DevLearningTools

LEARN · DOCKER

Volumes, Networks, and Ports

Containers lose their data when removed, so volumes keep it. Networks let containers reach each other by name, and port mapping and environment variables connect containers to the outside world.

A container's writable layer is deleted with the container, so anything it writes is lost unless you store it elsewhere. Volumes keep data outside the container. Networks let containers talk to each other, and port mapping lets your browser reach a container.

Learning Objectives

  • Keep data after a container is removed, using a named volume.
  • Let two containers reach each other by name on a user-defined network.
  • Map a container port to your computer and pass in configuration with environment variables.

Volumes: Data That Outlives the Container

The volume mydata still exists after db is removed, so its data survives and a new container can mount the same volume.

Shell
docker volume create mydata
docker run -d --name db -v mydata:/var/lib/data nginx
docker rm -f db
docker volume ls

Networks: Containers Finding Each Other by Name

Shell
docker network create appnet
docker run -d --name api --network appnet nginx
docker run --rm --network appnet alpine wget -qO- http://api
NOTE

Name-based lookup works on user-defined networks such as appnet. Containers on the default bridge network can only reach each other by IP address, unless you use the legacy --link option, which Docker considers legacy.

Ports and Environment Variables

OptionExampleMeaning
-p host:container-p 8080:80Your port 8080 forwards to the container's port 80
-e NAME=value-e APP_MODE=testSets an environment variable inside the container
-v name:path-v mydata:/app/dataMounts a volume at a path inside the container

Learning Check

Why does removing a container not delete its named volume?

Volumes are stored separately from the container. Removing the container leaves the volume, so you have to remove it explicitly.

Why can't one container reach another by name on the default network?

Name resolution only works on user-defined networks. Create one with docker network create and attach both containers to it.

Step by Step: Prove Data Survives

  • Create a volume: docker volume create notes-data.
  • Start a container that writes to it, mounting the volume at /data.
  • Remove the container with docker rm -f.
  • Start a new container with the same volume and check that the data is still there.

Common Mistakes

Writing the mount path wrong

The path on the right of -v is inside the container. A typo there creates a new empty folder instead of the one the app uses.

Expecting name-based DNS on the default network

Create a user-defined network with docker network create and attach both containers to it.

Putting secrets directly in the command with -e

Values typed in -e stay in your shell history and in docker inspect. Use an env file or a secrets manager for real passwords.

Interview Questions

What is the difference between a volume and a bind mount?

A volume is managed by Docker and stored in its own location. A bind mount maps a specific folder from the host into the container.

Why doesn't EXPOSE let your browser reach a container?

EXPOSE only documents a port. You publish it with -p, which maps a host port to the container port.

When would you use the host network mode?

When the container must use the host's network stack directly, for example for performance-sensitive networking. It removes network isolation, so use it deliberately.

Summary

Volumes keep data beyond a container's life, user-defined networks let containers find each other by name, and -p and -e connect a container to your machine and its configuration.