← All resources

What is Docker used for? A short answer, then ten creative uses.

A short answer to what Docker actually is, then ten uses past the obvious one — ranked by what they take off your week, each with its honest limit.

Most explanations of Docker start with shipping containers and end with a diagram of a whale. This one is shorter, and it starts from the question people actually ask: what is Docker used for? Docker is a way to package a piece of software together with everything it needs to run, so that it behaves the same on your laptop, on a colleague’s laptop and on a server. That is the whole idea, and its obvious use — packaging your own application for production — is covered by every tutorial there is. This article is about the other uses: the ones that turn a single command into a server, a sandbox, a time capsule or a second pair of hands. First, briefly, what Docker is. Then ten creative ways to use it, counted down from ten, which is genuinely just for fun, to one, the use we would keep if we could keep only one.

What is Docker, actually?

Three words do most of the work. An image is a read-only package: an application plus the exact libraries, runtime and settings it needs, frozen at one version. A container is a running copy of that image, isolated from everything else on the machine. And a Dockerfile is the short text recipe that builds the image, which means the environment is written down instead of remembered — anyone can rebuild it, and it comes out the same every time.

Images live in registries, of which Docker Hub is the largest, so most well-known software already comes packaged: a database, a web server, a mail catcher, a game server. Getting one running is a single command, and deleting it leaves nothing behind on the machine. Since 2015 the image format has been an open standard maintained by the Open Container Initiative, which is why the same image runs under Docker, under Podman or on a cloud provider’s own engine.

A container is not a virtual machine, and most of the confusion about Docker starts there. A virtual machine emulates a whole computer with its own operating system. A container shares the kernel of the machine it runs on and isolates only the process, its files and its network, using Linux features called namespaces and control groups. That is why a container starts in about a second rather than a minute, and why you can run dozens of them on a laptop — and, as number four explains, also why it is a weaker wall than people assume.

By now it is simply the default. In the 2025 Stack Overflow Developer Survey, 71.1% of respondents said they use Docker, up 17 points in a single year, the largest jump of any technology in the survey. The everyday side of it — containerising an app and building the pipeline that ships it — is what our Docker page describes. This article is about everything else.

How we ranked them

Creative is a cheap word, so we gave it a test. Every entry had to be something other than the standard use, and it had to take something real off somebody’s week: a subscription, a day of setup, a risky manual step, a job nobody wants to do.

The order runs from ten to one on how much that is worth to a small business or a small development team, not on how clever the trick is. Number ten is genuinely fun and saves nobody any money. Number one changes how a project is run.

Every entry gets the same three beats: what it replaces, roughly how it is done, and the honest limit — the point at which the idea stops working, or starts costing more than it saves.

10. A game server for the team, in one command

What it replaces: a rented game server, or an afternoon of somebody following a forum guide. The community-maintained itzg/minecraft-server image turns a Minecraft server into one command, with the version, the world and the player whitelist set as plain options. Valheim, Terraria and most other self-hostable games have images of the same kind.

It earns its place for a reason that has nothing to do with games. It is the cleanest demonstration of what Docker is for: a whole server, configured and running, then gone without a trace when the Friday tournament is over. If you want to understand the idea in one evening, this is the evening.

The honest limit: it saves nobody money that matters, and a game server open to the internet is a server open to the internet. Keep the whitelist on, keep the world on a named volume so that a restart does not delete it, and switch it off when nobody is playing.

9. Ad-blocking for the whole office network

What it replaces: installing an ad blocker in every browser on every device, and never quite managing it on the phones or on the smart TV in the meeting room. Pi-hole runs in a container on any small always-on machine — a Raspberry Pi is the classic — and answers the network’s DNS requests, quietly refusing the ones that go to advertising and tracking domains.

Every device that joins the network gets the benefit without installing anything. Pages load faster on a slow office connection, and the dashboard shows exactly which devices call home, and to whom. More than one business has used that dashboard to find out what a cheap security camera was really doing.

The honest limit: it becomes the thing the internet depends on. If the container stops and nothing else answers DNS, the whole office decides the internet is down. Give it a fallback, and expect the odd site to break because a domain it relies on is blocked — somebody has to own the allow-list.

8. A time capsule for software that no longer installs

What it replaces: keeping an ancient server alive because nobody dares to touch it. Official images of old runtimes stay on Docker Hub long after those runtimes stop being supported, so a site built on PHP 5.6 or a script that needs Node 8 can be brought back to life on a modern machine in minutes, running exactly as it did in 2016.

This is how you rescue a legacy project before a migration. Run the old site in a container, export its data properly, compare the new version against the old one side by side, and retire the old server knowing you can bring its behaviour back whenever something in the new one looks wrong. It is also how you open the files of a program whose vendor went out of business years ago.

The honest limit: it is life support, not a cure. An end-of-life runtime has known vulnerabilities that will never be patched, so a time capsule must never face the internet. Run it locally or on a closed network, for exactly as long as the migration takes. If the plan is to leave it running, that is the moment to read when to redesign your website instead.

7. A mailbox that catches every email your app sends

What it replaces: the test order confirmation that reached a real customer, and the developer’s own inbox full of password-reset emails. Mailpit runs as a container that pretends to be a mail server. Point the application at it during development, and every message it sends — receipts, notifications, newsletters — lands in a web inbox on your own machine instead of anywhere real.

That turns email into something you can actually review. You can check how the HTML renders, click the links, read the plain-text version and compare what the Romanian and German templates really say, all without a mailing list and without the risk of a test campaign reaching ten thousand people.

The honest limit: it tests the message, not its delivery. Whether real inboxes accept your email depends on SPF, DKIM, DMARC and your sender’s reputation, and none of that exists inside a mail catcher. Development should catch everything; production deserves its own test, with real mailboxes you own.

6. A robot that takes screenshots, makes PDFs and checks pages

What it replaces: somebody opening twenty pages every Monday to see whether they still look right, or a paid screenshot or PDF service billed per call. A container running headless Chrome — the official Playwright images are the usual starting point — can open any page, render it exactly as a browser would, and save it as an image or a PDF.

The uses pile up once it exists. Invoices and offers rendered to PDF from the same HTML the site already uses. Social share images generated from one template. A weekly screenshot of every key page, compared against last week’s, so that a broken layout is found by the robot rather than by a customer. A scheduled check that a supplier’s price page still says what it said.

The honest limit: Chrome is heavy. Each browser takes hundreds of megabytes of memory, a stuck page can hold one open forever, and a container that launches browsers without closing them will fill a small server by the end of the day. Cap the memory, set timeouts, and make sure every run closes what it opened. Scraping somebody else’s site also comes with terms of service and, in the EU, data-protection questions of its own.

5. A private AI model that never leaves the building

What it replaces: pasting client material into a cloud assistant and hoping the terms say what you think they say. Ollama publishes an official image that runs open-weight language models on your own hardware, and Docker’s own Model Runner does the same job behind an OpenAI-compatible API, so existing code can often be pointed at it unchanged. Add a web interface in a second container, and the office has its own chat assistant whose data never leaves the machine.

The best fit is narrow, repetitive work on material that should not leave the company: summarising internal documents, sorting incoming enquiries, pulling fields out of invoices, drafting a first reply. Connected to your own documents, it becomes the private version of the idea explained in RAG for business.

The honest limit is hardware, and it is not a small one. A model that fits on an ordinary office PC is noticeably weaker than the paid cloud assistants, and without a capable graphics card it is slow enough to test people’s patience. Using an NVIDIA card from inside a container also needs NVIDIA’s container toolkit on Linux. For general writing and reasoning, a business account with a no-training clause is usually the better trade; the local model wins where the data simply cannot leave.

4. A cage for AI agents and code you do not trust

What it replaces: letting an AI coding agent, a script from a forum or a freshly downloaded tool run with full access to your laptop — your SSH keys, your browser sessions, your client folders. Run it in a container instead, with only the one project folder mounted and no credentials inside, and the worst it can do is damage that folder.

This matters more in 2026 than it did a year ago, because more and more of the code running on developers’ machines is written or run by something that is not a person. Agents install packages, execute commands and follow instructions hidden in the files they read. We covered what that does to code in AI-generated code security, and what it does for attackers in how AI agents changed hacking. A container is the cheapest seatbelt against both.

The honest limit is the one from the first section: a container shares the host’s kernel, so it is a wall, not a vault. A kernel bug or a careless option — mounting the Docker socket, running a container as privileged — lets code out. Docker itself draws the line here: Docker Sandboxes, its product for coding agents, runs each agent in a microVM with its own kernel rather than in a plain container. For code you believe is hostile, use a virtual machine. For code you simply do not trust yet, a container with nothing worth stealing inside it is a big step up from nothing.

3. Three subscriptions replaced by one small server

What it replaces: a stack of monthly SaaS bills for tools that are, underneath, small web apps. Docker Compose describes several services in one short file and starts them all with one command, on a rented server that costs a few euros a month. The usual first set: n8n for automations, Uptime Kuma to watch your sites and alert you when one goes down, Umami or Plausible Community Edition for privacy-friendly analytics, and Vaultwarden as the team’s self-hosted password manager.

The appeal is not only the money. The data stays on infrastructure you control, which answers a GDPR question before anybody asks it, and nothing is priced per seat or per task, so adding a colleague or another workflow costs nothing. For automations in particular, Zapier vs Make vs n8n explains why self-hosted n8n is the only one of the four that keeps customer records on your own server — and our n8n Automation at €399 is installed with Docker for exactly that reason.

The honest limit is the one we repeat every time self-hosting comes up: free means no licence fee, not free. Somebody has to apply updates, take backups, test that the backups actually restore, and notice when a container has quietly stopped. A self-hosted password manager left unpatched is worse than a paid one. If nobody on the team will own that work, the subscriptions were cheaper than they looked — or the ownership becomes part of a Monthly Maintenance plan, from €299 a month.

2. A new developer’s laptop, ready before lunch

What it replaces: the first day of every new developer, or of every freelancer joining for a month, spent installing the right version of the language, the database, the extensions and the one tool the README forgot to mention. A dev container puts the whole development environment into an image described by a single devcontainer.json file inside the project. Open the project in an editor that supports the open Dev Containers specification — VS Code, the JetBrains IDEs, GitHub Codespaces — and it builds that environment and opens inside it.

The time saved on day one is the small part. The bigger part is that “it works on my machine” stops being a sentence anybody can say, because every machine is the same machine. Upgrading the database becomes one line in a file that everybody receives, not a message in the team chat that half the team misses. And a project picked up again after two years opens in exactly the environment it was left in.

The honest limit: on macOS and Windows, containers run inside a small Linux virtual machine, and projects with tens of thousands of small files — a large node_modules folder is the usual culprit — can be noticeably slower through the shared file system than natively. Check the licence too. Docker Desktop is free for personal use and for companies with fewer than 250 employees and less than $10 million in annual revenue; a company over either line needs a paid subscription for everyone who uses it. Docker Engine on Linux is open source and free for everyone.

1. A live preview of every change, for the client to click

What it replaces: the single shared staging server that is always half-broken because three changes are on it at once, and the client review that happens once, at the end, when every change is at its most expensive. With containers, every branch or pull request can start its own complete copy of the site — application, database, cache — at its own address, and remove it automatically when the change is merged.

It is number one because it moves the review to the moment a change is still cheap. A client who can click a link and see this one change today gives feedback on it today, not in week ten, on a staging site with everything mixed together. It fixes the pattern in how long a website project takes, where the client never opens staging until the end, and it closes the staging leak described in enterprise CMS migrations, because every preview is built from the same image that goes to production, with its settings decided in one place.

It is also the use where every other benefit on this list arrives at once. The environment is written down in a file, so a preview matches production. The preview is disposable, so trying a risky migration on it costs nothing. And because the machine does the setup, the tenth preview of the week takes no more effort than the first.

The honest limits are data and cost. A preview needs a database, and the tempting shortcut — a copy of production with real customer data in it — is a GDPR problem sitting at a public address. Use seeded, anonymised data, and keep previews behind a password and out of search engines. Previews also use server resources for as long as they exist, so automatic teardown is not optional: a forgotten preview is a small server bill that grows every week. Setting it up is pipeline work, done once per project. After that, the machine does it.

Five we left off, and why

Docker for a simple brochure website. A five-page site with a contact form does not need a container, a registry and a pipeline; it needs good hosting. Docker earns its place once there are several services, a team to keep in sync, or deploys that must be repeatable. Our own Docker page says exactly that, and we would rather lose the project than sell complexity.

Kubernetes for three containers. Kubernetes solves the problems of running hundreds of containers across many machines, and brings the operational weight to match. For a handful of services on one or two servers, Docker Compose does the job with a fraction of the moving parts. Move up when the problem actually arrives, not when a conference talk says it will.

Any image, from anyone, because it was the first search result. Docker Hub is open to everybody, attackers included: in 2024, JFrog’s researchers found that almost 20% of public Docker Hub repositories — close to three million — had been set up to spread malware or phishing, and Docker removed them. Prefer official and verified-publisher images, pin exact versions, and read what an image does before you run it.

The production database in a container that nobody backs up. Running a database in Docker is fine, and common. Running it without a named volume, without backups and without a tested restore is how a “docker compose down -v” typed in the wrong folder deletes a year of orders. The container is disposable by design; the data inside it must not be.

Treating a container as a malware lab. It follows from number four: a container is good enough for code you do not trust yet, and not good enough for code you know is hostile. Opening a suspicious attachment “safely, in Docker” is a false sense of safety. That job belongs in a virtual machine with no network, on a computer that holds nothing you care about.

What it all costs

Less than any other list we have written. Docker Engine, the part that actually runs containers, is open source and free on Linux, and every image named in this article is free to use. The costs sit elsewhere.

The first is the Docker Desktop licence, which applies only on Mac and Windows desktops and only to companies with 250 or more employees or $10 million or more in annual revenue. Below both lines it is free. Over either one, every user needs a paid subscription — check Docker’s own pricing page for the current figure rather than trusting a number copied into an article.

The second is a server, for anything that has to stay running: a small virtual server with enough memory for a handful of containers costs a few euros a month in Europe. The third, and the only large one, is somebody’s time — to set things up, and then to keep them patched and backed up. That line is where every self-hosting plan is really decided, so decide it on purpose.

If you only try one

Try number ten, tonight, even if you never play the game. It takes ten minutes, costs nothing, and teaches the idea behind every other entry better than any tutorial: a whole server that starts with one command and disappears without a trace.

After that, if you run a business, do number three. If you build software for one, do number one. Those are the two uses on this list whose payoff grows every month they stay in place.

And if you would rather somebody else built the pipeline behind number one, or moved an existing app into containers without a rewrite, that is our Docker work. Tell us what runs where today, and we will tell you honestly whether containers would help — including when the answer is that your site does not need them.

Sources

Every product and licence claim above comes from the project’s or vendor’s own public pages, checked in September 2026. Licence terms and product names move, so confirm before you commit.

  • Docker Docs — Docker overview ↗

    Defines an image as a read-only template with instructions for creating a container, and a container as a runnable instance of an image. Docker uses Linux namespaces to give each container an isolated workspace, and is written in Go.

  • Open Container Initiative ↗

    The Linux Foundation project, formed in 2015, that maintains the open image, runtime and distribution specifications — the reason one image runs under Docker, Podman and cloud container engines alike.

  • Stack Overflow — 2025 Developer Survey, Technology ↗

    Docker used by 71.1% of respondents in 2025, up 17 percentage points from 54% in 2024 — the largest single-year increase of any technology in the survey.

  • Docker — pricing FAQ ↗

    Docker Desktop is free under Docker Personal for companies with fewer than 250 employees and less than US$10 million in annual revenue; all other organisations, and government entities regardless of size, need a paid subscription.

  • Docker Docs — Engine security ↗

    Containers rely on kernel namespaces and control groups for isolation and share the host kernel; access to the Docker daemon is effectively root access to the host, which is why mounting the Docker socket into a container defeats the isolation.

  • Docker Docs — Docker Sandboxes ↗

    Runs coding agents such as Claude Code and Codex in a microVM with its own kernel and a private Docker Engine, with the files, network endpoints and secrets the agent may reach defined explicitly — isolation beyond what a plain container provides.

  • Docker Docs — Docker Model Runner ↗

    Pulls models from Docker Hub, OCI registries or Hugging Face and serves them locally through OpenAI- and Ollama-compatible APIs.

  • Ollama — official Docker image ↗

    The official image for running open-weight models locally; GPU acceleration on NVIDIA cards requires the NVIDIA Container Toolkit on the host.

  • Development Containers specification ↗

    The open specification behind devcontainer.json, supported by VS Code, JetBrains IDEs and GitHub Codespaces, for describing a full development environment as a container.

  • Mailpit ↗

    An email testing tool that acts as an SMTP server with a web interface for viewing captured messages, distributed as the axllent/mailpit multi-architecture Docker image.

  • Pi-hole — Docker image ↗

    The official container for Pi-hole, a network-wide DNS sinkhole that blocks advertising and tracking domains for every device that uses it as its DNS server.

  • itzg/docker-minecraft-server ↗

    A widely used community image that runs a Minecraft server configured entirely through environment variables, including version, world settings and player whitelist.

  • Playwright — Docker ↗

    Official Playwright images with the browsers and system dependencies preinstalled, used for headless screenshots, PDF generation and automated browser tests.

  • JFrog Security Research — malicious repositories on Docker Hub ↗

    April 2024: of roughly 4.6 million imageless Docker Hub repositories, about 2.81 million were linked to three malware and phishing campaigns — close to 20% of all public repositories. Docker removed them before publication.

Frequently asked questions

Wondering whether containers would help your project?

Tell us what runs where today — we will tell you honestly whether Docker would help, and build it if it does.