4 ms·
When I want a very specific version if the image, I use the SHA to pull/run $ docker pull hello-world@sha256:7d91b69e04a9029b99f3585aaaccae2baa80bcf318f4a5d2
by techthumb 5y ago
When I want a very specific version if the image, I use the SHA to pull/run
$ docker pull hello-world@sha256:7d91b69e04a9029b99f3585aaaccae2baa80bcf318f4a5d2165a9898cd2dc0a1
- _joel 5y agoOr you could tag a little more optimally.
- rileymichael 5y agoTags are mutable, digests aren't.
- _joel 5y agoWhy, how often do you change tags after you've built a container and for what reason if so?
- jonjonsonjr 5y agoDigests cryptographically guarantee that you get the correct content, which prevents both malicious tampering (mitm, stolen credentials, etc) or accidental mutations. This is why "immutable tags" are a bad substitute and an oxymoron. There are also better caching properties when using content addressable identifiers. For example with kubernetes pull policies, using IfNotPresent and deploying by digest means you don't even have to check with the registry to initialize a pod if the image is already cached, which can improve startup latency.
- knicknic 5y agoWith a sha you shouldn’t have to change the pull policy. However there isn’t a need for always if you have the sha.
- darkwater 5y ago> There are also better caching properties when using content addressable identifiers. For example with kubernetes pull policies, using IfNotPresent and deploying by digest means you don't even have to check with the registry to initialize a pod if the image is already cached, which can improve startup latency. While agree on the unquoted part, this is true also for human-readable (aka mutable-that-should-be-immutable) tags, when that pull policy is set (which is by default for everything that is not `latest`)