage Build Example
# Build stage
FROM python:3.12 AS builder
WORKDIR /app
COPY requirements.txt .
RUN pip install --no-cache-dir -r requirements.txt
COPY . .
RUN python -m py_compile app.py
# Runtime stage
FROM python:3.12-slim
WORKDIR /app
COPY --from=builder /app .
EXPOSE 8080
CMD ["python", "app.py"]Docker Commands
Images
# List images
docker images
# Pull image
docker pull python:3.12-slim
# Build image
docker build -t myapp .
# Remove image
docker rmi python:3.12-slim
# Push image to registry
docker push myapp:latestContainers
# List containers
docker ps # Running
docker ps -a # All containers
# Run container
docker run -d --name myapp python:3.12-slim
docker run -p 8080:8080 -v /data:/app/data myapp:latest
# Stop container
docker stop myapp
# Remove container
docker rm myapp
# Execute command in container
docker exec -it myapp bash
# View logs
docker logs myapp
docker logs -f myapp # Follow logs
# Copy files from/to container
docker cp myapp:/app/data.txt .
docker cp data.txt myapp:/app/Networks
# List networks
docker network ls
# Create network
docker network create mynet
# Connect container to network
docker network connect mynet myapp
# Inspect network
docker network inspect mynetVolumes
# List volumes
docker volume ls
# Create volume
docker volume create mydata
# Inspect volume
docker volume inspect mydata
# Remove volume
docker volume rm mydataDocker Compose
Basic Configuration
version: '3.8'
services:
web:
build: .
ports:
- "8080:8080"
volumes:
- ./data:/app/data
environment:
- DEBUG=true
depends_on:
- db
db:
image: postgres:15
environment:
POSTGRES_DB: myapp
POSTGRES_USER: user
POSTGRES_PASSWORD: password
volumes:
- pgdata:/var/lib/postgresql/data
volumes:
pgdata:Common Commands
# Start all services
docker-compose up
# Start in background
docker-compose up -d
# Stop all services
docker-compose down
# Build and start
docker-compose up --build
# View logs
docker-compose logs
# Scale services
docker-compose up --scale web=3Docker Registry
Docker Hub
- Public repositories: Free to use
- Private repositories: Paid plan required
- Automated builds: Connect to GitHub/GitLab
Private Registry
# docker-compose.yml
services:
registry:
image: registry:2
ports:
- "5000:5000"
volumes:
- ./registry-data:/var/lib/registryPush/ Pull Images
# Tag image
docker tag myapp:latest localhost:5000/myapp:latest
# Push to registry
docker push localhost:5000/myapp:latest
# Pull from registry
docker pull localhost:5000/myapp:latestDocker Security
Best Practices
- Use official images: Verified and maintained
- Scan images: Use
docker scanortrivy - Limit privileges: Run as non-root user
- Use secrets: Avoid hardcoding sensitive data
- Keep updated: Regularly update base images
Example: Non-root User
FROM python:3.12-slim
WORKDIR /app
COPY requirements.txt .
RUN pip install --no-cache-dir -r requirements.txt
COPY . .
RUN adduser --disabled-password appuser && \
chown -R appuser:appuser /app
USER appuser
EXPOSE 8080
CMD ["python", "app.py"]Docker with AI/ML
GPU Support
# Install NVIDIA Docker
distribution=$(. /etc/os-release; echo $ID$VERSION_ID)
curl -s -L https://nvidia.github.io/nvidia-docker/gpgkey | \
sudo apt-key add -
curl -s -L https://nvidia.github.io/nvidia-docker/$distribution/nvidia-docker.list | \
sudo tee /etc/apt/sources.list.d/nvidia-docker.list
sudo apt-get update
sudo apt-get install -y nvidia-docker2
sudo systemctl restart dockerPyTorch Container
FROM nvidia/cuda:12.0-cudnn8-runtime-ubuntu22.04
RUN apt-get update && apt-get install -y python3 python3-pip
RUN pip install torch torchvision torchaudio
WORKDIR /app
COPY . .
CMD ["python", "train.py"]TensorFlow Container
FROM tensorflow/tensorflow:latest-gpu
WORKDIR /app
COPY . .
CMD ["python", "train.py"]Resources
Documentation
Tools
- Portainer - Docker management UI
- Docker Compose - Multi-container apps
- Trivy - Container security scanner
- Dive - Image analysis tool