Docker definition
Docker is an open-source platform for building, sharing and running applications in containers. Developers describe an application's environment in a Dockerfile, build it into an image, push it to a registry such as Docker Hub and run identical containers on laptops, test servers and production. Docker made containers mainstream after its release in 2013.
How does Docker work?
Docker has a client-server design. The docker command-line tool sends instructions to the Docker Engine, a background service that builds images and manages containers, using containerd and runc underneath to actually start them. An image is a stack of read-only layers, one for each build step, and layers are cached and shared, so rebuilding after a small code change is fast and images download only the layers that changed.
A Dockerfile lists the build steps. For a Node.js API, it might start FROM an official Node image, COPY the package files, RUN the dependency install, COPY the source code and set the CMD that starts the server. Multi-stage builds compile the application in one stage and copy only the output into a slim final image, keeping compilers and build tools out of production.
Key Docker components
- Dockerfile: the text recipe for building an image.
- Image: a packaged, versioned application environment.
- Container: a running instance of an image.
- Registry: storage for images, such as Docker Hub, Amazon ECR or GitHub Container Registry.
- Volumes: persistent storage that outlives individual containers.
- Networks: virtual networks that let containers talk to each other.
- Docker Compose: a YAML file that defines and runs multi-container setups.
- Docker Buildx: extended builds for multiple CPU architectures, such as Intel and ARM.
- Docker Scout: analysis of images for known vulnerabilities.
Docker vs Kubernetes
Docker builds images and runs containers on a single machine. Kubernetes orchestrates containers across a cluster of machines, handling scheduling, scaling, self-healing and rolling updates. They are complementary rather than competing: teams typically build images with Docker and run them in production on Kubernetes, which uses runtimes such as containerd directly. Docker Desktop also includes a single-node Kubernetes option for local testing.
Docker Compose for local development
Compose is where many developers feel Docker's value first. One file describes the web application, a PostgreSQL database, a Redis cache and a background worker, with their ports, environment variables and volumes. A single command starts the whole stack, and a new team member can run the project on day one without installing databases or matching versions by hand.
Compose files also document how services fit together, and the same images used locally move through CI into production. Note that Docker Desktop requires a paid subscription for larger companies under its license terms, while Docker Engine on Linux and alternatives such as Podman and Rancher Desktop are free.
Docker best practices
Order Dockerfile steps so rarely changing layers, such as dependency installation, come before frequently changing source code, which keeps builds fast. Use small official base images, pin versions, add a .dockerignore file, run as a non-root user and scan images in CI. Tag images with the Git commit rather than relying on "latest". Nexzem sets up Docker builds with these defaults so client images stay small, reproducible and secure from the first release.