Docker

Docker packages an app with everything it needs into an image made of read-only layers. Containers run from that image, isolated from each other but sharing the host's kernel.

The Dockerfile

Dockerfile

  1. FROM node:20-alpine
  2. WORKDIR /app
  3. COPY package*.json ./
  4. RUN npm ci
  5. COPY . .
  6. CMD ["node", "server.js"]

Image layers

FROM node:20-alpine
WORKDIR /app
COPY package*.json ./
RUN npm ci
COPY . .
CMD ["node", "server.js"]

Each instruction becomes a read-only layer of the image. Docker caches layers and reuses one if nothing it depends on changed.

Step 1 / 16
Build time
0 s

Times are illustrative.

Step by step

The example above, written out — the same steps the animation plays.

  1. 1The Dockerfile. Each instruction becomes a read-only layer of the image. Docker caches layers and reuses one if nothing it depends on changed.
  2. 2Build 1 · FROM node:20-alpine. A new layer on top of the previous one.
  3. 3Build 1 · WORKDIR /app. A new layer on top of the previous one.
  4. 4Build 1 · COPY package*.json ./. A new layer on top of the previous one.
  5. 5Build 1 · RUN npm ci. Installing dependencies — the slow layer.
  6. 6Build 1 · COPY . .. A new layer on top of the previous one.
  7. 7Build 1 · CMD ["node", "server.js"]. A new layer on top of the previous one.
  8. 8Image built in 41 s. The image is the stack of layers. Now you change one line of server.js and build again.
  9. 9Build 2 · FROM node:20-alpine. Nothing it depends on changed: reused from the cache instantly.
  10. 10Build 2 · WORKDIR /app. Nothing it depends on changed: reused from the cache instantly.
  11. 11Build 2 · COPY package*.json ./. Nothing it depends on changed: reused from the cache instantly.
  12. 12Build 2 · RUN npm ci. Nothing it depends on changed: reused from the cache instantly.
  13. 13Build 2 · COPY . .. Your code changed, so this layer — and every layer after it — must be rebuilt.
  14. 14Build 2 · CMD ["node", "server.js"]. Rebuilt because a layer below it changed.

…and 2 more steps — press Play above to watch them all.

What's happening?

  1. Each Dockerfile instruction adds a layer; Docker caches layers and reuses them when nothing they depend on changed.
  2. A change invalidates its layer and every layer after it — so the order of instructions decides how much rebuilds.
  3. Containers from the same image share its layers and each add only a thin writable layer, so they start fast and use little disk.

Where you'll meet it

Shipping the same build from a laptop to CI to production, running databases locally, and as the unit Kubernetes deploys.

Common mistake

COPY . . before installing dependencies: every code change reinstalls all packages. Copy the dependency files first, install, then copy the code.

FAQ

Container vs virtual machine?

A VM runs a whole operating system; a container shares the host kernel and isolates only the process — lighter and faster to start.

Image vs container?

An image is the read-only template; a container is a running instance of it with its own writable layer.

Are the build times real?

They are illustrative; the cache rules they show are exactly how Docker behaves.