StudyToCert

All certifications / CKAD / Lessons

Certified Kubernetes Application Developer CKAD (Kubernetes v1.35 curriculum) · Domain 1: Application Design and Build

Building, tagging, saving and loading images with docker or podman (build, tag, save, load)

▶ Watch the overview video

Last reviewed September 25, 2026 · Leer en español

Once you have a Dockerfile, you turn it into an image with a container engine. Docker and Podman accept almost identical commands, so on the exam you can usually type the same thing with either tool. Podman runs without a central daemon and can run rootless, but for building, tagging and moving images the workflow is the same.

docker build -t myapp:1.0 . builds an image. The -t flag gives it a name and tag, and the final . is the build context: the directory whose files are sent to the builder and can be referenced by COPY. If the Dockerfile has another name or location, point to it with -f path/to/Dockerfile. A .dockerignore file in the context keeps large or secret files, such as .git or local credentials, out of the build.

An image reference has the form registry/repository:tag, for example registry.example.com/team/myapp:1.0. If you omit the registry, Docker Hub is assumed; if you omit the tag, latest is assumed. A tag is just a movable label pointing to an image; the immutable identity is the content digest, written myapp@sha256:.... docker tag myapp:1.0 registry.example.com/team/myapp:1.0 adds a second name to the same image without copying anything, which you do before docker push to a registry.

Sometimes there is no registry, for example on an air-gapped host or in an exam task that asks you to export an image. docker save -o myapp.tar myapp:1.0 writes the image, with all its layers and tags, to a tar archive. docker load -i myapp.tar imports it on another machine. Podman supports the same save and load commands, and can also save in OCI (Open Container Initiative) format with --format oci-archive. Do not confuse these with docker export and docker import, which work on a container's flattened filesystem and lose the image history and metadata such as CMD.

docker build -t myapp:1.0 .
docker tag myapp:1.0 myapp:latest
docker images | grep myapp
docker save -o /tmp/myapp.tar myapp:1.0
docker load -i /tmp/myapp.tar

In a local cluster, nodes do not see the images on your workstation. With kind you run kind load docker-image myapp:1.0; with minikube you can use minikube image load myapp:1.0. In the Pod spec, set imagePullPolicy: IfNotPresent or Never so the kubelet uses the loaded image instead of trying to pull it. Note that for an image tagged latest (or with no tag), the default pull policy is Always, which will fail if the image exists only locally.

Useful inspection commands are docker images (or podman images) to list images, docker image inspect to see the configured ENTRYPOINT, CMD, environment and exposed ports, and docker history to see the layers and their sizes.

Key terms

Build context
The directory sent to the builder whose files COPY and ADD can reach.
Tag
A human-readable, movable label such as 1.0 that points to an image.
Digest
The immutable sha256 content hash that uniquely identifies an image.
docker save / load
Commands that export images with all layers and metadata to a tar archive and import them again.
Real-world example

An exam-style task says: build the image from /opt/app with the name webapp and tag v2, then save it to /opt/webapp-v2.tar. You run podman build -t webapp:v2 /opt/app followed by podman save -o /opt/webapp-v2.tar webapp:v2, then verify with ls -lh /opt/webapp-v2.tar.

Exam tip: Tasks that ask for an image archive want save (image with layers and metadata), not export (a container's flat filesystem). Also read the exact tag and output path the task asks for.

Check yourself

What does the trailing dot in docker build -t app:1 . mean?

It sets the build context to the current directory, which is sent to the builder and is what COPY can read from.

You loaded an image called app:latest into kind but the Pod shows ErrImagePull. Why?

For a latest tag the default imagePullPolicy is Always, so the kubelet tries a registry; set imagePullPolicy to IfNotPresent or Never, or use a specific tag.

Does docker tag copy the image?

No, it only adds another name pointing to the same image content.

Study CKAD for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the CKAD study plan