⚡ ~/naveed Interview Prep
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 1,000+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
← Back to All Docker & Containers Interview Questions Scenario 130 of 158 in Docker & Containers
Senior DevOps Engineer Docker Container Runtime & Systems Engineering Production Scenario

Q: Your microservice image size has crept up to 850MB despite the compiled application binary being only 30MB. Developers attempted cleaning up build tools by running `apt-get clean` in subsequent `RUN` commands, unaware that files created in earlier image layers remain permanently baked into the image history. Image push and pull times are degrading pipeline performance. You need to use `dive` to inspect layer deltas, identify wasted space, and enforce an image efficiency gate in GitHub Actions.

Analyze Docker container image layer structures using Wagoodman's `dive`. Pinpoint duplicate files across layers, unpurged package manager caches, and integrate automated layer efficiency gates into CI/CD pipelines.

#Docker #Performance #Optimization #CI/CD #Tooling
🎙️ Candidate Opening & Architectural Context
"Analyze Docker container image layer structures using Wagoodman's `dive`. Pinpoint duplicate files across layers, unpurged package manager caches, and integrate automated layer efficiency gates into CI/CD pipelines."
Advertisement
⚡ Recommended Practice Lab

Want to master this scenario in a live sandbox? KodeKloud's Docker Certified Associate (DCA) Hands-On Lab Course covers this exact problem with hands-on terminal drills.

🛠️ Production Runbook & Step-by-Step Resolution

Step 1

Understand the Immutability of Container Layers

In Docker's union filesystem (OverlayFS), each `RUN`, `COPY`, and `ADD` instruction creates a new read-only layer. Deleting or modifying a file in a later layer (`RUN rm -rf /tmp/build`) does not reclaim space; it merely creates a whiteout marker masking the file while preserving the underlying bytes in previous layers.

<!-- Layer Immutability Pitfall -->
Layer 1: RUN apt-get update && apt-get install -y build-essential  (+300MB)
Layer 2: RUN ./compile-app.sh                                      (+30MB)
Layer 3: RUN apt-get purge -y build-essential && rm -rf /var/lib/apt (+10KB whiteout)

Result: Image size is still 330MB! Build-essential bytes still exist in Layer 1!
Pro Tip: Understand the Immutability of Container Layers
Step 2

Analyze Images Interactively with Dive CLI

Run `dive ` to inspect the layer-by-layer diff. Dive highlights wasted space, file modifications between layers, and assigns an efficiency score percentage.

# Run interactive inspection with dive
dive my-bloated-app:latest

# Key UI metrics in dive:
# - Efficiency Score (e.g., 68%)
# - Wasted Bytes (e.g., 280MB duplicated or deleted across layers)
# - Layer view: toggle between added, modified, and removed files
Pro Tip: Analyze Images Interactively with Dive CLI
Advertisement
Step 3

Refactor Dockerfile to Chain Instructions and Clean in the Same Layer

Combine package installation, compilation, and cache cleanup into a single contiguous `RUN` instruction so temporary build assets are purged before the layer is committed.

# Efficient single-layer pattern
RUN apt-get update && apt-get install -y --no-install-recommends \
    curl \
    ca-certificates \
    && rm -rf /var/lib/apt/lists/* \
    && rm -rf /tmp/* /var/tmp/*
Pro Tip: Refactor Dockerfile to Chain Instructions and Clean in the Same Layer
Step 4

Automate CI Efficiency Gates with Dive in GitHub Actions

Integrate `dive` into automated CI pipelines with non-interactive flags (`CI=true`). Fail the build if the image efficiency drops below 95% or if wasted space exceeds 20MB.

# CI Pipeline Step
- name: Check Image Efficiency with Dive
  env:
    CI: true
  run: |
    curl -sL https://github.com/wagoodman/dive/releases/download/v0.12.0/dive_0.12.0_linux_amd64.tar.gz | tar -xz
    ./dive my-app:latest --ci --lowestEfficiency=0.95 --highestWastedBytes=20MB
Pro Tip: Automate CI Efficiency Gates with Dive in GitHub Actions
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Container layers are immutable; files deleted in subsequent layers remain trapped in prior layers. Chaining commands within a single `RUN` instruction and running `dive` in CI gates guarantees optimal image efficiency and catches layer bloat before deployment."
⚡ 60-Second Elevator Pitch Talking Points
  • W
  • e
  • r
  • e
  • d
  • u
  • c
  • e
  • d
  • o
  • u
  • r
  • c
  • o
  • n
  • t
  • a
  • i
  • n
  • e
  • r
  • f
  • o
  • o
  • t
  • p
  • r
  • i
  • n
  • t
  • a
  • c
  • r
  • o
  • s
  • s
  • 4
  • 0
  • m
  • i
  • c
  • r
  • o
  • s
  • e
  • r
  • v
  • i
  • c
  • e
  • s
  • b
  • y
  • a
  • n
  • a
  • v
  • e
  • r
  • a
  • g
  • e
  • o
  • f
  • 7
  • 0
  • %
  • b
  • y
  • i
  • n
  • t
  • e
  • g
  • r
  • a
  • t
  • i
  • n
  • g
  • `
  • d
  • i
  • v
  • e
  • `
  • i
  • n
  • t
  • o
  • o
  • u
  • r
  • p
  • u
  • l
  • l
  • r
  • e
  • q
  • u
  • e
  • s
  • t
  • v
  • a
  • l
  • i
  • d
  • a
  • t
  • i
  • o
  • n
  • .
  • `
  • d
  • i
  • v
  • e
  • `
  • v
  • i
  • s
  • u
  • a
  • l
  • i
  • z
  • e
  • s
  • e
  • x
  • a
  • c
  • t
  • l
  • y
  • w
  • h
  • e
  • r
  • e
  • f
  • i
  • l
  • e
  • s
  • a
  • r
  • e
  • d
  • u
  • p
  • l
  • i
  • c
  • a
  • t
  • e
  • d
  • o
  • r
  • m
  • a
  • s
  • k
  • e
  • d
  • a
  • c
  • r
  • o
  • s
  • s
  • l
  • a
  • y
  • e
  • r
  • s
  • ,
  • a
  • n
  • d
  • o
  • u
  • r
  • a
  • u
  • t
  • o
  • m
  • a
  • t
  • e
  • d
  • C
  • I
  • g
  • a
  • t
  • e
  • r
  • e
  • j
  • e
  • c
  • t
  • s
  • a
  • n
  • y
  • i
  • m
  • a
  • g
  • e
  • w
  • i
  • t
  • h
  • a
  • n
  • e
  • f
  • f
  • i
  • c
  • i
  • e
  • n
  • c
  • y
  • s
  • c
  • o
  • r
  • e
  • b
  • e
  • l
  • o
  • w
  • 9
  • 5
  • %
  • ,
  • e
  • n
  • s
  • u
  • r
  • i
  • n
  • g
  • n
  • o
  • u
  • n
  • p
  • u
  • r
  • g
  • e
  • d
  • p
  • a
  • c
  • k
  • a
  • g
  • e
  • c
  • a
  • c
  • h
  • e
  • s
  • e
  • v
  • e
  • r
  • r
  • e
  • a
  • c
  • h
  • p
  • r
  • o
  • d
  • u
  • c
  • t
  • i
  • o
  • n
  • .
Advertisement
Want more Docker & Containers scenarios?
Explore our complete collection of scenario-based Docker & Containers interview runbooks.
Browse All Docker & Containers Questions →