Reverse Engineering a Docker Image
theartofmachinery.com
theartofmachinery.com
You can also use Portainer https://www.portainer.io/ which will show the image layer details in the images section.
Dive will even show you the exact command (directive?) that resulted in a layer being added. It also lets you browse the file system at every step.
docker history --no-trunc <image_id> --format '{{ .CreatedBy }}' | tail -r
this is pretty closeAs seen in this Dive issue[1], Google's Kaniko uses a different naming convention for the config files. Docker config files are called <hash>.json, Kaniko uses "sha256:<hash>".
It's also super awesome in general.
GitHub Repo: https://github.com/jesseduffield/lazydocker
It’s a great tool! Docker for Desktop is now shipping with a lot of the same features built into its GUI, too.
Working on CI/CD systems, I’ve wanted to make a fast way to bundle a new layer of copied files without needing docker engine.
Does anyone know if there is a tool available for this use case? I know bazel docker rules has some magic for fast file only layers.
As it is ... maybe /work is everything, maybe not.
I don't think it was a big secret.
Welcome to Linux, everything is a file.
$ docker history tmknom/prettier:2.0.5 --no-trunc
IMAGE CREATED CREATED BY SIZE COMMENT
sha256:88f38be28f05f38dba94ce0c1328ebe2b963b65848ab96594f8172a9c3b0f25b 10 months ago /bin/sh -c #(nop) CMD ["--help"] 0B
<missing> 10 months ago /bin/sh -c #(nop) ENTRYPOINT ["/usr/bin/prettier"] 0B
<missing> 10 months ago /bin/sh -c #(nop) WORKDIR /work 0B
<missing> 10 months ago |6 BUILD_DATE=2020-04-29T06:34:01Z NODEJS_VERSION=12.15.0-r1 PRETTIER_VERSION=2.0.5 REPO_NAME=tmknom/prettier VCS_REF=35d2587 VERSION=2.0.5 /bin/sh -c set -x && apk add --no-cache nodejs=${NODEJS_VERSION} nodejs-npm=${NODEJS_VERSION} && npm install -g prettier@${PRETTIER_VERSION} && npm cache clean --force && apk del nodejs-npm 42.5MB
<missing> 10 months ago /bin/sh -c #(nop) ARG PRETTIER_VERSION 0B
<missing> 10 months ago /bin/sh -c #(nop) ARG NODEJS_VERSION=12.15.0-r1 0B
<missing> 10 months ago /bin/sh -c #(nop) LABEL org.label-schema.vendor=tmknom org.label-schema.name=tmknom/prettier org.label-schema.description=Prettier is an opinionated code formatter. org.label-schema.build-date=2020-04-29T06:34:01Z org.label-schema.version=2.0.5 org.label-schema.vcs-ref=35d2587 org.label-schema.vcs-url=https://github.com/tmknom/prettier org.label-schema.usage=https://github.com/tmknom/prettier/blob/master/README.md#usage org.label-schema.docker.cmd=docker run --rm -v $PWD:/work tmknom/prettier --parser=markdown --write '**/*.md' org.label-schema.schema-version=1.0 0B
<missing> 10 months ago /bin/sh -c #(nop) ARG REPO_NAME 0B
<missing> 10 months ago /bin/sh -c #(nop) ARG VERSION 0B
<missing> 10 months ago /bin/sh -c #(nop) ARG VCS_REF 0B
<missing> 10 months ago /bin/sh -c #(nop) ARG BUILD_DATE 0B
<missing> 10 months ago /bin/sh -c #(nop) CMD ["/bin/sh"] 0B
<missing> 10 months ago /bin/sh -c #(nop) ADD file:b91adb67b670d3a6ff9463e48b7def903ed516be66fc4282d22c53e41512be49 in / 5.61MBIt is a tool I created myself for figuring out the contents of layered docker images.
It does these things:
1. Compares two docker images to see exact file differences
2. Diffs the contents of two directory structures
3. Views contents of a docker image without mounting it or using docker itself
4. Generates a standalone index of the contents of a docker image
5. Determines the resultant layer composition of a directory within a docker image
6. Extracts a specific pathed file from a layered docker image
It is extremely helpful when trying to determine the exact differences between two different builds of the same Dockerfile.