Painless Docker
Exploiter toute la puissance de Docker et de son écosystème
Formats : Kindle, Broché, Cours en ligne
Ce que vous apprendrez
- Construire et optimiser des images de conteneur légères et reproductibles
- Câbler réseau, volumes et Compose pour de vraies applications
- Durcir des conteneurs pour la production, du moindre privilège à l'analyse d'images
À propos de ce livre
Un guide pas à pas pour maîtriser Docker et son écosystème. La conteneurisation reprise depuis la base - des images et des volumes jusqu'au réseau, à l'orchestration et à une sécurité prête pour la production. Pour les développeurs qui passent au DevOps moderne et aux architectures en microservices.
Table des matières
-
Preface
- Who This Guide is For
- What You Will Learn
- About the Author
- Join the Community
- Your Feedback Matters
-
How to Use This Guide
- The Companion Kit
- Heredoc
- Long Commands
-
The Missing Introduction to Containerization
- We Are Made by History
- History Is Layered, Not Isolated
- OS Containers vs. App Containers
- Docker's Place in Container History
- Does CRI Mean the Death of Docker?
- The Open Container Initiative: What is a Standard Container?
- The Birth of the Moby Project: When Docker Outgrew Itself
-
Hack the Container: Understanding Docker's Inner Workings
- Prerequisites
- Peekaboo Kernel: Understanding Namespaces and Cgroups
- A Deep Dive into Container Prototyping with runC
- containerd, shim and runC: How Everything Works Together
- Docker Runtimes: An Overview
- Adding a New Runtime to Docker
- Where Docker and containerd Store Data on the Host
-
Introduction to Docker CLI
- Docker CLI
- General Information About Your Docker Installation
- Docker Help
- The 4 Resources of Docker
-
Docker Containers
- Creating Containers
- Running Containers
- TTY, Interactive and Detached Modes
- Restarting Containers
- Stopping Containers
- Pausing and Unpausing Containers
- Sending Signals to Containers
- Removing and Pruning Containers
- Container Lifecycle
- Starting Containers Automatically
- Accessing Container Ports
- Running Commands in Containers
- Running Docker in Docker
-
Managing Container Resources
- Memory Usage Reservations and Limits
- CPU Usage Reservations and Limits
-
Docker Images
- What is an Image?
- Images are Layers
- Managing & Inspecting Images
- Tags and Digests
- Intermediate Images & Dangling Images
-
Dockerfile: Instructions, Best Practices, and Gotchas
- The Dockerfile
- Dockerfile Instructions
- Key Takeaways
-
Optimizing Docker Builds: Everything You Need to Know
- The Base Image
- Extending the Base Image
- Optimizing Docker Builds: The Multi-Stage Build
- Optimizing Docker Builds: Caching Strategies & Best Practices
- Optimizing Docker Builds: Leveraging BuildKit Caching & Advanced Techniques
- Optimizing Docker Builds: Reducing the Context Size
- Optimizing Docker Builds: The Base Image
-
Docker Volumes & Data Management
- Why and When to Use Volumes?
- What is a Docker Volume?
- Creating and Using Docker Volumes
- Listing and Inspecting Docker Volumes
- Named Volumes vs Anonymous Volumes
- Bind Mounts
- Volume Initialization Behavior
- Data Propagation & Updates
- Dangling Volumes
- TMPFS Mounts
-
Docker Networks
- Docker Networking Model
- Understanding the Bridge Network
- User-Defined Bridge Networks
- The Host Network
- The None Network
- The Macvlan Network
-
Cleaning Docker
- Delete Volumes
- Delete Networks
- Delete Images
- Remove Docker Containers
- Cleaning Up Everything
-
Modern Docker OCI Registries
- Why Use a Registry?
- Types of Registries
- Deployment of an OCI Registry
- Harbor Security Scan & SBOM
- Replication of Images
-
Docker Compose: A Mini Orchestration Tool for Local Development
- What Is Docker Compose & Why Should I Care?
- Understanding Docker Compose and How it Works
- Understanding Docker Compose Syntax
- Managing Service Dependencies
- Healthchecks and Wait-for-it Scripts
- Using Dockerfile with Docker Compose
- Docker Compose with Bind Mounts
- Creating Custom Networks
- Docker Compose Secrets
- Scaling Docker Compose Services
-
Logs: Container/Daemon Logging, Logging Drivers & Best Practices
- Understanding Docker Logs Internals
- Logging Best Practices and Recommendations
- Logging Drivers
- Docker Daemon Logging
-
Common Security Threats
- Docker vs. VMs: Which is more secure?
- Kernel Panic and Container Exploits
- Container Breakouts and Privilege Escalation
- Poisoned Images
- Denial-of-Service (DoS) Attacks
- Compromising Secrets
- Application-Level Threats
- Host System-Level Threats
- setuid/setgid Binaries
-
Docker Security Best Practices
- Secure by Design and DevSecOps
- setuid/setgid Binaries
- Control Resources
- Sign Your Images for Integrity and Authenticity
- Scan your Images for Vulnerabilities and Misconfigurations
- Set Container Filesystem to Read-Only
- Set Volumes to Read-Only
- Do Not Use the Root User
- Avoid Environment Variables for Sensitive Data & Use a Secret Manager
- Disable Inter-Container Communication (ICC)
- Know Your Software Bill of Materials (SBOM)
- Privileged Mode & Capabilities
- Use Seccomp
- Use AppArmor to Restrict Container Actions
- Use SELinux
- Use Docker Hardened Images
-
Docker API
- Docker SDKs
- Docker API: Hello World
- Prototyping a Log Collector Service
-
Debugging and Troubleshooting
- Docker daemon logs
- Activating Debug Mode
- Debugging Docker Objects
- Troubleshooting Docker Using Sysdig
-
Docker Events
- Using Docker Events for Troubleshooting
- Prototyping a Docker Events Listener
-
Understanding How Docker Swarm Works
- What is Docker Swarm?
- Creating a Swarm Cluster
- Swarm Services and Tasks
- Networking in Docker Swarm
- Performing Operations on Nodes
- Multi-manager Docker Swarm
- Docker Swarm Environment Variables and Secrets
- Docker Swarm Volumes
- Docker Swarm Limitations, Challenges & Use Cases
-
Deploying Applications on Docker Swarm: A Practical Guide
- Deploying a WordPress Application on Docker Swarm
- Docker Swarm Global Services
- Docker Swarm Resource Management
-
Deploying and Managing Services at Scale with Docker Swarm
- Docker Swarm Stacks
- Docker Swarm Rolling Updates
- Healthchecks and Restart Policies
- Dependencies Between Services in Docker Swarm
- Using an External Load Balancer with Docker Swarm
- Using Traefik as a Front-End Load Balancer with Docker Swarm
- Integrating Traefik with the WordPress Stack
- Docker Swarm Logging
-
Docker Model Runner: Running Machine Learning Models with Docker
- Docker Model Runner Overview
- Pulling and Running Models
- LLM Models: Back to the Basics
- Understanding How to Choose Model Variants
- Docker Model Runner APIs
- A Better User Experience with OpenWebUI
-
Afterword
- Let's Stay Connected
- Your Feedback Matters
Pour qui
Développeurs et exploitants qui passent des machines virtuelles aux conteneurs, et veulent le modèle mental autant que les commandes.
À propos de l'auteur
Aymen El Amri est ingénieur logiciel, auteur et maker. Il dirige eralabs, a construit FAUN.dev, et écrit sur les systèmes cloud native, l'ingénierie de l'IA et les outils pour développeurs (developer tooling). Qui est Aymen.