Engine Operations
The dockerd daemon itself: how daemon.json configures it, how the CLI reaches a local or remote engine, where container stdout and image data land on the host, and what to reclaim when disk fills. Most production Docker incidents are host incidents.
part ofDockeroverview, primer and where to startread it →on this pageshowhide
explore
- Daemon Configuration4 questions
- Inspect, Stats & Events4 questions
- Log Drivers & Rotation5 questions
- Disk Usage & Pruning4 questions
- Contexts & Remote Engines4 questions
- Desktop's Linux VM4 questions
- Install & Version Skew4 questions
- Windows Containers3 questions
- Egress Proxies & Registry TLS3 questions
- Engine API & Clients4 questions
- Dockerskillanchors this topic
- AI Engineerrole
- Backend Developerrole
- Data Engineerrole
- DevOps / SRE Engineerrole
- DevSecOps Engineerrole
- Forward Deployed Engineerrole
- Full Stack Developerrole
- Java Backend Developerrole
- Java SDETrole
- Kotlin Backend Developerrole
- MLOps Engineerrole
- Machine Learning Engineerrole
- PostgreSQL DBArole
- QA Engineerrole
- Server-Side Game Developerrole
questions
page 2 of 2How would you design a Docker disk-reclamation policy for a shared build fleet?
basics
~10 sGive build runners and service hosts separate rules, reclaim continuously with age and label filters instead of during incidents, budget the build cache rather than wiping it, and keep --volumes out of automation.
How would you choose a fleet-wide container logging strategy: a shipping log driver in dockerd, or files plus a host collector?
basics
~20 sChoose on failure coupling. A shipping driver inside dockerd puts a remote system on every container's write path; bounded local files read by a host collector keep that write local and logs readable on the host, at the cost of an agent.
Why does raw output from the Docker Engine API's /containers/{id}/logs look corrupted?
basics
~20 sIt is framed, not corrupted. A container created without a TTY has stdout and stderr multiplexed into one stream, each chunk preceded by an 8-byte header holding the stream number and payload length. The docker CLI demultiplexes it.
What do `docker top` and `docker diff` show for a container built with no shell?
basics
~20 sdocker top runs the host's ps against the container's processes, and docker diff lists files added, changed or deleted in the container's writable layer since the image. Both run entirely on the host, so they work on a distroless image that contains no shell and no tools.
What does `dockerd-rootless-setuptool.sh install` set up, and what must already be on the host for it to succeed?
basics
~10 sThe script ships in docker-ce-rootless-extras and installs a per-user Docker Engine: a systemd user unit for dockerd and a socket under $XDG_RUNTIME_DIR. It requires the newuidmap tools and subordinate UID/GID ranges for the user.
A docker context with an ssh:// endpoint fails to connect. What does that transport require?
basics
~20 sDocker's ssh:// endpoint runs the local ssh client to execute docker system dial-stdio remotely and pipes the Engine API over it. It needs a non-interactive key login, a trusted host key, a remote Docker CLI, and daemon-socket access there.
What does Docker's log-opt mode=non-blocking change, and what does max-buffer-size control?
basics
~20 sDocker log drivers deliver in blocking mode by default, so a stalled driver back-pressures the container's writes to stdout and can stall the application. mode=non-blocking inserts a memory ring buffer, sized by max-buffer-size (1 MB default), that drops messages instead.
The host trusts the TLS-intercepting proxy's CA and `docker pull` works, so why does the JVM inside the container still fail?
basics
~20 sTrust is per trust store, and the container has its own. The host bundle dockerd verified against is not inside the image, and a JVM reads its own cacerts keystore rather than the operating system's, so the CA must be added in both places in the image.
How would you roll out a daemon.json change that requires a dockerd restart across a production fleet?
basics
~20 sRestarting dockerd stops every container on that host unless live-restore is already on, and a bad key stops the daemon entirely. Render and validate the file from configuration management, canary one host, then roll in batches with a rollback that works without Docker.
showing 31–39 of 39