Container Images (CKAD)
From Dockerfile to running container: layers, tags, registries, pull policy and the pull failures you will meet.
An interactive Kubernetes lesson: 20 steps, about 30 minutes, on a live simulation in your browser.
Your team wrote the shop's backend, api, in Go. It runs on your laptop. The frontend pod web is already in the cluster, calling a Service named api that has nothing behind it yet.
You apply a Deployment that asks for two pods from the image registry.shop.example/api:1.0. Both pods are scheduled, and both stop at ErrImagePull, then ImagePullBackOff. Nobody has built that image or put it anywhere a node could fetch it.
What you will learn
A pod runs an image
- A Deployment with nothing to pull: An image is a read-only package: files plus a start command. A container is one running copy of it.
- A Dockerfile is the recipe: RUN executes while the image is built. CMD and ENTRYPOINT only record what to execute when a container starts.
- Build, tag, push: build creates the image on your machine, push copies it to a registry, the kubelet pulls it from there. A node never sees your laptop.
Layers and the build cache
- An image is a stack of layers: An image is a stack of read-only layers, one per instruction that changes files. Identical layers are stored and pulled only once.
- One changed file, one rebuild: A layer is reused only if its instruction and every layer before it are unchanged. One change re-runs everything after it.
- Order the Dockerfile for the cache
Smaller and safer
- Multi-stage: ship only the result: Multi-stage: build in a big image, copy only the result into a small one. Only the final stage ships.
- Break it: the image runs as root: No USER instruction means root. An image's default user is part of the image, decided at build time.
- USER: build it non-root: USER sets who the container's process runs as. Put a numeric, non-zero uid in the image and runAsNonRoot can be verified.
Tags, digests and pull policy
- Tags and digests: A tag is a movable label. A digest is the image's fingerprint and can never point at anything else.
- Someone reuses a tag: Kubernetes compares the text of the image field, never what is behind the tag. Reuse a tag and nothing rolls out.
- imagePullPolicy and its defaults: latest or no tag defaults to Always. Any other tag defaults to IfNotPresent. Never means the node must already hold the image.
Private registries
- Break it: the registry wants a login: ErrImagePull is one failed pull; ImagePullBackOff is the wait before the next try. Only the event says whether the image is missing or forbidden.
- Create the pull secret: A pull secret does nothing by existing. The pod must name it in imagePullSecrets, or use a ServiceAccount that does.
- imagePullSecrets
- Read the pull error: Same status, three causes: the image is missing, forbidden or unreachable. The Failed event says which.
At exam speed
- Drill: build and tag
- Drill: registry credentials
Recap & playground
- Cheat sheet
- Playground