The OCI specifications let a Docker-built image run under Podman 47,580 , containerd 234,762 or Kubernetes 5,150 . The Runtime Specification (1.3.0, which runc 1.5.1 13,463 implements) defines a bundle: a config.json describing the process, namespaces, mounts, limits and capabilities, beside a rootfs directory. The Image Specification (1.1.1) defines an index with one manifest per platform, each pointing to a JSON config and ordered layer tarballs, all addressed by SHA-256 digest. The Distribution Specification (1.1.1) is the registry HTTP API (Image Registries).
mkdir bundle && cd bundle && runc spec
jq -c '.ociVersion, .process.args, [.linux.namespaces[].type], .root' config.json
cd ..
docker buildx imagetools inspect --raw alpine:3 | jq -r '.mediaType'
M=$(docker buildx imagetools inspect --raw alpine:3 | jq -r '.manifests[0].digest')
docker buildx imagetools inspect --raw "alpine:3@$M" |
jq -c '.config.mediaType, [.layers[] | .mediaType, .size]'"1.3.0"
["sh"]
["pid","network","ipc","uts","mount","cgroup"]
{"path":"rootfs","readonly":true}
application/vnd.oci.image.index.v1+json
"application/vnd.oci.image.config.v1+json"
["application/vnd.oci.image.layer.v1.tar+gzip",3849738]runc spec writes a template: run sh in six new namespaces on a read-only rootfs. containerd generates a longer version of this file for every container from the image config and your docker run flags. alpine:3 resolves to an OCI index whose linux/amd64 manifest has one config and one 3.8 MB layer; since every blob is named by its digest, a registry, cache or signature (Container Security) can verify each piece independently.