Image vs container
An image is a frozen filesystem plus a start command. Think of it as a recipe card: nginx:1.27 is the recipe, with the version pinned.
A container is that recipe being cooked. It is a normal process on the host, fenced off so it sees only its own filesystem, its own network and its own slice of CPU and memory. Start the same image three times and you get three containers; stop one and the image is untouched.
Layers
Images are built in layers. A base layer (say, Debian), a layer that installs nginx, a layer that copies your config. Each layer is identified by a hash and cached. Two images that share a base share that base on disk and on the wire, which is why pulling your tenth image is faster than your first.
Layers are read-only. When a container writes a file, the write lands in a thin, disposable layer on top. Delete the container and that layer is gone. Keep that in mind for later: containers forget things.
Registries
Images live in a registry, which is a content-addressed warehouse. Docker Hub is the default public one; companies run private ones. An image reference is registry/repository:tag, and the tag is just a label. nginx:1.27 means "the repository nginx, the tag 1.27". A tag that does not exist, like nginx:1.99-nope, fails to pull and you will meet that failure soon.
Why orchestration
Three containers on one laptop are easy: start them, watch them, restart one when it dies. Now scale that to 300 containers across 30 machines.
| Question | One laptop | Thirty machines |
|---|---|---|
| Where should this container run? | Here | Whichever machine has room |
| It died at 3am. Who restarts it? | You | Something that never sleeps |
| Machine 7 is gone. Now what? | n/a | Move its containers elsewhere |
| I need 5 copies, not 3 | Start two more | Start two more, on the right machines |
Kubernetes is the thing that answers those questions continuously. You describe the state you want, and a set of controllers nudges the real world toward it, forever. Everything in this course is a variation on that one idea.
Next: you will ask Kubernetes to run its smallest unit, a Pod, and clear your first lab.