OCI image archive inspector
Inspect local OCI and Docker-save archives, layer changes and the final path inventory without installing Docker.
What it does
Inspect local OCI and Docker-save archives, layer changes and the final path inventory without installing Docker.
How to use it
- Select a TAR or gzip archive, or inspect the built-in local example. Archives with several images offer an image selector.
- Inspect per-layer changes, filter the final paths and export a JSON report. Regular files, directories and link metadata are listed; no files are extracted or executed.
- Processing stays in your browser. No registry connection, image pull, upload or account required.
Example
The local example has two layers: app/old.txt is removed by a whiteout, app/keep.txt remains and app/new.txt is added.
Methodology
TAR checksums and bounds are validated. OCI SHA-256 descriptors and image layer diff IDs are verified. Lower-layer whiteouts and opaque directories are applied before same-layer entries. Final paths and per-layer replacements are reported without extracting files or running container code.
Limitations
128 MiB input, 256 MiB expanded outer TAR, 128 MiB per layer, 512 MiB total layer expansion, 100 layers and 50,000 entries. Plain TAR/gzip only; no zstd, sparse TAR, external blobs or non-SHA-256 descriptors. Links/devices are metadata, not emulated. Replaced does not mean content changed. Hidden payload bytes are not reclaimable disk space. 20-million-character report and 30-second worker deadline. Digest checks do not prove publisher trust.
Automation
This tool runs in your browser. No upload API or MCP endpoint is available.
View capabilities and documentationReference updated
Join the conversation
Helpful tips, questions, and ideas for making this tool better.
Loading discussion…