Manifest Lists

Manifest Lists and Multi-Platform Tags

A multi-platform tag points at an image index (Docker 514 's older name is manifest list): a small JSON document listing one image manifest per platform. A client pulling the tag reads the index, picks the entry that matches its own OS and architecture, and fetches only that image's config and layers. Push BookNest's two variants to a lab registry (Self-Hosted Registry covers running one properly) and read the index back:

Pushing a multi-platform image and inspecting its indexShell
docker run -d --name l3-registry -p 127.0.0.1:33500:5000 registry:2 >/dev/null
docker buildx build -q --builder l3-builder --platform linux/amd64,linux/arm64 \
  -t localhost:33500/l3-booknest-api:1.2 --push . >/dev/null
docker buildx imagetools inspect localhost:33500/l3-booknest-api:1.2 |
  grep -E '^MediaType|Platform|reference.type'
Output
MediaType: application/vnd.oci.image.index.v1+json
  Platform:    linux/amd64
  Platform:    linux/arm64
  Platform:    unknown/unknown
    vnd.docker.reference.type:   attestation-manifest
  Platform:    unknown/unknown
    vnd.docker.reference.type:   attestation-manifest
The image index behind a multi-platform tag
The image index behind a multi-platform tag

The two unknown/unknown entries are attestation manifests: BuildKit 10,294 's provenance record for each platform, which scanners and policy tools read (Container Security). Per-platform builds from separate native runners are joined with docker buildx imagetools create -t <repo>:1.2 <repo>:1.2-amd64 <repo>:1.2-arm64, which writes a new index without moving any layers. Kubernetes 5,150 nodes (Kubernetes) resolve the same index.