Ch. 13 · Docker

Docker Exposed Ports Versus Published Ports

Docker Exposed Ports Versus Published Ports. Learn the reasoning, a practical example, common mistakes and an interview exercise.

~2 min readintermediateupdated Oct 3, 2026

Expose documents intended ports; publishing maps a host port to a container port. Actual reachability also depends on listening addresses and network controls.

Before you start

You should understand the difference between an image, a running container and the host. Record where a file, process or network endpoint actually lives before diagnosing a problem. Commands illustrate local experiments; adapt image names and paths to a disposable development environment.

The practical goal is to reason through this situation: An app listening on all container interfaces can be published to a selected host interface. Read the walkthrough first, then try the interview exercise before opening its answer. The important part is explaining the decision and its consequences, rather than remembering a definition alone.

Step-by-step walkthrough

Step 1: Separate documentation from mapping

EXPOSE describes intended ports; publishing creates host-to-container reachability.

Step 2: Choose host interface

A local database can publish on loopback rather than every host interface.

Step 3: Verify application binding

The process must listen on the appropriate container interface.

Worked scenario

An app listening on all container interfaces can be published to a selected host interface.

docker run --rm -p 127.0.0.1:8080:80 nginx
Terminal

This illustrative command maps host loopback port 8080 to container port 80. Actual access still depends on the host environment and network controls; a port number in image metadata does not provide the same mapping.

Common mistake

Expose alone does not necessarily publish a port on the host.

Verify the behavior

Inspect host listening interfaces and test both intended local access and unintended remote reachability.

Interview exercise

Keep a development database local.

Answer and reasoning

Bind the published host port deliberately and verify which interfaces can reach it.

Continue learning

Compare the scenario with the Docker interview questions and test your understanding with the Docker MCQs. For terminology and implementation details, consult the reference material.

More in Docker

read ✓Docker · mid

Docker BuildKit and Cache Mounts

Speed up image builds with BuildKit cache mounts, multi-stage builds and dependency-first layer ordering.

~2 min readread →
read ✓Docker · mid

Docker Compose Profiles

Start only the services you need with Compose profiles, and keep the default set small for focused local development.

~2 min readread →
esc