Docker Production Readiness
Take a container from "works on my machine" to production-safe: build errors, runtime failures, Compose, and a hardening pass with the auditor.
- Who it’s for
- Engineers shipping containers who want fewer 2am surprises.
- Prerequisites
- You can build and run a basic container.
Skills you’ll build
- ✓Debug build/image failures
- ✓Diagnose container runtime crashes
- ✓Write safer Compose
- ✓Run a production-readiness audit
-
Module 1
Build and image errors
Fix the common build and image failures and understand layer caching.
-
Module 2
Container and runtime errors
Diagnose crash loops, exit codes, and resource limits.
Diagnostic commands run in order — each one narrows the fault
- Find containers that are restarting
docker ps -a --filter "status=restarting" --format "{{.Names}}\\t{{.Status}}"A restart loop means the process exits immediately. The exit code in `docker inspect` tells you why.
- Read the exit code and OOM flag
docker inspect --format "{{.Name}} exit={{.State.ExitCode}} oom={{.State.OOMKilled}} err={{.State.Error}}" $(docker ps -aq)exit=137 with oom=true is a memory limit, not a crash. exit=125/126/127 are Docker, permission and PATH problems respectively.
- Check health check status
docker inspect --format "{{.Name}} {{if .State.Health}}{{.State.Health.Status}}{{else}}no-healthcheck{{end}}" $(docker ps -q)"no-healthcheck" is itself a production-readiness finding: nothing can tell whether the container is actually serving.
- Read the last logs before the exit
docker logs --tail 100 --timestamps <CONTAINER>Read from the bottom up to the FIRST error — the last line is usually just the process giving up.
Exercise
A container exits immediately with code 1. Work through image, entrypoint, config, and resource limits to find why.
Open in Workspace → -
-
Module 3
Compose you can trust
Structure a multi-service Compose file and catch security issues before they ship.
Diagnostic commands run in order — each one narrows the fault
- Validate the resolved configuration
docker compose config --quiet && echo "compose file is valid"Resolves variables, extends and overrides. Catches the mistakes that only appear once the file is merged.
- Check restart policies
docker compose config | grep -A1 -E "^\\s+restart:" || echo "NO restart policy set"A production service with no restart policy will stay down after a host reboot.
- Check resource limits
docker compose config | grep -B2 -A6 "deploy:" | grep -A4 "resources:" || echo "NO resource limits set"Without limits, one container can starve every other service on the host.
- Look for secrets committed as environment values
docker compose config | grep -iE "(password|secret|token|key)\\s*[:=]" | grep -v "_FILE"Any literal value here is baked into the config and visible to anyone who can run `docker inspect`. Use secrets or *_FILE.
-
-
Module 4
Run a production-readiness audit
Score an image/Compose against 50 production rules and fix the findings.
Mission complete 🎉
You’ve worked every module of Docker Production Readiness.
Next: Kubernetes Production Troubleshooting →Related