Linux's OverlayFS (mainline since 3.18) is a union filesystem: it stacks read-only lower directories under one writable upper directory and shows the merged result. Reads return the topmost copy; the first write to a lower file copies it up; a deletion leaves a whiteout (a 0/0 character device) in the upper directory. Image layers are the lower directories, so a hundred containers from one image share one copy of its files. docker diff lists the upper layer's changes, and the mount options show the directories:
docker exec l3-ns sh -c 'echo hi > /tmp/note.txt; rm /etc/motd'
docker diff l3-ns
S=/var/lib/containerd/io.containerd.snapshotter.v1.overlayfs
sudo findmnt -N "$PID" -no OPTIONS / | tr ',' '\n' | grep dir= | sed "s|$S|\$S|g"C /tmp A /tmp/note.txt C /etc D /etc/motd lowerdir=$S/snapshots/542/fs:$S/snapshots/201/fs upperdir=$S/snapshots/543/fs workdir=$S/snapshots/543/work
alpine:3 has a single layer (snapshot 201), yet there are two lower directories: 542 is Docker 514 's init layer, holding /.dockerenv and empty placeholders for /etc/hostname, /etc/hosts and /etc/resolv.conf, which Docker then bind-mounts from /var/lib/docker/containers/<id>/. Snapshot 543 is the writable layer. All of them live under containerd 234,762 's overlayfs snapshotter, not the older /var/lib/docker/overlay2, because Docker Engine 29 514 uses the containerd image store by default on new installations (Images and Layers).
