The quickest way to tell a strong Docker developer from a weak one is a short Dockerfile and five minutes. Hand over this deliberately flawed one and ask what they'd change:
FROM node:latest
WORKDIR /app
COPY . .
RUN npm install
RUN npm run build
ENV NODE_ENV=production
EXPOSE 3000
CMD npm startIn our design, a mid-level candidate tends to change only the CMD, while a senior one starts listing problems before they've finished reading. This guide shows how to hire Docker developers around that kind of review, with the current Engine and Desktop versions as of 3 October 2026 and the Docker Desktop licensing rule that catches larger companies out. It's part of our series Hire developers by tech stack: rates, vetting and interview guides.
What a Docker developer actually does
A Docker developer containerises applications. They write and own the Dockerfiles, define local environments in Compose, and make sure CI builds produce small, repeatable images. They're often a backend or full-stack engineer with strong container habits, not a separate species.
That's different from the person who runs pipelines, infrastructure and on-call. If your real need is Terraform, deployment automation and incident response, read the DevOps, SRE and platform-engineering split first, because that's a separate hire. If you need someone to operate clusters, that's hiring for the cluster layer, and it's a different skill set again.
Our view, and it's an opinion rather than a finding: most smaller teams need Docker skills spread across the developers they already have, plus one person who owns the build standards. A dedicated hire makes sense when images are slow, large or insecure and nobody has the time to fix them.
Docker Engine and Desktop versions: what to put in the job description
Docker moves fast, so pin the versions you run and say so in the posting. As of 3 October 2026, the Docker Engine 29 release notes list 29.8.2 as the latest, dated 30 September 2026. It carries security fixes for CVE-2026-53493, CVE-2026-92543 and CVE-2026-92542, plus BuildKit v0.33.1, containerd v2.3.6 and runc v1.5.2. The 29.0.0 release came out on 10 November 2025, so the 29 line is about eleven months old.
Version 29.8.0, from 3 September 2026, changed AppArmor and SELinux rules to block the 32-bit socketcall(2) path for creating AF_VSOCK sockets, and added a --umask flag. A candidate who tracks release notes will have heard of that sort of change. One who doesn't isn't disqualified, but ask how they keep up.
Docker Desktop ships faster. The Docker Desktop release notes show four weekly releases in September: 4.90.0 on 7 September, 4.91.0 on 14 September, 4.92.0 on 21 September and 4.93.0 on 28 September. Desktop 4.93.0 bundles Engine 29.8.1, one patch behind the current Engine.
We couldn't find a published Engine support or end-of-life policy in the Docker documentation, so we haven't printed one. If you need a support window for compliance, ask Docker or your subscription contact directly.
For the job description, name the Engine major version you run in production and ask for experience with it. "Docker" alone tells a candidate nothing about whether you're on a current release.
Docker Desktop licensing: a cost line for companies
Docker Desktop isn't free for everyone. According to Docker's Desktop license page, it's free for small businesses (fewer than 250 employees and under $10 million in annual revenue), personal use, education, and non-commercial open source. Professional use in larger organisations and in government entities needs a paid Pro, Team or Business subscription.
Both thresholds apply together. A company with 80 employees and $12 million in revenue is over the line.
That makes licensing a hiring and procurement question. Every developer you add who runs Desktop on a company laptop could be a seat. Ask candidates what they use locally and what their last team paid for. If you're above the thresholds, budget for it or settle on an alternative before onboarding. This is a procurement check, not legal advice, so have whoever signs your software contracts read the license page.
The build skills to screen for
Most of what separates a senior Docker developer is build practice, and Docker documents it well. Screen for these.
Multi-stage builds. The multi-stage build documentation describes them as multiple FROM statements where each begins a new stage, with COPY --from=build pulling artifacts from an earlier stage and --target selecting where to stop. A strong answer explains why you'd compile in one stage and ship from a smaller one. The same page says BuildKit builds only the stages a target depends on, while the legacy builder processes every stage up to the target.
BuildKit. Docker's BuildKit overview calls it the default builder for Docker Desktop and Docker Engine users. Few people should need to switch it on by hand now. A candidate who treats "enabling BuildKit" as a special step may be working from older habits.
The Dockerfile best-practices guide covers the rest. It says multi-stage builds reduce final image size, pinning a base image to a digest guarantees you get the same image even if the tag is replaced, a .dockerignore file should keep unneeded files out of the build context, and a USER instruction should drop to non-root if the service can run without privileges. It also says to rebuild images regularly and to write CMD in exec form, CMD ["executable", ...]. A strong candidate can explain each in a sentence and say what goes wrong without it. A weak one has heard of two.
Rootless mode is a step further. The rootless mode documentation describes running the Docker daemon and containers as a non-root user to mitigate potential vulnerabilities in the daemon and the container runtime. The install script isn't supported on s390x. Not every role needs it, but anyone working on shared build hosts should know what it is and what it costs.
How to hire a Docker developer
1. Define the role and where the image runs
Write down what the person will containerise, where the images run (a managed cloud service, your own servers, a cluster) and who owns the pipeline that builds them. If the answer to the last question is "nobody", you may be hiring for the wrong role. Where the images are hosted and who controls the cloud account is a cloud-engineering question, covered in hiring cloud engineers, more than Dockerfile work.
2. Screen with a Dockerfile review
Send the Dockerfile from the top of this article before the first call, or share it in the call. Ask for a written list of what they'd change and why. Five minutes of reading shows how they think; a CV line saying "Docker, 5 years" does not.
3. Run a build-and-debug exercise
Give them a small repo and a failing build or a container that exits at startup. Ask them to narrate. How they investigate matters more than speed. The exercises further down are designed for this step.
4. Check security habits
Ask whether their images run as root, how they pin base images, how often they rebuild, and what they know about rootless mode. You're listening for habits, not trivia. Someone who pins digests and drops privileges by default does it without being asked.
5. Choose the engagement model
A defined containerisation project, such as moving a monolith into images and writing the CI build, suits a contractor. Ongoing ownership of build standards and image upkeep suits a permanent hire. Be honest about which one you have.
Docker exercises that separate senior from mid-level
These four are our own design, not an official assessment. The pinning, .dockerignore, non-root, rebuild and exec-form points come from Docker's documentation, cited above; the layer-ordering and Compose health-check points are our own practice.
Dockerfile review
Use the Dockerfile at the top. It has a floating latest tag, runs as root, copies everything before installing dependencies, runs as a single stage, and uses shell-form CMD.
A strong candidate lists most of those unprompted. They pin the base image, ideally by digest, split the build into stages, copy the dependency manifest first so the install layer caches, add a .dockerignore and add a non-root USER. They'll also mention rebuilding often to pick up base image fixes. A weak candidate fixes the CMD and calls it done.
Multi-stage conversion
Ask them to rewrite the same file as a multi-stage build and explain what ends up in the final image. Strong answers use COPY --from to take only the built output, say why the compiler and dev dependencies stay behind, and mention --target for building one stage while debugging. Weak answers add a second FROM and copy everything across.
Container that exits at startup
Give them an image that starts and stops straight away. Strong candidates read the logs and exit code first, check the entrypoint and CMD, then run the image with a shell to look inside. Weak ones rebuild repeatedly and hope. Ask what changed recently, because the strongest candidates ask it first.
Compose service dependencies
Give them a Compose file where an app starts before its database accepts connections. Ask how they'd fix it. A strong answer separates "the container has started" from "the service is ready" and reaches for a health check rather than a sleep. A weak answer adds a delay.
Docker interview questions
These are supporting questions for the call, each with what to listen for.
1. Why would you use a multi-stage build?
Listen for smaller final images, a build toolchain that doesn't ship, and a mention of COPY --from and --target.
2. How do you keep builds fast?
Listen for layer ordering (dependency manifests before source), a .dockerignore file and BuildKit building only the stages a target needs.
3. Why pin a base image by digest?
Listen for repeatability. A tag can point to a different image tomorrow, and a digest can't.
4. Does your container run as root, and should it?
Listen for a non-root USER as the default, with a reason when the answer is no.
5. What's the difference between shell and exec form for CMD?
Listen for a clear explanation and a preference for exec form, as the best-practices guide recommends.
6. What would you check if a container exits straight after starting?
Listen for logs, exit code, entrypoint and a shell into the image, in that sort of order.
7. What do you use for Docker locally, and who pays for it?
Listen for awareness of the Desktop licensing rule. It shows whether they know the rule.
Hiring Docker developers through HighCircl
HighCircl's covered stacks include DevOps, and it takes Docker briefs through HighCircl, hiring from seven European countries. It doesn't run Docker-specific vetting stages. Candidates go through four stages of engineer-led vetting, and about 1 in 10 applicants pass. HighCircl matches within 72 hours and shortlists 3-5 candidates. The margin is 20%, capped and disclosed, there's no minimum hour commitment, and a replacement guarantee applies if an engagement isn't working.
FAQ
What's the difference between a Docker developer and a DevOps engineer?
A Docker developer containerises applications: Dockerfiles, Compose files and image builds. A DevOps or platform engineer runs the pipelines, infrastructure and on-call around them. The roles overlap on CI image builds, but you can hire one without the other.
Do Docker developers need to know Kubernetes?
Not necessarily. Docker skills cover building and running images. Kubernetes is the layer that schedules them across machines, and it's a separate specialism. Ask for it only if the person will deploy to your clusters.
Is Docker Desktop free for companies?
Only for small ones. According to Docker's license page, it's free for businesses with fewer than 250 employees and under $10 million in annual revenue, plus personal use, education and non-commercial open source. Larger organisations and government entities need a paid subscription for professional use.
What is a multi-stage build and why ask about it?
It's a Dockerfile with several FROM statements, where each begins a new stage and later stages copy only what they need from earlier ones. It reduces final image size, and a candidate's explanation shows quickly whether they've built production images or only followed tutorials.
How much does a Docker developer cost?
There's no sourced, dated Docker-specific rate worth printing. The rate tables we found on competing pages state no method. For HighCircl's general senior engineer range, it's €45-105/hr ($50-115/hr), which isn't a Docker-specific rate.
How long does it take to hire a Docker developer?
HighCircl matches within 72 hours and shortlists 3-5 candidates for its covered stacks, which include DevOps. A direct hire takes longer once interviews and notice periods are counted.
