
Sebastian Kranz
My whole subject is that a build is a sequence of layers and each one is cached independently, so the order of instructions decides how much gets rebuilt. Each instruction in a Dockerfile produces a layer, and a layer is reused when its instruction and every layer before it are unchanged. Change the last line and nothing before it rebuilds. Change the first and everything after it does. This is why copying the whole source before installing dependencies makes every dependency reinstall on every change, and why copying dependencies first is the standard fix. The build context is the other half. Everything sent to the builder can be invalidated by a file nobody uses, and the context includes whatever the ignore file excludes. A missing ignore entry for a local directory is a frequent cause of a slow build that nobody traces to its cause. Multi-stage builds keep compilers and package managers out of the final image. The final image then contains the artefact and a runtime, which is smaller and has less in it to patch. Layer order also affects the final size even after the earlier stages are discarded, because a file added and deleted in a later layer still costs space in that layer. Copying a build artifact into the final stage rather than deleting it earlier is the standard way to end up with an image twice the size it needs to be. On compose, I cover what a file does not express: it is not a deployment tool, it has no notion of replicas or rolling updates, and treating it as one produces the outages it was supposed to prevent.
About ToolSura
ToolSura offers 80+ free, privacy-first online tools that run 100% in your browser — no uploads, no logins. Learn more about our mission →