Infrastructure & Operations › Containers
Dockerfile
The recipe for building an image.
Also known as: Dockerfile instructions, docker build
A Dockerfile is a text file of instructions that docker build follows to create an image. Each instruction adds a layer.
FROM python:3.12-slim # start from a base image
WORKDIR /app # set the working directory
COPY requirements.txt . # copy only the dependency list first
RUN pip install --no-cache-dir -r requirements.txt
COPY . . # then copy the rest of the code
EXPOSE 8000 # documents the port; doesn't publish it
CMD ["python", "-m", "myapp"] # default command when the container starts
docker build -t myapp:1.0 . # build from the Dockerfile in this folder
docker run --rm -p 8000:8000 myapp:1.0
The main instructions: FROM (base image), COPY (add files), RUN (run a command while building), ENV (set variables), CMD and ENTRYPOINT (what runs at start; see entrypoint vs CMD).
The classic mistake: bad ordering
Docker caches each layer and reuses it if nothing above it changed. If you COPY . . before installing dependencies, every code edit invalidates the cache and reinstalls everything. Copying the dependency file first, installing, then copying the code keeps rebuilds fast.
Other habits
- Pin the base image version (
python:3.12-slim, notlatest) for repeatable builds. - Keep secrets out. Anything copied or set during the build stays in the image’s layers, even if you delete it in a later step.
- Use a
.dockerignorefile to leave out.git,node_modulesand local env files. - Don’t run as root. See non-root containers.
- Smaller images build, ship and start faster. See multi-stage builds and minimal base images.