Q: You need to verify whether a Docker image tagged `myapp:v2.1.0` in your registry is truly a multi-architecture image that supports both `linux/amd64` and `linux/arm64`, without pulling the entire image. How do you inspect this remotely?
Use docker manifest inspect to query the registry's manifest list without downloading any image layers:
🛠️ Production Runbook & Step-by-Step Resolution
Production Solution & Architecture
Use docker manifest inspect to query the registry's manifest list without downloading any image layers: For a multi-arch image, this returns a manifest list (also called a "fat manifest") containing multiple entries — one per platform. Each entry specifies the architecture, os, and a digest pointing to the platform-specific image manifest. If the image is single-architecture, the command returns a single image manifest with layer digests instead of a list. You can also use tools like crane (from Google's go-containerregistry): Or skopeo: skopeo inspect --raw docker://myregistry.com/myapp:v2.1.0 | jq . These tools query the registry API directly, never downloading image layers.
docker manifest inspect myregistry.com/myapp:v2.1.0
- Immediate Triage: Use docker manifest inspect to query the registry's manifest list without downloading any image
- Run targeted verification commands before modifying configuration.
- Automate permanent guardrails (CI check, alerts, IaC policy) to prevent recurrence.