Docker Image
- In Turkish
- docker imajı
In short
A Docker image is a read-only, layered package of an application, its dependencies and settings, used as the template from which containers are started.
What is a Docker image?
A Docker image holds everything an application needs to run: its code, a runtime such as Node.js or Python, system libraries, files, and metadata such as the default command, environment variables and the port it listens on. Images are read-only and are identified by a name and tag, such as postgres:17, and by a digest, a SHA-256 hash of their contents. Docker builds images in the Open Container Initiative (OCI) format, so the same image also runs on containerd, Podman and Kubernetes, which is why it is also called a container image.
An image is built from a Dockerfile with docker build. Each instruction that changes files, such as COPY or RUN, adds a layer that records only those changes. Layers are cached and shared: ten images built on the same base image store that base only once, and a rebuild after a code change reuses every layer before the step that changed. Images are shared through registries such as Docker Hub, and one image name can cover several processor architectures, such as amd64 and arm64.
The relationship is like a class and its objects in programming, or a cookie cutter and the cookies: the image is the template, and each container is one instance made from it. When a container starts, Docker adds a thin writable layer on top of the image. Files the container changes go into that layer, the image itself never changes, and many containers can run from the same image at once.
The most common confusion is between an image and a container. An image is a static artifact you build, store and copy; a container is a running, or stopped, instance of it with its own processes, writable layer and network. Deleting a container doesn't delete its image, and changes made inside a container are lost when it is removed unless they were saved to a volume. A Dockerfile is a third thing: the recipe that produces the image.
Key takeaways
- A Docker image is a read-only template with an app, its dependencies and settings.
- It is built from a Dockerfile in layers, which are cached and shared.
- Tags name versions; a digest identifies the exact contents.
- Images follow the OCI format, so they run on any compatible runtime.
- An image is the template; a container is a running instance of it.
Example
# Build an image from the Dockerfile in this folder and tag it
docker build -t shop-api:1.0 .
# List local images and look at the layers of this one
docker image ls
docker history shop-api:1.0
# Start two independent containers from the same image
docker run -d --name api-1 -p 8081:3000 shop-api:1.0
docker run -d --name api-2 -p 8082:3000 shop-api:1.0
# Removing the containers leaves the image untouched
docker rm -f api-1 api-2
docker image ls shop-apiReaders ask
What is the difference between a Docker image and a container?
An image is a read-only template; a container is a running instance created from it, with its own writable layer. You can start many containers from one image, and removing them leaves the image in place.
Where are Docker images stored?
Locally, in storage that Docker manages on your machine, and remotely in container registries such as Docker Hub, GitHub Container Registry or a cloud provider's registry, from which any server can pull them.
How can I make a Docker image smaller?
Start from a small base image, such as an Alpine, slim or distroless variant, use a multi-stage build so compilers and build tools stay out of the final image, and list files the image doesn't need in .dockerignore.
See also
- DockerDevOps & Cloud, p. 20Docker is an open-source platform for packaging an application and everything it needs into a container that runs the same way on any machine.
- ContainerDevOps & Cloud, p. 13A container is a lightweight, isolated package that bundles an application with its dependencies and runs it on the host's shared operating system kernel.
- Container RegistryDevOps & Cloud, p. 14A container registry is a storage and distribution service for container images, letting teams push built images and pull them onto any server that runs them.
- Docker ComposeDevOps & Cloud, p. 21Docker Compose is a tool for defining and running multi-container applications, such as a web server plus a database, from one YAML file with one command.
- PodDevOps & Cloud, p. 47A pod is the smallest deployable unit in Kubernetes: one or more containers that share a network address and storage and are scheduled together on one node.
- Immutable InfrastructureDevOps & Cloud, p. 33Immutable infrastructure is an approach where servers are never changed after deployment; every update replaces them with new, freshly built ones.
Sources
Spotted a mistake or something missing on this page?Suggest an edit