learninfra · Linux · Networking · Kubernetes · System Design · AI Infrastructure · Exam blueprints · Drills

Container Images (CKAD)

From Dockerfile to running container: layers, tags, registries, pull policy and the pull failures you will meet.

An interactive Kubernetes lesson: 20 steps, about 30 minutes, on a live simulation in your browser.

Your team wrote the shop's backend, api, in Go. It runs on your laptop. The frontend pod web is already in the cluster, calling a Service named api that has nothing behind it yet.

You apply a Deployment that asks for two pods from the image registry.shop.example/api:1.0. Both pods are scheduled, and both stop at ErrImagePull, then ImagePullBackOff. Nobody has built that image or put it anywhere a node could fetch it.

What you will learn

  1. A pod runs an image

    • A Deployment with nothing to pull: An image is a read-only package: files plus a start command. A container is one running copy of it.
    • A Dockerfile is the recipe: RUN executes while the image is built. CMD and ENTRYPOINT only record what to execute when a container starts.
    • Build, tag, push: build creates the image on your machine, push copies it to a registry, the kubelet pulls it from there. A node never sees your laptop.
  2. Layers and the build cache

    • An image is a stack of layers: An image is a stack of read-only layers, one per instruction that changes files. Identical layers are stored and pulled only once.
    • One changed file, one rebuild: A layer is reused only if its instruction and every layer before it are unchanged. One change re-runs everything after it.
    • Order the Dockerfile for the cache
  3. Smaller and safer

    • Multi-stage: ship only the result: Multi-stage: build in a big image, copy only the result into a small one. Only the final stage ships.
    • Break it: the image runs as root: No USER instruction means root. An image's default user is part of the image, decided at build time.
    • USER: build it non-root: USER sets who the container's process runs as. Put a numeric, non-zero uid in the image and runAsNonRoot can be verified.
  4. Tags, digests and pull policy

    • Tags and digests: A tag is a movable label. A digest is the image's fingerprint and can never point at anything else.
    • Someone reuses a tag: Kubernetes compares the text of the image field, never what is behind the tag. Reuse a tag and nothing rolls out.
    • imagePullPolicy and its defaults: latest or no tag defaults to Always. Any other tag defaults to IfNotPresent. Never means the node must already hold the image.
  5. Private registries

    • Break it: the registry wants a login: ErrImagePull is one failed pull; ImagePullBackOff is the wait before the next try. Only the event says whether the image is missing or forbidden.
    • Create the pull secret: A pull secret does nothing by existing. The pod must name it in imagePullSecrets, or use a ServiceAccount that does.
    • imagePullSecrets
    • Read the pull error: Same status, three causes: the image is missing, forbidden or unreachable. The Failed event says which.
  6. At exam speed

    • Drill: build and tag
    • Drill: registry credentials
  7. Recap & playground

    • Cheat sheet
    • Playground