Q: Your microservice image size has crept up to 850MB despite the compiled application binary being only 30MB. Developers attempted cleaning up build tools by running `apt-get clean` in subsequent `RUN` commands, unaware that files created in earlier image layers remain permanently baked into the image history. Image push and pull times are degrading pipeline performance. You need to use `dive` to inspect layer deltas, identify wasted space, and enforce an image efficiency gate in GitHub Actions.
Analyze Docker container image layer structures using Wagoodman's `dive`. Pinpoint duplicate files across layers, unpurged package manager caches, and integrate automated layer efficiency gates into CI/CD pipelines.
Want to master this scenario in a live sandbox? KodeKloud's Docker Certified Associate (DCA) Hands-On Lab Course covers this exact problem with hands-on terminal drills.
🛠️ Production Runbook & Step-by-Step Resolution
Understand the Immutability of Container Layers
In Docker's union filesystem (OverlayFS), each `RUN`, `COPY`, and `ADD` instruction creates a new read-only layer. Deleting or modifying a file in a later layer (`RUN rm -rf /tmp/build`) does not reclaim space; it merely creates a whiteout marker masking the file while preserving the underlying bytes in previous layers.
<!-- Layer Immutability Pitfall -->
Layer 1: RUN apt-get update && apt-get install -y build-essential (+300MB)
Layer 2: RUN ./compile-app.sh (+30MB)
Layer 3: RUN apt-get purge -y build-essential && rm -rf /var/lib/apt (+10KB whiteout)
Result: Image size is still 330MB! Build-essential bytes still exist in Layer 1!
Analyze Images Interactively with Dive CLI
Run `dive
# Run interactive inspection with dive
dive my-bloated-app:latest
# Key UI metrics in dive:
# - Efficiency Score (e.g., 68%)
# - Wasted Bytes (e.g., 280MB duplicated or deleted across layers)
# - Layer view: toggle between added, modified, and removed files
Refactor Dockerfile to Chain Instructions and Clean in the Same Layer
Combine package installation, compilation, and cache cleanup into a single contiguous `RUN` instruction so temporary build assets are purged before the layer is committed.
# Efficient single-layer pattern
RUN apt-get update && apt-get install -y --no-install-recommends \
curl \
ca-certificates \
&& rm -rf /var/lib/apt/lists/* \
&& rm -rf /tmp/* /var/tmp/*
Automate CI Efficiency Gates with Dive in GitHub Actions
Integrate `dive` into automated CI pipelines with non-interactive flags (`CI=true`). Fail the build if the image efficiency drops below 95% or if wasted space exceeds 20MB.
# CI Pipeline Step
- name: Check Image Efficiency with Dive
env:
CI: true
run: |
curl -sL https://github.com/wagoodman/dive/releases/download/v0.12.0/dive_0.12.0_linux_amd64.tar.gz | tar -xz
./dive my-app:latest --ci --lowestEfficiency=0.95 --highestWastedBytes=20MB
- W
- e
- r
- e
- d
- u
- c
- e
- d
- o
- u
- r
- c
- o
- n
- t
- a
- i
- n
- e
- r
- f
- o
- o
- t
- p
- r
- i
- n
- t
- a
- c
- r
- o
- s
- s
- 4
- 0
- m
- i
- c
- r
- o
- s
- e
- r
- v
- i
- c
- e
- s
- b
- y
- a
- n
- a
- v
- e
- r
- a
- g
- e
- o
- f
- 7
- 0
- %
- b
- y
- i
- n
- t
- e
- g
- r
- a
- t
- i
- n
- g
- `
- d
- i
- v
- e
- `
- i
- n
- t
- o
- o
- u
- r
- p
- u
- l
- l
- r
- e
- q
- u
- e
- s
- t
- v
- a
- l
- i
- d
- a
- t
- i
- o
- n
- .
- `
- d
- i
- v
- e
- `
- v
- i
- s
- u
- a
- l
- i
- z
- e
- s
- e
- x
- a
- c
- t
- l
- y
- w
- h
- e
- r
- e
- f
- i
- l
- e
- s
- a
- r
- e
- d
- u
- p
- l
- i
- c
- a
- t
- e
- d
- o
- r
- m
- a
- s
- k
- e
- d
- a
- c
- r
- o
- s
- s
- l
- a
- y
- e
- r
- s
- ,
- a
- n
- d
- o
- u
- r
- a
- u
- t
- o
- m
- a
- t
- e
- d
- C
- I
- g
- a
- t
- e
- r
- e
- j
- e
- c
- t
- s
- a
- n
- y
- i
- m
- a
- g
- e
- w
- i
- t
- h
- a
- n
- e
- f
- f
- i
- c
- i
- e
- n
- c
- y
- s
- c
- o
- r
- e
- b
- e
- l
- o
- w
- 9
- 5
- %
- ,
- e
- n
- s
- u
- r
- i
- n
- g
- n
- o
- u
- n
- p
- u
- r
- g
- e
- d
- p
- a
- c
- k
- a
- g
- e
- c
- a
- c
- h
- e
- s
- e
- v
- e
- r
- r
- e
- a
- c
- h
- p
- r
- o
- d
- u
- c
- t
- i
- o
- n
- .