5 ms·
Dive: A tool for exploring a Docker image, layer contents and more
- notatoad 3y agoI found dive super useful for understanding how docker images work, and how to write efficient dockerfiles. Reading the docs is one thing, but making a change to the dockerfile and then seeing how it has affected the resulting layer structure is what really made me get it.
- greenie_beans 3y agothis helped me debug a docker thing recently, very handy tool!
- animeshjain 3y agoI used dive when I was trying to cut down on the size of the image. Diffing and seeing what files/directories go into each layer was very useful.
- runfaster2000 3y agoDive is great. Tools like that are critical for both learning and developing confidence on what you are precisely building/shipping. Dredge is another tool to look at. I use it for diffing layers. https://github.com/mthalman/dredge/blob/main/docs/commands/images.md#compare-image-layers https://github.com/mthalman/dredge/blob/main/docs/commands/i...
- geek_at 3y agoIt really does sound amazing. Would have needed this when you guys (hn) and reddit helped me figure out what a rogue Raspberry Pi was doing in our server closet https://blog.haschek.at/2019/the-curious-case-of-the-RasPi-in-our-network.html https://blog.haschek.at/2019/the-curious-case-of-the-RasPi-i...
- thunderbong 3y agoThat's an awesome article!
- WirelessGigabit 3y ago2019! Can you post an update?
- 8organicbits 3y ago(edit) See https://news.ycombinator.com/item?id=29965250 https://news.ycombinator.com/item?id=29965250
- TechIsCool 3y agoI love dive and its something that I use in my tool kit multiple times a month. I am curious if anyone knows how to get the contents of the file you have highlighted, a lot of the times I use dive to validate that a file exists in a layer and then I want to peak at it. Currently I normally revert to running the container and using cat or extracting the contents and then wandering into the folders.
- a_t48 3y agoYou can use rsync with some magic to get at the files, but it's not much removed from using cat.
- oooyay 3y agoDive is incredible, it saved my butt numerous times and taught me a lot about layers. It's so good that Docker Desktop emulated its functionality.
- diazc 3y agoThere’s other great TUI terminal tools like dive here [0], lazydocker and dry come to mind. And some in the docker category as well: [0] https://terminaltrove.com/ https://terminaltrove.com/
- pricci 3y agoLazydocker has a similar, although simpler, funtionality. Edit: just checked and it allows to see the layers, but only shows the commands of each one
- a_t48 3y agoDive is great. It struggles a bit with very very large images but beyond that no real complaints.
- tornadofart 3y agoWhat exactly is meant by a layer?
- manojlds 3y agoDocker images have layers. Sort of like snapshots.
- gilnaa 3y agoLike an onion
- jake_morrison 3y agoLike ogres
- iCarrot 3y agoIt is a Docker's term: https://docs.docker.com/build/guide/layers/ https://docs.docker.com/build/guide/layers/
- tornadofart 3y agoThanks.
- miquong 3y agoFor image and layer manipulation, crane is awesome - as is the underlying go-containerregistry library. It lets you add new layers, or edit any metadata (env vars, labels, entrypoint, etc) in existing images. You can also "flatten" an image with multiple layers into a single layer. Additionally you can "rebase" an image (re-apply your changes onto a new/updated base image). It does all this directly in the registry, so no docker needed (though it's still useful for creating the original image). https://github.com/google/go-containerregistry/blob/main/cmd/crane/recipes.md https://github.com/google/go-containerregistry/blob/main/cmd... (updated: better link)
- pbowyer 3y agoIs there any performance benefit to having fewer layers? My understanding is that there's no gain by merging layers as the size of the image remains constant.
- natebc 3y agosome startup performance savings in fewer http requests to fetch the image. small for sure but it's something?
- electroly 3y agoIn practice I've found the performance savings often goes the other way--for large (multi-GB) images it's faster to split it up into more layers that it can download in parallel from the registry. It won't parallelize the download of a single layer and in EC2+ECR you won't get particularly good throughput with a single layer.
- whirlwin 3y agoDepends. If you would have to fetch a big layer often because of updates, that's not good. But if what is changing frequently is in a smaller layer, it will be more favorable
- mcpherrinm 3y agoIf files are overwritten or removed in a lower layer, there can be size savings from that.
- vbezhenar 3y agoWhat's the reason docker uses tar archives instead of ordinary directories for layer contents? This tool is great but it fixes something that should not exist in the first place.
- cachvico 3y agoSo images are serialized and able to be transmitted over a network. When an image is used (or "run"), it becomes a container, which makes it behave (to the client) like ordinary files & directories.
- maxloh 3y agoA dumb question: Why are most of the container/infrastructure tools written in GoLang? Examples that come to my mind include Docker, Podman, nerdctl, Terraform and Kubernetes. Is there any obvious advantage that GoLang offers, making it so popular for building these tools?
- bombela 3y agoI think I can answer for Docker. The first prototype was written in Python, the company was a Python shop. The main reason for a rewrite in Go was to ride the popularity of Go that was growing at the time (2012). source: I was there.
- mardifoufs 3y agoIn hindsight, docker is probably much better off with Go, considering the use case. And I say that as someone who loves python and isn't too much into go!
- baby_souffle 3y ago> In hindsight, docker is probably much better off with Go, considering the use case. And I say that as someone who loves python and isn't too much into go! Same. I use docker to escape the versioning hell that is modern python. When you're trying to build a tool, the more self-contained the better.
- arccy 3y agowhen you run containers, you want to care as little about the underlying system as possible, and go makes it easy to be in its own little world. plus ecosystem effects of you can just use the packages of a different implementation for part of your code.
- fishpen0 3y agoKubernetes specifically is in go because google invented go and also invented Kubernetes. Their internal teams have a lot of go engineers due to the whole inventing it thing
- sureglymop 3y agoThere's a tool from google called container-diff that's also really useful! I use it to see what random scripts one is encouraged to pipe into bash would do to a system.
- roastedfunction 3y agoThis is less related to general container utilities but I’m an avid user of GoogleContainerTools/container-structure-test. It’s a handy way to run integration tests on container apps or images. These Google open source projects seem to be in need of some TLC as a lot of the original maintainers have moved on, which is a shame. I try to throw a PR their way and close out the odd issue when I can. The testing tool in particular is invaluable to keep my sanity with a large amount of base images I have to maintain internally.
- eris_agx 3y agoOther than being super useful, Dive has an underrated feature: its author is a great developer and very fun to work with.
- indrora 3y agoDive has saved my ass so many times it's not funny when trying to pull apart what various common docker containers do when I'm extending them. A+ software.
- tonymet 3y agoDive is a gem. It's helped me find a lot of cruft ... - unneeded build dependencies. Used a scratch image and/or removed build deps in the same step - node_modules for dev-deps . Used prod - Embeded Chromium builds (with puppetteer). Removed chromium and remoted an external build Docker desktop now has this feature built in, but I've been using dive for years to find wasted space & potential security issues.
- radus 3y agoGreat tool, I use it with this alias: alias dive='docker run -ti --rm -v /var/run/docker.sock:/var/run/docker.sock wagoodman/dive' (as suggested in project the README)
- kylegalbraith 3y agoDive is an amazing tool in the container/Docker space. It makes life so much easier to debug what is actually in your container. When we were first getting started with Depot [0], we often got asked how to reduce image size as well as make builds faster. So we wrote up a quick blog post that shows how to use Dive to help with that problem [1]. It might be a bit dated now, but in case it helps a future person. Dive also inspired us to make it easier to surface what is actually in your build context, on every build. So we shipped that as a feature in Depot a few weeks back. [0] https://depot.dev https://depot.dev [1] https://depot.dev/blog/reducing-image-size-with-dive https://depot.dev/blog/reducing-image-size-with-dive [2] https://depot.dev/blog/build-context https://depot.dev/blog/build-context