Key idea
A tag is a name that points at an image, and it can be moved to point at another one. A digest is the image's fingerprint, worked out from its contents, and it never changes. Pinning an exact version means using something that can't move.
Tags are labels
In quay.io/computesphere/learn-hello-web:1.0.0, the part after the colon is the tag. Whoever publishes the image chooses it, and they can push a different image under the same tag tomorrow.
Most publishers leave version tags alone once they're pushed, though few registries (the servers images are pushed to and pulled from, covered in module 5) enforce it. A tag is only as stable as the people who push to it.
latest is only the tag you get when you don't write one. It doesn't mean newest, and nothing keeps it current. node:22 is a moving tag too: it follows every Node 22 patch release and every rebuild of its base.
Digests are fingerprints
A digest is a SHA-256 hash of the image's manifest, the file that lists its layers. Change one byte in any layer and the digest changes. Ask Docker for it:
docker image ls --digests quay.io/computesphere/learn-hello-web
REPOSITORY TAG DIGEST IMAGE ID SIZE
quay.io/computesphere/learn-hello-web 1.0.0 sha256:5491c5caf6e768b5f69c1abe675a03f1927eb7474a31fd3e2e1787b89d7ad442 5491c5caf6e7 12.9MB
Docker also prints a CREATED column, left out here because its value depends on when you look.
Pull by digest, with @ instead of :, and you get exactly those bytes, whatever the tag points at now:
docker pull quay.io/computesphere/learn-hello-web@sha256:5491c5caf6e768b5f69c1abe675a03f1927eb7474a31fd3e2e1787b89d7ad442
Why pin
A moving tag makes two builds, or two deploys, of "the same" image differ without anyone changing a line. When something breaks, you can't tell which image was running. Pinning gives you:
- Repeatable builds:
FROM node:22-alpine@sha256:…gets the same base every time. - Honest history: each release names exactly one image.
- Real rollbacks: going back means going back to the same bytes.
The cost is that a pinned base doesn't pick up security fixes on its own. You move the pin on purpose, and review the change like any other.
Private registries and credentials are in lesson 5.8.1, Private images and registry credentials.
Check yourself