Q: After a container has been running for several days, you want to see exactly what files were added, modified, or deleted inside the container compared to its original image. How do you do this without stopping the container?
Use docker diff <container> to inspect the container's writable layer against its base image:
#Docker #Must enable BuildKit #L2 #Containers #Linux
🎙️ Candidate Opening & Architectural Context
""During an image optimization initiative across our services, we solved this exact problem. The interviewer is testing: `docker diff`, container writable layer inspection.. I structure my answer around systematic triage first, root cause analysis second, and permanent remediation third.""
Advertisement
🛠️ Production Runbook & Step-by-Step Resolution
1️⃣
Initial Diagnostics & Root Cause Analysis
Use docker diff to inspect the container's writable layer against its base image:
A— Added (file didn't exist in the image)C— Changed (file was modified)D— Deleted (file existed in image but was removed)
2️⃣
Remediation & Permanent Safeguards
Output uses three markers: Example output: This is invaluable for debugging unexpected disk growth, verifying that containers aren't writing to unexpected locations, and auditing what a compromised container may have modified. Combine with --read-only root filesystem to prevent unexpected mutations in the first place.
docker diff my-running-container
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: A — Added (file didn't exist in the image)."
⚡ 60-Second Elevator Pitch Talking Points
- A — Added (file didn't exist in the image)
- C — Changed (file was modified)
- D — Deleted (file existed in image but was removed)
Advertisement