docker exec starts an extra process inside a running container, in the same namespaces and cgroup as its main process (How Linux Isolates), so you can use the image's own tools, such as psql, without installing them on the host (-u picks the user, -w the working directory). docker top lists the processes as the host sees them:
docker exec l3-postgres psql -U booknest -Atc 'SHOW server_version'
docker top l3-postgres -o pid,user,args | head -318.6 (Debian 18.6-1.pgdg13+2) PID USER COMMAND 395658 999 postgres 395740 999 postgres: io worker 0
docker top shows UID 999 because the postgres user exists only in the image's /etc/passwd. The io worker processes are PostgreSQL 18 1,289 's new asynchronous I/O workers.
For interactive work add -it: docker exec -it l3-postgres psql -U booknest gives a psql prompt, and docker exec -it l3-postgres bash a shell. Leaving the session ends only that process. Minimal images may have no shell at all (Alpine 13,255 lacks bash; distroless images lack sh), which docker debug handles with docker debug. Anything you change by hand inside a container vanishes when it is replaced, so treat exec as a diagnostic tool.