Docker / OCI image file format
.tar · archive (container image) · introduced 2013 by Docker / OCI
What is a Docker / OCI image file?
A Docker image is a stack of TAR layers, each compressed with gzip or zstd, plus a manifest JSON describing the layers and configuration. The OCI Image Specification standardized the format in 2017. docker save exports an image to a single .tar file you can transfer offline; docker load reads it back.
Most readers reach this page after double-clicking a .tar file and finding their operating system unsure what to do with it. The good news: Docker / OCI image is a well-understood format with mature tooling on every major platform. It is supported in one click by mainstream archivers on Windows, macOS, and Linux.
How to extract a Docker / OCI image file
Opening a .tar file is straightforward on every modern operating system. The exact steps depend on which platform you are on:
On Windows
- Locate the
.tarfile in File Explorer. - Right-click the file. If you have 7-Zip installed, choose 7-Zip → Extract Here. On Windows 11 the built-in extractor handles ZIP, 7z, RAR and several other formats directly through Extract All…
- If prompted, pick a destination folder and click Extract.
- The extracted files appear in a folder next to the original archive.
On macOS
- Find the
.tarfile in Finder. - Install The Unarchiver from the Mac App Store, or Keka for both creating and extracting.
- Right-click the file → Open With → The Unarchiver (or just double-click after Unarchiver is set as the default).
- The extracted folder appears next to the archive.
On Linux
- Use your file manager: right-click the archive → Extract Here (file-roller on GNOME, Ark on KDE).
- On the command line, run one of:
7z x archive.tar # works for almost any format
- The files appear in the current directory.
How to create a Docker / OCI image file
To pack files into a .tar archive, you typically need an archiver that supports writing this format. Not every tool can create every format — for example, only WinRAR can create real RAR files. The sidebar lists the software known to read and write Docker / OCI image.
On the command line, the canonical create command is:
# Use 7-Zip, PeaZip, or the format's reference tool to create .tar files.
If you regularly create archives at scale, a dedicated archive automation suite can wrap this command in scheduled jobs, integrity checks, and offsite replication.
Strengths
- Layered — share common bases
- Content-addressed by SHA-256
- Open standard (OCI)
Weaknesses and limitations
- Layer count balloons easily
- Squash needs explicit tooling
Typical use cases
- Container distribution
- Offline air-gapped deployment
- CI/CD artifacts
Technical details
Docker / OCI image uses the TAR + GZIP / Zstandard layers algorithm and is identified on disk by the magic byte sequence (tar headers). The standard MIME type is application/vnd.oci.image.layer.v1.tar+gzip. The format is an open specification and is free for any use.
Frequently asked questions
Is Docker / OCI image safe to open?
Archive files are containers — they are only as safe as what they contain. A .tar from a trusted source is fine; one received from a stranger can hold malicious executables, scripts, or files engineered to exploit bugs in your archiver. Always keep your archiver updated, and never run unknown executables that come out of an archive. A safe workflow is to extract into a sandbox and scan the contents before opening anything.
What is the maximum file size?
Modern implementations support archives in the multi-terabyte range. The practical limit is your filesystem (FAT32 caps at 4 GB; ext4, NTFS, APFS, and exFAT all comfortably handle multi-TB files).
Can I password-protect a Docker / OCI image?
Some archivers can wrap Docker / OCI image files in an encrypted container, but the format itself does not always include built-in encryption. Check your archiver's documentation.
How does Docker / OCI image compare to other formats?
See our format comparison pages such as ZIP vs 7z, ZIP vs RAR, and tar.gz vs tar.xz for side-by-side feature tables.