A Dockerfile downloads a large tarball, extracts it, and then `rm -rf`s the tarball and the extraction directory in a later `RUN`. The image is still just as large as if the cleanup never happened. Why doesn't the delete shrink the image, and what actually would?
Each RUN instruction produces its own read-only layer, and a layer, once written, never changes — a later RUN rm -rf doesn't edit the earlier layer that created the tarball, it produces a brand-new layer of its own that records "these files are deleted from here on." OverlayFS implements that record as a small placeholder file called a whiteout, not an actual removal of bytes; the tarball's real content is still sitting in the earlier, untouched layer, and the image ships every layer in the stack, including that one. docker history shows exactly this: the download layer as large as ever, and the cleanup layer as a small extra entry that changes nothing about total size. The actual fix is deleting the file in the same RUN instruction that created it (so it never becomes part of a persisted layer at all), or, better, using a multi-stage build so the download and extraction happen in a stage that's discarded entirely and never contributes any layer to the final image.