<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title>Docker on Bill Glover</title>
		<link>https://old.bill.dev/tags/docker/</link>
		<description>Recent content in Docker on Bill Glover</description>
		<generator>Hugo</generator>
		<language>en-gb</language>
		
			<managingEditor>hello@bill.dev (Bill)</managingEditor>
		
		
			<webMaster>hello@bill.dev (Bill)</webMaster>
		
		
		
			<lastBuildDate>Sun, 28 Sep 2025 22:27:35 +0100</lastBuildDate>
		
			<atom:link href="https://old.bill.dev/tags/docker/index.xml" rel="self" type="application/rss+xml" />
			<item>
				<title>Dockerfile Revisited</title>
				<link>https://old.bill.dev/notes/2024-07-26_dockerfile-revisited/</link>
				<pubDate>Fri, 26 Jul 2024 16:08:00 +0100</pubDate><author>hello@bill.dev (Bill)</author>
				<guid>https://old.bill.dev/notes/2024-07-26_dockerfile-revisited/</guid>
				<description>&lt;p&gt;For years I&amp;rsquo;ve been building container images by using the &lt;code&gt;COPY&lt;/code&gt; command to bring files from my Docker context into the build container.&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-Dockerfile&#34; data-lang=&#34;Dockerfile&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;k&#34;&gt;FROM&lt;/span&gt;&lt;span class=&#34;w&#34;&gt; &lt;/span&gt;&lt;span class=&#34;s&#34;&gt;golang:1.22&lt;/span&gt;&lt;span class=&#34;w&#34;&gt; &lt;/span&gt;&lt;span class=&#34;k&#34;&gt;AS&lt;/span&gt;&lt;span class=&#34;w&#34;&gt; &lt;/span&gt;&lt;span class=&#34;s&#34;&gt;build&lt;/span&gt;&lt;span class=&#34;err&#34;&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;err&#34;&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;k&#34;&gt;WORKDIR&lt;/span&gt;&lt;span class=&#34;w&#34;&gt; &lt;/span&gt;&lt;span class=&#34;s&#34;&gt;/src/build&lt;/span&gt;&lt;span class=&#34;err&#34;&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;k&#34;&gt;COPY&lt;/span&gt; . .&lt;span class=&#34;err&#34;&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;err&#34;&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;k&#34;&gt;RUN&lt;/span&gt; go mod verify&lt;span class=&#34;err&#34;&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;k&#34;&gt;RUN&lt;/span&gt; &lt;span class=&#34;nv&#34;&gt;CGO_ENABLED&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;=&lt;/span&gt;&lt;span class=&#34;m&#34;&gt;0&lt;/span&gt; &lt;span class=&#34;nv&#34;&gt;GOOS&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;=&lt;/span&gt;linux &lt;span class=&#34;nv&#34;&gt;GOARCH&lt;/span&gt;&lt;span class=&#34;o&#34;&gt;=&lt;/span&gt;arm64 go build -o /app .&lt;span class=&#34;err&#34;&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;err&#34;&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;k&#34;&gt;FROM&lt;/span&gt;&lt;span class=&#34;w&#34;&gt; &lt;/span&gt;&lt;span class=&#34;s&#34;&gt;scratch&lt;/span&gt;&lt;span class=&#34;err&#34;&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;k&#34;&gt;COPY&lt;/span&gt; --from&lt;span class=&#34;o&#34;&gt;=&lt;/span&gt;build /app .&lt;span class=&#34;err&#34;&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;&lt;span class=&#34;k&#34;&gt;CMD&lt;/span&gt; &lt;span class=&#34;p&#34;&gt;[&lt;/span&gt;&lt;span class=&#34;s2&#34;&gt;&amp;#34;./app&amp;#34;&lt;/span&gt;&lt;span class=&#34;p&#34;&gt;]&lt;/span&gt;&lt;span class=&#34;err&#34;&gt;&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Today I came across the following section in the Docker &lt;a href=&#34;https://docs.docker.com/build/building/best-practices/#add-or-copy&#34;&gt;documentation&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;blockquote&gt;&#xA;&lt;p&gt;&amp;ldquo;You&amp;rsquo;ll mostly want to use COPY for copying files from one stage to another in a multi-stage build. If you need to add files from the build context to the container temporarily to execute a RUN instruction, you can often substitute the COPY instruction with a bind mount instead.&amp;rdquo;&lt;/p&gt;&#xA;&lt;/blockquote&gt;</description>
			</item>
			<item>
				<title>Docker Desktop (Mac) Unix Socket</title>
				<link>https://old.bill.dev/2024/04/13/docker-desktop-mac-unix-socket/</link>
				<pubDate>Sat, 13 Apr 2024 18:37:00 +0000</pubDate><author>hello@bill.dev (Bill)</author>
				<guid>https://old.bill.dev/2024/04/13/docker-desktop-mac-unix-socket/</guid>
				<description>&lt;p&gt;Two of the tools in my container toolkit stopped working at some point recently. To demonstrate the issue, I first make sure that I have an image pulled locally.&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;bg@Bills-MBP ~ % docker image ls&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;REPOSITORY   TAG       IMAGE ID       CREATED       SIZE&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;golang       1.22      824aa3c1d42c   10 days ago   830MB&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;demo         latest    cf12555b1219   10 days ago   830MB&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The first tool, Dive, started producing errors like this.&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;bg@Bills-MBP tmp % dive demo&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Image Source: docker://demo&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Fetching image... (this can take a while for large images)&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Handler not available locally. Trying to pull &amp;#39;demo&amp;#39;...&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Using default tag: latest&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Error response from daemon: pull access denied for demo, repository does not exist or may require &amp;#39;docker login&amp;#39;: denied: requested access to the resource is denied&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;cannot fetch image&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;exit status 1&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The image was present locally and the docker daemon definitely running. I logged out, logged in again and tried different accounts. When I first hit this error I assumed that this was an issue with Dive. The workaround I used was to export the image to a &lt;code&gt;.tar&lt;/code&gt; file and then use dive to browse the disk image. But then I hit this error with Trivy.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Docker and LetsEncrypt</title>
				<link>https://old.bill.dev/notes/docker-and-letsencrypt/</link>
				<pubDate>Thu, 20 Oct 2022 20:14:45 +0100</pubDate><author>hello@bill.dev (Bill)</author>
				<guid>https://old.bill.dev/notes/docker-and-letsencrypt/</guid>
				<description>&lt;p&gt;If you are running a private container registry and using a certificate provided by &lt;a href=&#34;https://letsencrypt.org/&#34;&gt;LetsEncrypt&lt;/a&gt;, make sure you are using &lt;code&gt;fullchain.pem&lt;/code&gt; and not &lt;code&gt;cert.pem&lt;/code&gt;. If you miss this, the Docker CLI will report that your certificate is signed by an unknown authority.&lt;/p&gt;&#xA;&lt;p&gt;I have an instance of &lt;a href=&#34;https://goharbor.io/&#34;&gt;Harbor&lt;/a&gt; running as a private container registry. The certificate used by this instance is provided by LetsEncrypt and yet the Docker CLI refused to let me log in.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Dive Through the Layers</title>
				<link>https://old.bill.dev/2020/02/28/dive-through-the-layers/</link>
				<pubDate>Fri, 28 Feb 2020 06:16:35 +0000</pubDate><author>hello@bill.dev (Bill)</author>
				<guid>https://old.bill.dev/2020/02/28/dive-through-the-layers/</guid>
				<description>&lt;h1 id=&#34;dive-through-the-layers&#34;&gt;Dive Through the Layers&lt;/h1&gt;&#xA;&lt;p&gt;I&amp;rsquo;ve been working with a container image for a Django application and was surprised to find that an image for a simple application was 1.2 GB. This was particularly jarring as, coming from the world of Go, I&amp;rsquo;m used to images that come in at under 20 MB.&lt;/p&gt;&#xA;&lt;p&gt;It&amp;rsquo;s not the size of the container image that&amp;rsquo;s the problem. Layer caching and re-use means that you are rarely transferring the full image around and that storage on disk is usually less than the sum of all your images. The worry I have with an image that is 1.2 GB is that everything that makes up that image needs to be maintained, patched, watched for security vulnerabilities, etc. 1.2 GB is a lot of software.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Docker Compose: Conditional Services</title>
				<link>https://old.bill.dev/2020/02/21/docker-compose-conditional-services/</link>
				<pubDate>Fri, 21 Feb 2020 06:16:35 +0000</pubDate><author>hello@bill.dev (Bill)</author>
				<guid>https://old.bill.dev/2020/02/21/docker-compose-conditional-services/</guid>
				<description>&lt;p&gt;I recently added a &lt;code&gt;docker-compose&lt;/code&gt; definition of services to make it easier for people to contribute to the new &lt;a href=&#34;https://codebuddies.org&#34;&gt;CodeBuddies&lt;/a&gt; back-end. This addresses some of the pain new contributors were feeling with setting up a local development environment. The CodeBuddies backend is an API built using the Django REST Framework. PostgreSQL provides the data store. Everything is fronted by an Nginx reverse proxy. This is often referred to as a &lt;a href=&#34;https://en.wikipedia.org/wiki/Multitier_architecture#Three-tier_architecture&#34;&gt;three-tier architecture&lt;/a&gt;.&lt;/p&gt;</description>
			</item>
	</channel>
</rss>
