Trace Container Filesystem Changes with docker diff
You will inspect the files and directories that Docker reports as added, deleted or changed in a container since that container was created. The command is read-only: it does not edit the container or its image. Allow about ten minutes if you already have a container to inspect.
The route
Jump straight to the step you need, or tick off Done means at the end.
This guide uses Docker Community Edition CLI 29.8.1 from the docker-ce-cli package, version 5:29.8.1-1~ubuntu.24.04~noble. The command is useful for a quick investigation, but it is not a complete audit trail and it does not show every detail of a file change.
1. Check the installed command
Run these commands as your normal user. Docker CLI commands usually need no elevated privileges when your account can already access the Docker daemon. Do not add sudo automatically: changing between Docker clients or daemon contexts can make an investigation harder to reproduce.
$ docker --version
Docker version 29.8.1, build 4a63305
$ docker container diff --help
Usage: docker container diff CONTAINER
Inspect changes to files or directories on a container's filesystem
The short command docker diff is an alias for docker container diff. Both forms take exactly one container argument.
Checkpoint: you have confirmed that the Docker client is installed and that the syntax is docker container diff CONTAINER.
2. Choose the container without changing it
List containers and copy the name or ID of the one you want to inspect:
$ docker ps --all --format 'table {{.ID}}\t{{.Names}}\t{{.Status}}'
CONTAINER ID NAMES STATUS
abc123def456 example-service Exited (0) 2 hours ago
The displayed values are examples. Replace example-service with an exact name from your own output. The manual accepts a full or shortened container ID, or the name supplied to docker run --name. Inspecting a stopped container is often convenient because it leaves the workload undisturbed.
Do not confuse a container name with an image name. docker container diff operates on one existing container, not directly on an image, a host directory or a running process selected by its service name.
3. Read the change list
Run the command with the selected container:
$ docker container diff example-service
C /etc
C /etc/service.conf
A /var/log/example-service.log
D /tmp/old-marker
Each line begins with one status symbol followed by a path in the container filesystem:
Ameans a file or directory was added.Dmeans a file or directory was deleted.Cmeans a file or directory was changed.
The exact paths depend on the container and its workload. A parent directory can appear as changed when a file below it changed. Runtime-created paths such as logs, PID files or temporary directories can therefore create noise. Treat a line as a lead to investigate, not as proof of which process made the change.
Checkpoint: save the output if you need to compare it with a later inspection. The command itself has not changed container state.
4. Compare a second snapshot carefully
If the container remains active, run the same command again after the event you are investigating:
$ docker container diff example-service > /tmp/example-service-diff-after.txt
$ sed -n '1,80p' /tmp/example-service-diff-after.txt
C /etc
A /var/log/example-service.log
Redirecting to a file changes only the host-side output file. It does not write inside the container. Use a temporary path that you own, and make the filename specific enough that you do not overwrite another investigation.
For a before-and-after comparison, capture the first result before the event as well, then use a host tool such as diff:
$ docker container diff example-service > /tmp/example-service-diff-before.txt
$ diff -u /tmp/example-service-diff-before.txt /tmp/example-service-diff-after.txt
--- /tmp/example-service-diff-before.txt
+++ /tmp/example-service-diff-after.txt
@@
+A /var/log/example-service.log
A new line in this comparison means Docker now reports that path in the container's changed-file set. It does not include file contents, checksums, timestamps or the identity of the process responsible.
5. Handle common errors
If Docker cannot find the target, check the spelling and list all containers again:
$ docker container diff does-not-exist
Error response from daemon: No such container: does-not-exist
The wording can vary slightly by Docker release. An unknown name is not fixed by restarting the container; select the correct name or ID instead.
If Docker reports a daemon connection or permission error, check the client context and your normal Docker access before retrying with elevated privileges:
$ docker context show
default
$ docker info
docker info is a diagnostic command and can expose environment details, so do not paste its complete output into a public issue without reviewing it. If your installation intentionally restricts daemon access, ask the administrator for the approved read-only investigation route.
6. Remove only temporary host reports
The earlier commands do not require an undo action because they do not alter the container. If you created the two host-side report files and no longer need them, remove those exact files after checking their contents:
$ rm -- /tmp/example-service-diff-before.txt /tmp/example-service-diff-after.txt
This deletion is irreversible. Do not substitute a directory, a wildcard or a variable you have not inspected. Never run docker rm as part of this workflow: removing a container is a separate, destructive operation and is not needed to inspect its filesystem changes.
Done means
- You checked the installed Docker CLI version and confirmed the command syntax.
- You selected an existing container by an exact name or ID.
- You can interpret
A,DandCwithout treating directory noise as a complete explanation. - You know that the output lists paths, not contents, checksums, timestamps or responsible processes.
- You kept any comparison reports on the host and removed them only by their exact paths when finished.