Learning paths / Containers / Images and layers

Tags and digests

Reading · 6 min · Module 2, lesson 2 of 529 min left in this module

Module 2 · Images and layersLesson 2 of 5

Goal: Pin an exact image version, by digest in Docker and by a never-reused tag on ComputeSphere.

Key idea

A tag is a name that points at an image, and it can be moved to point at another one. A digest is the image's fingerprint, worked out from its contents, and it never changes. Pinning an exact version means using something that can't move.

Tags are labels

In quay.io/computesphere/learn-hello-web:1.0.0, the part after the colon is the tag. Whoever publishes the image chooses it, and they can push a different image under the same tag tomorrow.

Most publishers leave version tags alone once they're pushed, though few registries (the servers images are pushed to and pulled from, covered in module 5) enforce it. A tag is only as stable as the people who push to it.

latest is only the tag you get when you don't write one. It doesn't mean newest, and nothing keeps it current. node:22 is a moving tag too: it follows every Node 22 patch release and every rebuild of its base.

Digests are fingerprints

A digest is a SHA-256 hash of the image's manifest, the file that lists its layers. Change one byte in any layer and the digest changes. Ask Docker for it:

docker image ls --digests quay.io/computesphere/learn-hello-web
REPOSITORY                              TAG       DIGEST                                                                    IMAGE ID       SIZE
quay.io/computesphere/learn-hello-web   1.0.0     sha256:5491c5caf6e768b5f69c1abe675a03f1927eb7474a31fd3e2e1787b89d7ad442   5491c5caf6e7   12.9MB

Docker also prints a CREATED column, left out here because its value depends on when you look.

Pull by digest, with @ instead of :, and you get exactly those bytes, whatever the tag points at now:

docker pull quay.io/computesphere/learn-hello-web@sha256:5491c5caf6e768b5f69c1abe675a03f1927eb7474a31fd3e2e1787b89d7ad442

Why pin

A moving tag makes two builds, or two deploys, of "the same" image differ without anyone changing a line. When something breaks, you can't tell which image was running. Pinning gives you:

  • Repeatable builds: FROM node:22-alpine@sha256:… gets the same base every time.
  • Honest history: each release names exactly one image.
  • Real rollbacks: going back means going back to the same bytes.

The cost is that a pinned base doesn't pick up security fixes on its own. You move the pin on purpose, and review the change like any other.

Private registries and credentials are in lesson 5.8.1, Private images and registry credentials.

Check yourself

You deploy myapp:latest on Monday. On Tuesday a teammate pushes a new image as myapp:latest. On Wednesday you redeploy without changing anything. What runs?
Two images have the same tag but different digests. What does that tell you?

In the docs