Up to now you've run images other people built. This module is about building your own, and about building them well: fast to rebuild, small to ship, and hard to attack.
A Dockerfile is a text file of instructions describing how to build an image: the base image (FROM), the commands to run at build time (RUN), the files to copy in, and the command to start (CMD). Each instruction creates a layer, so layer caching matters: put steps that rarely change, like installing dependencies, before steps that change often, like copying source code, and rebuilds reuse the cache.
Image size and security go together. Smaller base images such as Alpine carry fewer packages, and multi-stage builds let you compile in one stage and ship only the result. That means faster builds and pulls and a smaller attack surface. Watch the lessons in order, then continue on to Container Registries.
A step-by-step beginner's guide to Dockerfiles and building efficient Docker images: the file that describes your base image, dependencies, files, and startup command.
A hands-on walkthrough of creating a Dockerfile, building an image from it, and running that image as a container.
A guide to shrinking Docker images from gigabytes down to megabytes, with practical Dockerfile changes you can apply to your own images.
How multi-stage builds keep the final image small: build in one stage with all the tools, then copy only the finished output into a lean final image.
Three more techniques for trimming image size, which helps builds, pulls, and deployments and leaves less in the image for attackers to use.