Docker Command Generator
Pick what you want to do and fill in a few fields to get a correct Docker command, with each option on its own line so it is easy to read and edit. docker run commands come with the matching compose.yaml service, build commands handle build arguments and multi-platform images, and cleanup commands explain exactly what they delete.
- Runs in your browser
- No sign-up
- Free to use
How to use Docker Command Generator
- Choose run, build, exec, logs or cleanup.
- Fill in the image, ports, volumes and options.
- Read the notes about security and data.
- Copy the command, or the compose.yaml version.
Docker Command Generator features
docker run
Ports, bind mounts and named volumes, environment, restart policy, limits.
Hardening
Drop capabilities, no-new-privileges, read-only root file system.
Compose equivalent
The same container as a compose.yaml service.
docker build
Tags, targets, build arguments, buildx multi-platform and push.
exec and logs
Interactive shells, users, tail, since and follow.
Safe cleanup
Prune commands with warnings about volumes and images.
When to use Docker Command Generator
- Starting a database or web server container for development.
- Turning a long docker run command into a compose file.
- Building images for both Intel and ARM machines.
- Freeing disk space without deleting important data.
Docker Command Generator FAQ
What is the difference between a bind mount and a named volume?
A bind mount (./data:/data) maps a folder on your machine into the container; a named volume (pgdata:/var/lib/…) is storage managed by Docker that survives when the container is removed.
Why publish a database on 127.0.0.1?
A plain -p 5432:5432 opens the port on every network interface. 127.0.0.1:5432:5432 lets only programs on your own machine connect.
What does dropping capabilities do?
Containers get a set of Linux capabilities by default. --cap-drop ALL removes them, so a compromised process can do much less.
Is docker system prune safe?
It removes stopped containers, unused networks and dangling images. With -a it also removes unused images, and with --volumes it deletes data, which is why the tool warns about volumes.
Why are passwords in -e flagged?
They end up in shell history and are visible with docker inspect. Use --env-file or Docker secrets.
Is anything executed?
No. The command is generated in your browser for you to run.
Writing Docker commands correctly
The Docker command line is powerful but dense. A realistic docker run command combines ports, volumes, environment variables, a restart policy, resource limits and security options, and a single misplaced colon publishes a port to the whole network or mounts the wrong folder. Generating the command from labelled fields avoids those mistakes and keeps each option on its own line.
For docker run, ports are validated and can be bound to 127.0.0.1 so databases are not exposed, volumes distinguish bind mounts from named volumes, and environment variables are quoted for the shell. Memory and CPU limits stop a container from starving the host, and the hardening option drops Linux capabilities and blocks privilege escalation.
Compose files are the better long-term home for container settings, so every docker run command is also translated into an equivalent compose.yaml service, including named volumes, limits and security options. Start with the command to try something, then keep the compose version.
docker build commands cover tags, targets of multi-stage Dockerfiles, build arguments and multi-platform builds with buildx, which produce images for both amd64 and arm64 machines and push them directly to a registry. Build arguments that look like secrets are flagged, because they are stored in the image history.
Cleanup commands show docker system df first, so you can see what uses space, and explain the difference between dangling and unused images and why pruning volumes deletes data.