Data Scientist → AI Engineer • Training 03
Article-Training • AI Engineering Foundations

Docker

From “Works on My Machine” to Portable AI Services

Learn the container mindset: package your code, runtime and dependencies into a reproducible image that can run consistently on laptops, servers and cloud platforms.

Code → Dockerfile → Image → Container → Registry → Deployment
📁 CODE
→
📦 IMAGE
→
🐳 CONTAINER
→
🚀 DEPLOY
8learning modules
24interactive practices
5rapid review questions
50%certificate threshold
Learning target
Understand images vs containers, write a Dockerfile for a Python API, manage dependencies and environment variables, persist data correctly, use Compose and prepare images for registries and deployment.
Practice progress0 / 24

Complete 12 of 24 practices (50%) and enter your name to unlock the Certificate of Participation.

MODULE 01
🧭

Why Containers Matter

Containers package an application with the environment it needs. This reduces dependency drift between development, testing and production.

👁️
See it this way

Docker does not replace good dependency management; it makes the runtime boundary explicit and repeatable.

Core ideas

  • Reproducible runtime
  • Portable packaging
  • Fast startup
  • Isolation between services
Try this
# Local
python app.py

# Container mindset
docker run my-ai-api:1.0
✅

Docker does not replace good dependency management; it makes the runtime boundary explicit and repeatable.

Practice — 3 cases

Practice 1 / Práctica 1
Which statement best reflects this module?
Practice 2 / Práctica 2
Which action is the best engineering choice?
Practice 3 / Práctica 3
Which option would you avoid in a production system?
MODULE 02
🧱

Images vs Containers

An image is an immutable packaged blueprint. A container is a running instance of that image. Many containers can be started from the same image.

👁️
See it this way

If important state disappears when the container is replaced, that state belongs outside the container filesystem.

Core ideas

  • Image = build artifact
  • Container = running process
  • Tag images for versions
  • Containers should be disposable
Try this
docker build -t risk-api:1.0 .
docker run --rm -p 8000:8000 risk-api:1.0
✅

If important state disappears when the container is replaced, that state belongs outside the container filesystem.

Practice — 3 cases

Practice 4 / Práctica 4
Which statement best reflects this module?
Practice 5 / Práctica 5
Which action is the best engineering choice?
Practice 6 / Práctica 6
Which option would you avoid in a production system?
MODULE 03
🛠️

Write Your First Dockerfile

A Dockerfile describes how to assemble an image layer by layer: base runtime, working directory, dependencies, source code and startup command.

👁️
See it this way

Layer order affects build speed. Put stable dependency layers before frequently changing source code.

Core ideas

  • Choose small trusted base image
  • Copy dependency file first
  • Install dependencies
  • Copy app and define CMD
Try this
FROM python:3.12-slim
WORKDIR /app
COPY requirements.txt .
RUN pip install --no-cache-dir -r requirements.txt
COPY . .
CMD ["uvicorn","app:app","--host","0.0.0.0","--port","8000"]
✅

Layer order affects build speed. Put stable dependency layers before frequently changing source code.

Practice — 3 cases

Practice 7 / Práctica 7
Which statement best reflects this module?
Practice 8 / Práctica 8
Which action is the best engineering choice?
Practice 9 / Práctica 9
Which option would you avoid in a production system?
MODULE 04
🧪

Ports, Networking & Health

Containers have their own network namespace. Port publishing connects a host port to the service inside the container; health checks help platforms determine whether the app is ready.

👁️
See it this way

EXPOSE documents intent; -p actually publishes a port when you run a container.

Core ideas

  • Bind app to 0.0.0.0
  • Publish host:container port
  • Use service names in Compose networks
  • Expose health endpoint
Try this
docker run -p 8080:8000 risk-api:1.0

# host: http://localhost:8080
# container app listens on :8000
✅

EXPOSE documents intent; -p actually publishes a port when you run a container.

Practice — 3 cases

Practice 10 / Práctica 10
Which statement best reflects this module?
Practice 11 / Práctica 11
Which action is the best engineering choice?
Practice 12 / Práctica 12
Which option would you avoid in a production system?
MODULE 05
⚙️

Environment Variables & Secrets

Runtime configuration should be separated from the image. Environment variables let the same image run with different settings without rebuilding it.

👁️
See it this way

An image should be safe to share with a registry. If it contains production passwords, the design is already broken.

Core ideas

  • Keep configuration outside image
  • Never bake secrets into layers
  • Use .env only for local convenience
  • Use platform secret stores in production
Try this
docker run \
  -e MODEL_PATH=/models/risk.joblib \
  -e LOG_LEVEL=INFO \
  risk-api:1.0
✅

An image should be safe to share with a registry. If it contains production passwords, the design is already broken.

Practice — 3 cases

Practice 13 / Práctica 13
Which statement best reflects this module?
Practice 14 / Práctica 14
Which action is the best engineering choice?
Practice 15 / Práctica 15
Which option would you avoid in a production system?
MODULE 06
📡

Volumes & Persistent Data

Containers are ephemeral. Volumes and bind mounts provide durable or host-managed storage for models, databases, logs or development source code.

👁️
See it this way

The container should be replaceable; the important data should survive replacement.

Core ideas

  • Volume for managed persistent data
  • Bind mount for host files/dev
  • Avoid writing important state to container layer
  • Back up persistent stores
Try this
docker run --rm \
  -v model_store:/models \
  risk-api:1.0
✅

The container should be replaceable; the important data should survive replacement.

Practice — 3 cases

Practice 16 / Práctica 16
Which statement best reflects this module?
Practice 17 / Práctica 17
Which action is the best engineering choice?
Practice 18 / Práctica 18
Which option would you avoid in a production system?
MODULE 07
🛡️

Docker Compose for Multi-Service AI

Compose defines multiple local services in one file: API, database, vector store or worker. It is excellent for reproducible development environments.

👁️
See it this way

Compose is a development and simple-hosting tool; large-scale production orchestration usually moves to a managed platform or Kubernetes-like scheduler.

Core ideas

  • Define services
  • Create shared network
  • Inject environment settings
  • Start stack with one command
Try this
services:
  api:
    build: .
    ports: ["8000:8000"]
  redis:
    image: redis:7-alpine

# docker compose up -d
✅

Compose is a development and simple-hosting tool; large-scale production orchestration usually moves to a managed platform or Kubernetes-like scheduler.

Practice — 3 cases

Practice 19 / Práctica 19
Which statement best reflects this module?
Practice 20 / Práctica 20
Which action is the best engineering choice?
Practice 21 / Práctica 21
Which option would you avoid in a production system?
MODULE 08
🚀

Registry, Versioning & Deployment Handoff

A registry stores versioned images so deployment systems can pull the exact build that was tested. Immutable tags or digests improve traceability.

👁️
See it this way

Promote the same image across environments. Rebuilding separately for production breaks reproducibility.

Core ideas

  • Build once
  • Tag version
  • Push to registry
  • Deploy exact image
Try this
docker tag risk-api:1.0 registry.example.com/risk-api:1.0
docker push registry.example.com/risk-api:1.0
✅

Promote the same image across environments. Rebuilding separately for production breaks reproducibility.

Practice — 3 cases

Practice 22 / Práctica 22
Which statement best reflects this module?
Practice 23 / Práctica 23
Which action is the best engineering choice?
Practice 24 / Práctica 24
Which option would you avoid in a production system?
5-Question Knowledge Check

Can you explain the core ideas clearly?

Open each item only after answering it in your own words.

1. What is the difference between an image and a container?

An image is a packaged immutable blueprint; a container is a running instance of that image.

2. Why copy requirements before application code in a Dockerfile?

To maximize build-cache reuse when source code changes but dependencies do not.

3. Where should production secrets live?

Outside the image, ideally in the deployment platform or a dedicated secret manager.

4. Why use volumes?

To persist or share data independently from the disposable container filesystem.

5. Why push images to a registry?

So deployment environments can retrieve a versioned, tested artifact consistently.

Decision Guide

What should you reach for?

NeedRecommended approach
Package runtimeDocker image
Run packaged appContainer
Persist stateVolume / external store
Share buildContainer registry

Certificate of Participation

Complete at least 12 of the 24 practice cases (50%) and enter your name.

0 / 24 • 0%