Tags are names that can point to different image contents. Digests identify specific content and improve deployment traceability.
Before you start
You should understand the difference between an image, a running container and the host. Record where a file, process or network endpoint actually lives before diagnosing a problem. Commands illustrate local experiments; adapt image names and paths to a disposable development environment.
The practical goal is to reason through this situation: Record the digest deployed alongside a human-readable release tag. Read the walkthrough first, then try the interview exercise before opening its answer. The important part is explaining the decision and its consequences, rather than remembering a definition alone.
Step-by-step walkthrough
Step 1: Distinguish name from content
A tag can point to different image contents over time.
Step 2: Record deployed digest
Associate a human release name with the actual immutable content identifier.
Step 3: Retain recovery configuration
Rollback includes runtime settings and data compatibility, not only an old image.
Worked scenario
Record the digest deployed alongside a human-readable release tag.
Two deployments both named latest can run different bytes if the tag moved between pulls. Recording the digest makes the deployed artifact identifiable. Rolling back to a previous digest is predictable only if its configuration and database expectations remain compatible with the current environment.
Common mistake
Using latest does not describe a reproducible version.
Verify the behavior
Inspect running content identifiers and rehearse rollback with compatible state.
Interview exercise
Roll back predictably.
Answer and reasoning
Retain the previous tested digest and deployment configuration, including data compatibility considerations.
Continue learning
Compare the scenario with the Docker interview questions and test your understanding with the Docker MCQs. For terminology and implementation details, consult the reference material.