Learn the container mindset: package your code, runtime and dependencies into a reproducible image that can run consistently on laptops, servers and cloud platforms.
Complete 12 of 24 practices (50%) and enter your name to unlock the Certificate of Participation.
Containers package an application with the environment it needs. This reduces dependency drift between development, testing and production.
Docker does not replace good dependency management; it makes the runtime boundary explicit and repeatable.
# Local
python app.py
# Container mindset
docker run my-ai-api:1.0Docker does not replace good dependency management; it makes the runtime boundary explicit and repeatable.
An image is an immutable packaged blueprint. A container is a running instance of that image. Many containers can be started from the same image.
If important state disappears when the container is replaced, that state belongs outside the container filesystem.
docker build -t risk-api:1.0 .
docker run --rm -p 8000:8000 risk-api:1.0If important state disappears when the container is replaced, that state belongs outside the container filesystem.
A Dockerfile describes how to assemble an image layer by layer: base runtime, working directory, dependencies, source code and startup command.
Layer order affects build speed. Put stable dependency layers before frequently changing source code.
FROM python:3.12-slim
WORKDIR /app
COPY requirements.txt .
RUN pip install --no-cache-dir -r requirements.txt
COPY . .
CMD ["uvicorn","app:app","--host","0.0.0.0","--port","8000"]Layer order affects build speed. Put stable dependency layers before frequently changing source code.
Containers have their own network namespace. Port publishing connects a host port to the service inside the container; health checks help platforms determine whether the app is ready.
EXPOSE documents intent; -p actually publishes a port when you run a container.
docker run -p 8080:8000 risk-api:1.0
# host: http://localhost:8080
# container app listens on :8000EXPOSE documents intent; -p actually publishes a port when you run a container.
Runtime configuration should be separated from the image. Environment variables let the same image run with different settings without rebuilding it.
An image should be safe to share with a registry. If it contains production passwords, the design is already broken.
docker run \
-e MODEL_PATH=/models/risk.joblib \
-e LOG_LEVEL=INFO \
risk-api:1.0An image should be safe to share with a registry. If it contains production passwords, the design is already broken.
Containers are ephemeral. Volumes and bind mounts provide durable or host-managed storage for models, databases, logs or development source code.
The container should be replaceable; the important data should survive replacement.
docker run --rm \
-v model_store:/models \
risk-api:1.0The container should be replaceable; the important data should survive replacement.
Compose defines multiple local services in one file: API, database, vector store or worker. It is excellent for reproducible development environments.
Compose is a development and simple-hosting tool; large-scale production orchestration usually moves to a managed platform or Kubernetes-like scheduler.
services:
api:
build: .
ports: ["8000:8000"]
redis:
image: redis:7-alpine
# docker compose up -dCompose is a development and simple-hosting tool; large-scale production orchestration usually moves to a managed platform or Kubernetes-like scheduler.
A registry stores versioned images so deployment systems can pull the exact build that was tested. Immutable tags or digests improve traceability.
Promote the same image across environments. Rebuilding separately for production breaks reproducibility.
docker tag risk-api:1.0 registry.example.com/risk-api:1.0
docker push registry.example.com/risk-api:1.0Promote the same image across environments. Rebuilding separately for production breaks reproducibility.
Open each item only after answering it in your own words.
An image is a packaged immutable blueprint; a container is a running instance of that image.
To maximize build-cache reuse when source code changes but dependencies do not.
Outside the image, ideally in the deployment platform or a dedicated secret manager.
To persist or share data independently from the disposable container filesystem.
So deployment environments can retrieve a versioned, tested artifact consistently.
| Need | Recommended approach |
|---|---|
| Package runtime | Docker image |
| Run packaged app | Container |
| Persist state | Volume / external store |
| Share build | Container registry |
Complete at least 12 of the 24 practice cases (50%) and enter your name.