Cheatsheets / Docker Cheatsheet
Docker Cheatsheet
Everyday Docker commands for images, containers, volumes, networks, and Compose - plus cleanup commands that actually free disk space.
Images
docker images
Lists locally stored images.
docker pull nginx:latest
Downloads an image from a registry without running it.
docker build -t myapp:1.0 .
Builds an image from a Dockerfile in the current directory.
docker build --no-cache -t myapp:1.0 .
Rebuilds an image ignoring any cached layers - use when a build seems stale.
docker tag myapp:1.0 myrepo/myapp:1.0
Adds an additional tag/name to an existing image.
docker push myrepo/myapp:1.0
Uploads a tagged image to a registry (requires docker login first).
docker rmi myapp:1.0
Deletes a local image (fails if a container still references it).
docker history myapp:1.0
Shows the layers that make up an image and their sizes.
Containers: running and lifecycle
docker run -d -p 8080:80 --name web nginx
Runs a container in the background (-d), mapping host port 8080 to container port 80.
docker run -it ubuntu bash
Runs a container attached to an interactive terminal - useful for exploring an image.
docker run --rm alpine echo hi
Runs a container and automatically removes it once it exits.
docker ps
Lists running containers.
docker ps -a
Lists all containers, including stopped ones.
docker stop web
Gracefully stops a running container (sends SIGTERM, then SIGKILL after a timeout).
docker start web
Starts a previously stopped container.
docker restart web
Stops then starts a container.
docker rm web
Deletes a stopped container.
docker rm -f web
Force-stops and deletes a container in one step.
docker kill web
Immediately sends SIGKILL to a running container, skipping the graceful shutdown window.
Logs and exec
docker logs web
Shows a container’s stdout/stderr output.
docker logs -f web
Follows a container’s logs live, like tail -f.
docker exec -it web bash
Opens an interactive shell inside a running container.
docker exec web ls /app
Runs a one-off command inside a running container without attaching a shell.
docker inspect web
Prints detailed JSON metadata about a container (IP, mounts, env vars, config).
docker stats
Shows live CPU, memory, and network usage for all running containers.
docker cp web:/app/log.txt ./log.txt
Copies a file out of a running container to the host.
Volumes
docker volume create mydata
Creates a named volume for persistent storage.
docker volume ls
Lists all volumes.
docker run -v mydata:/data alpine
Mounts a named volume into a container at /data.
docker run -v $(pwd):/app alpine
Bind-mounts the current host directory into a container - common for local development.
docker volume rm mydata
Deletes a volume (fails if it’s still in use by a container).
docker volume prune
Deletes all volumes not referenced by any container.
Networks
docker network ls
Lists Docker networks.
docker network create mynet
Creates a custom bridge network - lets containers reach each other by name.
docker run --network mynet --name db postgres
Attaches a container to a specific network.
docker network inspect mynet
Shows which containers are attached to a network and their IPs.
Docker Compose
docker compose up -d
Starts every service defined in compose.yaml in the background.
docker compose down
Stops and removes containers, networks created by up (add -v to also remove volumes).
docker compose ps
Lists the status of services defined in the compose file.
docker compose logs -f api
Follows logs for a single service.
docker compose build
Rebuilds images for services with a build: section.
docker compose exec api bash
Opens a shell inside a running Compose service’s container.
docker compose restart api
Restarts a single service without touching the others.
Cleanup
docker system df
Shows disk space used by images, containers, volumes, and build cache.
docker container prune
Removes all stopped containers.
docker image prune
Removes dangling (untagged) images.
docker image prune -a
Removes all images not currently used by a container - more aggressive.
docker system prune -a --volumes
Removes everything unused: stopped containers, unused networks, dangling images, and volumes. Frees the most space, but be sure nothing you need is only stored there.