Skip to main content

container-inspector is a suite of analysis utilities and command line tools for Docker images, containers, root filesystems and virtual machine images.

For Docker images, it can process layers and how these relate to each other as well as Dockerfiles.

container-inspector provides utilities to:

  • identify Docker images in a file system, its layers and the related metadata.

  • given a Docker image, collect and report its metadata.

  • given a Docker image, extract the layers used to rebuild what how a runtime rootfs would look.

  • find and parse Dockerfiles.

  • find how Dockerfiles relate to actual images and their layers.

  • given a Docker image, rootfs or Virtual Machime image collect inventories of packages and files installed in an image or layer or rootfs (implemented using a provided callable)

  • detect the “distro” of a rootfs of image using os-release files (and an extensive test suite for these)

  • detect the operating system, architecture and

Quick start

  • Only runs on POSIX OSes

  • Get Python 3.6+

  • Check out a clone or download of container-inspector, then run: ./configure –dev.

  • Then run env/bin/container-inspector -h for help.

Container image formats

container-inspector handles the formats of Docker images as created by the docker save command. There are three versions for this Docker image format. The latest v1.2 is a minor update to v1.1.

  • v1.1 provides improved and richer metadata over v1.0 with a top level manifest.json file and a Config file for each image with full layer history and ordeing. It also use checksum for enhanced security and traceability of images and layers.

  • v1.0 uses a simple repositories meta file and requires infering the ordering of the layers in an image based on each individual layer json meta file. This format is no longer support in the latest version of container-inspector.

  • All V1.x formats use the same storage format for layers e.g the layer format V1.0 where each layer is stored in a sub-directories named after the layer id. Each of this directories contains a “layer.tar” tarball with the layer payload, a “json” JSON metadata file describing the layer and a “VERSION” file describing the layer format version. Each tarball represents a slice or diff of the image root file system using the AUFS conventions.

At runtime, in a sequence of layers of an image, each root filesystem slice of a layer is “layered” on top of each other from the root bottom layer to the latest layer (or selected tagged layer) using a union file system (e.g. AUFS). In AUFS, any file or directory prefixed with .wh. are “white outs” files deleting files in the underlying layers.

See the image specifications saved in docs/references/

Internal data model

  • Image: this is a runnable image composed of metadata and a sequence of layers.

  • Layer: this is a slice of an image root filesystem with a payload and metadata

  • Resource: this a file or directory

Plans

  • in progress: support OCI image layout

  • improved suport for Windows containers

Metadata

Release files for container-inspector 33.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for container-inspector 33.1.0
File Size Uploaded
container_inspector-33.1.0.tar.gz 96.9 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for container-inspector 33.1.0
File Interpreter ABI Platform
container_inspector-33.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 139.4 kB

Release files / container_inspector-33.1.0.tar.gz

Download URL container_inspector-33.1.0.tar.gz
Size 96.9 kB
Tags Source
SHA-256 checksum
How to use checksums
9ada0e8235cb5f48d05d748ab0a20f55991bacd53f8f491e55b8baa05b740501
BLAKE2b-256 checksum
How to use checksums
392fa3336185c8bf50bf5c13c9bdb262f43113da51169fb0df5b748dedb8af0b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jan 21, 2026.

Transparency log

Release files / container_inspector-33.1.0-py3-none-any.whl

Download URL container_inspector-33.1.0-py3-none-any.whl
Size 42.4 kB
Tags Python 3
SHA-256 checksum
How to use checksums
0061e48948d67920f3f1074ddd63b7b4b7e45cda3c8b67f7ed1b71f5dc2d6cd0
BLAKE2b-256 checksum
How to use checksums
f76aa7f04e29ff9518cf64496c85e1498732b56f6725832658b4e87b09e97ff6
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jan 21, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

33.1.0 This release

2 release files

33.0.0

2 release files

32.0.1

2 release files

32.0.0

2 release files

31.1.0

2 release files

30.0.0

2 release files

3.1.2

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page