Docker Installation and Usage
Add the Docker CE Repository
Section titled “Add the Docker CE Repository”Docker provides an official repository for enterprise Linux. The following steps apply to RHEL, CentOS Stream, AlmaLinux, Rocky Linux, and other EL-based distributions.
# Install the DNF plugin that provides config-managersudo dnf install -y dnf-plugins-core
# Add the official Docker repositorysudo dnf config-manager --add-repo \ https://download.docker.com/linux/centos/docker-ce.reposudo yum install -y yum-utils
sudo yum-config-manager --add-repo \ https://download.docker.com/linux/centos/docker-ce.repoInstall Docker
Section titled “Install Docker”-
Install Docker Engine, CLI, and container runtime:
Terminal window sudo dnf install -y docker-ce docker-ce-cli containerd.io docker-compose-pluginTerminal window sudo yum install -y docker-ce docker-ce-cli containerd.io docker-compose-plugin -
Start Docker and enable it at boot:
Terminal window sudo systemctl enable --now docker -
Verify the installation:
Terminal window sudo docker versionsudo docker run hello-world -
(Optional) Add the current user to the docker group to avoid using sudo every time:
Terminal window sudo usermod -aG docker $(whoami)Log out and log back in for the change to take effect.
Basic Usage
Section titled “Basic Usage”Pull Images
Section titled “Pull Images”# Pull images from Docker Hubdocker pull nginx:latestdocker pull almalinux:9
# Search for imagesdocker search mariadb
# View local imagesdocker imagesRun Containers
Section titled “Run Containers”# Run in the foreground, automatically remove on exitdocker run --rm -it almalinux:9 /bin/bash
# Run Nginx in the backgrounddocker run -d --name my-nginx -p 80:80 nginx:latest
# Run MariaDB with environment variables and volume mountsdocker run -d --name my-db \ -p 3306:3306 \ -e MYSQL_ROOT_PASSWORD=your_password \ -v /data/mysql:/var/lib/mysql \ mariadb:10.11View Containers
Section titled “View Containers”# View running containersdocker ps
# View all containersdocker ps -a
# View container logsdocker logs my-nginxdocker logs -f --tail 100 my-nginx
# View container detailsdocker inspect my-nginx
# View container resource usagedocker statsStop and Remove
Section titled “Stop and Remove”# Stop a containerdocker stop my-nginx
# Start a stopped containerdocker start my-nginx
# Restart a containerdocker restart my-nginx
# Remove a stopped containerdocker rm my-nginx
# Force remove a running containerdocker rm -f my-nginx
# Remove all stopped containersdocker container prune
# Remove unused imagesdocker image prune -aEnter a Container
Section titled “Enter a Container”# Enter a container with an interactive terminaldocker exec -it my-nginx /bin/bash
# Execute a command inside a containerdocker exec my-nginx nginx -tDocker Compose
Section titled “Docker Compose”Docker Compose is used to define and manage multi-container applications. Docker CE includes the docker compose subcommand (V2) out of the box.
Write a Compose File
Section titled “Write a Compose File”Create docker-compose.yml:
services: web: image: nginx:latest ports: - "80:80" - "443:443" volumes: - ./nginx.conf:/etc/nginx/nginx.conf:ro - ./html:/usr/share/nginx/html:ro - certbot_data:/etc/letsencrypt:ro depends_on: - app restart: unless-stopped
app: build: ./app expose: - "8000" environment: - DATABASE_URL=mysql://root:changeme@db:3306/myapp depends_on: - db restart: unless-stopped
db: image: mariadb:10.11 environment: MYSQL_ROOT_PASSWORD: changeme MYSQL_DATABASE: myapp volumes: - db_data:/var/lib/mysql restart: unless-stopped
redis: image: redis:7-alpine restart: unless-stopped
volumes: db_data: certbot_data:Manage Compose Services
Section titled “Manage Compose Services”# Start all services (in the background)docker compose up -d
# View service statusdocker compose ps
# View logsdocker compose logs -f
# View logs for a specific service onlydocker compose logs -f app
# Rebuild and startdocker compose up -d --build
# Stop all servicesdocker compose down
# Stop and remove data volumesdocker compose down -v
# Scale service instancesdocker compose up -d --scale app=3Build Custom Images
Section titled “Build Custom Images”Write a Dockerfile
Section titled “Write a Dockerfile”FROM almalinux:9-minimal
RUN microdnf install -y python3 python3-pip && \ microdnf clean all
WORKDIR /appCOPY requirements.txt .RUN pip3 install --no-cache-dir -r requirements.txt
COPY . .
EXPOSE 8000
USER 1001
CMD ["python3", "-m", "uvicorn", "main:app", "--host", "0.0.0.0", "--port", "8000"]Build and Push
Section titled “Build and Push”# Build the imagedocker build -t my-app:v1 .
# Tag the imagedocker tag my-app:v1 registry.example.com/my-app:v1
# Push to a private registrydocker push registry.example.com/my-app:v1Storage Driver Configuration
Section titled “Storage Driver Configuration”Docker uses the overlay2 storage driver by default on EL systems, which is the recommended option.
Check the Current Storage Driver
Section titled “Check the Current Storage Driver”docker info | grep "Storage Driver"Configure the Docker Daemon
Section titled “Configure the Docker Daemon”Edit or create /etc/docker/daemon.json:
{ "storage-driver": "overlay2", "data-root": "/data/docker", "log-driver": "json-file", "log-opts": { "max-size": "100m", "max-file": "3" }, "registry-mirrors": [ "https://mirror.example.com" ]}Restart Docker to apply the configuration:
sudo systemctl restart dockerMigrate the Storage Directory
Section titled “Migrate the Storage Directory”To migrate Docker data from the default /var/lib/docker to a new location:
-
Stop Docker:
Terminal window sudo systemctl stop docker -
Copy existing data:
Terminal window sudo rsync -aP /var/lib/docker/ /data/docker/ -
Set
data-rootin/etc/docker/daemon.json:{"data-root": "/data/docker"} -
Start Docker and verify:
Terminal window sudo systemctl start dockerdocker info | grep "Docker Root Dir" -
After confirming everything works, remove the old directory:
Terminal window sudo rm -rf /var/lib/docker
Firewall Configuration
Section titled “Firewall Configuration”Docker manages its own iptables rules. If you are using firewalld, note the following:
# Allow inter-container communicationsudo firewall-cmd --permanent --zone=trusted --add-interface=docker0sudo firewall-cmd --reloadCommon Maintenance Commands
Section titled “Common Maintenance Commands”# View Docker disk usagedocker system df
# Comprehensive cleanup of unused resourcesdocker system prune -a --volumes
# Export a container as an imagedocker commit my-nginx my-nginx-backup:latest
# Export/import image filesdocker save -o nginx-backup.tar nginx:latestdocker load -i nginx-backup.tar