CONTAINERS / A CONCEPT NOTE

Container Layers

how images are built from stacked, cached snapshots

~65 sec read

Overview · mechanism
pitfall · examples

01 / THE SHORT VERSION

The idea in a few sentences.

Every RUN, COPY, or ADD in a Dockerfile creates an immutable layer. Layers stack to form the image. When you rebuild, only changed layers are recreated; unchanged layers come from cache. At runtime, a thin writable layer sits on top — changes never modify the underlying image.

02 / FOLLOW THE MECHANISM

How a layered build works

  1. Build kit

    reads the Dockerfile and executes each instruction sequentially.

  2. Each RUN

    creates a new layer by running the command in a temporary container and snapshotting its filesystem.

  3. Each COPY

    adds a layer containing just the copied files and their metadata.

  4. Cache lookup

    before executing, Docker checks if a layer with the same parent + instruction hash already exists.

  5. Final image

    is the union of all read-only layers, with metadata (CMD, ENTRYPOINT, ports) from the last layer.

04 / COMMAND NOTES

Read the command, then the result.

Inspect the flags and arguments before trying an example. Snippets can need local setup, replacement values, or resources in your own environment.

EXAMPLE 01 · REFERENCE

inspect every layer in an image

docker history IMAGE_NAME

EXAMPLE 02 · REFERENCE

see full image metadata and layer digests

docker image inspect IMAGE_NAME

Explore command anatomy in the CLI lab