Concept and mechanism
An image is a distribution artifact, while a container adds execution state. With multi-stage builds, compile in one stage and copy required artifacts into an appropriate final stage. Check runtime libraries; copying only the executable can be insufficient. Dockerfile order also affects caching: stable dependency manifests should precede frequently changing source where that separation is valid. EXPOSE documents ports rather than configuring listeners or host publishing. In exec form, ENTRYPOINT defines the executable and CMD supplies default arguments that docker run arguments can replace. Test the effective command to avoid diagnoses based only on the source file.
Guided application
In a fictional payment-adapter delivery, record the approved digest and tested platform. A reused tag can identify different content without changing its name. A digest connects approval to the artifact, but does not establish absence of vulnerabilities or replace security updates. For private-registry publication, the reference needs the correct hostname, port where required, and repository; login handles authentication rather than automatically renaming the image. When expanding to arm64 workers, confirm available variants and native dependencies. A multi-platform manifest points to different variants. Renaming a tag does not convert binaries. The pipeline should retain evidence of what was built, tested, and actually deployed.
Same release tag, different digest: the artifact needs a new acceptance decision.
Common pitfalls
Tag as immutable identity; EXPOSE as publishing; final stage without libraries; arm64 name as conversion.
Related topics: Swarm: desired state, placement, and quorum · Delivery, rollback, and readiness · Daemon, logs, and recovery
Build, identify, and validate the artifact for its target platform.
Reference: Dockerfile reference · DCA Study Guide v1.5 (January2025); current exam listing checked2026-09-30