Key idea
docker run starts a container from an image. Two flags connect it to the outside: -p opens a door from a port on your machine to a port inside the container, and -e hands the app a setting. Neither changes the image, so one image runs anywhere with different doors and settings.
The commands here are for reading; no need to run them. You'll run them for real in the Try it lesson, 3.3.3.
One command, read left to right
docker run -d --name hello-api -p 3000:8080 -e GREETING="Hello from a container" quay.io/computesphere/learn-sample-api:1.0.0
-druns it in the background and prints the new container's ID.--name hello-apigives it a name to use in later commands, instead of the ID.-p 3000:8080maps port 3000 on your machine to port 8080 in the container.-e GREETING=...sets an environment variable inside the container.- The last argument is the image. Every flag must come before it.
Anything after the image name is passed to the container as its command, not read as a flag.
Ports: your side, then the container's side
The app inside listens on 8080 and has no idea your machine exists. The container has its own network, so without -p, localhost on your laptop doesn't lead to the app at all.
-p 3000:8080 reads host:container. The right side must match where the app listens; the left side is any free port on your machine. So curl localhost:3000/hello reaches the app:
{"api_key_set":false,"message":"Hello from a container"}
Two containers can both listen on 8080 inside, as long as each gets its own host port.
Environment: settings at run time
Path 2 put configuration outside the code. Containers follow the same rule: the image holds the code, and -e gives each run its settings. This app reads GREETING and PORT, so you can move it too:
docker run -d --name moved -p 3001:9000 -e PORT=9000 quay.io/computesphere/learn-sample-api:1.0.0
Change PORT and the right side of -p changes with it. For more than a few variables, --env-file .env reads them from a file.
Ran these anyway? docker rm -f hello-api moved removes both, so the names are free for 3.3.3.
docker inspect prints every variable a container was started with, in plain text. Anyone who can run Docker commands on that machine can read them.
Check yourself