Docker and Podman Cheatsheet
Common Docker and Podman commands for opening a shell in a container, reading logs, updating images, and cleaning up.
On this page
Short recipes for everyday container work. Podman accepts the same commands, so you can replace docker with podman in any example below.
List Containers
Show running containers, or add -a to include stopped ones:
docker ps
docker ps -aOpen a Shell in a Running Container
Start an interactive shell inside an existing container by name or ID:
docker exec -it <CONTAINER> bashMinimal images (Alpine, distroless, BusyBox) often have no bash, so fall back to sh. Add --user root if the image runs as an unprivileged user and you need to install tools:
docker exec -it --user root <CONTAINER> shFollow a Container's Logs
Stream the last 100 lines of output and keep following:
docker logs -f --tail 100 <CONTAINER>Copy Files In or Out
Copy a file between the host and a container (running or stopped):
docker cp <CONTAINER>:/path/in/container ./local-copy
docker cp ./local-file <CONTAINER>:/path/in/containerPull the Latest Version of Every Local Image
Re-pull every tagged image on the host:
docker images --format '{{.Repository}}:{{.Tag}}' | grep -v '<none>' | while read -r image; do
docker pull "$image"
doneNote
Pulling a newer image doesn't change containers that are already running. Recreate them to pick up the update, as shown in the next section.
Update a Compose Stack
Pull new images and recreate only the containers whose image changed:
docker compose pull
docker compose up -dUpdate Podman Containers Automatically
Podman can update containers that run as systemd services (Quadlet units or podman generate systemd). Label the container with io.containers.autoupdate=registry, then check for or apply updates:
podman auto-update --dry-run
podman auto-updateEnable podman-auto-update.timer to run this daily.
Clean Up Unused Images and Containers
Remove dangling images left behind by updates, or everything not used by a container:
docker image prune
docker system pruneWarning
docker system prune -a --volumes also deletes every unused image and every volume not attached to a container, including data volumes for stopped stacks. Check docker volume ls before using --volumes.
Sources
This article is in the public domain (CC0 1.0), code samples included. Use it however helps you.