While reviewing common Dockerfile questions for a developer position, I noticed that interviewers often ask about the distinction between the ADD and COPY instructions. In many basic examples, both commands seem to perform the exact same action of placing files into a container image.
Consider this example snippet from a sample build script:
# Copy local file into the container filesystem
COPY app.tar.gz /tmp/app.tar.gz
# Extract local tar archive automatically into the container destination
ADD app.tar.gz /tmp/app/
# Fetch remote file from a URL during build time
ADD https://example.com/config.json /etc/config.jsonI want to understand the precise operational differences between these two commands so I can answer confidently in an interview context. Specifically, I am trying to break down:
- What additional capabilities does
ADDpossess overCOPY(such as auto-extraction or remote URL downloading)? - Why do official Docker documentation and security guidelines generally favor
COPYfor standard local file transfers? - Are there edge cases where using
ADDis actually recommended, or is it considered bad practice in modern container builds?