whatis container-image
Container Image
Also known as: Docker image, OCI image, Dockerfile
A read-only, layered template containing an app and its filesystem, from which containers are started. Built from a Dockerfile.
What Is a Container Image?
Images are stacks of filesystem layers plus metadata like the default command and exposed ports. Each Dockerfile instruction adds a layer, and layers are shared between images to save space and download time.
Images are stored in registries such as Docker Hub, GitHub Container Registry, or a self-hosted one, and referenced by name and tag (nginx:1.27) or immutable digest.
Example
FROM debian:stable-slim
RUN apt-get update && apt-get install -y curl
CMD ["curl", "--version"] Learn more about Container Image
- Building Container Images That Are Small, Fast, and Not Full of Holes Layer caching, multi-stage builds, non-root users, and not baking secrets into an image. The handful of practices that separate a 1.2GB image from a 40MB one.
- Running Your Own Container Registry Why Docker Hub rate limits push people to self-host, the difference between the reference registry and Harbor, and getting authentication and garbage collection right.
- Supply Chain Security: Verifying What You Install Your distribution signs packages and your package manager checks them automatically. Everything outside that, curl piped to shell, language registries, container images, has weaker guarantees or none. What each layer actually proves.