skip to content

Containers & Orchestration

Packaging an application into an OCI image, running it as an isolated process under kernel namespaces and cgroups, and handing fleets of them to a scheduler that keeps declared state true. Every deployment answer bottoms out in an image and a scheduler.

on this pageshow

explore

→ has its own guide

questions

1,343 · 6 sections

Why must a container on a managed platform bind the injected PORT on 0.0.0.0?

level: juniorimportance: must knowfreq 78%
basics
~20 s

The platform chooses the port, passes it in as an environment variable, and then connects to the container's IP on that port. An app that hardcodes a different port, or listens only on 127.0.0.1, is unreachable from outside its own network namespace.

open as a page

On a single Docker host, how do you replace a running container with a new image version?

level: juniorimportance: must knowfreq 58%
basics
~20 s

Pull the new image while the old container still serves, then stop it, remove it and run a new container on the new tag. Pin an immutable tag, and keep the previous image for rollback.

open as a page

What does `docker buildx build --push` do that `docker build` followed by `docker push` does not?

level: juniorimportance: must knowfreq 72%
basics
~20 s

--push is shorthand for --output type=registry: buildx streams the finished layers from the builder straight to the registry. On a docker-container builder the image never enters the local image store, so a separate docker push would find nothing to push.

open as a page

Why do developers bind-mount source into a running Docker container instead of rebuilding the image on every edit?

level: juniorimportance: must knowfreq 76%
basics
~20 s

A bind mount maps a host directory onto a path inside the running container, so an edit on the host is visible to the process instantly. Source baked in with COPY changes only when you rebuild the image.

open as a page

In a Dockerfile, what happens to `docker build` when a `RUN` test command exits non-zero?

level: juniorimportance: must knowfreq 66%
basics
~20 s

A non-zero exit from any RUN command aborts docker build immediately: no layer is committed for that step and no image is tagged. Running the test suite in a RUN step is what turns a failing test into a failing build.

open as a page

With Docker Compose, what is the difference between `docker compose run` and `docker compose exec`, and when do you use each?

level: juniorimportance: must knowfreq 64%
basics
~20 s

docker compose run starts a new one-off container from a service's definition; docker compose exec runs a command inside that service's already running container. Use run for migrations and scripts, exec to inspect a live service.

open as a page

In Docker Compose, what is the difference between the project `.env` file and a service's `env_file` and `environment` attributes?

level: juniorimportance: must knowfreq 66%
basics
~20 s

The project .env file only feeds ${VAR} substitution while Compose parses compose.yaml. A service's env_file and environment attributes set variables inside its container; nothing in .env reaches a container unless one of them passes it on.

open as a page

What problem does Docker Compose solve, and what are the main top-level sections of a compose.yaml file?

level: juniorimportance: must knowfreq 70%
basics
~20 s

Compose runs a multi-container stack from one declarative YAML file instead of many long docker run commands. The main top-level keys are services (the containers), networks, and volumes. docker compose up creates everything; down removes it.

open as a page

With Docker Compose, you edit the API's source and run `docker compose restart api`, but the old code still runs. Why, and what fixes it?

level: middleimportance: must knowfreq 56%
basics
~20 s

The code is baked into the image, and docker compose restart only restarts the existing container from that old image. Rebuild and recreate with docker compose up -d --build api; a plain up skips the build because a local image already exists.

open as a page

In a compose.yaml, how do `${VAR:-default}`, `${VAR-default}` and `${VAR:?err}` differ, and when would you use each one?

level: middleimportance: must knowfreq 52%
basics
~20 s

${VAR:-default} uses the default when VAR is unset or empty, ${VAR-default} only when it is unset, and ${VAR:?err} makes Compose stop with err when VAR is unset or empty. Use defaults for tunables and :? for values that must be supplied.

open as a page

Before moving a ticket-booking checkout service onto Kubernetes, what must the application itself change to run well as a container?

level: juniorimportance: must knowfreq 70%
basics
~20 s

The app must read configuration from environment variables or mounted files, log to stdout and stderr, expose a readiness signal that reflects real ability to serve, shut down cleanly on SIGTERM, and size itself from its container limits.

open as a page

On a Kubernetes platform run by a platform team, what is a golden-path template, and why use it instead of hand-written manifests?

level: juniorimportance: must knowfreq 58%
basics
~20 s

A golden-path template is a platform-maintained, pre-approved way to deploy a service: developers fill in a few values and the template produces the Deployment, Service, probes and resources, so every team gets safe defaults without writing raw Kubernetes manifests.

open as a page

In Kubernetes, what is the difference between a label and an annotation, and how do you decide which one to use?

level: juniorimportance: must knowfreq 78%
basics
~20 s

Labels are short identifying key/value pairs that selectors match, so Services, Deployments and kubectl -l find objects by them. Annotations carry non-identifying data of any shape, capped at 256 KiB in total, that tools read by key but nothing can select on.

open as a page

In Kubernetes, how do `kubectl create -f`, `kubectl replace -f` and `kubectl apply -f` differ when you manage an object from a YAML file?

level: juniorimportance: must knowfreq 74%
basics
~20 s

kubectl create only makes new objects and fails if the name exists. kubectl replace overwrites an existing object with the whole file. kubectl apply creates or updates by merging the file into the live object and leaves fields it never set alone.

open as a page

In Kubernetes, what are labels, and how do equality-based and set-based label selectors decide which objects match?

level: juniorimportance: must knowfreq 74%
basics
~20 s

Kubernetes labels are key/value pairs on an object's metadata. A label selector lists requirements, all of which must match: equality (=, !=) or set-based (in, notin, exists). Services, ReplicaSets and kubectl use selectors to find objects.

open as a page

How do Helm and Kustomize differ in how they produce the final manifests applied to a cluster?

level: juniorimportance: must knowfreq 78%
basics
~20 s

Helm renders a chart's Go templates against values, so the final YAML is generated from files that are not YAML. Kustomize patches complete YAML instead. Helm also stores each apply as a release; kubectl apply -k stores nothing.

open as a page

Why is helm upgrade described as a one-shot apply rather than a reconcile loop?

level: juniorimportance: must knowfreq 72%
basics
~20 s

helm upgrade runs once: it renders the chart, sends the result to the API server, records a new release revision and exits. Nothing then watches the cluster, so drift survives until somebody runs Helm again.

open as a page

What does helm lint check in a chart, and what does it not catch?

level: juniorimportance: must knowfreq 72%
basics
~20 s

helm lint parses the chart metadata, renders the templates with the values it is given, and reports INFO, WARNING and ERROR findings. It never contacts a cluster, so a manifest that renders as valid YAML but is an invalid Kubernetes object still passes.

open as a page

What makes a Helm chart's values.yaml defaults safe to install unedited?

level: juniorimportance: must knowfreq 64%
basics
~20 s

Defaults that render runnable YAML with no -f file: every key a template reads is present and typed, empty extension points declared as {} or [], nothing secret or site-specific baked in, and required inputs failing the render loudly.

open as a page

In a Helm Chart.yaml, what is the difference between version and appVersion?

level: juniorimportance: must knowfreq 84%
basics
~20 s

version is the chart package's own version and must be valid SemVer 2; Helm names the tarball, indexes and resolves the chart from it. appVersion is a free-form label naming the application release the chart ships, and Helm never parses it.

open as a page

What does Docker Swarm mode add on top of a single Docker Engine, and how is a swarm service different from a container you start with `docker run`?

level: juniorimportance: must knowfreq 40%
basics
~20 s

Swarm mode turns several engines into one cluster of manager and worker nodes. A service is declared desired state — image, replica count, update policy — and managers keep that many tasks (containers) running, rescheduling them when containers or nodes fail.

open as a page

Walk through what `docker service update --image myapp:2.0` does to a 10-replica swarm service, and which settings control the blast radius if the new image is broken.

level: middleimportance: should knowfreq 30%
basics
~20 s

The manager updates the service spec and replaces tasks in batches. update_config sets parallelism, delay, order (stop-first or start-first), monitor window, max failure ratio and failure_action (pause, continue, rollback). docker service rollback restores the previous spec.

open as a page

How does deploying a Compose file with `docker stack deploy` differ from running the same file with `docker compose up`, and which Compose keys are ignored when deploying to a swarm?

level: middleimportance: should knowfreq 34%
basics
~20 s

docker compose up runs containers on one engine and can build images. docker stack deploy sends the file to swarm managers, which create services across the cluster; it honours the deploy: section and ignores single-host keys such as build, container_name, depends_on and links.

open as a page

How many manager nodes should a Docker Swarm cluster run, what happens when a majority of managers becomes unreachable, and how do you recover from that?

level: seniorimportance: should knowfreq 28%
basics
~20 s

Managers replicate cluster state with Raft, so use an odd number — 3 or 5 — tolerating (N-1)/2 failures. Losing quorum freezes all cluster changes while existing tasks keep running. Recover by restoring managers, or run docker swarm init --force-new-cluster on a survivor.

open as a page

In a Docker Swarm cluster, how does a client request reach a service replica when it hits a published port on a node that is running no replica of that service, and how do containers on different hosts reach each other?

level: seniorimportance: should knowfreq 32%
basics
~20 s

Published ports use the ingress overlay network and routing mesh: every node listens on the port and load balances to a task anywhere via IPVS. Container-to-container traffic runs over VXLAN-encapsulated overlay networks, with service names resolving to a virtual IP.

open as a page

The mounted configuration file changed minutes ago, yet the service still enforces the old rate limit — why?

level: juniorimportance: must knowfreq 66%
basics
~20 s

Delivery and consumption are separate events. The process parsed the file once at start-up and serves from that in-memory copy; nothing re-reads it unless the process was written to, so the old value stands until it re-reads or is replaced.

open as a page

The same report-renderer image runs in an integration environment and in production — what may legitimately differ between the two?

level: juniorimportance: must knowfreq 65%
basics
~20 s

Only the values supplied around the artifact may differ: endpoints, credentials, copy count, verbosity, feature switches. The image bytes stay identical, because identical bytes are what makes an earlier environment's test evidence mean anything in production.

open as a page

If a payments ledger's datastore password is baked into the image it ships as, who can read it and what does changing it cost?

level: juniorimportance: must knowfreq 68%
basics
~20 s

Everyone who can obtain the artifact holds the credential, because the value travels with the image to every registry, mirror, host and environment it reaches. Changing it means building a new artifact and rolling it out, so rotation becomes a release.

open as a page

How does a tuning value reach a process running inside a container, and what does the delivery shape decide?

level: juniorimportance: must knowfreq 72%
basics
~20 s

Two shapes: a flat set of name-value pairs the process inherits when it is created, or a directory of files mounted into its filesystem. The choice decides who else can read the value and what changing it costs.

open as a page

A service image moves from a full distribution base to a minimal base — what goes away with it?

level: juniorimportance: must knowfreq 72%
basics
~20 s

Everything the distribution shipped that the process does not carry itself: the shell and its utilities, the package manager, usually the trusted-certificate store, timezone and locale data, and most system libraries. Only the artifact and whatever the build copied in remain.

open as a page