Glossary · Automation software engineering and architecture
Container image
Also known as: Image (container), OCI image
German: Container-Image
In software engineering, a container image is an immutable, layered package that contains an application, its libraries, runtime and configuration defaults, plus metadata describing how to run it, from which containers are created. The Open Container Initiative (OCI) specifies a common image format.
- Software engineering
In one sentence
A container image is an immutable, layered package of an application and its dependencies from which containers are started.
Example
The vision inspection service is shipped as a container image tagged 2.4.1 and identified by its digest, which the edge device verifies before starting it.
How it applies
- Engineering: Images are built from a definition file, such as a Dockerfile, in a Build pipeline and published to a Container registry. Minimal base images reduce size and attack surface.
- Security and maintenance: Images contain operating system packages and libraries that receive security fixes. They must be rebuilt and redeployed regularly, which is part of Patch management. Signatures and digests protect against tampered images.
- Documentation: Reference images by version and digest in release notes and deployment files, not only by mutable tags like 'latest'. A software bill of materials for each image helps customers assess vulnerabilities; the documentation team should know where these are published.
Container image vs. container
The image is the static package, like a program file; the Container (software) is a running instance of it, like a process. Many containers can run from one image, and changes made inside a running container are lost when it is recreated unless they are stored in volumes.