Contents

Infrastructure & Operations › Containers

Image

A read-only template that containers are created from.

Also known as: Docker image, container image, image

An image is a read-only template that contains everything needed to run a program: a minimal file system, your code, its dependencies and the default command. A container is a running instance of an image. One image can start any number of containers, and all start from the same state.

An image is built in layers from a Dockerfile, then stored under a name and tag in a registry.

docker build -t myapp:1.0 .      # create an image
docker images                    # list local images
docker run myapp:1.0             # start a container from it
docker pull postgres:16          # download one from a registry
docker rmi myapp:1.0             # delete a local image

A useful comparison: the image is like a class (or a recipe), the container is like an object (or a meal made from it). Changing a running container doesn’t change the image.

Names, tags and digests

myapp:1.0 is a name plus a tag. Tags are labels that can be moved to a different image later, so :latest can mean different things on different days. A digest (myapp@sha256:...) points at exactly one image and never changes. See image tags.

Practical points

  • Build once, run anywhere. The same image goes from CI to staging to production, which removes “different on the server” bugs.
  • Smaller is better: faster pulls and fewer things to attack. See minimal base images.
  • Everything in the image can be read by anyone who gets the image. Don’t bake in secrets.
  • Images contain third-party packages that may have known vulnerabilities; scan them. See image scanning.