A container's writable layer is deleted with the container, so anything it writes is lost unless you store it elsewhere. Volumes keep data outside the container. Networks let containers talk to each other, and port mapping lets your browser reach a container.
Learning Objectives
- Keep data after a container is removed, using a named volume.
- Let two containers reach each other by name on a user-defined network.
- Map a container port to your computer and pass in configuration with environment variables.
Volumes: Data That Outlives the Container
The volume mydata still exists after db is removed, so its data survives and a new container can mount the same volume.
docker volume create mydata docker run -d --name db -v mydata:/var/lib/data nginx docker rm -f db docker volume ls
Networks: Containers Finding Each Other by Name
docker network create appnet docker run -d --name api --network appnet nginx docker run --rm --network appnet alpine wget -qO- http://api
Name-based lookup works on user-defined networks such as appnet. Containers on the default bridge network can only reach each other by IP address, unless you use the legacy --link option, which Docker considers legacy.
Ports and Environment Variables
| Option | Example | Meaning |
|---|---|---|
| -p host:container | -p 8080:80 | Your port 8080 forwards to the container's port 80 |
| -e NAME=value | -e APP_MODE=test | Sets an environment variable inside the container |
| -v name:path | -v mydata:/app/data | Mounts a volume at a path inside the container |
Learning Check
Why does removing a container not delete its named volume?
Volumes are stored separately from the container. Removing the container leaves the volume, so you have to remove it explicitly.
Why can't one container reach another by name on the default network?
Name resolution only works on user-defined networks. Create one with docker network create and attach both containers to it.
Step by Step: Prove Data Survives
- Create a volume: docker volume create notes-data.
- Start a container that writes to it, mounting the volume at /data.
- Remove the container with docker rm -f.
- Start a new container with the same volume and check that the data is still there.
Common Mistakes
Writing the mount path wrong
The path on the right of -v is inside the container. A typo there creates a new empty folder instead of the one the app uses.
Expecting name-based DNS on the default network
Create a user-defined network with docker network create and attach both containers to it.
Putting secrets directly in the command with -e
Values typed in -e stay in your shell history and in docker inspect. Use an env file or a secrets manager for real passwords.
Interview Questions
What is the difference between a volume and a bind mount?
A volume is managed by Docker and stored in its own location. A bind mount maps a specific folder from the host into the container.
Why doesn't EXPOSE let your browser reach a container?
EXPOSE only documents a port. You publish it with -p, which maps a host port to the container port.
When would you use the host network mode?
When the container must use the host's network stack directly, for example for performance-sensitive networking. It removes network isolation, so use it deliberately.
Summary
Volumes keep data beyond a container's life, user-defined networks let containers find each other by name, and -p and -e connect a container to your machine and its configuration.