Docker Commands Cheat Sheet: The Complete Reference With Examples
Docker has more than a hundred commands and subcommands, but day-to-day work relies on a few dozen of them. The difficulty for most engineers is not learning what a command does once; it is remembering the exact flag at the moment something breaks in production.
This cheat sheet groups the Docker commands you will actually use by task: working with images, running and managing containers, debugging, storage, networking, Docker Compose, building, registries and cleanup. Every section includes real examples, and the guide ends with ready-to-use workflows for common situations.
All commands are written for Docker Engine 29 and Docker Compose v5, as of October 2026. They work the same way on Linux, on Windows with WSL 2, and on macOS with Docker Desktop. If you have not installed Docker yet, start with our guide How to Install Docker on Ubuntu, Windows (WSL2) and macOS.
How Docker Commands Are Structured
Modern Docker commands follow a consistent pattern: the object you want to work with, then the action.
docker <object> <command> [options] [arguments]
docker container ls
docker image pull nginx
docker volume create pgdata
docker network inspect bridge
Docker also keeps shorter legacy forms of the most common commands. Both styles do exactly the same thing, and you will see both in documentation and scripts:
Management command (current style) | Short form (legacy, still supported) |
|---|
docker container ls | docker ps |
docker container run | docker run |
docker container rm | docker rm |
docker image ls | docker images |
docker image rm | docker rmi |
docker image pull | docker pull |
docker image build | docker build |
Add --help to any command to see all of its options, for example docker run --help or docker network create --help.
The 20 Most Used Docker Commands
If you only memorise one table, make it this one:
Command | What it does |
|---|
docker run -d --name web -p 8080:80 nginx | Run a container in the background with a name and a published port |
docker ps | List running containers |
docker ps -a | List all containers, including stopped ones |
docker logs -f web | Follow a container's logs |
docker exec -it web sh | Open a shell inside a running container |
docker stop web | Stop a container gracefully |
docker start web | Start a stopped container |
docker rm web | Remove a stopped container |
docker images | List images |
docker pull nginx:1.29 | Download an image |
docker build -t myapp:1.0 . | Build an image from the Dockerfile in the current directory |
docker tag myapp:1.0 user/myapp:1.0 | Give an image another name (for pushing) |
docker push user/myapp:1.0 | Upload an image to a registry |
docker rmi myapp:1.0 | Remove an image |
docker inspect web | Show full low-level details as JSON |
docker stats | Live CPU, memory and network usage |
docker volume ls | List volumes |
docker network ls | List networks |
docker compose up -d | Start a multi-container app from compose.yaml |
docker system prune | Remove stopped containers, unused networks, dangling images and build cache |
1. System and Information Commands
Command | What it does |
|---|
docker version | Client and server (daemon) versions |
docker info | Engine details: containers, images, storage, cgroup version, security options |
docker system df | Disk space used by images, containers, volumes and build cache |
docker system df -v | Detailed per-object disk usage |
docker system events | Live stream of daemon events (start, stop, die, pull and so on) |
docker context ls | List Docker contexts (local, rootless, remote engines) |
docker context use <name> | Switch the CLI to another Docker engine |
docker system df is the first command to run when a host is running out of disk space.
2. Image Commands
Command | What it does |
|---|
docker pull <image>:<tag> | Download an image from a registry |
docker pull <image>@sha256:<digest> | Download an exact, immutable image by digest |
docker pull --platform linux/arm64 <image> | Download the image for a specific platform |
docker images or docker image ls | List images |
docker image ls -a | List all images, including untagged ones |
docker image ls --tree | Show images with their platform variants in a tree |
docker image ls --digests | Show image digests |
docker image history <image> | Show the layers and the instruction that created each one |
docker image inspect <image> | Full image metadata: entrypoint, environment, labels, layers |
docker tag <source> <target> | Create a new name (tag) for an existing image |
docker rmi <image> | Remove an image (fails if a container uses it) |
docker image prune | Remove dangling (untagged) images |
docker image prune -a | Remove all images not used by any container |
docker save -o app.tar <image> | Export one or more images to a tar archive |
docker load -i app.tar | Import images from a tar archive |
Docker 29 change: Since Docker Engine 29.0, docker image ls uses a new collapsed tree view by default and no longer shows untagged images unless you add -a (--all). If images seem to be "missing" after an upgrade, this is why.
Examples:
# Pull a specific version rather than "latest"
docker pull postgres:17
# See why an image is large
docker image history --no-trunc myapp:1.0
# Read one field with a Go template
docker image inspect --format "{{.Config.Entrypoint}}" nginx
3. Running Containers: docker run
docker run creates a new container from an image and starts it. It is the command with the most options, so it is worth knowing the important flags well.
docker run [OPTIONS] IMAGE [COMMAND] [ARG...]
Option | Meaning | Example |
|---|
-d | Run in the background (detached) | docker run -d nginx |
-it | Interactive terminal (keep STDIN open and allocate a TTY) | docker run -it ubuntu bash |
--rm | Remove the container automatically when it exits | docker run --rm alpine date |
--name | Give the container a fixed name | --name api |
-p host:container | Publish a container port on the host | -p 8080:80 |
-p 127.0.0.1:host:container | Publish only on localhost (not reachable from other machines) | -p 127.0.0.1:5432:5432 |
-e KEY=value | Set an environment variable | -e TZ=Asia/Kolkata |
--env-file | Load environment variables from a file | --env-file .env |
-v name:/path | Mount a named volume | -v pgdata:/var/lib/postgresql/data |
-v /host/path:/path | Bind-mount a host directory | -v "$(pwd)":/app |
--mount | Explicit, more readable mount syntax | --mount type=volume,src=pgdata,dst=/data |
--network | Connect to a specific network | --network backend |
--restart | Restart policy: no, on-failure, always, unless-stopped | --restart unless-stopped |
-w | Working directory inside the container | -w /app |
-u | Run as a specific user or UID | -u 1000:1000 |
--entrypoint | Override the image's entrypoint | --entrypoint sh |
--memory | Memory limit | --memory 512m |
--cpus | CPU limit | --cpus 1.5 |
--ulimit | Set a resource limit such as open files | --ulimit nofile=65536:65536 |
--init | Run a tiny init process as PID 1 (signal handling, zombie reaping) | --init |
--read-only | Make the container's root filesystem read-only | --read-only --tmpfs /tmp |
--cap-drop | Drop Linux capabilities | --cap-drop ALL |
--security-opt | Security options | --security-opt no-new-privileges |
--health-cmd | Define a health check at run time | --health-cmd "curl -f http://localhost/" |
--pull | When to pull the image: missing, always, never | --pull always |
--platform | Run an image built for another platform | --platform linux/amd64 |
Docker 29 change: Containers now get a default open-file limit (ulimit -n) of 1024 instead of 1048576. Databases, message brokers and high-connection servers may need --ulimit nofile=65536:65536 (or the equivalent in Compose) after upgrading.
Real examples:
# Web server in the background
docker run -d --name web -p 8080:80 --restart unless-stopped nginx:1.29
# PostgreSQL with persistent data, reachable only from this machine
docker run -d --name db \
-e POSTGRESPASSWORD=change-me \
-v pgdata:/var/lib/postgresql/data \
-p 127.0.0.1:5432:5432 \
postgres:17
# One-off command, container deleted afterwards
docker run --rm -v "$(pwd)":/work -w /work python:3.13-slim python script.py
# Hardened container
docker run -d --name api --read-only --tmpfs /tmp --cap-drop ALL \
--security-opt no-new-privileges -u 1000:1000 myapp:1.0
On Windows PowerShell, replace the line-continuation character \ with a backtick, and use ${PWD} instead of $(pwd).
4. Managing the Container Lifecycle
Command | What it does |
|---|
docker ps | List running containers |
docker ps -a | List all containers, including stopped ones |
docker ps -q | Print only container IDs (useful in scripts) |
docker create --name x <image> | Create a container without starting it |
docker start <container> | Start a stopped container |
docker stop <container> | Send SIGTERM, then SIGKILL after 10 seconds |
docker stop -t 30 <container> | Wait 30 seconds before force-killing |
docker restart <container> | Stop and start a container |
docker kill <container> | Send SIGKILL immediately (no graceful shutdown) |
docker pause / docker unpause | Freeze and resume all processes in a container |
docker rm <container> | Remove a stopped container |
docker rm -f <container> | Force-remove a container, stopping it first if needed |
docker rename <old> <new> | Rename a container |
docker update --memory 1g --cpus 2 <container> | Change resource limits of a running container |
docker wait <container> | Block until a container stops, then print its exit code |
You can refer to a container by its name or by its ID. A unique prefix of the ID is enough, for example docker stop 3f2a.
5. Inspecting and Debugging Containers
Command | What it does |
|---|
docker logs <container> | Show the container's output (STDOUT and STDERR) |
docker logs -f --tail 100 <container> | Follow logs, starting from the last 100 lines |
docker logs --since 15m -t <container> | Logs from the last 15 minutes, with timestamps |
docker exec -it <container> sh | Open a shell in a running container (use bash if available) |
docker exec -u root -it <container> sh | Open a shell as root |
docker exec <container> env | Run a single command without a shell |
docker inspect <container> | Full configuration and state as JSON |
docker top <container> | Processes running inside the container |
docker stats | Live resource usage for all running containers |
docker stats --no-stream | One snapshot of resource usage (good for scripts) |
docker port <container> | Show published port mappings |
docker diff <container> | Files added (A), changed (C) or deleted (D) in the container |
docker cp <container>:/path ./local | Copy files from a container to the host |
docker cp ./local <container>:/path | Copy files from the host into a container |
docker events --since 1h | Daemon events from the last hour (useful for restart loops) |
Useful docker inspect one-liners with Go templates:
# Container IP address(es)
docker inspect -f "{{range .NetworkSettings.Networks}}{{.IPAddress}} {{end}}" web
# Why did the container stop? Exit code and OOM flag
docker inspect -f "{{.State.ExitCode}} OOMKilled={{.State.OOMKilled}}" web
# Health status
docker inspect -f "{{.State.Health.Status}}" web
# Mounts
docker inspect -f "{{json .Mounts}}" web
Container images built for production often have no shell. In that case docker exec -it ... sh fails. Docker Desktop provides docker debug <container>, which attaches a toolbox shell to any container, even a minimal one. On a plain Linux engine, you can run a debugging container in the same network namespace instead:
docker run --rm -it --network container:web nicolaka/netshoot
6. Volume Commands
Command | What it does |
|---|
docker volume create <name> | Create a named volume |
docker volume ls | List volumes |
docker volume inspect <name> | Show a volume's driver, mount point and labels |
docker volume rm <name> | Remove a volume (fails if a container uses it) |
docker volume prune | Remove unused anonymous volumes |
docker volume prune -a | Remove all unused volumes, including named ones |
Warning: Removing a volume permanently deletes its data. Run docker volume ls and check what you are deleting before using docker volume prune -a.
Back up a volume to a tar file using a temporary container:
docker run --rm -v pgdata:/data -v "$(pwd)":/backup alpine \
tar czf /backup/pgdata-backup.tar.gz -C /data .
7. Network Commands
Command | What it does |
|---|
docker network ls | List networks |
docker network create <name> | Create a user-defined bridge network |
docker network create --driver bridge --subnet 172.30.0.0/16 <name> | Create a network with a custom subnet |
docker network inspect <name> | Show the network's subnet and connected containers |
docker network connect <network> <container> | Attach a running container to a network |
docker network disconnect <network> <container> | Detach a container from a network |
docker network rm <name> | Remove a network |
docker network prune | Remove all unused networks |
Containers on the same user-defined network can reach each other by container name, because Docker provides built-in DNS on those networks. This does not work on the default bridge network:
docker network create backend
docker run -d --name db --network backend -e POSTGRESPASSWORD=change-me postgres:17
docker run --rm --network backend postgres:17 pgisready -h db
8. Docker Compose Commands
Docker Compose runs multi-container applications defined in a compose.yaml file. Use docker compose (with a space). The old standalone docker-compose command is no longer the recommended tool.
Command | What it does |
|---|
docker compose up -d | Create and start all services in the background |
docker compose up -d --build | Rebuild images before starting |
docker compose down | Stop and remove containers and networks |
docker compose down -v | Also remove the volumes declared in the file (deletes data) |
docker compose ps | List the project's containers |
docker compose logs -f <service> | Follow logs for one service (omit the name for all) |
docker compose exec <service> sh | Open a shell in a running service container |
docker compose run --rm <service> <cmd> | Run a one-off command in a new service container |
docker compose build | Build or rebuild service images |
docker compose pull | Pull the latest images for all services |
docker compose restart <service> | Restart a service |
docker compose stop / docker compose start | Stop or start services without removing them |
docker compose config | Validate the file and print the fully resolved configuration |
docker compose watch | Sync, rebuild or restart services automatically when files change |
docker compose -f compose.prod.yaml up -d | Use a specific Compose file |
docker compose --profile debug up -d | Also start services assigned to the "debug" profile |
9. Build Commands
Command | What it does |
|---|
docker build -t myapp:1.0 . | Build and tag an image from the current directory |
docker build -f docker/Dockerfile.prod -t myapp . | Use a Dockerfile with a different name or location |
docker build --target builder -t myapp:build . | Build only up to a named stage in a multi-stage Dockerfile |
docker build --build-arg VERSION=1.2.3 . | Pass a build argument |
docker build --no-cache . | Build without using the layer cache |
docker build --check . | Lint the Dockerfile against best-practice rules without building |
docker build --secret id=npmrc,src=.npmrc . | Pass a secret to the build without storing it in a layer |
docker buildx build --platform linux/amd64,linux/arm64 -t user/myapp:1.0 --push . | Build a multi-platform image and push it |
docker buildx ls | List builders and the platforms they support |
docker buildx imagetools inspect <image> | Show a multi-platform image's manifest list |
docker builder prune | Remove unused build cache |
docker build uses BuildKit by default. For a detailed guide to stages and smaller images, see our Complete Guide to Multi-Stage Docker Builds.
10. Registry Commands
Command | What it does |
|---|
docker login | Log in to Docker Hub |
docker login ghcr.io | Log in to another registry (here GitHub Container Registry) |
echo "$TOKEN" | docker login -u <user> --password-stdin <registry> | Log in non-interactively (CI pipelines) |
docker tag myapp:1.0 <registry>/<namespace>/myapp:1.0 | Name an image for a specific registry |
docker push <registry>/<namespace>/myapp:1.0 | Push the image |
docker search <term> | Search Docker Hub |
docker logout <registry> | Remove stored credentials |
Push to Amazon ECR (replace the account ID and region with your own):
aws ecr get-login-password --region ap-south-1 | \
docker login --username AWS --password-stdin 123456789012.dkr.ecr.ap-south-1.amazonaws.com
docker tag myapp:1.0 123456789012.dkr.ecr.ap-south-1.amazonaws.com/myapp:1.0
docker push 123456789012.dkr.ecr.ap-south-1.amazonaws.com/myapp:1.0
Security: Never pass a password with -p or --password on the command line, because it is saved in your shell history and visible in the process list. Use --password-stdin with a token instead.
11. Cleanup Commands
Command | What it does |
|---|
docker container prune | Remove all stopped containers |
docker image prune | Remove dangling (untagged) images |
docker image prune -a | Remove all images not used by a container |
docker volume prune | Remove unused anonymous volumes |
docker network prune | Remove unused networks |
docker builder prune | Remove unused build cache |
docker system prune | Stopped containers, unused networks, dangling images and dangling build cache |
docker system prune -a | As above, plus all unused images and all unused build cache |
docker system prune -a --volumes | As above, plus unused anonymous volumes |
docker image prune -a --filter "until=168h" | Remove unused images older than 7 days |
All prune commands ask for confirmation. Add -f to skip the prompt in scripts, but only once you are sure what will be removed. A safe routine on a busy build server is:
docker system df
docker container prune -f
docker image prune -a -f --filter "until=168h"
docker builder prune -f --filter "until=168h"
docker system df
12. Filtering and Formatting Output
Most list commands accept --filter (-f) to narrow results and --format to choose what is printed.
Command | What it does |
|---|
docker ps -a -f status=exited | Only stopped containers |
docker ps -f name=api | Containers whose name contains "api" |
docker ps -f ancestor=nginx | Containers created from the nginx image |
docker ps -f label=env=prod | Containers with a specific label |
docker images -f dangling=true | Untagged images |
docker ps --format "table {{.Names}}\t{{.Status}}\t{{.Ports}}" | Custom table of name, status and ports |
docker ps --format "{{.Names}}: {{.HealthStatus}}" | Name and health status of each container |
docker ps --format json | One JSON object per container (pipe into jq) |
Combine -q with other commands for bulk operations:
# Stop all running containers
docker stop $(docker ps -q)
# Remove all stopped containers
docker rm $(docker ps -aq -f status=exited)
# Remove all images from one repository
docker rmi $(docker images -q myapp)
13. Security and Image Scanning Commands
Command | What it does |
|---|
docker scout quickview <image> | Summary of vulnerabilities and base-image recommendations |
docker scout cves <image> | List known vulnerabilities (CVEs) in an image |
docker scout recommendations <image> | Suggested base-image updates to reduce vulnerabilities |
docker run --cap-drop ALL --security-opt no-new-privileges ... | Run with minimal privileges |
docker run -u 1000:1000 ... | Run as a non-root user |
docker run --read-only --tmpfs /tmp ... | Read-only root filesystem with a writable temporary directory |
Docker Scout is included with Docker Desktop and is available as a CLI plugin for Docker Engine. For a deeper explanation of container hardening, see our Docker Security Fundamentals tutorial.
14. Project Starter Commands
Command | What it does |
|---|
docker init | Generate a Dockerfile, compose.yaml and .dockerignore for your project interactively |
docker compose config | Check the generated Compose file |
docker build --check . | Check the generated Dockerfile against best practices |
Ready-to-Use Workflows
Workflow 1: Debug a Container That Keeps Restarting
docker ps -a -f name=api
docker logs --tail 50 api
docker inspect -f "{{.State.ExitCode}} OOMKilled={{.State.OOMKilled}}" api
docker events --since 10m --filter container=api
The exit code usually tells you where to look next (see the exit code table below). OOMKilled=true means the container exceeded its memory limit.
Workflow 2: Build, Test and Push an Image
docker build --check .
docker build -t myapp:1.0 .
docker run --rm -p 8080:8080 myapp:1.0
docker tag myapp:1.0 user/myapp:1.0
docker push user/myapp:1.0
Workflow 3: Update a Running Service to a New Image
docker pull nginx:1.29
docker stop web && docker rm web
docker run -d --name web -p 8080:80 --restart unless-stopped nginx:1.29
With Docker Compose, the same update is simply docker compose pull followed by docker compose up -d, which recreates only the services whose images changed.
Workflow 4: Free Up Disk Space Safely
docker system df
docker container prune
docker image prune -a
docker builder prune
docker system df
Volumes are deliberately left out, because they contain data. Remove specific volumes by name only after checking them.
Container Exit Codes Quick Reference
Exit code | Meaning | Common cause |
|---|
0 | Exited normally | The main process finished its work |
1 | Application error | An unhandled exception or error in your code |
125 | Docker could not run the container | Invalid docker run option or daemon error |
126 | Command cannot be executed | File is not executable or permission denied |
127 | Command not found | Wrong command or entrypoint, or missing binary in the image |
137 | Killed with SIGKILL | Out of memory (OOM), or docker kill, or stop timeout exceeded |
139 | Segmentation fault (SIGSEGV) | Crash in native code or wrong-architecture binary |
143 | Terminated with SIGTERM | Normal response to docker stop |
For a detailed walkthrough of exit code 137, see our guide How to Fix Docker Exit Code 137.
What Changed in Docker 29 for Everyday Commands
docker image ls uses a collapsed tree view by default and hides untagged images unless you pass -a.
Default open-file limit for containers is now 1024; raise it with --ulimit nofile=... where needed.
docker ps --format supports a {{.HealthStatus}} placeholder (Engine 29.5 and later).
docker login --password - reads the password from STDIN, as an alternative to --password-stdin (Engine 29.6 and later).
Docker Content Trust (DOCKERCONTENT_TRUST) has been removed from the CLI. Use image signing tools such as Sigstore Cosign instead.
Frequently Asked Questions
What is the difference between docker ps and docker ps -a?
docker ps lists only running containers. docker ps -a lists all containers, including those that have stopped or exited, which is what you need when a container has crashed.
What is the difference between docker stop and docker kill?
docker stop sends SIGTERM so the application can shut down cleanly, and sends SIGKILL only if it has not stopped after 10 seconds. docker kill sends SIGKILL immediately, with no chance to clean up.
What is the difference between docker rm and docker rmi?
docker rm removes containers. docker rmi (or docker image rm) removes images. An image cannot be removed while a container, even a stopped one, still uses it.
How do I get a shell inside a running container?
Run docker exec -it <container> sh, or bash if the image includes it. If the image has no shell, use docker debug in Docker Desktop or attach a debugging container to its network namespace.
How do I remove all stopped containers?
Run docker container prune. To remove every container, including running ones, use docker rm -f $(docker ps -aq), but be careful: this deletes containers you may still need.
Should I use docker-compose or docker compose?
Use docker compose (with a space). It is the current Compose implementation, built into Docker Desktop and installed as a plugin with Docker Engine. The older standalone docker-compose binary is no longer the recommended tool.
Conclusion and Next Steps
You do not need to memorise every Docker command. Learn the structure (docker <object> <command>), keep the top 20 commands at your fingertips, and use this cheat sheet and --help for the rest. Above all, get comfortable with docker logs, docker exec and docker inspect, because these three commands solve most problems you will meet.
Continue the Docker course with these tutorials on BitCodeMatrix:
How to Install Docker on Ubuntu, Windows (WSL2) and macOS — set up Docker the right way
Rootless Docker: Setup and Limitations — run Docker without root privileges
Docker Volumes and Persistent Storage — keep data safe beyond the container lifecycle
Docker Container Lifecycle Explained (next in the course) — what happens at each stage from create to remove