Лучиано Маммино объясняет, как слои Docker добавляют, заменяют и удаляют файлы. Слой — набор изменений файловой системы.
Для передачи слоёв используют tar, формат упаковки файлов в архив.
Удаление обозначают записи whiteout, специальные отметки об удалении файлов из предыдущих слоёв. Например, запись .wh.old-config.json скрывает old-config.json из предыдущего слоя и сама не появляется в итоговой файловой системе.
Удаление большого файла в следующем слое не уменьшает предыдущий слой: файл остаётся в нём.
Проверка утверждений:
- Лучиано Маммино опубликовал разбор устройства слоёв Docker и механизма удаления файлов. (подтверждено самой публикацией: доказательство; «The hidden design compromises of Docker layers How layers really work: tar archives, whiteouts, and the file names you can’t use in a container image User Icon Author Luciano Mammino Calendar Icon Published 2026-09-30 08:17»)
- В разборе Маммино показывает, как слои Docker добавляют, заменяют и удаляют файлы. (подтверждено самой публикацией: доказательство; «The key idea: A layer is not a complete filesystem. It is a filesystem changeset that only has meaning when applied after the layers that came before it. So what does a changeset contain? According to the OCI spec, there are three types of change: Additions Modifications Removals»)
- Для передачи слоёв используют tar. (подтверждено самой публикацией: доказательство; «When an image is distributed (for instance, when you push it to or pull it from a registry), each layer is represented as a tar-based changeset.»)
- Удаление обозначают записи whiteout: запись .wh.old-config.json скрывает old-config.json из предыдущего слоя и сама не появляется в итоговой файловой системе. (подтверждено самой публикацией: доказательство; «Note that .wh.old-config.json is present in the layer archive , but it is not supposed to become a regular file in the final filesystem. It’s an instruction encoded as a specially named tar entry. After the layer is applied: the earlier old-config.json is gone from the merged view; the whiteout itself is also hidden (the spec says: “Once a whiteout is applied, the whiteout itself MUST also be hidden”).»)
- Удаление большого файла в следующем слое не уменьшает предыдущий слой: файл остаётся в нём. (подтверждено самой публикацией: доказательство; «The second RUN removes the file from the final filesystem , but it doesn’t magically shrink the layer created by the first RUN . That layer is immutable and it still contains the whole file.»)
Первоисточники:
- https://loige.co/hidden-design-compromises-of-docker-layers
- https://github.com/awslabs/soci-snapshotter
- https://github.com/opencontainers/image-spec/blob/main/layer.md
- https://docs.docker.com/engine/storage/drivers/overlayfs-driver/
- https://pubs.opengroup.org/onlinepubs/9699919799/utilities/pax.html
оценка 57,2 из 100 · тип: руководство