Outcome
Docker Engine and the Compose plugin run on Ubuntu Server 26.04.1 LTS, and a disposable web container responds only on the host's loopback interface. This deliberately avoids publishing a service to the household network or internet. It is a learning service, not a backed-up application.
Before you start
Finish guides 05–07. Use a fresh host with no existing Docker or Podman workloads; Docker's own install guide lists packages that conflict with its packages. If this machine already has containers, stop and plan a migration instead of removing packages. Have sudo access, working DNS, and enough free disk space to download packages and an image. Docker's supported Ubuntu list includes 26.04 LTS as checked on 2026-09-29.
Steps
-
Review the install path. Open Docker's Ubuntu installation guide and confirm it still lists your release. Follow its apt repository method, which adds Docker's signing key and source, refreshes package lists, then installs
docker-ce,docker-ce-cli,containerd.io,docker-buildx-plugin, anddocker-compose-plugin. Read commands before running them. Avoid the convenience script for this maintained host. -
Verify the engine. Run
sudo systemctl status docker,sudo docker run --rm hello-world, andsudo docker compose version. The one-shothello-worldimage should print a success message and exit. If it does not, stop before creating a service. -
Keep Docker administration privileged. Use
sudo dockerin this beginner path. Docker documents that membership in thedockergroup grants root-level privileges; adding yourself to that group is not a harmless convenience. -
Create a disposable service definition. Make a new directory for the exercise, then save this as
compose.yamlthere:services: web: image: nginx:stable-alpine ports: - "127.0.0.1:8080:80"For a long-lived service, pin an exact reviewed image digest and plan its upgrades. The moving tag above is only for this disposable exercise.
-
Inspect before starting. In the exercise directory, run
sudo docker compose config. Confirm the published host IP is127.0.0.1, the host port is8080, and the target port is80. If it shows0.0.0.0or a missing host IP, fix the file before starting. -
Start and test. Run
sudo docker compose up -d, thencurl -I http://127.0.0.1:8080/on the host. An HTTP response confirms the container can be reached locally. Runsudo docker compose psandsudo docker compose logs --tail=30to see its state. From another computer, the host's LAN address on port 8080 should not serve this page; record the result. -
Stop the exercise. Run
sudo docker compose down. Repeat the localcurltest; it should now fail to connect. Keep the Compose file for reference or remove it only after you are sure it contains no data you need.
Check it worked
The one-shot engine test succeeds, Compose displays the expected configuration, the localhost request succeeds while the stack is up, and it fails after down. A second computer cannot reach the test service through the host's LAN address. These are checks to perform on a real lab; PebbleRack has not run them for your hardware.
If it fails / rollback
If apt reports package conflicts, use Docker's conflict list and inspect installed workloads before making changes. If the service is unreachable, check docker compose ps, logs, and the configured port. If the port is occupied, choose a different unused local port and repeat the config inspection. docker compose down removes the exercise container and network but does not undo Docker installation; use Docker's official uninstall instructions only after checking for data and other workloads.
Safety and data notes
Docker warns that published container ports can bypass ufw rules. Binding to 127.0.0.1 is intentional; changing the port to 8080:80 may expose the service. Do not place secrets in the Compose file or publish it with credentials. Never give an AI agent unrestricted Docker socket access as an early “self-healing” shortcut.
Sources
- Docker, install Engine on Ubuntu — supported release and official apt workflow; checked 2026-09-29.
- Docker, Linux post-installation — Docker group privilege; checked 2026-09-29.
- Docker, Compose service reference — host-IP port binding; checked 2026-09-29.
- Docker, packet filtering and firewalls — published ports and
ufw; checked 2026-09-29. - Docker, Compose quickstart — config, up, logs, and down; checked 2026-09-29.
Next guide
Continue to guide 09, “Choose Proxmox or a plain Linux host,” to decide whether the next task needs a hypervisor at all. You can stay with the working Ubuntu host if it does not.