Does LABEL add new layer to docker image or apply to all layers, and does it matter where LABEL is place in dockerfile?

Viewed 438

Does LABEL add new layer to docker image?

Does LABEL apply to all layers? Because pruning image based on label filter deletes all layers for that image.

Does it make any difference whether I place the LABEL at the beginning or end of the dockerfile?

2 Answers

I've performed a few tests using a very simple Dockerfile, and adding a LABEL doesn't add any layers, but it does change the image's sha256 id.

Any change to the label's value will change the sha256 and even moving it to a different part of the Dockerfile will too, but the layers remain unaffected by the label's presence or value.

As for whether a LABEL "applies to all layers", I suppose we could conclude that the label is applicable to the overall image but has no effect on its layers.

This depends on the builder and what you mean by layer. With the classic docker build tooling, a new label created a temporary container to capture the change. If you did this early in the build, that change could break the cache so you would put metadata like this at the end of the build.

With buildkit, it avoids temporary containers for these steps, and it ignores this metadata when looking up cached layers, so order doesn't matter for these.

For layers, you will see them in the image history, but they are defined as "empty_layer": true, meaning the step has no filesystem changes. There's no tar file to download for that step of the build, which is why the following image has 4 layers listed in the "rootfs" and 9 history entries:

$ regctl image config localhost:5000/regclient/regctl
{
  "created": "2021-12-27T19:26:50.630484996Z",
  "architecture": "amd64",
  "os": "linux",
  "config": {
    "User": "appuser",
    "Env": [
      "PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin"
    ],
    "Entrypoint": [
      "/regctl"
    ],
    "WorkingDir": "/",
    "Labels": {
      "maintainer": "",
      "org.opencontainers.image.authors": "Regclient contributors",
      "org.opencontainers.image.created": "2021-12-27T19:25:15Z",
      "org.opencontainers.image.description": "",
      "org.opencontainers.image.documentation": "https://github.com/regclient/regclient",
      "org.opencontainers.image.licenses": "Apache 2.0",
      "org.opencontainers.image.revision": "6a1a13c410f734f5e18a6032936bc6764814eae7",
      "org.opencontainers.image.source": "git://github.com/regclient/regclient.git",
      "org.opencontainers.image.title": "regctl",
      "org.opencontainers.image.url": "https://github.com/regclient/regclient",
      "org.opencontainers.image.vendor": "",
      "org.opencontainers.image.version": "v0.3.10"
    }
  },
  "rootfs": {
    "type": "layers",
    "diff_ids": [
      "sha256:132414a5f587782f893460744b6d5872335d2ccd7b668af59c36fdd83e48d3d8",
      "sha256:482fa28623966b82c52505731df79398729a36956d18b620a6434b8a147dd520",
      "sha256:8e47dcad786aa3f447bbfe6ed60b24924627535f7c10a7eb93a5c8d5d59052c2",
      "sha256:2d9d57f598a12d3cdd770ed50df2e950dad13cea14dd62444f64b2cc72873a66"
    ]
  },
  "history": [
    {
      "created": "2021-09-20T13:39:49.998835208Z",
      "created_by": "COPY /etc/passwd /etc/group /etc/ # buildkit",
      "comment": "buildkit.dockerfile.v0"
    },
    {
      "created": "2021-09-20T13:39:50.016894649Z",
      "created_by": "COPY /etc/ssl/certs/ca-certificates.crt /etc/ssl/certs/ # buildkit",
      "comment": "buildkit.dockerfile.v0"
    },
    {
      "created": "2021-09-20T13:39:50.043111544Z",
      "created_by": "COPY /home/appuser /home/appuser # buildkit",
      "comment": "buildkit.dockerfile.v0"
    },
    {
      "created": "2021-12-27T19:26:50.630484996Z",
      "created_by": "COPY /src/bin/regctl /regctl # buildkit",
      "comment": "buildkit.dockerfile.v0"
    },
    {
      "created": "2021-12-27T19:26:50.630484996Z",
      "created_by": "USER appuser",
      "comment": "buildkit.dockerfile.v0",
      "empty_layer": true
    },
    {
      "created": "2021-12-27T19:26:50.630484996Z",
      "created_by": "ENTRYPOINT [\"/regctl\"]",
      "comment": "buildkit.dockerfile.v0",
      "empty_layer": true
    },
    {
      "created": "2021-12-27T19:26:50.630484996Z",
      "created_by": "ARG BUILD_DATE",
      "comment": "buildkit.dockerfile.v0",
      "empty_layer": true
    },
    {
      "created": "2021-12-27T19:26:50.630484996Z",
      "created_by": "ARG VCS_REF",
      "comment": "buildkit.dockerfile.v0",
      "empty_layer": true
    },
    {
      "created": "2021-12-27T19:26:50.630484996Z",
      "created_by": "LABEL maintainer= org.opencontainers.image.created= org.opencontainers.image.authors=Regclient contributors org.opencontainers.image.url=https://github.com/regclient/regclient org.opencontainers.image.documentation=https://github.com/regclient/regclient org.opencontainers.image.source=https://github.com/regclient/regclient org.opencontainers.image.version=latest org.opencontainers.image.revision= org.opencontainers.image.vendor= org.opencontainers.image.licenses=Apache 2.0 org.opencontainers.image.title=regctl org.opencontainers.image.description=",
      "comment": "buildkit.dockerfile.v0",
      "empty_layer": true
    }
  ]
}
Related