Two words cause the most confusion in Docker: image and container. An image is the template, and a container is what you get when you run that template. You can start many containers from one image, and each one is separate.
Learning Objectives
- Explain why an image is read-only and a container is not.
- Connect docker build and docker run to the image and container lifecycle.
- Start two containers from the same image.
Image vs Container
| Image | Container | |
|---|---|---|
| What it is | A read-only template | A running instance of an image |
| Changes | Never changes after it's built | Has its own writable layer for changes |
| Created by | docker build or docker pull | docker run |
| Analogy | A recipe | A dish cooked from the recipe |
Image Layers: Stacked Like Floors
An image is built in layers, like floors of a building. The bottom floor is a base operating system, then a language runtime, then your app. The layers never change. When you run the image, Docker adds one thin, writable copy on top, and that copy is the container.
- 1Base OS: The bottom layer: a small operating system.
- 2Python: The language your app needs, added on top.
- 3Your app: Your code, the top layer of the image.
- 4Container: A running copy of the image, created by docker run. Layers never change, the container adds its own writable layer.
Dockerfile
instructions for building
docker build
produces an image
docker run
starts a container
Application Running
in an isolated container
Try It: Two Containers, One Image
Both containers below come from the same nginx image. Changes made inside one container don't appear in the other, because each one has its own writable layer.
docker pull nginx docker run -d --name web1 nginx docker run -d --name web2 nginx docker ps
docker ps lists running containers. Use docker ps -a to include stopped ones.
Learning Check
If you delete a container, is the image deleted too?
No. Removing a container leaves the image in place, so you can run new containers from it.
Can you run two containers from one image at the same time?
Yes. Each container is a separate running instance, with its own name and state.
Step by Step: Your First Image and Container
- Pull an image: docker pull nginx downloads it from the registry.
- Check it's on your machine: docker images lists it.
- Start a container from it: docker run -d -p 8080:80 --name mysite nginx.
- Open http://localhost:8080 in your browser to see the running server.
- Stop and remove it: docker stop mysite, then docker rm mysite. The image stays.
Common Mistakes
Deleting the image when you only meant to remove the container
docker rm removes a container. docker rmi removes an image. Keep the image if you plan to run it again.
Relying on the latest tag
latest points to whatever was published last, so the same command can give you a different version next month. Pin a version tag such as nginx:1.27 for repeatable results.
Expecting a stopped container to keep running
A container runs only while its main process runs. When that process ends, the container stops, and docker ps won't list it.
Interview Questions
What is the difference between an image and a container?
An image is a read-only template. A container is a running instance of that image with its own writable layer.
Can you run several containers from one image?
Yes. Each container is a separate instance with its own name, state, and writable layer.
What's the difference between docker pull and docker run?
pull downloads an image from a registry. run creates and starts a container, and downloads the image first if it isn't on the machine.
Summary
An image is a read-only template built from a Dockerfile, and a container is a running instance of an image. One image can start many containers, and each one keeps its own writable state.