Regex for Docker image tag
Docker image reference with tag, e.g. ubuntu:22.04.
The Docker image tag regex is ^[a-z0-9]+([._-][a-z0-9]+)*(/[a-z0-9]+([._-][a-z0-9]+)*)*(:[\w][\w.-]{0,127})?$ — copy it below, or open it in the explainer for a token-by-token breakdown.
The pattern
^[a-z0-9]+([._-][a-z0-9]+)*(/[a-z0-9]+([._-][a-z0-9]+)*)*(:[\w][\w.-]{0,127})?$
Token-by-token breakdown
Every part of the pattern, left to right:
| Token | Meaning |
|---|---|
^ | start of string (or line in multiline mode) |
[a-z0-9]+ | one or more: any of: lowercase letters, digits |
( | start of a capturing group |
[._-] | any of: “.”, “_”, “-” |
[a-z0-9]+ | one or more: any of: lowercase letters, digits |
)* | end of group, zero or more |
( | start of a capturing group |
/ | literal text “/” |
[a-z0-9]+ | one or more: any of: lowercase letters, digits |
( | start of a capturing group |
[._-] | any of: “.”, “_”, “-” |
[a-z0-9]+ | one or more: any of: lowercase letters, digits |
)* | end of group, zero or more |
)* | end of group, zero or more |
( | start of a capturing group |
: | literal text “:” |
[\w] | any of: word chars (A–Z, a–z, 0–9, _) |
[\w.-]{0,127} | between 0 and 127 times: any of: word chars (A–Z, a–z, 0–9, _), “.”, “-” |
)? | end of group, optional (zero or one) |
$ | end of string (or line in multiline mode) |
About this pattern
Developer-oriented patterns help with code analysis, log parsing, and data transformation. Use these in build scripts, CI tools, IDE search-and-replace, and code review utilities.
Quick usage in different languages
This exact pattern — with the correct escaping and idioms for each language:
- JavaScript:
/^[a-z0-9]+([._-][a-z0-9]+)*(\/[a-z0-9]+([._-][a-z0-9]+)*)*(:[\w][\w.-]{0,127})?$/.test(value) - Python:
re.match(r"^[a-z0-9]+([._-][a-z0-9]+)*(/[a-z0-9]+([._-][a-z0-9]+)*)*(:[\w][\w.-]{0,127})?$", value) - Java:
Pattern.compile("^[a-z0-9]+([._-][a-z0-9]+)*(/[a-z0-9]+([._-][a-z0-9]+)*)*(:[\\w][\\w.-]{0,127})?$").matcher(value).matches() - C# / .NET:
Regex.IsMatch(value, @"^[a-z0-9]+([._-][a-z0-9]+)*(/[a-z0-9]+([._-][a-z0-9]+)*)*(:[\w][\w.-]{0,127})?$") - Go:
regexp.MustCompile(`^[a-z0-9]+([._-][a-z0-9]+)*(/[a-z0-9]+([._-][a-z0-9]+)*)*(:[\w][\w.-]{0,127})?$`).MatchString(value) - Ruby:
/^[a-z0-9]+([._-][a-z0-9]+)*(\/[a-z0-9]+([._-][a-z0-9]+)*)*(:[\w][\w.-]{0,127})?$/.match?(value) - PHP:
preg_match('~^[a-z0-9]+([._-][a-z0-9]+)*(/[a-z0-9]+([._-][a-z0-9]+)*)*(:[\w][\w.-]{0,127})?$~', $value)
The explainer’s Code tab regenerates these for any pattern you paste, and the downloadable cheat sheet bundles the breakdown, all seven snippets, and the pitfalls below onto one printable page.
Common pitfalls
- Anchored to the whole string. This pattern uses ^ and $, so it requires the entire input to match. To find it inside a longer text, drop the anchors and use the global (g) flag.
- Lowercase only. Ranges like [a-z] won't match uppercase. Add A-Z (or the i flag) if uppercase input should be accepted.
- Watch for backtracking. This pattern nests quantifiers; on adversarial input that can cause exponential backtracking (ReDoS). Test with long non-matching strings, or use an RE2-based engine.
- Escape it correctly per language. In Java and JavaScript strings each backslash must be doubled (\\d); in Python, Go, and C# use raw/verbatim strings so the backslashes survive.
- Validate beyond format. Matching the format doesn't guarantee the value is real. Confirm the docker image tag against a source of truth (database, API, or checksum) where it matters.
Standards & sources
This pattern is based on the following authoritative specification(s) and issuing authorities. Formats can change — always confirm against the primary source.
Related patterns
More patterns in the Developer category:
- JSON key
- Kubernetes resource name
- YAML key
- Environment variable reference
- Markdown image
- Shell variable assignment
See also
Browse all 300 patterns in the library, or open this regex in the interactive explainer to see a token-by-token breakdown, test against custom input, and generate code in seven languages.