Docker Interview Questions
Containers vs VMs, images, Dockerfiles, layers, volumes, networking, multi-stage builds, Compose and container security.
61 questions
Popular Searches
1. What is Docker and how does containerization differ from virtual machines?
easyContainerization Fundamentals 6 mins2. What is a Docker image and how does it differ from a container?
easyImages and Containers 6 mins3. What is a Dockerfile and what are its most important instructions?
mediumBuilding Images 7 mins4. How do Docker image layers and the build cache work?
mediumImages & Builds 7 mins5. What is the difference between the CMD and ENTRYPOINT instructions in a Dockerfile?
mediumDockerfile Instructions 6 mins6. What is the difference between COPY and ADD in a Dockerfile?
easyDockerfile Instructions 6 mins7. What are Docker volumes and how do they differ from bind mounts?
mediumStorage 7 mins8. How does Docker networking work and what are the built-in network drivers?
mediumNetworking 8 mins9. What is a multi-stage build and why does it matter for image size?
mediumImage Optimization 7 mins10. What is the difference between docker run, docker start, and docker exec?
easyContainer Lifecycle 6 mins11. How do you reduce Docker image size and why does it matter?
mediumImage Optimization 7 mins12. What is Docker Compose and when should you use it?
easyOrchestration 6 mins13. What is the difference between EXPOSE and publishing a port with -p?
mediumNetworking 6 mins14. How does the Docker layer cache get invalidated and how do you order instructions to exploit it?
mediumImage Optimization 7 mins15. What are Docker image tags and why is relying on latest a bad practice?
easyImage Management 6 mins16. What is the difference between a container's writable layer and a persistent volume?
mediumStorage 6 mins17. How do environment variables and ARG differ in a Dockerfile?
mediumDockerfile 6 mins18. What is a Docker registry and how do push and pull work?
easyRegistry 5 mins19. How do you run a container as a non-root user and why does it matter for security?
mediumContainer Security 7 mins20. What is the difference between stopping and killing a container?
easyContainer Lifecycle 6 mins21. What are health checks in Docker and how do they work?
mediumContainer Monitoring 7 mins22. How does Docker handle logging and how do you view container logs?
mediumObservability 6 mins23. What is the difference between docker system prune and removing images manually?
mediumResource Management 6 mins24. How do you pass secrets to a container securely?
hardSecurity 7 mins25. What is the role of the .dockerignore file?
easyBuild Context 6 mins26. How do resource limits (memory and CPU) work for Docker containers?
mediumRuntime 7 mins27. What is the difference between an image digest and a tag?
mediumImages 6 mins28. How does container restart policy work in Docker?
mediumContainer Lifecycle 6 mins29. What is the difference between Docker Compose and Docker Swarm?
mediumOrchestration 6 mins30. How do you debug a container that exits immediately on start?
mediumTroubleshooting 6 mins31. What Is a Docker Container?
easyFundamentals 5 mins32. What Is a Docker Network?
mediumNetworking 6 mins33. What Is a Docker Registry?
mediumImages & Distribution 6 mins34. What Is a Docker Image Layer?
mediumImages & Distribution 6 mins35. What Is a Docker ENTRYPOINT?
mediumDockerfile 6 mins36. What Does Docker Exec Do?
mediumCLI & Operations 5 mins37. What Is Port Mapping in Docker?
hardNetworking 7 mins38. What Does Docker Prune Do?
hardCLI & Operations 6 mins39. How do BuildKit cache mounts change the way you write a Dockerfile for a large dependency tree?
hardBuild Optimisation 8 mins40. Why does the process running as PID 1 inside a container behave differently, and how do you handle zombie reaping?
hardRuntime Internals 8 mins41. How does the overlay2 storage driver work, and what performance problems does copy-up cause?
hardStorage 8 mins42. How would you design a defensive image scanning and patching workflow for containers in production?
hardSecurity 9 mins43. How do you build and publish a multi-architecture image, and what goes wrong when you do not?
hardBuild Optimisation 8 mins44. A production container keeps dying with exit code 137. How do you diagnose and fix it?
hardTroubleshooting 8 mins45. Why is depends_on not enough for service startup ordering, and what do you do instead?
mediumDocker Compose 7 mins46. Two containers cannot talk to each other. How do you debug Docker DNS and network connectivity systematically?
hardNetworking 8 mins47. What is rootless Docker, how does user-namespace remapping differ, and when would you use each?
hardSecurity 8 mins48. How do you make container builds reproducible and verifiable enough to trust in a release pipeline?
hardSupply Chain 9 mins49. How can a container's logging driver stall the application, and how do you configure logging for production?
hardObservability 8 mins50. How do you run Docker builds inside CI safely — docker-in-docker, socket mounting, or something else?
hardCI/CD 9 mins51. You switched a service to an Alpine base image to cut size and it now fails at runtime. What went wrong?
hardBase Images 8 mins52. How do Linux capabilities work in Docker, and why is --privileged almost always the wrong fix?
hardSecurity 9 mins53. A bind-mounted directory gives 'permission denied' inside the container but looks fine on the host. Why?
mediumStorage 8 mins54. When would you use --network host, none, or container:<name> instead of the default bridge?
mediumNetworking 8 mins55. How do you use multi-stage build targets to produce dev, test and production images from one Dockerfile?
hardBuild Optimisation 9 mins56. Your container is marked unhealthy but Docker never restarts it. Why, and how do health checks and restart policies actually interact?
hardReliability 9 mins57. Latency spikes but CPU usage looks low. How does cgroup CPU throttling cause this, and why do runtimes misread their limits?
hardResource Management 9 mins58. How do you debug a distroless or scratch container that has no shell and no diagnostic tools?
hardTroubleshooting 9 mins59. You added `RUN rm -rf /var/cache/*` but the image is the same size. Why, and what actually reduces it?
mediumImage Optimisation 9 mins60. How do you run a container with a read-only root filesystem, and what do you do about the paths it still needs to write?
mediumSecurity 8 mins61. What do Docker's default seccomp and AppArmor profiles do, and when would you change them?
hardSecurity 9 mins