docker

Docker Commands Cheat Sheet (2026): Complete List With Examples

By Shubhankar Tripathi • • 5 min read

Docker Commands Cheat Sheet: The Complete Reference With Examples

Docker has more than a hundred commands and subcommands, but day-to-day work relies on a few dozen of them. The difficulty for most engineers is not learning what a command does once; it is remembering the exact flag at the moment something breaks in production.

This cheat sheet groups the Docker commands you will actually use by task: working with images, running and managing containers, debugging, storage, networking, Docker Compose, building, registries and cleanup. Every section includes real examples, and the guide ends with ready-to-use workflows for common situations.

All commands are written for Docker Engine 29 and Docker Compose v5, as of October 2026. They work the same way on Linux, on Windows with WSL 2, and on macOS with Docker Desktop. If you have not installed Docker yet, start with our guide How to Install Docker on Ubuntu, Windows (WSL2) and macOS.

How Docker Commands Are Structured

Modern Docker commands follow a consistent pattern: the object you want to work with, then the action.

docker <object> <command> [options] [arguments]

 

docker container ls

docker image pull nginx

docker volume create pgdata

docker network inspect bridge

Docker also keeps shorter legacy forms of the most common commands. Both styles do exactly the same thing, and you will see both in documentation and scripts:

Management command (current style)

Short form (legacy, still supported)

docker container ls

docker ps

docker container run

docker run

docker container rm

docker rm

docker image ls

docker images

docker image rm

docker rmi

docker image pull

docker pull

docker image build

docker build


Add --help to any command to see all of its options, for example docker run --help or docker network create --help.

The 20 Most Used Docker Commands

If you only memorise one table, make it this one:

Command

What it does

docker run -d --name web -p 8080:80 nginx

Run a container in the background with a name and a published port

docker ps

List running containers

docker ps -a

List all containers, including stopped ones

docker logs -f web

Follow a container's logs

docker exec -it web sh

Open a shell inside a running container

docker stop web

Stop a container gracefully

docker start web

Start a stopped container

docker rm web

Remove a stopped container

docker images

List images

docker pull nginx:1.29

Download an image

docker build -t myapp:1.0 .

Build an image from the Dockerfile in the current directory

docker tag myapp:1.0 user/myapp:1.0

Give an image another name (for pushing)

docker push user/myapp:1.0

Upload an image to a registry

docker rmi myapp:1.0

Remove an image

docker inspect web

Show full low-level details as JSON

docker stats

Live CPU, memory and network usage

docker volume ls

List volumes

docker network ls

List networks

docker compose up -d

Start a multi-container app from compose.yaml

docker system prune

Remove stopped containers, unused networks, dangling images and build cache


1. System and Information Commands

Command

What it does

docker version

Client and server (daemon) versions

docker info

Engine details: containers, images, storage, cgroup version, security options

docker system df

Disk space used by images, containers, volumes and build cache

docker system df -v

Detailed per-object disk usage

docker system events

Live stream of daemon events (start, stop, die, pull and so on)

docker context ls

List Docker contexts (local, rootless, remote engines)

docker context use <name>

Switch the CLI to another Docker engine


docker system df is the first command to run when a host is running out of disk space.

2. Image Commands

Command

What it does

docker pull <image>:<tag>

Download an image from a registry

docker pull <image>@sha256:<digest>

Download an exact, immutable image by digest

docker pull --platform linux/arm64 <image>

Download the image for a specific platform

docker images or docker image ls

List images

docker image ls -a

List all images, including untagged ones

docker image ls --tree

Show images with their platform variants in a tree

docker image ls --digests

Show image digests

docker image history <image>

Show the layers and the instruction that created each one

docker image inspect <image>

Full image metadata: entrypoint, environment, labels, layers

docker tag <source> <target>

Create a new name (tag) for an existing image

docker rmi <image>

Remove an image (fails if a container uses it)

docker image prune

Remove dangling (untagged) images

docker image prune -a

Remove all images not used by any container

docker save -o app.tar <image>

Export one or more images to a tar archive

docker load -i app.tar

Import images from a tar archive


Docker 29 change: Since Docker Engine 29.0, docker image ls uses a new collapsed tree view by default and no longer shows untagged images unless you add -a (--all). If images seem to be "missing" after an upgrade, this is why.

Examples:

# Pull a specific version rather than "latest"

docker pull postgres:17

 

# See why an image is large

docker image history --no-trunc myapp:1.0

 

# Read one field with a Go template

docker image inspect --format "{{.Config.Entrypoint}}" nginx

3. Running Containers: docker run

docker run creates a new container from an image and starts it. It is the command with the most options, so it is worth knowing the important flags well.

docker run [OPTIONS] IMAGE [COMMAND] [ARG...]

Option

Meaning

Example

-d

Run in the background (detached)

docker run -d nginx

-it

Interactive terminal (keep STDIN open and allocate a TTY)

docker run -it ubuntu bash

--rm

Remove the container automatically when it exits

docker run --rm alpine date

--name

Give the container a fixed name

--name api

-p host:container

Publish a container port on the host

-p 8080:80

-p 127.0.0.1:host:container

Publish only on localhost (not reachable from other machines)

-p 127.0.0.1:5432:5432

-e KEY=value

Set an environment variable

-e TZ=Asia/Kolkata

--env-file

Load environment variables from a file

--env-file .env

-v name:/path

Mount a named volume

-v pgdata:/var/lib/postgresql/data

-v /host/path:/path

Bind-mount a host directory

-v "$(pwd)":/app

--mount

Explicit, more readable mount syntax

--mount type=volume,src=pgdata,dst=/data

--network

Connect to a specific network

--network backend

--restart

Restart policy: no, on-failure, always, unless-stopped

--restart unless-stopped

-w

Working directory inside the container

-w /app

-u

Run as a specific user or UID

-u 1000:1000

--entrypoint

Override the image's entrypoint

--entrypoint sh

--memory

Memory limit

--memory 512m

--cpus

CPU limit

--cpus 1.5

--ulimit

Set a resource limit such as open files

--ulimit nofile=65536:65536

--init

Run a tiny init process as PID 1 (signal handling, zombie reaping)

--init

--read-only

Make the container's root filesystem read-only

--read-only --tmpfs /tmp

--cap-drop

Drop Linux capabilities

--cap-drop ALL

--security-opt

Security options

--security-opt no-new-privileges

--health-cmd

Define a health check at run time

--health-cmd "curl -f http://localhost/"

--pull

When to pull the image: missing, always, never

--pull always

--platform

Run an image built for another platform

--platform linux/amd64


Docker 29 change: Containers now get a default open-file limit (ulimit -n) of 1024 instead of 1048576. Databases, message brokers and high-connection servers may need --ulimit nofile=65536:65536 (or the equivalent in Compose) after upgrading.

Real examples:

# Web server in the background

docker run -d --name web -p 8080:80 --restart unless-stopped nginx:1.29

 

# PostgreSQL with persistent data, reachable only from this machine

docker run -d --name db \

  -e POSTGRESPASSWORD=change-me \

  -v pgdata:/var/lib/postgresql/data \

  -p 127.0.0.1:5432:5432 \

  postgres:17

 

# One-off command, container deleted afterwards

docker run --rm -v "$(pwd)":/work -w /work python:3.13-slim python script.py

 

# Hardened container

docker run -d --name api --read-only --tmpfs /tmp --cap-drop ALL \

  --security-opt no-new-privileges -u 1000:1000 myapp:1.0

On Windows PowerShell, replace the line-continuation character \ with a backtick, and use ${PWD} instead of $(pwd).

4. Managing the Container Lifecycle

Command

What it does

docker ps

List running containers

docker ps -a

List all containers, including stopped ones

docker ps -q

Print only container IDs (useful in scripts)

docker create --name x <image>

Create a container without starting it

docker start <container>

Start a stopped container

docker stop <container>

Send SIGTERM, then SIGKILL after 10 seconds

docker stop -t 30 <container>

Wait 30 seconds before force-killing

docker restart <container>

Stop and start a container

docker kill <container>

Send SIGKILL immediately (no graceful shutdown)

docker pause / docker unpause

Freeze and resume all processes in a container

docker rm <container>

Remove a stopped container

docker rm -f <container>

Force-remove a container, stopping it first if needed

docker rename <old> <new>

Rename a container

docker update --memory 1g --cpus 2 <container>

Change resource limits of a running container

docker wait <container>

Block until a container stops, then print its exit code


You can refer to a container by its name or by its ID. A unique prefix of the ID is enough, for example docker stop 3f2a.

5. Inspecting and Debugging Containers

Command

What it does

docker logs <container>

Show the container's output (STDOUT and STDERR)

docker logs -f --tail 100 <container>

Follow logs, starting from the last 100 lines

docker logs --since 15m -t <container>

Logs from the last 15 minutes, with timestamps

docker exec -it <container> sh

Open a shell in a running container (use bash if available)

docker exec -u root -it <container> sh

Open a shell as root

docker exec <container> env

Run a single command without a shell

docker inspect <container>

Full configuration and state as JSON

docker top <container>

Processes running inside the container

docker stats

Live resource usage for all running containers

docker stats --no-stream

One snapshot of resource usage (good for scripts)

docker port <container>

Show published port mappings

docker diff <container>

Files added (A), changed (C) or deleted (D) in the container

docker cp <container>:/path ./local

Copy files from a container to the host

docker cp ./local <container>:/path

Copy files from the host into a container

docker events --since 1h

Daemon events from the last hour (useful for restart loops)


Useful docker inspect one-liners with Go templates:

# Container IP address(es)

docker inspect -f "{{range .NetworkSettings.Networks}}{{.IPAddress}} {{end}}" web

 

# Why did the container stop? Exit code and OOM flag

docker inspect -f "{{.State.ExitCode}} OOMKilled={{.State.OOMKilled}}" web

 

# Health status

docker inspect -f "{{.State.Health.Status}}" web

 

# Mounts

docker inspect -f "{{json .Mounts}}" web

Container images built for production often have no shell. In that case docker exec -it ... sh fails. Docker Desktop provides docker debug <container>, which attaches a toolbox shell to any container, even a minimal one. On a plain Linux engine, you can run a debugging container in the same network namespace instead:

docker run --rm -it --network container:web nicolaka/netshoot

6. Volume Commands

Command

What it does

docker volume create <name>

Create a named volume

docker volume ls

List volumes

docker volume inspect <name>

Show a volume's driver, mount point and labels

docker volume rm <name>

Remove a volume (fails if a container uses it)

docker volume prune

Remove unused anonymous volumes

docker volume prune -a

Remove all unused volumes, including named ones


Warning: Removing a volume permanently deletes its data. Run docker volume ls and check what you are deleting before using docker volume prune -a.

Back up a volume to a tar file using a temporary container:

docker run --rm -v pgdata:/data -v "$(pwd)":/backup alpine \

  tar czf /backup/pgdata-backup.tar.gz -C /data .

7. Network Commands

Command

What it does

docker network ls

List networks

docker network create <name>

Create a user-defined bridge network

docker network create --driver bridge --subnet 172.30.0.0/16 <name>

Create a network with a custom subnet

docker network inspect <name>

Show the network's subnet and connected containers

docker network connect <network> <container>

Attach a running container to a network

docker network disconnect <network> <container>

Detach a container from a network

docker network rm <name>

Remove a network

docker network prune

Remove all unused networks


Containers on the same user-defined network can reach each other by container name, because Docker provides built-in DNS on those networks. This does not work on the default bridge network:

docker network create backend

docker run -d --name db --network backend -e POSTGRESPASSWORD=change-me postgres:17

docker run --rm --network backend postgres:17 pgisready -h db

8. Docker Compose Commands

Docker Compose runs multi-container applications defined in a compose.yaml file. Use docker compose (with a space). The old standalone docker-compose command is no longer the recommended tool.

Command

What it does

docker compose up -d

Create and start all services in the background

docker compose up -d --build

Rebuild images before starting

docker compose down

Stop and remove containers and networks

docker compose down -v

Also remove the volumes declared in the file (deletes data)

docker compose ps

List the project's containers

docker compose logs -f <service>

Follow logs for one service (omit the name for all)

docker compose exec <service> sh

Open a shell in a running service container

docker compose run --rm <service> <cmd>

Run a one-off command in a new service container

docker compose build

Build or rebuild service images

docker compose pull

Pull the latest images for all services

docker compose restart <service>

Restart a service

docker compose stop / docker compose start

Stop or start services without removing them

docker compose config

Validate the file and print the fully resolved configuration

docker compose watch

Sync, rebuild or restart services automatically when files change

docker compose -f compose.prod.yaml up -d

Use a specific Compose file

docker compose --profile debug up -d

Also start services assigned to the "debug" profile


9. Build Commands

Command

What it does

docker build -t myapp:1.0 .

Build and tag an image from the current directory

docker build -f docker/Dockerfile.prod -t myapp .

Use a Dockerfile with a different name or location

docker build --target builder -t myapp:build .

Build only up to a named stage in a multi-stage Dockerfile

docker build --build-arg VERSION=1.2.3 .

Pass a build argument

docker build --no-cache .

Build without using the layer cache

docker build --check .

Lint the Dockerfile against best-practice rules without building

docker build --secret id=npmrc,src=.npmrc .

Pass a secret to the build without storing it in a layer

docker buildx build --platform linux/amd64,linux/arm64 -t user/myapp:1.0 --push .

Build a multi-platform image and push it

docker buildx ls

List builders and the platforms they support

docker buildx imagetools inspect <image>

Show a multi-platform image's manifest list

docker builder prune

Remove unused build cache


docker build uses BuildKit by default. For a detailed guide to stages and smaller images, see our Complete Guide to Multi-Stage Docker Builds.

10. Registry Commands

Command

What it does

docker login

Log in to Docker Hub

docker login ghcr.io

Log in to another registry (here GitHub Container Registry)

echo "$TOKEN" | docker login -u <user> --password-stdin <registry>

Log in non-interactively (CI pipelines)

docker tag myapp:1.0 <registry>/<namespace>/myapp:1.0

Name an image for a specific registry

docker push <registry>/<namespace>/myapp:1.0

Push the image

docker search <term>

Search Docker Hub

docker logout <registry>

Remove stored credentials


Push to Amazon ECR (replace the account ID and region with your own):

aws ecr get-login-password --region ap-south-1 | \

  docker login --username AWS --password-stdin 123456789012.dkr.ecr.ap-south-1.amazonaws.com

docker tag myapp:1.0 123456789012.dkr.ecr.ap-south-1.amazonaws.com/myapp:1.0

docker push 123456789012.dkr.ecr.ap-south-1.amazonaws.com/myapp:1.0

Security: Never pass a password with -p or --password on the command line, because it is saved in your shell history and visible in the process list. Use --password-stdin with a token instead.

11. Cleanup Commands

Command

What it does

docker container prune

Remove all stopped containers

docker image prune

Remove dangling (untagged) images

docker image prune -a

Remove all images not used by a container

docker volume prune

Remove unused anonymous volumes

docker network prune

Remove unused networks

docker builder prune

Remove unused build cache

docker system prune

Stopped containers, unused networks, dangling images and dangling build cache

docker system prune -a

As above, plus all unused images and all unused build cache

docker system prune -a --volumes

As above, plus unused anonymous volumes

docker image prune -a --filter "until=168h"

Remove unused images older than 7 days


All prune commands ask for confirmation. Add -f to skip the prompt in scripts, but only once you are sure what will be removed. A safe routine on a busy build server is:

docker system df

docker container prune -f

docker image prune -a -f --filter "until=168h"

docker builder prune -f --filter "until=168h"

docker system df

12. Filtering and Formatting Output

Most list commands accept --filter (-f) to narrow results and --format to choose what is printed.

Command

What it does

docker ps -a -f status=exited

Only stopped containers

docker ps -f name=api

Containers whose name contains "api"

docker ps -f ancestor=nginx

Containers created from the nginx image

docker ps -f label=env=prod

Containers with a specific label

docker images -f dangling=true

Untagged images

docker ps --format "table {{.Names}}\t{{.Status}}\t{{.Ports}}"

Custom table of name, status and ports

docker ps --format "{{.Names}}: {{.HealthStatus}}"

Name and health status of each container

docker ps --format json

One JSON object per container (pipe into jq)


Combine -q with other commands for bulk operations:

# Stop all running containers

docker stop $(docker ps -q)

 

# Remove all stopped containers

docker rm $(docker ps -aq -f status=exited)

 

# Remove all images from one repository

docker rmi $(docker images -q myapp)

13. Security and Image Scanning Commands

Command

What it does

docker scout quickview <image>

Summary of vulnerabilities and base-image recommendations

docker scout cves <image>

List known vulnerabilities (CVEs) in an image

docker scout recommendations <image>

Suggested base-image updates to reduce vulnerabilities

docker run --cap-drop ALL --security-opt no-new-privileges ...

Run with minimal privileges

docker run -u 1000:1000 ...

Run as a non-root user

docker run --read-only --tmpfs /tmp ...

Read-only root filesystem with a writable temporary directory


Docker Scout is included with Docker Desktop and is available as a CLI plugin for Docker Engine. For a deeper explanation of container hardening, see our Docker Security Fundamentals tutorial.

14. Project Starter Commands

Command

What it does

docker init

Generate a Dockerfile, compose.yaml and .dockerignore for your project interactively

docker compose config

Check the generated Compose file

docker build --check .

Check the generated Dockerfile against best practices


Ready-to-Use Workflows

Workflow 1: Debug a Container That Keeps Restarting

docker ps -a -f name=api

docker logs --tail 50 api

docker inspect -f "{{.State.ExitCode}} OOMKilled={{.State.OOMKilled}}" api

docker events --since 10m --filter container=api

The exit code usually tells you where to look next (see the exit code table below). OOMKilled=true means the container exceeded its memory limit.

Workflow 2: Build, Test and Push an Image

docker build --check .

docker build -t myapp:1.0 .

docker run --rm -p 8080:8080 myapp:1.0

docker tag myapp:1.0 user/myapp:1.0

docker push user/myapp:1.0

Workflow 3: Update a Running Service to a New Image

docker pull nginx:1.29

docker stop web && docker rm web

docker run -d --name web -p 8080:80 --restart unless-stopped nginx:1.29

With Docker Compose, the same update is simply docker compose pull followed by docker compose up -d, which recreates only the services whose images changed.

Workflow 4: Free Up Disk Space Safely

docker system df

docker container prune

docker image prune -a

docker builder prune

docker system df

Volumes are deliberately left out, because they contain data. Remove specific volumes by name only after checking them.

Container Exit Codes Quick Reference

Exit code

Meaning

Common cause

0

Exited normally

The main process finished its work

1

Application error

An unhandled exception or error in your code

125

Docker could not run the container

Invalid docker run option or daemon error

126

Command cannot be executed

File is not executable or permission denied

127

Command not found

Wrong command or entrypoint, or missing binary in the image

137

Killed with SIGKILL

Out of memory (OOM), or docker kill, or stop timeout exceeded

139

Segmentation fault (SIGSEGV)

Crash in native code or wrong-architecture binary

143

Terminated with SIGTERM

Normal response to docker stop


For a detailed walkthrough of exit code 137, see our guide How to Fix Docker Exit Code 137.

What Changed in Docker 29 for Everyday Commands

  • docker image ls uses a collapsed tree view by default and hides untagged images unless you pass -a.

  • Default open-file limit for containers is now 1024; raise it with --ulimit nofile=... where needed.

  • docker ps --format supports a {{.HealthStatus}} placeholder (Engine 29.5 and later).

  • docker login --password - reads the password from STDIN, as an alternative to --password-stdin (Engine 29.6 and later).

  • Docker Content Trust (DOCKERCONTENT_TRUST) has been removed from the CLI. Use image signing tools such as Sigstore Cosign instead.

Frequently Asked Questions

What is the difference between docker ps and docker ps -a?

docker ps lists only running containers. docker ps -a lists all containers, including those that have stopped or exited, which is what you need when a container has crashed.

What is the difference between docker stop and docker kill?

docker stop sends SIGTERM so the application can shut down cleanly, and sends SIGKILL only if it has not stopped after 10 seconds. docker kill sends SIGKILL immediately, with no chance to clean up.

What is the difference between docker rm and docker rmi?

docker rm removes containers. docker rmi (or docker image rm) removes images. An image cannot be removed while a container, even a stopped one, still uses it.

How do I get a shell inside a running container?

Run docker exec -it <container> sh, or bash if the image includes it. If the image has no shell, use docker debug in Docker Desktop or attach a debugging container to its network namespace.

How do I remove all stopped containers?

Run docker container prune. To remove every container, including running ones, use docker rm -f $(docker ps -aq), but be careful: this deletes containers you may still need.

Should I use docker-compose or docker compose?

Use docker compose (with a space). It is the current Compose implementation, built into Docker Desktop and installed as a plugin with Docker Engine. The older standalone docker-compose binary is no longer the recommended tool.

Conclusion and Next Steps

You do not need to memorise every Docker command. Learn the structure (docker <object> <command>), keep the top 20 commands at your fingertips, and use this cheat sheet and --help for the rest. Above all, get comfortable with docker logs, docker exec and docker inspect, because these three commands solve most problems you will meet.

Continue the Docker course with these tutorials on BitCodeMatrix:

  • How to Install Docker on Ubuntu, Windows (WSL2) and macOS — set up Docker the right way

  • Rootless Docker: Setup and Limitations — run Docker without root privileges

  • Docker Volumes and Persistent Storage — keep data safe beyond the container lifecycle

  • Docker Container Lifecycle Explained (next in the course) — what happens at each stage from create to remove