Skip to content

Image, Container, and Registry ​

These three concepts will appear throughout the course. Understand how they relate to each other before running Docker commands.

Image and container ​

An image is a package that contains everything needed to create a container, such as application files, a runtime, libraries, and a start command.

A container is a running instance of an image. One image can be used to create many containers.

A simple analogy:

  • An image is like a recipe.
  • A container is like a dish made from that recipe.

One recipe can be used many times. In the same way, one image can be used to create several containers.

Loading diagram...

An image does not run by itself. The container runs using the image. If you delete a container, its image remains. If you delete the image, you cannot create a new container from it until the image is available on the machine again, for example after pulling it from a registry.

Registry ​

A registry is a place to store and share images. Docker Engine can pull images from a registry or push images to it. A registry is like a repository for images, not a place where containers run.

Docker Hub is a public registry commonly used as the default. When you run docker pull nginx, Docker pulls the Nginx image from Docker Hub.

In a work environment, a registry can be private, such as GHCR, Amazon ECR, Google Artifact Registry, or GitLab Container Registry. The flow is the same:

  1. Build an image.
  2. Push the image to a registry.
  3. Pull the image from the registry on the machine that needs it.

Image names usually use the format name:tag, such as nginx:1.27 or postgres:16. The latest tag only means the default tag. For production, use a clear version tag so the image does not change unexpectedly.

How Docker CLI, Docker Engine, and a registry work together ​

When you type a Docker command in a terminal, several components work together:

Loading diagram...
  • Docker CLI is the program that receives commands such as docker run and docker images. The CLI does not run containers directly.
  • Docker Engine is the service that runs containers, builds images, and manages networks and volumes.
  • Docker daemon is the main process inside Docker Engine. It waits for and handles requests from Docker CLI.
  • Registry stores images. Containers do not run in a registry.

For example, when you run docker run nginx:1.27, this is what happens:

  1. Docker CLI sends the command to the Docker daemon.
  2. The Docker daemon checks whether nginx:1.27 is already on the local machine.
  3. If it is not there, the daemon pulls the image from a registry.
  4. The daemon creates and runs a container from the image.

Because of this, the CLI can be installed while the command still fails if Docker Engine or its daemon is not running. An error such as Cannot connect to the Docker daemon usually means that Docker Desktop or Docker Engine needs to be started first.

In the next lesson, you will pull an image from a registry and run a container using Docker CLI.