Blog · Tutorial

How to deploy a Docker container.

To deploy a Docker container, write a production Dockerfile, build the image, and run it on a host that restarts it and puts HTTPS in front. This guide covers the Dockerfile rules that matter, then the host options.

Published Sep 24, 2026Updated Sep 25, 20263 min read

key takeaways
  • Small base image, non-root user
  • Never copy .env into the image
  • Listen on 0.0.0.0 and $PORT
  • A platform removes the server and TLS work
tl;drrunex

Dockerfile

What makes a Dockerfile production-ready?

Small, cached, non-root, and secret-free. Runex builds images the same way when you host a Docker container from GitHub.

Dockerfile
FROM node:22-alpine              # small base
WORKDIR /app
COPY package*.json ./
RUN npm ci --omit=dev            # cached layer
COPY . .
USER node                        # non-root
CMD ["node", "server.js"]        # 0.0.0.0:$PORT
Dockerfilerunex

Copy dependency files before the source so Docker reuses the install layer when only code changes.

Rules

What are the Dockerfile best practices for production?

Six rules that prevent most container problems.

  • Use a minimal base image such as -alpine, -slim, or distroless
  • Add a .dockerignore for node_modules, .git, and .env
  • Run as a non-root user
  • Pass secrets as environment variables at runtime, never in the image
  • Bind the server to 0.0.0.0
  • Use multi-stage builds to leave compilers out of the final image

Compare

Where can you run a Docker container in production?

Three options, from most to least work. For the trade-offs between a managed platform and your own server, read PaaS vs VPS.

Where can you run a Docker container in production?
Runex, Render, RailwayContainer platformYour serverVPS + DockerClusterKubernetes
SetupConnect repoInstall Docker, proxy, TLSCreate and run a cluster
HTTPSAutomaticManualIngress + cert-manager
ScalingBuilt inManualPowerful, complex
Best forMost appsFull controlLarge platform teams

On Runex

How do you deploy a Docker container on Runex?

Commit the Dockerfile and push. If the container starts but the URL doesn't load, check the port configuration.

  1. You

    Add a Dockerfile

    At the repo root.

  2. You

    Connect the repo

    Install the Runex GitHub App.

  3. Runex

    Build the image

    On every push.

  4. Runex

    Run with HTTPS

    Isolated container, live URL.

FAQ

Frequently asked questions

Short answers to related searches.

Do I need Kubernetes to deploy a Docker container?

No. A container platform or a single server with Docker runs containers without Kubernetes. Kubernetes helps mainly at large scale.

What is a .dockerignore file?

A list of files Docker leaves out of the build context, such as node_modules, .git, and .env. It speeds up builds and keeps secrets out of images.

What is a multi-stage Docker build?

A Dockerfile with several FROM stages. You compile in one stage and copy only the output into a small final image.

Why can't I reach my container after it starts?

The server is probably listening on 127.0.0.1. Bind it to 0.0.0.0 and the port the host expects.

Next step

Put it into practice.

Deploy an app from GitHub on Runex and get a live HTTPS URL. Free to start.