October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PCOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
World desk4 min

Dockerfile CMD: Set a Container’s Default Startup Command

Dockerfile CMD sets a container’s startup default, not a build-time action. Learn its forms, how it works with ENTRYPOINT, and how to override it with docker run.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

CMD sets an image’s default command or default arguments for when a container starts; it does not run a command during the image build. For build-time work—such as installing packages or creating files—use RUN. At startup, Docker combines the image’s CMD with its ENTRYPOINT, if present, and command-line arguments can replace the defaults.

What does CMD do in a Dockerfile?

CMD records the default action or arguments in the image configuration. Building the image stores that configuration; the configured default takes effect when you start a container. Docker’s Dockerfile reference puts it plainly: “CMD doesn’t execute anything at build time, but specifies the intended command for the image.”

As an Amazon Associate I earn from qualifying purchases.

By contrast, RUN executes during the build, and its result becomes part of an image layer. For example:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
FROM alpine
RUN apk add --no-cache curl
CMD ["curl", "--version"]

The package installation happens while the image is built. If you start a container from that image without supplying a replacement command, Docker uses curl --version as the default. See Docker’s Dockerfile overview for the distinction between build instructions and the command used when a container starts.

Which CMD syntax should you use?

Docker documents three forms:

CMD ["executable", "param1", "param2"]
CMD ["param1", "param2"]
CMD command param1 param2
  • Exec form with an executable: The first form specifies the default command and its arguments.
  • Exec form with arguments only: The second form provides default arguments for an ENTRYPOINT; it is not a complete command by itself.
  • Shell form: The third form is written as a command line rather than a JSON array. Docker processes it through a shell.

Only the last CMD instruction in a Dockerfile takes effect. If you intend CMD to provide default arguments to an ENTRYPOINT, Docker recommends using exec form for both instructions.

How CMD and ENTRYPOINT work together

A Dockerfile should specify at least one of CMD or ENTRYPOINT. Use ENTRYPOINT when the image should behave like a particular executable; use CMD for a default command or for default arguments to that executable.

CMD supplies a replaceable default command

Without an ENTRYPOINT, CMD supplies the default command. Arguments provided after the image name in docker run replace that default command and its arguments.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Exec-form ENTRYPOINT keeps the executable fixed

ENTRYPOINT ["python", "app.py"]
CMD ["--port", "8000"]

With this combination, the default startup runs python app.py --port 8000. If you run docker run my-image --port 9000, Docker keeps the exec-form entrypoint and replaces the CMD arguments with --port 9000. This is useful when the executable should stay fixed but users need to change its options.

Shell-form ENTRYPOINT does not pass arguments the same way

Docker’s reference says a shell-form ENTRYPOINT ignores both CMD and command-line arguments supplied to docker run. If you expect runtime arguments to reach an entrypoint, do not assume shell form behaves like the exec-form pattern above.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to override CMD when starting a container

Docker’s running containers guide documents the command shape as docker run [OPTIONS] IMAGE [COMMAND] [ARG...]. The command is optional when the image already has a default.

# Use the image's CMD default
docker run my-image

# Replace CMD with another command and its arguments
docker run my-image echo hello

# Replace ENTRYPOINT; this also clears the image's default CMD
docker run --entrypoint /bin/sh my-image
  1. To use the default: Run the image name without a command after it. Docker uses the image’s startup configuration.
  2. To replace CMD: Put the replacement command and any arguments after the image name. If there is no ENTRYPOINT, these replace CMD; with an exec-form ENTRYPOINT, they become its arguments and replace the CMD arguments.
  3. To replace ENTRYPOINT: Use --entrypoint before the image name, followed by the image and any arguments for the new entrypoint. Docker clears the image’s default CMD when this option is used.

These are choices made for a container startup. They do not change the Dockerfile or rebuild the image.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Docker Container Linux Devops Programming Coding T-Shirt
  • Docker, Docker Swarm, Docker Compose, Programmer, Developer, Coding, Programming, Software Engineer, Code, DevOps, Deploy, Deployment, Kubernetes, Salt, Puppet, Chef, Terraform, Container, AWS, Azure, Cloud, Geek, Funny, Computer, Software, Tech, IT
  • Integration, Scrum, Compile, Compilation, Science, Bug, Debug, Python, Linux, Java, Javascript, Scala, Dotnet, Kotlin
  • Lightweight, Classic fit, Double-needle sleeve and bottom hem

Choosing between CMD and ENTRYPOINT

Pattern Use it when Runtime behavior
CMD alone The image needs a default command that users may replace wholesale. Arguments after the image name replace the default command and arguments.
Exec-form ENTRYPOINT plus exec-form CMD The executable should remain fixed while users can adjust its default arguments. Arguments after the image name replace the CMD arguments and are passed to the entrypoint.
Shell-form ENTRYPOINT Use only when its shell-command behavior is intended. Docker’s reference says it ignores CMD and docker run command-line arguments.

Common CMD mistakes

  • Expecting a build-time command: Use RUN for actions that must happen while building. CMD sets startup defaults.
  • Assuming CMD always names an executable: With an ENTRYPOINT, exec-form CMD can contain only default arguments.
  • Expecting runtime arguments to be added to CMD: Arguments after the image name replace the CMD defaults. With exec-form ENTRYPOINT, they replace the default arguments passed to that entrypoint.
  • Using shell-form ENTRYPOINT but expecting normal argument passing: Docker documents that shell-form ENTRYPOINT ignores CMD and docker run arguments.
  • Adding several CMD instructions: Only the last one applies.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.