You need Docker running (set up in lesson 3.1.1), Git, and a terminal. You don't need Node, Python or Go installed: the build stage brings its own.
Pick one of the three samples, ideally not the language you know best, and close the recipe tabs. You'll work from the app's README and the checklist in your head. The hints are there if you get stuck.
Get the samples
git clone https://github.com/computesphere-samples/learn.git cd learn/labs ls -d containerize-*Already cloned it? Run
git pullinlearninstead. Thencdinto the sample you picked.You should seeThree folders: containerize-go, containerize-node, containerize-python.
Read the README
Before writing anything, find three facts: which port it listens on, where its health endpoint is, and how it's started. Every Dockerfile choice follows from them.
You should seeYou can name the app's port, its health path and the command that starts it.
Write the .dockerignore
List what must never reach the build:
.git, any.envfile, and whatever your machine builds locally (installed packages, a virtual environment, a compiled binary).You should seeA .dockerignore next to the app's files.
Write the Dockerfile
Two stages. The first installs dependencies or compiles. The second copies in only what the app needs to run, switches to a non-root user, sets
PORT, and starts the app.You should seeA Dockerfile with two FROM lines and a USER line.
Build it
docker build -t containerize-<language>:1.0.0 .A failed step prints the command that failed and its error. Fix the Dockerfile and build again; the steps before it come from the cache.
You should seeThe build finishes and names your image, such as containerize-go:1.0.0.
Run it and call /healthz
docker run -d --rm --name my-app -p 3000:3000 containerize-<language>:1.0.0 curl -i localhost:3000/healthzCheck yourself
You should seeHTTP/1.1 200 OK and {"status":"ok"}.
Review it like a teammate would
docker image inspect containerize-<language>:1.0.0 --format '{{.Config.User}}' docker image ls containerize-<language> docker stop my-appCompare with the recipe now: about 15 MB for Go, a little over 200 MB for Node and Python. Keep your folder and Dockerfile: the lab rebuilds the image for ComputeSphere and deploys it.
You should seeA user that isn't root or empty, and a size you can explain.
Hints, by language
- Node:
node:22-slimto runnpm ci --omit=dev, thengcr.io/distroless/nodejs22-debian12:nonroot. Copynode_modulesandserver.js;CMD ["server.js"]. The README saysnpm start, but distroless has no npm: it already runsnode, soCMD ["server.js"]meansnode server.js, andCMD ["npm", "start"]fails with Cannot find module '/app/npm'. - Python:
python:3.13-slimfor both stages. Install into a virtual environment in/opt/venv, copy it across, add a user withuseradd, and start gunicorn bound to0.0.0.0:${PORT}. - Go:
golang:1.27-alpineto build withCGO_ENABLED=0, thengcr.io/distroless/static-debian12:nonrootwith only the binary.
If it doesn't work
- The container exits at once: run it without
--rm, thendocker logs my-app. A missing file means the runtime stage didn't copy it. - Permission denied: the non-root user can't read or write a path. Distroless images have no shell, so fix it in the build stage or with
COPY --chown. - Port already in use: something else has 3000 on your machine. Use
-p 3001:3000and curl port 3001.