Docker Easy technical 1 views 1 min read

What is the difference between CMD and ENTRYPOINT?

Peer-reviewed by HireXTech Technical Panel Updated for 2025/2026 hiring Editorial standards
Practise this track
Interviewer Expectations for this Question
01
Core Competency

Assesses fundamental understanding of Docker conventions, runtime behavior, and memory/performance considerations.

02
Evaluation Criteria

Hiring managers look for precision, avoidance of ambiguous jargon, and ability to explain trade-offs under real production conditions.

Comprehensive Model Answer Verified Solution

Both define what runs when a container starts, but they behave differently.

  • ENTRYPOINT sets the executable. It is hard to override and defines the container's purpose.
  • CMD provides default arguments to ENTRYPOINT, or a default command if no ENTRYPOINT exists. It is easily overridden by arguments passed to docker run.
ENTRYPOINT ["python", "app.py"]
CMD ["--port", "8080"]

Running docker run image --port 9000 replaces the CMD arguments but keeps the ENTRYPOINT. Use the exec form, the JSON array, so signals such as SIGTERM reach your process directly, which matters for graceful shutdown. Avoid the shell form because it wraps the command in /bin/sh -c and can swallow signals. Combine both for a sensible default that users can still customise.

Candidate Response Strategy & Interview Tips

  1. Start with a concise one-sentence summary: Deliver a direct, confident answer first before expanding into nuances.
  2. Demonstrate real-world trade-offs: Discuss where this approach excels and when you would avoid it in production systems.
  3. Discuss complexity & edge cases: Proactively explain time/space complexity or boundary conditions (null values, scale limits).
  4. Prepare for interviewer follow-ups: Technical hiring panels frequently probe deeper into concurrency, backward compatibility, or alternative libraries.
Related Topics & Skills
Spotted an error or have an alternative solution?