Docker Deep Dive · Reference
Linux & Shell Cheatsheet
Everything phase 0 (P1–P7) teaches, in the shape you'll reach for it.
The Docker CLI gets its own cheatsheet as those lessons arrive; this page is the Linux underneath every Docker command.
Your Linux playground
Real Linux practice happens inside a disposable container — identical on macOS, Windows, and Linux.
One command in, exit out, nothing on your Mac can break:
docker run -it --rm ubuntu:24.04 bash
Move around, look around · P1
command -f --long-flag argument1 argument2
| command | does | remember |
pwd | print working directory — "where am I?" | prompt ≠ location; trust pwd |
ls -lah | list: long form, hidden files, human sizes | -l rows are P2's mode strings |
cd path | change directory | cd alone → home, cd - → back |
mkdir -p a/b/c | make directories, parents included | no -p: parents must exist |
touch f | create empty file (or bump its date) | |
cp -r src dst | copy (-r for directories) | silently overwrites — -i asks |
mv old new | move and rename (same command) | |
rm -r dir | delete forever — no trash, no undo | read the line twice before Enter |
cat f / less f | dump file / page through it | in less: space, /find, q |
head -n 20 f / tail -n 20 f | first / last lines | tail -f = follow live (→ docker logs -f) |
| key | effect |
| Tab | complete the path/command — if it won't complete, it doesn't exist (your best typo detector) |
| ↑ / ↓ | walk command history |
| Ctrl-R | search history as you type |
| Ctrl-C | interrupt the foreground process (sends SIGINT — see P4) |
| Ctrl-L | clear screen (history stays) |
/etc/nginx/nginx.conf
../logs/app.log
~/projects
ls --help
man ls
type ls
Files, permissions, root · P2
- rwx r-x r-- 1 app staff 4096 Jul 17 deploy.sh
│ │ │ │ └owner └group
│ │ │ └─ everyone else: read only
│ │ └────── group "staff": read + execute
│ └─────────── owner "app": read + write + execute
└─ type: - file · d directory · l symlink
| octal | triad | typical use |
7 = rwx | read+write+execute | owner of a script/dir |
6 = rw- | read+write | owner of a data file |
5 = r-x | read+execute | group/others on dirs |
4 = r-- | read only | config for others |
0 = --- | nothing | secrets for others |
chmod +x deploy.sh
chmod 644 app.conf
chmod 600 secret.env
chmod 755 bin/
chown -R app:app /data
id
su - dev
Directory triads read differently: r = list names, w = create/delete
entries, x = enter/traverse. Containers run as root by default — the
whole point of lesson 11's USER.
Streams, pipes, text · P3
| fd | stream | default |
0 | stdin — what the process reads | your keyboard |
1 | stdout — its results | your screen |
2 | stderr — its complaints | your screen (separately!) |
cmd > out.txt
cmd >> out.txt
cmd 2> err.txt
cmd > all.txt 2>&1
cmd 2> /dev/null
cmd < input.txt
grep " 500 " access.log | cut -d' ' -f7 | sort | uniq -c | sort -rn | head -3
| tool | does | flags that matter |
grep PATTERN f | keep matching lines | -i case-blind · -v invert · -rn recurse+numbers · -c count |
wc -l | count lines | |
sort | order lines | -n numeric · -r reverse · -u unique |
uniq -c | collapse+count adjacent dupes | always sort first |
cut -d' ' -f7 | take field 7, space-delimited | |
find DIR -name '*.conf' | walk tree, filter | -type f/d · -mtime -1 · -size +1M |
xargs CMD | stdin lines → CMD arguments | docker ps -q | xargs docker stop |
docker rm $(docker ps -aq)
Processes, environment, signals · P4
ps aux
ps -ef --forest
sleep 500 &
jobs
kill PID
kill -9 PID
echo $?
| signal | n | meaning | catchable? |
| SIGINT | 2 | Ctrl-C from the keyboard | yes |
| SIGTERM | 15 | "please exit" — kill's and docker stop's default | yes — graceful shutdown lives here |
| SIGKILL | 9 | kernel removes the process, no appeal | never |
| SIGHUP | 1 | terminal closed / "reload config" by convention | yes |
| exit code | means |
0 | success — the only success |
1–125 | program-defined failure |
126 / 127 | found but not executable / command not found |
128+N | killed by signal N → 137 = SIGKILL (OOM!, lesson 10) · 143 = SIGTERM |
NAME=harbor
export NAME=harbor
NAME=harbor cmd
echo "$NAME"
echo "${PORT:-8000}"
env | sort
echo "$PATH"
Kernel, /proc, namespaces · P5
uname -r
ls /proc
cat /proc/1/cmdline
cat /proc/meminfo
ls -l /proc/$$/ns
strace -c ls
strace -e trace=openat cat /etc/hostname
unshare --pid --fork --mount-proc bash
| namespace | isolates | you met it in |
pid | which processes are visible | lesson 10's docker top vs exec ps |
net | interfaces, IPs, ports | why -p exists (lesson 4) |
mnt | the filesystem view | image layers (lessons 2–3) |
uts | hostname | container id as hostname (lesson 1) |
user | uid/gid mapping | rootless mention (lesson 11) |
cat /sys/fs/cgroup/memory.max
cat /sys/fs/cgroup/cgroup.procs
Ports, DNS, packages · P6
ip addr
ss -tlnp
curl -v localhost:8000
getent hosts db
cat /etc/hosts
cat /etc/resolv.conf
The bind rule that explains half of all container bugs
A server that listens on 127.0.0.1 accepts connections only from
inside its own network namespace — docker run -p can't reach it.
Listen on 0.0.0.0 (all interfaces) and publishing works. Ports below 1024
need root or CAP_NET_BIND_SERVICE.
apt-get update
apt-get install -y curl
dpkg -L curl
rm -rf /var/lib/apt/lists/*
apk add --no-cache curl
Scripts & entrypoints · P7
#!/usr/bin/env bash
set -euo pipefail
name="${1:?usage: $0 NAME}"
echo "deploying ${name} to ${ENV:-dev}"
| test | true when |
[ -f p ] / [ -d p ] | file / directory exists |
[ -z "$v" ] / [ -n "$v" ] | string empty / non-empty |
[ "$a" = "$b" ] | strings equal (spaces around =!) |
if cmd; then… | any command's exit code 0 is "true": if grep -q err log |
#!/usr/bin/env bash
set -e
echo "preparing config from env…"
exec "$@"
CMD ["python", "app.py"]
CMD python app.py
Terms · phase 0 glossary
| term | in one line |
| terminal | the program drawing text on your screen; it hosts a shell |
| shell | the command interpreter (zsh, bash): parses your line, runs programs, reports exit codes |
| kernel | the one program that owns hardware, processes, files, and the network; everything else asks it |
| syscall | the only doorway from a program into the kernel (open, read, execve, …) |
| process | a running program: PID + memory + open files + environment + one parent |
| PID 1 | the first process in a (namespace's) tree; special signal rules — your container's main process |
| signal | an asynchronous one-byte message to a process (SIGTERM, SIGKILL…) |
| environment variable | per-process key=value strings, copied to children at spawn — 12-factor config's carrier |
| namespace | kernel feature limiting what a process can see (pids, mounts, network…) |
| cgroup | kernel feature limiting what a process can use (memory, CPU) |
| socket / port | a communication endpoint; TCP port = 16-bit number one listener may claim per address |
| DNS | name → IP resolution; containers get a per-network resolver at 127.0.0.11 |
| package manager | installs software + its dependencies from an indexed repository (apt, apk) |
Where each section was taught
P1 The Terminal & the Shell ·
P2 Files, Permissions & root ·
P3 Streams, Pipes & Text Tools (soon) ·
P4 Processes, Environments & Signals (soon) ·
P5 Kernel, Syscalls & Namespaces (soon) ·
P6 Ports, DNS & Packages (soon) ·
P7 Shell Scripts & Entrypoints (soon)