COPY vs ADD

COPY, ADD and When to Prefer One

COPY src... dest copies files from the build context into the image; a trailing slash makes dest a directory, and --chown=user:group and --chmod=644 set ownership and permissions without an extra RUN layer. BookNest copies twice, the two package manifests first and everything else later, for the caching reason in RUN and Caching.

ADD does everything COPY does plus two things: it downloads URLs, and it unpacks local tar archives. Built from the same assets.tgz, COPY assets.tgz /copied/ leaves /copied/assets.tgz, while ADD assets.tgz /added/ leaves an extracted /added/public/index.html, a surprise if you only wanted the archive. Use COPY unless you need what only ADD does; Hadolint 12,433 enforces this (Hadolint). For a remote file, ADD --checksum=sha256:<hash> https://example.com/tool.tgz /opt/ is reasonable, because the build fails if the download ever changes. Never ADD an unpinned URL.