skip to content

Engine Operations

The dockerd daemon itself: how daemon.json configures it, how the CLI reaches a local or remote engine, where container stdout and image data land on the host, and what to reclaim when disk fills. Most production Docker incidents are host incidents.

part ofDockeroverview, primer and where to startread it →
on this pageshow

questions

page 2 of 2

How would you design a Docker disk-reclamation policy for a shared build fleet?

level: principalimportance: should knowfreq 42%

basics

~10 s

Give build runners and service hosts separate rules, reclaim continuously with age and label filters instead of during incidents, budget the build cache rather than wiping it, and keep --volumes out of automation.

open as a page

How would you choose a fleet-wide container logging strategy: a shipping log driver in dockerd, or files plus a host collector?

level: principalimportance: should knowfreq 33%

basics

~20 s

Choose on failure coupling. A shipping driver inside dockerd puts a remote system on every container's write path; bounded local files read by a host collector keep that write local and logs readable on the host, at the cost of an agent.

open as a page

Why does raw output from the Docker Engine API's /containers/{id}/logs look corrupted?

level: middleimportance: nice to knowfreq 16%

basics

~20 s

It is framed, not corrupted. A container created without a TTY has stdout and stderr multiplexed into one stream, each chunk preceded by an 8-byte header holding the stream number and payload length. The docker CLI demultiplexes it.

open as a page

What do `docker top` and `docker diff` show for a container built with no shell?

level: middleimportance: nice to knowfreq 29%

basics

~20 s

docker top runs the host's ps against the container's processes, and docker diff lists files added, changed or deleted in the container's writable layer since the image. Both run entirely on the host, so they work on a distroless image that contains no shell and no tools.

open as a page

What does `dockerd-rootless-setuptool.sh install` set up, and what must already be on the host for it to succeed?

level: middleimportance: nice to knowfreq 24%

basics

~10 s

The script ships in docker-ce-rootless-extras and installs a per-user Docker Engine: a systemd user unit for dockerd and a socket under $XDG_RUNTIME_DIR. It requires the newuidmap tools and subordinate UID/GID ranges for the user.

open as a page

A docker context with an ssh:// endpoint fails to connect. What does that transport require?

level: seniorimportance: nice to knowfreq 32%

basics

~20 s

Docker's ssh:// endpoint runs the local ssh client to execute docker system dial-stdio remotely and pipes the Engine API over it. It needs a non-interactive key login, a trusted host key, a remote Docker CLI, and daemon-socket access there.

open as a page

What does Docker's log-opt mode=non-blocking change, and what does max-buffer-size control?

level: seniorimportance: nice to knowfreq 26%

basics

~20 s

Docker log drivers deliver in blocking mode by default, so a stalled driver back-pressures the container's writes to stdout and can stall the application. mode=non-blocking inserts a memory ring buffer, sized by max-buffer-size (1 MB default), that drops messages instead.

open as a page

The host trusts the TLS-intercepting proxy's CA and `docker pull` works, so why does the JVM inside the container still fail?

level: seniorimportance: nice to knowfreq 24%

basics

~20 s

Trust is per trust store, and the container has its own. The host bundle dockerd verified against is not inside the image, and a JVM reads its own cacerts keystore rather than the operating system's, so the CA must be added in both places in the image.

open as a page

How would you roll out a daemon.json change that requires a dockerd restart across a production fleet?

level: principalimportance: nice to knowfreq 30%

basics

~20 s

Restarting dockerd stops every container on that host unless live-restore is already on, and a bad key stops the daemon entirely. Render and validate the file from configuration management, canary one host, then roll in batches with a rollback that works without Docker.

open as a page

showing 31–39 of 39