Cheatsheets / Docker Cheatsheet

Docker Cheatsheet

Everyday Docker commands for images, containers, volumes, networks, and Compose - plus cleanup commands that actually free disk space.

Last verified

Images

docker images

Lists locally stored images.

docker pull nginx:latest

Downloads an image from a registry without running it.

docker build -t myapp:1.0 .

Builds an image from a Dockerfile in the current directory.

docker build --no-cache -t myapp:1.0 .

Rebuilds an image ignoring any cached layers - use when a build seems stale.

docker tag myapp:1.0 myrepo/myapp:1.0

Adds an additional tag/name to an existing image.

docker push myrepo/myapp:1.0

Uploads a tagged image to a registry (requires docker login first).

docker rmi myapp:1.0

Deletes a local image (fails if a container still references it).

docker history myapp:1.0

Shows the layers that make up an image and their sizes.

Containers: running and lifecycle

docker run -d -p 8080:80 --name web nginx

Runs a container in the background (-d), mapping host port 8080 to container port 80.

docker run -it ubuntu bash

Runs a container attached to an interactive terminal - useful for exploring an image.

docker run --rm alpine echo hi

Runs a container and automatically removes it once it exits.

docker ps

Lists running containers.

docker ps -a

Lists all containers, including stopped ones.

docker stop web

Gracefully stops a running container (sends SIGTERM, then SIGKILL after a timeout).

docker start web

Starts a previously stopped container.

docker restart web

Stops then starts a container.

docker rm web

Deletes a stopped container.

docker rm -f web

Force-stops and deletes a container in one step.

docker kill web

Immediately sends SIGKILL to a running container, skipping the graceful shutdown window.

Logs and exec

docker logs web

Shows a container’s stdout/stderr output.

docker logs -f web

Follows a container’s logs live, like tail -f.

docker exec -it web bash

Opens an interactive shell inside a running container.

docker exec web ls /app

Runs a one-off command inside a running container without attaching a shell.

docker inspect web

Prints detailed JSON metadata about a container (IP, mounts, env vars, config).

docker stats

Shows live CPU, memory, and network usage for all running containers.

docker cp web:/app/log.txt ./log.txt

Copies a file out of a running container to the host.

Volumes

docker volume create mydata

Creates a named volume for persistent storage.

docker volume ls

Lists all volumes.

docker run -v mydata:/data alpine

Mounts a named volume into a container at /data.

docker run -v $(pwd):/app alpine

Bind-mounts the current host directory into a container - common for local development.

docker volume rm mydata

Deletes a volume (fails if it’s still in use by a container).

docker volume prune

Deletes all volumes not referenced by any container.

Networks

docker network ls

Lists Docker networks.

docker network create mynet

Creates a custom bridge network - lets containers reach each other by name.

docker run --network mynet --name db postgres

Attaches a container to a specific network.

docker network inspect mynet

Shows which containers are attached to a network and their IPs.

Docker Compose

docker compose up -d

Starts every service defined in compose.yaml in the background.

docker compose down

Stops and removes containers, networks created by up (add -v to also remove volumes).

docker compose ps

Lists the status of services defined in the compose file.

docker compose logs -f api

Follows logs for a single service.

docker compose build

Rebuilds images for services with a build: section.

docker compose exec api bash

Opens a shell inside a running Compose service’s container.

docker compose restart api

Restarts a single service without touching the others.

Cleanup

docker system df

Shows disk space used by images, containers, volumes, and build cache.

docker container prune

Removes all stopped containers.

docker image prune

Removes dangling (untagged) images.

docker image prune -a

Removes all images not currently used by a container - more aggressive.

docker system prune -a --volumes

Removes everything unused: stopped containers, unused networks, dangling images, and volumes. Frees the most space, but be sure nothing you need is only stored there.