Skip to main content
RunBook Academy

containers ยท automation ยท security

Docker & Containers for Production Sysadmins

A hands-on, fully visual course that takes a Linux sysadmin from "I can run docker run" to "I can take operational responsibility for a business-critical Docker environment." Covers the Docker daemon, containerd, runc, networking, storage, Compose, security, supply chain, observability, backup, disaster recovery, and incident response.

Who this is for

  • Linux systems administrators adding containers to their stack
  • Infrastructure / platform engineers running Docker in production
  • SREs and DevOps engineers responsible for Docker hosts
  • Security engineers reviewing container deployments

Prerequisites

  • Comfortable on the Linux command line
  • Familiar with systemd and basic networking (IP, DNS, TLS)

Other RunBook Academy courses

  • Linux โ€” recommended. Docker relies directly on Linux primitives (namespaces, cgroups, capabilities, OverlayFS). The RunBook Academy Linux course covers each one in production depth.

What you'll be able to do

After completing this course, you should be capable of independently:

  • Explain how Linux namespaces, cgroups, and OverlayFS combine to form a container
  • Install and operate a Docker host from repositories with version pinning
  • Build minimal, reproducible, signed images with BuildKit
  • Design Docker networking across bridge, host, macvlan, and ipvlan drivers
  • Operate Docker storage with volumes, bind mounts, and tmpfs safely
  • Use Docker Compose to model multi-service production stacks
  • Harden containers with capabilities, seccomp, AppArmor, user namespaces, and rootless Docker
  • Run a private registry with authentication, immutability, retention, and offsite backup
  • Monitor and observe Docker hosts with Prometheus, cAdvisor, Grafana, Loki, and OpenTelemetry
  • Implement tested backup, restore, and disaster recovery procedures
  • Design TLS termination with nginx, HAProxy, Traefik, or Caddy
  • Respond to container incidents under time pressure

Curriculum overview

40 planned parts ยท 237 lessons currently published.

Part I

Foundations

Containers vs VMs, OCI ecosystem, Docker architecture, Linux primitives.

6 lessons

Part II

Linux Internals

Namespaces, cgroups v2, OverlayFS, capabilities, the kernel features Docker relies on.

8 lessons

Part III

Installation & Daemon

Repositories, version pinning, Docker Engine, containerd, runc, systemd, daemon.json.

7 lessons

Part IV

Images

Layers, manifests, digests, tags, multi-platform, inspection, lifecycle.

6 lessons

Part V

Dockerfiles & BuildKit

Instructions, caching, multi-stage, secrets, reproducibility, minimal images.

8 lessons

Part VI

Container Lifecycle

run / create / start / stop / exec / signals / PID 1 / graceful shutdown.

6 lessons

Part VII

Networking

Namespaces, veth, bridge, host, macvlan, ipvlan, DNS, published ports.

8 lessons

Part VIII

Storage

Writable layers, volumes, bind mounts, tmpfs, UID/GID, network storage.

7 lessons

Part IX

Docker Compose

Services, networks, volumes, secrets, healthchecks, profiles, production patterns.

7 lessons

Part X

Production Architecture

Host design, reverse proxies, TLS, segmentation, capacity, operational boundaries.

6 lessons

Part XI

Container & Host Security

Capabilities, seccomp, AppArmor, rootless, no-new-privileges, Docker socket risk.

6 lessons

Part XII

Supply Chain

Image provenance, SBOM, CVEs, scanners, signing, Cosign.

6 lessons

Part XIII

Registries

Docker Hub, private registries, auth, digests, retention, backup.

6 lessons

Part XIV

Secrets

Build secrets, runtime secrets, external secret managers.

6 lessons

Part XV

Resource Controls

CPU, memory, swap, PIDs, I/O, OOM behaviour, noisy neighbours.

6 lessons

Part XVI

Performance

Storage drivers, image size, startup, eBPF, Linux perf tools.

6 lessons

Part XVII

Logging

Drivers, rotation, journald, syslog, Fluent Bit, Loki.

6 lessons

Part XVIII

Monitoring

Host, Docker, container, application metrics; Prometheus, cAdvisor, Grafana.

6 lessons

Part XIX

Observability

Metrics, logs, traces, OpenTelemetry, Tempo, end-to-end correlation.

6 lessons

Part XX

Health & Failure Detection

Healthchecks, restart policies, dependency failures.

6 lessons

Part XXI

Backup

Volumes, bind mounts, application-consistent backups, offsite copies, restore tests.

6 lessons

Part XXII

Disaster Recovery

RPO/RTO, destroyed-host recovery, restore, exercise cadence.

6 lessons

Part XXIII

High Availability

Standalone Docker limits, multi-host patterns, external load balancing, when orchestration is needed.

6 lessons

Part XXIV

Reverse Proxies & TLS

nginx, HAProxy, Traefik, Caddy, HTTP versions, WebSockets.

6 lessons

Part XXV

Certificates & PKI

TLS, ACME, automated renewal, failure modes.

6 lessons

Part XXVI

DNS & Service Discovery

Embedded DNS, troubleshooting.

6 lessons

Part XXVII

Firewalls

nftables, iptables, ufw, Docker port exposure, effective validation.

6 lessons

Part XXVIII

Maintenance

Disk consumption, prune, build cache, image cleanup.

6 lessons

Part XXIX

Docker Upgrades

Change review, backups, rollback, maintenance window.

6 lessons

Part XXX

Host Maintenance

Kernel updates, reboots, security patching, filesystem maintenance.

6 lessons

Part XXXI

Troubleshooting

Startup, networking, DNS, storage, OOM, TLS, daemon, logging, registry, dependencies.

6 lessons

Part XXXII

Docker Internals

dockerd, containerd, shim, runc, OCI runtime lifecycle.

6 lessons

Part XXXIII

Incident Response

Triage, evidence, containment, root cause, recovery, prevention.

6 lessons

Part XXXIV

Capacity Planning

CPU, memory, disk, network, growth, operational headroom.

6 lessons

Part XXXV

Production Hardening

Host, daemon, container, network, storage, image, secrets, monitoring, backup checklists.

6 lessons

Part XXXVI

Automation

Shell, systemd, Ansible, CI/CD concepts.

6 lessons

Part XXXVII

Orchestration Transition

Why orchestrators exist; Swarm, Kubernetes, Nomad at a glance.

6 lessons

Part XXXVIII

Capstone

A complete production Docker environment, end-to-end.

6 lessons

Part XXXIX

Break/Fix Scenarios

Deliberate operational incidents.

0 lessons

Part XL

Final Assessment

Production-readiness examination.

0 lessons

Verified against

  • Docker Enginev29.xยท released 2026-06ยท verified 2026-08-11
  • Docker Enginev28.xยท released 2025-04ยท verified 2026-08-08
  • Docker Composev2.xยท verified 2026-08-08
  • containerdv2.xยท verified 2026-08-08
  • runcv1.2.xยท verified 2026-08-08
  • BuildKitv0.20+ยท verified 2026-08-08
  • Linux kernelv5.15+ยท verified 2026-08-08
  • Ubuntuv24.04 LTSยท verified 2026-08-08
  • Debianv12 (Bookworm)ยท verified 2026-08-08