Docker
Containers in practice — images, volumes, Compose, resource limits, and hardening them for multi-tenant use.
11 posts
What Is Docker? A Beginner's Explanation
Docker packages an app with everything it needs to run, so it works the same on any computer. What containers and images are, how they differ from virtual machines, why hosts and AI tools use them everywhere, and whether you need to learn Docker at all.
What Is a Dev Container? devcontainer.json Explained
A dev container defines your development environment as code — the tools, versions, services, and settings a project needs — so it runs the same on every machine and in the cloud. What goes in devcontainer.json, how it differs from a Dockerfile, and where it falls short.
Rootless Containers and User Namespaces: What They Actually Protect
Root in a container is root on the host unless something remaps it. How user namespaces work, subuid/subgid ranges, Docker userns-remap vs rootless mode vs Podman, Kubernetes hostUsers: false, the file-ownership and networking costs, and where rootless fits.
Writing a Production Dockerfile for a Node.js App
The Dockerfile an AI tool writes usually works — and ships a 1.5 GB image running as root that ignores shutdown signals and leaks build secrets into its layers. A line-by-line production Dockerfile: multi-stage builds, layer caching, non-root users, signal handling, secrets, and health checks.
Docker Volumes vs Bind Mounts: Where Your Data Actually Lives
Containers are meant to be thrown away. Your database, uploads, and certificates are not. The three ways Docker stores data — the container layer, named volumes, and bind mounts — what survives what, the command that silently deletes your database, and how to back a volume up.
Docker Compose for Local Development: App, Postgres, and Redis in One Command
A compose.yaml that starts your whole stack — app, database, cache, and workers — with one command. Services, networking by service name, volumes for data and code, health-checked startup order, env files, profiles, watch mode for live reload, and the pitfalls on macOS and Windows.
Containers vs Virtual Machines: The Difference, Simply Explained
Both let one physical computer act like many. A virtual machine pretends to be a whole computer; a container is an isolated group of processes sharing one operating system. How each works, the trade-offs in speed, size, and isolation, and when to use which.
Container Networking Internals: veth, Bridges, NAT, and Embedded DNS
What happens when a container sends a packet: network namespaces, veth pairs, bridges, NAT for egress and published ports, why published ports bypass firewalls like ufw, Docker's embedded DNS, inter-container isolation, and debugging with nsenter and tcpdump.
Hardening Containers With Capabilities, seccomp, AppArmor, and User Namespaces
A default container shares the host kernel and starts with more privilege than most workloads need. A layer-by-layer guide: dropping capabilities, no-new-privileges, seccomp, AppArmor and SELinux, read-only filesystems, and user namespaces — and how to verify each.
How Container CPU and Memory Limits Actually Work
docker run --cpus 2 --memory 4g looks simple. Underneath, it's cgroup v2 files with behaviour that surprises people: CPU limits that throttle rather than slow, memory limits that count page cache, and tools inside the container that report the host's resources. How to read the real numbers.
Docker vs Linux Users for Multi-Tenant Workspace Isolation
Separate Linux users look like a cheap way to isolate tenants until you try to enforce a CPU limit. A walkthrough of why containers win for multi-tenant development workspaces — and how to verify the limits are real.