Manage Docker Images Without Losing the Useful Ones
You will use docker image to find local images, download a known tag, inspect its metadata, give it another name, save a copy, and remove it carefully. The examples use Docker Community Edition CLI 29.8.1, installed here as package docker-ce-cli 5:29.8.1-1~ubuntu.24.04~noble. Allow about fifteen minutes if the Docker daemon is already running and the image is small.
The route
Jump straight to the step you need, or tick off Done means at the end.
You need a shell, the Docker CLI and access to a Docker daemon. Most commands are ordinary user commands. If the daemon socket is restricted to the docker group, fix that through your normal host administration rather than adding sudo to every command. Membership of that group is effectively privileged access to the host.
1. Check the command and daemon
The top-level command is a group for image operations. Confirm the installed version, then ask the daemon for its server version:
$ docker --version
Docker version 29.8.1, build 4a63305
$ docker info --format '{{.ServerVersion}}'
29.8.1
If the second command reports that it cannot connect, start or repair the Docker service using your distribution's normal service procedure. Do not treat a missing daemon as a reason to delete files under Docker's storage directory.
Checkpoint: both version checks work, or you have stopped here to repair daemon access.
2. List what is already local
Start with the default listing. It hides intermediate and dangling images, so add --all when investigating disk usage:
$ docker image ls
IMAGE ID DISK USAGE CONTENT SIZE EXTRA
alpine:3 294b683cb724 13MB 3.94MB
hello-world 5e2309035332 25.9kB 9.49kB
$ docker image ls --all --digests alpine
The exact rows depend on your host. An image can have more than one tag, and two tags can therefore show the same image ID. The short ID is useful for a quick view, but use a repository and tag, or the full digest, when recording an image in a script.
For a machine-readable list, use JSON output if your installed CLI supports it:
$ docker image ls --format json alpine
Do not confuse local image names with running containers. Removing an unused tag is an image operation; stopping or removing a container is a separate decision.
3. Pull a specific image reference
Pull an image from its registry with an explicit tag:
$ docker image pull alpine:3
3: Pulling from library/alpine
Digest: sha256:...
Status: Image is up to date for alpine:3
docker.io/library/alpine:3
A tag such as 3 is a registry label, not an immutable identity. For repeatable deployment, record the digest printed by the pull and use repository@sha256:... when you need that exact content. Pulling can download data and change local disk usage, but it does not start a container.
To target a multi-platform image deliberately, add a platform such as linux/amd64. Verify the result rather than assuming the host architecture:
$ docker image inspect alpine:3 --format '{{.Id}} {{.Os}}/{{.Architecture}}'
sha256:294b683cb724... linux/amd64
4. Inspect and rename an image
inspect returns detailed JSON, including the image ID, tags, architecture and configuration. A format expression is easier to scan:
$ docker image inspect alpine:3 --format '{{.Id}} {{.RepoTags}} {{.Architecture}}/{{.Os}}'
sha256:294b683cb724... [alpine:3 alpine:latest] amd64/linux
Create a second local reference with tag:
$ docker image tag alpine:3 example.local/tools/alpine:review
$ docker image ls example.local/tools/alpine
REPOSITORY TAG IMAGE ID CREATED SIZE
example.local/tools/alpine review 294b683cb724 ... 13MB
Tagging does not copy the image or upload it. It adds a reference to the same local content. If you created the tag only for a test, remove that reference after checking it:
$ docker image rm example.local/tools/alpine:review
5. Save a portable backup
Before changing or pruning an image you may need later, save it to a named archive. The -o option avoids sending binary data to your terminal:
$ docker image save --output alpine-3.tar alpine:3
$ test -s alpine-3.tar && echo 'archive is non-empty'
archive is non-empty
Load that archive on another Docker host with docker image load --input alpine-3.tar. Treat the tar file as sensitive if the image contains secrets in its layers. Saving an image does not prove that its build history is safe; inspect the history when provenance matters:
$ docker image history alpine:3 --no-trunc
6. Remove images only after a review
Warning
Image removal changes local state. It can remove a base image needed by a later build, and a forced removal can remove a reference even when normal dependency checks would stop you. First list the exact image and its tags:
$ docker image ls --all example.local/tools/alpine
$ docker image inspect example.local/tools/alpine:review
Remove one tag or image only when you have confirmed it is not needed:
$ docker image rm example.local/tools/alpine:review
For broader cleanup, run prune without --force so Docker shows a confirmation prompt. By default it removes dangling images. Adding --all expands the target to every image not used by an existing container:
$ docker image prune
WARNING! This will remove all dangling images.
Are you sure you want to continue? [y/N]
Cancel with n if the list or wording is not what you expected. There is no general undo for an image removed from the local cache. Re-pull it from its registry, or restore it from a previously saved archive with docker image load. Do not use --all --force in an unattended command until you have tested its filter and retention policy.
Done means
docker image lsshows the local references you intended to keep.- Images used in repeatable work are identified by a recorded digest, not only by a moving tag.
inspectconfirmed the image identity and platform before it was used.- Any test tag was removed without touching the source reference.
- Important images have an export or a documented way to pull them again.
- Cleanup was reviewed interactively, and no broad forced prune was run by accident.