Docker — Conteneurisation et DevOps

Status: Basic Tags: Docker DevOps Containers Cloud Created: 2026-08-09 Related: Ubuntu, Kubernetes, CD

Introduction

Docker is a platform for developing, shipping, and running applications in lightweight, portable containers. Containers package an application with all its dependencies into a standardized unit for software development.


Installation

Install Docker on Ubuntu

# Install Docker
curl -fsSL https://get.docker.com | sh
 
# Add user to docker group
sudo usermod -aG docker $USER
newgrp docker
 
# Verify installation
docker --version
docker run hello-world

Core Concepts

Images

  • Definition: Read-only template used to create containers
  • Layers: Composed of multiple layers (base image, dependencies, code)
  • Tags: Version identifiers (e.g., python:3.12-slim)
  • Registry: Centralized storage (Docker Hub, private registries)

Containers

  • Definition: Running instances of images
  • Isolation: Each container runs in its own namespace
  • Lifecycle: Created, started, stopped, removed
  • State: Can be saved as new images

Volumes and Networks

  • Volumes: Persistent storage for containers
  • Bind Mounts: Link host directories to containers
  • Networks: Isolate container communication
  • Bridge: Default network driver

Dockerfile

Structure

# Use base image
FROM python:3.12-slim
 
# Set working directory
WORKDIR /app
 
# Copy requirements and install dependencies
COPY requirements.txt .
RUN pip install --no-cache-dir -r requirements.txt
 
# Copy application code
COPY . .
 
# Set environment variables
ENV PORT=8080
ENV DEBUG=false
 
# Expose port
EXPOSE 8080
 
# Run application
CMD ["python", "app.py"]

Best Practices

  • Use slim images: Smaller attack surface, faster builds
  • Multi-stage builds: Separate build and runtime environments
  • Layer caching: Order instructions by frequency of change
  • Security: Run as non-root user
  • Health checks: Define health checks for monitoring

Multi-stage Build Example

# Build stage
FROM python:3.12 AS builder
WORKDIR /app
COPY requirements.txt .
RUN pip install --no-cache-dir -r requirements.txt
COPY . .
RUN python -m py_compile app.py
 
# Runtime stage
FROM python:3.12-slim
WORKDIR /app
COPY --from=builder /app .
EXPOSE 8080
CMD ["python", "app.py"]

Docker Commands

Images

# List images
docker images
 
# Pull image
docker pull python:3.12-slim
 
# Build image
docker build -t myapp .
 
# Remove image
docker rmi python:3.12-slim
 
# Push image to registry
docker push myapp:latest

Containers

# List containers
docker ps                    # Running
docker ps -a                # All containers
 
# Run container
docker run -d --name myapp python:3.12-slim
docker run -p 8080:8080 -v /data:/app/data myapp:latest
 
# Stop container
docker stop myapp
 
# Remove container
docker rm myapp
 
# Execute command in container
docker exec -it myapp bash
 
# View logs
docker logs myapp
docker logs -f myapp        # Follow logs
 
# Copy files from/to container
docker cp myapp:/app/data.txt .
docker cp data.txt myapp:/app/

Networks

# List networks
docker network ls
 
# Create network
docker network create mynet
 
# Connect container to network
docker network connect mynet myapp
 
# Inspect network
docker network inspect mynet

Volumes

# List volumes
docker volume ls
 
# Create volume
docker volume create mydata
 
# Inspect volume
docker volume inspect mydata
 
# Remove volume
docker volume rm mydata

Docker Compose

Basic Configuration

version: '3.8'
services:
  web:
    build: .
    ports:
      - "8080:8080"
    volumes:
      - ./data:/app/data
    environment:
      - DEBUG=true
    depends_on:
      - db
 
  db:
    image: postgres:15
    environment:
      POSTGRES_DB: myapp
      POSTGRES_USER: user
      POSTGRES_PASSWORD: password
    volumes:
      - pgdata:/var/lib/postgresql/data
 
volumes:
  pgdata:

Common Commands

# Start all services
docker-compose up
 
# Start in background
docker-compose up -d
 
# Stop all services
docker-compose down
 
# Build and start
docker-compose up --build
 
# View logs
docker-compose logs
 
# Scale services
docker-compose up --scale web=3

Docker Registry

Docker Hub

  • Public repositories: Free to use
  • Private repositories: Paid plan required
  • Automated builds: Connect to GitHub/GitLab

Private Registry

# docker-compose.yml
services:
  registry:
    image: registry:2
    ports:
      - "5000:5000"
    volumes:
      - ./registry-data:/var/lib/registry

Push/ Pull Images

# Tag image
docker tag myapp:latest localhost:5000/myapp:latest
 
# Push to registry
docker push localhost:5000/myapp:latest
 
# Pull from registry
docker pull localhost:5000/myapp:latest

Docker Security

Best Practices

  • Use official images: Verified and maintained
  • Scan images: Use docker scan or trivy
  • Limit privileges: Run as non-root user
  • Use secrets: Avoid hardcoding sensitive data
  • Keep updated: Regularly update base images

Example: Non-root User

FROM python:3.12-slim
WORKDIR /app
COPY requirements.txt .
RUN pip install --no-cache-dir -r requirements.txt
COPY . .
RUN adduser --disabled-password appuser && \
    chown -R appuser:appuser /app
USER appuser
EXPOSE 8080
CMD ["python", "app.py"]

Docker with AI/ML

GPU Support

# Install NVIDIA Docker
distribution=$(. /etc/os-release; echo $ID$VERSION_ID)
curl -s -L https://nvidia.github.io/nvidia-docker/gpgkey | \
  sudo apt-key add -
curl -s -L https://nvidia.github.io/nvidia-docker/$distribution/nvidia-docker.list | \
  sudo tee /etc/apt/sources.list.d/nvidia-docker.list
 
sudo apt-get update
sudo apt-get install -y nvidia-docker2
sudo systemctl restart docker

PyTorch Container

FROM nvidia/cuda:12.0-cudnn8-runtime-ubuntu22.04
RUN apt-get update && apt-get install -y python3 python3-pip
RUN pip install torch torchvision torchaudio
WORKDIR /app
COPY . .
CMD ["python", "train.py"]

TensorFlow Container

FROM tensorflow/tensorflow:latest-gpu
WORKDIR /app
COPY . .
CMD ["python", "train.py"]

Resources

Documentation

Tools