Container image
Also called: Docker image, image, Dockerfile.
A package with everything your app needs to run: a base system with the language runtime, your app files and the command that starts it. You build it once from a Dockerfile, give it a tag like shop:1.4.2 and push it to a registry. Every server then pulls that same image and starts containers from it, so they all run exactly the same code.
Build the image once, push it to a registry, and every server runs a container from that same image.
Image: none · In the registry: no · Containers: 0
No image yet. The servers have nothing to run.
Say it in a prompt
Write a Dockerfile for the shop service: start FROM eclipse-temurin:21-jre, copy only the built app.jar, run as a non-root user, and start it with CMD java -jar /app/app.jar. Build it in CI, tag it with the release version (shop:1.4.2), push it to our registry, and deploy by the image digest so every server runs the same build. Vague vs precise prompt
Vague prompt
put the app in Docker Typical resultWrites a Dockerfile FROM a full JDK image, copies the whole repo with the source code and build cache, runs as root and tags it latest. The image is huge, and nobody can tell which build a server is running.
Precise prompt
Dockerfile FROM eclipse-temurin:21-jre, copy only app.jar, non-root user, CMD java -jar /app/app.jar. CI builds it, tags it shop:1.4.2 and pushes it to the registry; deploys pull it by digest. Typical resultA small image with only the runtime and the jar. Every server pulls the same tagged build, so a bug can be traced to one version and a rollback is just the previous tag.
Seen on
- Docker docs: Describes an image as a standard package with all the files, binaries, libraries and configuration to run a container; images can't be changed after they are built.
- Docker docs: Explains that an image is made of layers, each a set of file changes, and that layers are reused between images and builds.
- Kubernetes docs: You build an image and push it to a registry before a Pod uses it; giving the digest instead of a tag makes every Pod run the same version.
You might describe it as
- build it once, run the same thing on every server
- package the app with its runtime so it starts anywhere
- the thing CI builds and the servers pull
Not to be confused with
- Sidecar
A container image is the package a container starts from; a sidecar is a second, running container next to your app in the same pod.