# Introduction to Docker

**Learning Objectives**
  * Build and run Docker containers
  * Pull Docker images from Docker Hub and Google Container Registry
  * Push Docker images to Google Container Registry

## Overview

Docker is an open platform for developing, shipping, and running applications. With Docker, you can separate your applications from your infrastructure and treat your infrastructure like a managed application. Docker helps you ship code faster, test faster, deploy faster, and shorten the cycle between writing code and running code.

Docker does this by combining kernel containerization features with workflows and tooling that helps you manage and deploy your applications.

Docker containers can be directly used in Kubernetes, which allows them to be run in the Kubernetes Engine with ease. After learning the essentials of Docker, you will have the skillset to start developing Kubernetes and containerized applications.

## Basic Docker commands

See what docker images you have. 

In [50]:
!docker images

REPOSITORY                                     TAG       IMAGE ID       CREATED        SIZE
gcr.io/qwiklabs-gcp-04-248da7eb1719/node-app   0.2       6ba7fbeb9eec   22 hours ago   884MB
gcr.io/inverting-proxy/agent                   <none>    fe507176d0e6   2 months ago   1.73GB


If this is the first time working with docker you won't have any repositories listed. 

**Note**. If you are running this in an AI Notebook, then you should see a single image `gcr.io/inverting-proxy/agent`. This is the container that is currently running the AI Notebook. 

Let's use `docker run` to pull a docker image called `hello-world` from the public registry. The docker daemon will search for the `hello-world` image, if it doesn't find the image locally, it pulls the image from a public registry called Docker Hub, creates a container from that image, and runs the container for you.

In [2]:
!docker run hello-world

Unable to find image 'hello-world:latest' locally
latest: Pulling from library/hello-world

[1Bde127a29: Pull complete 529kB/2.529kBB[1A[2KDigest: sha256:f2266cbfc127c960fd30e76b7c792dc23b588c0db76233517e1891a4e357d519
Status: Downloaded newer image for hello-world:latest

Hello from Docker!
This message shows that your installation appears to be working correctly.

To generate this message, Docker took the following steps:
 1. The Docker client contacted the Docker daemon.
 2. The Docker daemon pulled the "hello-world" image from the Docker Hub.
    (amd64)
 3. The Docker daemon created a new container from that image which runs the
    executable that produces the output you are currently reading.
 4. The Docker daemon streamed that output to the Docker client, which sent it
    to your terminal.

To try something more ambitious, you can run an Ubuntu container with:
 $ docker run -it ubuntu bash

Share images, automate workflows, and more with a free Docker ID:
 https://hub.docke

Now when we look at our docker images we should see `hello-world` there as well.

In [3]:
!docker images

REPOSITORY                     TAG       IMAGE ID       CREATED        SIZE
hello-world                    latest    d1165f221234   7 weeks ago    13.3kB
gcr.io/inverting-proxy/agent   <none>    fe507176d0e6   2 months ago   1.73GB


This is the image pulled from the Docker Hub public registry. The Image ID is in `SHA256` hash format—this field specifies the Docker image that's been provisioned. When the docker daemon can't find an image locally, it will by default search the public registry for the image. Let's run the container again:

Now, if we want to run `docker run hello-world` again, it won't have to download from the container registry.

To see all docker containers running, use `docker ps`.

In [4]:
!docker ps

CONTAINER ID   IMAGE                          COMMAND                  CREATED         STATUS         PORTS     NAMES
95d418205811   gcr.io/inverting-proxy/agent   "/bin/sh -c '/opt/bi…"   9 minutes ago   Up 9 minutes             proxy-agent


There are no running containers. **Note. If you are running this in at AI Notebook, you'll see one container running.**

The `hello-world` containers you ran previously already exited. In order to see all containers, including ones that have finished executing, run docker `ps -a`:

In [5]:
!docker ps -a

CONTAINER ID   IMAGE                          COMMAND                  CREATED         STATUS                              PORTS     NAMES
1aa9b55454da   hello-world                    "/hello"                 1 second ago    Exited (0) Less than a second ago             optimistic_merkle
95d418205811   gcr.io/inverting-proxy/agent   "/bin/sh -c '/opt/bi…"   9 minutes ago   Up 9 minutes                                  proxy-agent


This shows you the Container ID, a UUID generated by Docker to identify the container, and more metadata about the run. The container Names are also randomly generated but can be specified with docker run --name [container-name] hello-world.

## Build a Docker container

Let's build a Docker image that's based on a simple node application.

**Exercise**

Open the text file called `intro.docker` in the `dockerfiles` folder and complete the TODO there. 

Your dockerfile should have the following steps

 1. use `FROM` to inherit an official Node runtime as the parent image; e.g. node:6
 2. use `WORKDIR` to seet the working directory to /app
 3. use `ADD` to copy the current directory to the container at /app
 4. use `EXPOSE` to make the containers port 80 available to the outside world
 5. use `CMD` to run the command `node ./src/app.js`

This file instructs the Docker daemon on how to build your image.

The initial line specifies the base parent image, which in this case is the official Docker image for node version 6.
In the second, we set the working (current) directory of the container.
In the third, we add the current directory's contents (indicated by the "." ) into the container.
Then we expose the container's port so it can accept connections on that port and finally run the node command to start the application.

Check out the other [Docker command references](https://docs.docker.com/engine/reference/builder/#known-issues-run) to understand what each line does.

We're going to use this Docker container to run a simple node.js app. Have a look at `app.js`. This is a simple HTTP server that listens on port 80 and returns "Hello World."


Now let's build the image. Note again the "`.`", which means current directory so you need to run this command from within the directory that has the Dockerfile.

The `-t` is to name and tag an image with the `name:tag` syntax. The name of the image is `node-app` and the tag is `0.1`. The tag is highly recommended when building Docker images. If you don't specify a tag, the tag will default to latest and it becomes more difficult to distinguish newer images from older ones. Also notice how each line in the Dockerfile above results in intermediate container layers as the image is built.

**Exercise**

Use `docker build` to build the docker image at `dockerfiles/intro.docker`. Tag the image `node-app:0.1`. 

In [10]:
# %%bash
!docker build -t node-app:0.1 -f dockerfiles/intro.docker .

Sending build context to Docker daemon  91.65kB
Step 1/5 : FROM node:6
6: Pulling from library/node

[1B55d5a1d1: Pulling fs layer 
[1B80d00ae9: Pulling fs layer 
[1Bb3117dca: Pulling fs layer 
[1Ba19181b2: Pulling fs layer 
[1B7b2a5bcc: Pulling fs layer 
[1B12c70287: Pulling fs layer 
[1B5386a42d: Pulling fs layer 
[1BDigest: sha256:e133e66ec3bfc98da0440e552f452e5cdf6413319d27a2db3b01ac4b319759b34A[2K[4A[2K[8A[2K[8A[2K[4A[2K[2A[2K[4A[2K[2A[2K[4A[2K[2A[2K[1A[2K[1A[2K[4A[2K[4A[2K[4A[2K[8A[2K[4A[2K[8A[2K[4A[2K[8A[2K[4A[2K[8A[2K[8A[2K[8A[2K[4A[2K[4A[2K[8A[2K[4A[2K[8A[2K[4A[2K[4A[2K[4A[2K[8A[2K[8A[2K[7A[2K[7A[2K[7A[2K[7A[2K[7A[2K[6A[2K[6A[2K[6A[2K[5A[2K[5A[2K[5A[2K[5A[2K[5A[2K[5A[2K[5A[2K[5A[2K[5A[2K[5A[2K[5A[2K[5A[2K[5A[2K[5A[2K[5A[2K[5A[2K[5A[2K[5A[2K[5A[2K[4A[2K[4A[2K[4A[2K[4A[2K[4A[2K[4A[2K[4A[2K[4A[2K[4A[2K[4A[2K[4A[2K[4A[2K[4A[2K[

Let's check that the image has been created correctly. 

In [11]:
!docker images

REPOSITORY                     TAG       IMAGE ID       CREATED                  SIZE
node-app                       0.1       ca4185598a82   Less than a second ago   884MB
hello-world                    latest    d1165f221234   7 weeks ago              13.3kB
gcr.io/inverting-proxy/agent   <none>    fe507176d0e6   2 months ago             1.73GB
node                           6         ab290b853066   23 months ago            884MB


You should see a `node-app` repository that was created only seconds ago. 

Notice `node` is the base image and `node-app` is the image you built. You can't remove `node` without removing `node-app` first. The size of the image is relatively small compared to VMs. Other versions of the node image such as `node:slim` and `node:alpine` can give you even smaller images for easier portability. The topic of slimming down container sizes is further explored in Advanced Topics. You can view all versions in the official repository here.

Note, you can remove an image from your docker images using `docker rmi [repository]:[tag]`.

## Run a Docker container

Now we'll run the container based on the image you built above using the `docker run` command. The `--name` flag allows you to name the container if you like. And `-p` instructs Docker to map the host's port 4000 to the container's port 80. This allows you to reach the server at http://localhost:4000. Without port mapping, you would not be able to reach the container at localhost.

In [25]:
!docker ps -a

CONTAINER ID   IMAGE                          COMMAND                  CREATED          STATUS                      PORTS     NAMES
1aa9b55454da   hello-world                    "/hello"                 13 minutes ago   Exited (0) 13 minutes ago             optimistic_merkle
95d418205811   gcr.io/inverting-proxy/agent   "/bin/sh -c '/opt/bi…"   23 minutes ago   Up 23 minutes                         proxy-agent


**Exercise**

Use `docker run` to run the container you just build called `node-app:0.1`. Assign the host port `4000` to port `80` and assign it the name `my-app`.

In [26]:
# %%bash
!docker run -p 4000:80 --name my-app node-app:0.1

Server running at http://0.0.0.0:80/


To test out the server, open a terminal window and type the following command:

```bash
curl http://localhost:4000
```

You should see the server respond with `Hello World`

The container will run as long as the initial terminal is running. If you want to stop the container, run the following command in the terminal to stop and remove the container:

```bash
docker stop my-app && docker rm my-app
```
After a few moments the container will stop. You should notice the cell above will complete execution.

#### Running the container in the background
If you want to the container to run in the background (not tied to the terminal's session), you need to specify the `-d` flag.
Now run the following command to start the container in the background

**Exercise**

Modify your command above with `-d` flag to run `my-app` in the background.

In [27]:
# %%bash
!docker run -p 4000:80 --name my-app -d node-app:0.1

docker: Error response from daemon: Conflict. The container name "/my-app" is already in use by container "3139727991e55b88793104577f93563143a2cd0f4326a1de09110449b8f88c84". You have to remove (or rename) that container to be able to reuse that name.
See 'docker run --help'.


Your container is now running in the background. You can check the status of your running container using `docker ps`

In [28]:
!docker ps

CONTAINER ID   IMAGE                          COMMAND                  CREATED          STATUS          PORTS     NAMES
95d418205811   gcr.io/inverting-proxy/agent   "/bin/sh -c '/opt/bi…"   28 minutes ago   Up 28 minutes             proxy-agent


Notice the container is running in the output of docker ps. You can look at the logs by executing `docker logs [container_id]`. 

In [29]:
# Note, your container id will be different
!docker logs b9d5fd6b8e33

Error: No such container: b9d5fd6b8e33


You should see 
```bash
Server running at http://0.0.0.0:80/
```
If you want to follow the log's output as the container is running, use the `-f` option.

## Modify & Publish

Let's modify the application and push it to your Google Cloud Repository (gcr). After that you'll remove all local containers and images to simulate a fresh environment, and then pull and run your containers from gcr. This will demonstrate the portability of Docker containers.

### Edit `app.js`
Open the file `./src/app.js` with the text editor and replace "Hello World" with another string. Then build this new image. 

**Exercise**

After modifying the `app.js` file, use `docker build` to build a new container called `node-app:0.2` from the same docker file. 

In [30]:
# %%bash
!docker build -t node-app:0.2 -f dockerfiles/intro.docker .

Sending build context to Docker daemon  90.11kB
Step 1/5 : FROM node:6
 ---> ab290b853066
Step 2/5 : WORKDIR /app
 ---> Using cache
 ---> 7cadfaf3f198
Step 3/5 : ADD . /app
 ---> e106ceb1c719
Step 4/5 : EXPOSE 80
 ---> Running in 2aaf160fab95
Removing intermediate container 2aaf160fab95
 ---> 649116968a4e
Step 5/5 : CMD ["node", "./src/app.js"]
 ---> Running in 6ee8f14e4b08
Removing intermediate container 6ee8f14e4b08
 ---> 6ba7fbeb9eec
Successfully built 6ba7fbeb9eec
Successfully tagged node-app:0.2


Notice in `Step 2` of the output we are using an existing cache layer. From `Step 3` and on, the layers are modified because we made a change in `app.js`.

Run another container with the new image version. Notice how we map the host's port 8000 instead of 80. We can't use host port 4000 because it's already in use. 

**Exercise**

Run this new container in the background using a different port and with the name `my-app-2`.

In [32]:
# %%bash
!docker run -p 8000:80 --name my-app-2 -d node-app:0.2

18db02dd7f66ec909b451bd20117fa85dc114bf07e266b8ced547091d1fc1c33


You can check that both container are running using `docker ps`.

In [33]:
!docker ps

CONTAINER ID   IMAGE                          COMMAND                  CREATED          STATUS          PORTS                  NAMES
18db02dd7f66   node-app:0.2                   "node ./src/app.js"      3 seconds ago    Up 2 seconds    0.0.0.0:8000->80/tcp   my-app-2
95d418205811   gcr.io/inverting-proxy/agent   "/bin/sh -c '/opt/bi…"   29 minutes ago   Up 29 minutes                          proxy-agent


And let's test boht containers using `curl` as before:

In [34]:
!curl http://localhost:8000

Hello Baby!


In [35]:
!curl http://localhost:4000

curl: (7) Failed to connect to localhost port 4000: Connection refused


Recall, to stop a container running, you can execute the following command either in a terminal or (because they are running in the background) in a cell in this notebook. 

### Publish to gcr

Now you're going to push your image to the Google Container Registry (gcr). To push images to your private registry hosted by gcr, you need to tag the images with a registry name. The format is `[hostname]/[project-id]/[image]:[tag]`.

For gcr:

  * `[hostname]`= gcr.io
  * `[project-id]`= your project's ID
  * `[image]`= your image name
  * `[tag]`= any string tag of your choice. If unspecified, it defaults to "latest".

In [36]:
import os

PROJECT_ID = "qwiklabs-gcp-04-248da7eb1719" # REPLACE WITH YOUR PROJECT NAME
""
os.environ["PROJECT_ID"] = PROJECT_ID

Let's tag `node-app:0.2`.

In [37]:
!docker images

REPOSITORY                     TAG       IMAGE ID       CREATED          SIZE
node-app                       0.2       6ba7fbeb9eec   2 minutes ago    884MB
node-app                       0.1       ca4185598a82   14 minutes ago   884MB
hello-world                    latest    d1165f221234   7 weeks ago      13.3kB
gcr.io/inverting-proxy/agent   <none>    fe507176d0e6   2 months ago     1.73GB
node                           6         ab290b853066   23 months ago    884MB


**Exercise**

Tag the `node-app:0.2` image with a new image name conforming to the naming convention `gcr.io/[project-id]/[image]:[tag]`. Keep the image and tag names the same.

In [38]:
%%bash
docker tag node-app:0.2 gcr.io/${PROJECT_ID}/node-app:0.2

Now when we list our docker images we should see this newly tagged repository.

In [39]:
!docker images

REPOSITORY                                     TAG       IMAGE ID       CREATED          SIZE
node-app                                       0.2       6ba7fbeb9eec   3 minutes ago    884MB
gcr.io/qwiklabs-gcp-04-248da7eb1719/node-app   0.2       6ba7fbeb9eec   3 minutes ago    884MB
node-app                                       0.1       ca4185598a82   14 minutes ago   884MB
hello-world                                    latest    d1165f221234   7 weeks ago      13.3kB
gcr.io/inverting-proxy/agent                   <none>    fe507176d0e6   2 months ago     1.73GB
node                                           6         ab290b853066   23 months ago    884MB


Next, let's push this image to gcr.

**Exercise**

Push this new image to the gcr.

In [40]:
%%bash
docker push gcr.io/${PROJECT_ID}/node-app:0.2

The push refers to repository [gcr.io/qwiklabs-gcp-04-248da7eb1719/node-app]
cb01260d2456: Preparing
e1b29780c6e1: Preparing
f39151891503: Preparing
f1965d3c206f: Preparing
a27518e43e49: Preparing
910d7fd9e23e: Preparing
4230ff7f2288: Preparing
2c719774c1e1: Preparing
ec62f19bb3aa: Preparing
f94641f1fe1f: Preparing
910d7fd9e23e: Waiting
4230ff7f2288: Waiting
ec62f19bb3aa: Waiting
f94641f1fe1f: Waiting
2c719774c1e1: Waiting
f1965d3c206f: Layer already exists
f39151891503: Layer already exists
a27518e43e49: Layer already exists
2c719774c1e1: Layer already exists
910d7fd9e23e: Layer already exists
4230ff7f2288: Layer already exists
f94641f1fe1f: Layer already exists
ec62f19bb3aa: Layer already exists
cb01260d2456: Pushed
e1b29780c6e1: Pushed
0.2: digest: sha256:deaafab4c1fbce71e161b0b23f4e4ef948b44ac0b530fecb5e06b32ba90ba6b2 size: 2424


Check that the image exists in `gcr` by visiting the image registry Cloud Console. You can navigate via the console to `Navigation menu > Container Registry` or visit the url from the cell below:

In [41]:
%%bash
echo "http://gcr.io/${PROJECT_ID}/node-app"

http://gcr.io/qwiklabs-gcp-04-248da7eb1719/node-app


### Test the published gcr image

Let's test this image. You could start a new VM, ssh into that VM, and install gcloud. For simplicity, we'll just remove all containers and images to simulate a fresh environment.

First, stop and remove all containers using `docker stop` and `docker rm`. **Be careful not to stop the container running this AI Notebook!**.

In [42]:
!docker stop my-app && docker rm my-app

my-app
my-app


In [43]:
!docker stop my-app-2 && docker rm my-app-2

my-app-2
my-app-2


Now remove the docker images you've created above using `docker rmi`.

In [44]:
!docker images

REPOSITORY                                     TAG       IMAGE ID       CREATED          SIZE
node-app                                       0.2       6ba7fbeb9eec   4 minutes ago    884MB
gcr.io/qwiklabs-gcp-04-248da7eb1719/node-app   0.2       6ba7fbeb9eec   4 minutes ago    884MB
node-app                                       0.1       ca4185598a82   15 minutes ago   884MB
hello-world                                    latest    d1165f221234   7 weeks ago      13.3kB
gcr.io/inverting-proxy/agent                   <none>    fe507176d0e6   2 months ago     1.73GB
node                                           6         ab290b853066   23 months ago    884MB


In [45]:
%%bash
docker rmi node-app:0.2
docker rmi gcr.io/${PROJECT_ID}/node-app:0.2
docker rmi node-app:0.1
docker rmi node:6 
docker rmi -f hello-world:latest

Untagged: node-app:0.2
Untagged: gcr.io/qwiklabs-gcp-04-248da7eb1719/node-app:0.2
Untagged: gcr.io/qwiklabs-gcp-04-248da7eb1719/node-app@sha256:deaafab4c1fbce71e161b0b23f4e4ef948b44ac0b530fecb5e06b32ba90ba6b2
Deleted: sha256:6ba7fbeb9eecdf57acaf2ee88d9598615160109200ec23f0499d732c16ae4550
Deleted: sha256:649116968a4e2361a2993b26adee68c9ddbf1674eb1bd4fc65442cba32704ae2
Deleted: sha256:e106ceb1c7192a71ae8d1de2c9ce39375475b78fb3a36677fb56d3b59af2413f
Deleted: sha256:fd8b725cfcc1ec98bd6113d5025a89582158be11e750b5ee0cc88f4470541f60
Untagged: node-app:0.1
Deleted: sha256:ca4185598a8225685a94bb5c300fd016f18042f4cbff437aa1d47302c020b395
Deleted: sha256:3f8c6e60fe6321303491e0aff8b2664efcee992faa23708112d3da9f8c597450
Deleted: sha256:bbc5bff04ff7f3ef7c73801547c5e341581cc81c86ef9b07643b7db44d64130d
Deleted: sha256:f8cbaf5d0b229ae2aca6a8d5d4d840da1a8744f992ad93e09e7acf32409cc6c4
Deleted: sha256:7cadfaf3f19825cb0b691b5b07c33e9f1d2a70b582b5d582809673f59b11a50c
Deleted: sha256:ea7290bcdfe95519fa0bc56

Confirm all images are removed with `docker images`.

In [46]:
!docker images

REPOSITORY                     TAG       IMAGE ID       CREATED        SIZE
gcr.io/inverting-proxy/agent   <none>    fe507176d0e6   2 months ago   1.73GB


At this point you should have a pseudo-fresh environment. Now, pull the image and run it.

#### %%bash
docker pull gcr.io/${PROJECT_ID}/node-app:0.2
docker run -p 4000:80 -d gcr.io/${PROJECT_ID}/node-app:0.2

You can check that it's running as expected using before:

In [49]:
!curl http://localhost:4000

Hello Baby!


Copyright 2020 Google LLC Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at https://www.apache.org/licenses/LICENSE-2.0 Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.