Skip to main content

27 — Glossary

Read this first: the words that get used as though everyone already knows them. Use this from day one — it is not a reward for finishing. Each entry says what the thing is, not what it is for, and points at the lesson where you meet it.

Shell and Linux​

Shell — a program that reads a line of text, finds the program you named, and runs it with your arguments. bash is one. 01

Exit code — the number a program returns when it finishes. Zero is success; anything else is failure. This is how CI decides pass or fail. 01

stdout / stderr — two separate output streams. > redirects only the first; 2> the second; 2>&1 sends errors to wherever output is going. 01

Pipe (|) — connects one program's stdout to the next one's stdin. A pipeline reports only its last command's exit code unless pipefail is set. 01

Shebang — the #!/usr/bin/env bash on line 1 that says which interpreter runs the file. Must be the first line. 02

Word splitting — the shell chopping an unquoted variable at every space before the command sees it. The reason to quote every expansion. 02

errexit / nounset / pipefail — the three halves of set -euo pipefail: stop on failure, refuse unset variables, do not let a pipeline hide a failed stage. errexit is suspended inside if, &&, || and !. 03

Parameter expansion — cutting a string while expanding it: ${var#pattern} from the left, ${var%pattern} from the right, doubled is greedier. 04

Process substitution (< <(...)) — makes a command's output look like a file. Used instead of a pipe so a loop runs in the current shell and its variable assignments survive. 04

Subshell — a child shell. Anything on the right of a pipe runs in one, so variables set there are lost when it exits. 04

umask — the mask of permission bits removed from newly created files. umask 077 gives 600 files and 700 directories. 11

Daemon — a program that runs in the background with no terminal. dockerd is the Docker daemon.

systemd — the init system on most Linux distributions: starts services at boot, restarts them when they die, and collects their logs. Not present in containers.

Containers​

Image — a stack of read-only filesystem layers plus a default command. Built once, run many times. 05

Container — one running process using an image's filesystem, with its own view of the network and process list. Not a virtual machine — it shares your kernel. 05

Layer — the filesystem change produced by one Dockerfile instruction. Cached individually; invalidating one invalidates every layer after it. 06

Build context — the directory sent to the Docker daemon, named by the final argument to docker build. COPY can only see what is in it. 06

.dockerignore — what to exclude from the build context. Not optional. 06

Multi-stage build — several FROM lines in one Dockerfile, where a later stage copies artefacts out of an earlier one, leaving the build tools behind. 07

Exec form vs shell form — ENTRYPOINT ["java", "-jar", "x.jar"] makes your process PID 1; ENTRYPOINT java -jar x.jar makes /bin/sh PID 1 and your process never receives SIGTERM. 06

Volume — storage managed by Docker that outlives the container using it. The only thing that survives docker rm. 05

Healthcheck — a command Docker runs periodically to decide whether a container is healthy. What a deploy gate waits on. 08

start_period — a healthcheck's grace window; failures during it do not count against retries. 08

Compose project — a named group of services with its own lifecycle. Four of them share the production host. 25

Registry — where images live between being built and being run. GHCR is GitHub's. 16

Tag vs digest — a tag is a movable label (latest); a digest is the immutable sha256: hash of exact content. 16

CI/CD​

Runner — the temporary machine GitHub rents you to run a workflow. Destroyed afterwards. 15

Workflow — one YAML file in .github/workflows/. Job — steps sharing one runner; parallel by default. Step — one run: or uses:. 15

Action — a reusable step published by someone else, referenced with uses: owner/name@v4. Always pin the version. 16

Artifact — a file uploaded from one job so another job (or a human) can download it. How files cross job boundaries. 17

GITHUB_TOKEN — a credential minted for each run and expiring with it. What it may do is set by permissions:, and declaring that block zeroes every unlisted scope. 16

Environment — a named GitHub setting that is also a secrets scope. A job that does not declare it reads its secrets as empty strings. 17

Concurrency group — keeps one run executing and at most one pending; a third arrival replaces the pending one rather than queueing. 17

Reusable workflow — a workflow declaring on: workflow_call, callable as a job by another. 17

Workflow command — a specially formatted log line such as ::error:: that GitHub surfaces in the run summary. 15

Health gate — the step where a deploy waits for the new version to report healthy, and rolls back if it does not. 18

Promote — deploy an existing tested image to production rather than rebuilding it. 20

Build once, deploy twice — the rule that production runs the same bytes staging proved, not a rebuild from the same commit. 20

Networking​

Reverse proxy — a server that receives every request and forwards it to whichever backend should handle it. Caddy is one; nginx is another. 25

Edge — the outermost component, the only one publishing ports. 25

Publishing a port (-p 8080:80) — mapping a host port to a container port. Host first. A service with no ports: is unreachable from outside its network. 05

0.0.0.0 vs 127.0.0.1 — listening on every interface versus loopback only. The whole exposure story in one column of ss -tlnp. 12

X-Forwarded-For — a header carrying the original client IP through proxies. Trustworthy only when the number of hops is guaranteed. 25

DOCKER-USER — the iptables chain evaluated before Docker's own accept rules, and the only place a firewall rule can win. It sees forwarded traffic in both directions. 13

ACME / Let's Encrypt — the protocol and the authority that issue TLS certificates automatically. Requires that the issuer can reach your server. 25

SSH keypair — a public key you distribute and a private key you never do. The server stores the public half in authorized_keys. 10

SSH tunnel (-L) — forwards a local port to a port on the remote host, which is how you reach a service bound to the server's loopback. 12

Across machines​

Bridge network — Docker's default network driver. Local to one daemon, which is why container names stop resolving the moment a service moves to another host. 29

Overlay network — a network that spans hosts, provided by an orchestrator (Swarm, Kubernetes). This repository has none; every network in it is a bridge. 29

Service discovery — backends registering themselves so the proxy learns about them, instead of being listed in a file. Traefik's Docker provider is one. 30

Private networking — a provider-supplied network between your own servers that never touches the public internet. The simplest way to connect a split stack. 29

Router / service / middleware — Traefik's three pieces: a rule that matches requests, the backends they go to, and anything applied in between. 30

Entrypoint — a port a proxy listens on. Traefik names them (web, websecure). 30

pg_hba.conf — PostgreSQL's own access list: who may connect, from where, and whether TLS is required. Independent of, and in addition to, the firewall. 29

sslmode=verify-full — a Postgres client setting that encrypts and verifies the server's identity. require only encrypts, which does not stop an impostor. 29

Session vs transaction pooling — how a connection pooler such as PgBouncer hands out connections. This application sets a per-connection session variable for tenant isolation, so transaction pooling would break it; only session pooling is safe here.

Horizontal vs vertical scaling — more machines versus a bigger machine. Vertical needs no code change; horizontal needs the shared-state work in scaling.md.

Data​

Migration — a versioned, forward-only change to a database schema. Flyway runs them at startup. Rollback restores code, not data — which is why migrations must always go forwards. 19

Dump — a portable text export of a database (pg_dump), as opposed to a copy of its raw storage.

The two most useful sentences here​

Zero is success; anything else is failure. Everything in CI is that one fact wearing costumes.

A container is a process, not a machine. Almost every wrong prediction about Docker comes from forgetting it.