Published: October 5, 2026 · 8 min read
Docker Commands Cheat Sheet — Remember Every Command Easily
You know why Docker exists and you can read every Dockerfile instruction — now it's time to actually drive. This Docker commands cheat sheet covers the essential commands you'll type while learning Docker, organized the easy-to-remember way: not as a flat list, but as one image's journey from docker build all the way to docker push. Learn the journey once, and every command has a fixed place in the story.
In this cheat sheet, you will:
- See the big picture: build → images → run → ps → stop → rm → rmi → prune
- Decode
docker build -t username/project:label .piece by piece - Understand
-p host-port:container-portand why your side always comes first - Never confuse
rmvsrmiagain (one letter = one rule) - Clean your disk with
docker system prune -a - Share your image with the world:
login→push→logout - Keep builds fast and secrets safe with
.dockerignore - Pick up the three Linux commands (
pwd,ls -l,mkdir) that Docker work depends on

The Big Picture — One Image's Journey
Don't memorize commands as a list. Memorize one story — every command is a step in it:
Memory hook: build (cook) → images (check) → run (play) → ps (watch) → stop (pause) → rm/rmi (throw away) → prune (clean the kitchen). When you forget a command, find its place in the story.
docker build — Create the Image
This is the command with the most "mystery symbols", so let's decode every piece:
docker images and docker rmi — See and Remove Images
docker run -p — Start a Container with Port Mapping
The image exists — now run it. The -p flag is the part everyone gets backwards at first:
-p host:container — your machine's port always comes first. -p 8080:3000 means "I visit localhost:8080, the app inside listens on 3000." Remember: EXPOSE in the Dockerfile only documents the port — -p is what actually connects it.

docker ps — What's Running?
docker stop and docker rm — Stop, Then Remove
rm vs rmi — One Letter, One Rule
The most common beginner mix-up, solved forever:
docker system prune -a — Clean Everything Unused
After a week of practice your disk fills up with stopped containers and old images. One command cleans it all:
prune -a deletes all unused images — including ones you built yesterday but aren't running right now. You'll have to docker build them again. Fine while learning; pause and think before running it on a real server.
login → push → logout — Share Your Image
Docker Hub (opens in a new tab) is like GitHub, but for images. Three commands move your image from your laptop to the world:

.dockerignore — What NOT to Send to Docker
The Linux Commands You'll Need Alongside
Containers are Linux inside, so three tiny Linux commands keep showing up in Docker work:
A Complete Session — Everything in Order
Here's every command from this page in the exact order a real session uses them:
Docker Commands Quick Reference Table
Bookmark this table — it's the whole page in twelve rows. Every flag and option beyond these lives in the official Docker CLI reference (opens in a new tab), but you won't need it for a long while.
| I want to... | Command |
|---|---|
| Build an image | docker build -t username/project:label . |
| List my images | docker images |
| Run a container with a port | docker run -p 3000:3000 image-name |
| See running containers | docker ps |
| See ALL containers (stopped too) | docker ps -a |
| Stop a container | docker stop container-id |
| Remove a container | docker rm container-id |
| Remove an image | docker rmi image-id |
| Clean up everything unused | docker system prune -a |
| Log in to Docker Hub | docker login |
| Upload my image | docker push username/project:label |
| Log out | docker logout |
What's Next
You can now take an image through its full life: build it (docker build -t), check it (docker images), run it with a reachable port (docker run -p), watch it (docker ps / ps -a), stop and remove it (stop, rm, rmi), clean up after practice (system prune -a), and publish it to Docker Hub (login → push → logout) — with .dockerignore keeping your builds small and your secrets out of the image. These commands plus the 13 Dockerfile instructions are the complete toolkit for everything that comes next in the series.
← Back to Dockerfile Instructions Explained
Continue to Install Docker on AWS EC2 →
Frequently Asked Questions
What is the difference between docker rm and docker rmi?
One letter changes the target: docker rm removes a container, docker rmi removes an image — the i at the end of rmi stands for image. The cleanup order is always: docker stop the running container, docker rm the stopped container, then docker rmi the image. Docker refuses to delete an image while any container — even a stopped one — was created from it, which is why rm must come before rmi.
What is the difference between docker ps and docker ps -a?
docker ps shows only containers that are currently running. docker ps -a (the -a means All) shows every container, including stopped ones. This matters because a stopped container disappears from plain docker ps but still exists and still occupies disk space — docker ps -a is how you find its CONTAINER ID so you can delete it with docker rm.
What does -p 3000:3000 mean in docker run?
-p maps a port on your machine (the host) to a port inside the container, in the order host-port:container-port — your side always comes first. docker run -p 3000:3000 my-image means requests to http://localhost:3000 on your machine reach the app listening on port 3000 inside the container. The two can differ: -p 8080:3000 keeps the app on 3000 inside while you reach it at http://localhost:8080. Without -p, the container runs but no port on your machine reaches it.
What does the -t flag and the dot mean in docker build?
In docker build -t username/project_name:label ., the -t flag means Tag — it gives the image a human-readable name instead of a random ID. The name has three parts: your Docker Hub username (so docker push knows whose account receives the image), the project name, and a label such as v1 or latest for versioning. The dot at the end is the build context: it tells Docker the Dockerfile and the files to copy are in this folder.
What does docker system prune -a remove?
docker system prune -a removes unused Docker resources in one command: all stopped containers, all unused networks, and all unused images. Docker asks for confirmation before deleting anything. Use it when your disk fills up after days of practice builds — old experiments, stopped containers, and forgotten images all disappear at once. Anything currently in use by a running container is kept.
How do I push a Docker image to Docker Hub?
Three steps: docker login (enter your Docker Hub username and password), docker push username/project_name:label (uploads the image), and docker logout when you are done. The image must be named with your username prefix — that is why docker build -t starts with username/ — because Docker Hub uses it to know whose account receives the push. Once pushed, anyone can pull and run your app on any machine, which is the whole point of Docker: the image travels, and it works the same everywhere.
What is a .dockerignore file and why do I need it?
.dockerignore lists files and folders that should not be sent to Docker during docker build — the same idea as .gitignore, but for the build context. The classic entries are node_modules (huge, and rebuilt inside the image anyway by RUN npm install), .git, .env (so secrets never get baked into the image), and log files. The result is smaller images, faster builds, and no leaked credentials.