Concept and mechanism
A build combines a definition, context, and dependencies. The context determines which files are available to COPY; the Dockerfile location does not automatically expand that set. Review.dockerignore to exclude files that should not reach the builder, including sensitive material and unnecessary local outputs. An image consists of layers and its content does not change when a tag is reused. The tag may point to another image. To connect acceptance testing with production, record the actual identity evaluated and the expected platform. A digest helps pin content but does not independently establish quality, authorization, or functional compatibility.
Guided application
In an original example, the builder occupies 940 MB while the required executable occupies 38 MB. A multi-stage build can copy the result into an appropriate runtime image without retaining compilers merely for convenience. Confirm required libraries, certificates, and user: a dynamically linked binary can fail in a minimal image missing its dependencies. If compilation requires access to a private repository, use BuildKit secret mounts with limited scope. ARG or ENV are inappropriate ways to transport build secrets. Even a temporary mount can be read by the authorized command; that command must not print or copy the secret into its output.
The approved tag now points to another digest; earlier approval does not identify the new image.
Common pitfalls
Tag as immutable identity; small image as complete runtime; secret mount as protection against the consuming command.
Related topics: Processes and images · Networking and access · Data and mounts
Promote evaluated content with the resources required to run it.
Reference: Selective artifacts across build stages · Docker Engine Linux containers, BuildKit and Compose; official documentation consulted 2026-09-30; version-dependent behavior explicitly scoped