Reduce container attack surface by building application images on Google distroless base images that contain only the application runtime with no shell, package manager, or unnecessary OS utilities.
Scanned 9/8/2026
Install to Claude Code
npx -y skills add MustafaKemal0146/fetih --skill implementing-container-image-minimal-base-with-distroless --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Implementing Container Image Minimal Base With Distroless?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/mustafakemal0146-implementing-container-image-minimal-base-with-dis)More formats (shields.io, HTML) on the badges page.
---
name: implementing-container-image-minimal-base-with-distroless
description: Reduce container attack surface by building application images on Google distroless base images that contain only the application runtime with no shell, package manager, or unnecessary OS utilities.
tags:
- distroless
- security-hardening
- minimal-base
- docker
- container-security
- fetih
- container-images
- cybersecurity
- supply-chain
- attack-surface
- kubernetes
- siber-güvenlik
triggers:
- base
- cloud
- container
- distroless
- http
- image
- implementing
- malware
- minimal
- vulnerability
category: container-security
source_subdomain: container-security
nist_csf:
- PR.PS-01
- PR.IR-01
- ID.AM-08
- DE.CM-01
adapted_for: fetih
---
# Implementing Container Image Minimal Base with Distroless
## Genel Bakış
Google distroless images contain only your application and its runtime dependencies, without package managers, shells, or other programs found in standard Linux distributions. By eliminating unnecessary OS components, distroless images achieve up to 95% reduction in attack surface compared to traditional base images like ubuntu or debian. Major projects including Kubernetes itself, Knative, and Tekton use distroless images in production. As of 2025, Docker also offers Hardened Images (DHI) as an open-source alternative for minimal container bases.
## Ne Zaman Kullanılır
- Dağıt:ing yaparken or configuring implementing container image minimal base with distroless capabilities in your environment
- establishing yaparken: security controls aligned to compliance requirements
- building yaparken or improving security architecture for this domain
- conducting yaparken security assessments that require this implementation
## Ön Gereksinimler
- Docker 20.10+ or compatible container build tool (Buildah, Kaniko)
- Multi-stage Dockerfile knowledge
- Application compiled as a static binary or with runtime bundled
- Container registry for image storage
## Available Distroless Images
| Image | Use Case | Size |
|-------|----------|------|
| `gcr.io/distroless/static-debian12` | Statically compiled binaries (Go, Rust) | ~2MB |
| `gcr.io/distroless/base-debian12` | Dynamically linked binaries needing glibc | ~20MB |
| `gcr.io/distroless/cc-debian12` | C/C++ applications needing libstdc++ | ~25MB |
| `gcr.io/distroless/java21-debian12` | Java 21 applications | ~220MB |
| `gcr.io/distroless/python3-debian12` | Python 3 applications | ~50MB |
| `gcr.io/distroless/nodejs22-debian12` | Node.js 22 applications | ~130MB |
## Multi-Stage Build Patterns
### Go Application
```dockerfile
FROM golang:1.22-bookworm AS builder
WORKDIR /app
COPY go.mod go.sum ./
RUN go mod download
COPY . .
RUN CGO_ENABLED=0 GOOS=linux go build -ldflags="-s -w" -o /server ./cmd/server
FROM gcr.io/distroless/static-debian12:nonroot
COPY --from=builder /server /server
USER nonroot:nonroot
ENTRYPOINT ["/server"]
```
### Java Application
```dockerfile
FROM maven:3.9-eclipse-temurin-21 AS builder
WORKDIR /app
COPY pom.xml .
RUN mvn dependency:go-offline
COPY src ./src
RUN mvn package -DskipTests
FROM gcr.io/distroless/java21-debian12:nonroot
COPY --from=builder /app/target/app.jar /app.jar
USER nonroot:nonroot
ENTRYPOINT ["java", "-jar", "/app.jar"]
```
### Python Application
```dockerfile
FROM python:3.12-bookworm AS builder
WORKDIR /app
COPY requirements.txt .
RUN pip install --no-cache-dir --target=/deps -r requirements.txt
COPY . .
FROM gcr.io/distroless/python3-debian12:nonroot
WORKDIR /app
COPY --from=builder /deps /deps
COPY --from=builder /app /app
ENV PYTHONPATH=/deps
USER nonroot:nonroot
ENTRYPOINT ["python3", "/app/main.py"]
```
### Node.js Application
```dockerfile
FROM node:22-bookworm AS builder
WORKDIR /app
COPY package*.json ./
RUN npm ci --production
COPY . .
FROM gcr.io/distroless/nodejs22-debian12:nonroot
WORKDIR /app
COPY --from=builder /app .
USER nonroot:nonroot
CMD ["server.js"]
```
## Security Benefits
### Attack Surface Comparison
| Component | Ubuntu | Alpine | Distroless |
|-----------|--------|--------|-----------|
| Shell (bash/sh) | Yes | Yes | No |
| Package manager | apt | apk | No |
| coreutils | Full | BusyBox | No |
| curl/wget | Yes | Yes | No |
| User management | Yes | Yes | No |
| Known CVEs (typical) | 50-200+ | 5-20 | 0-5 |
| Image size (base) | ~77MB | ~7MB | ~2-20MB |
### Security Implications
- **No shell**: Attackers cannot exec into containers to run commands
- **No package manager**: Cannot install additional tools or malware
- **No coreutils**: No `cat`, `ls`, `Bul:`, `curl` for reconnaissance
- **Minimal CVEs**: Fewer packages means fewer vulnerabilities to patch
- **Non-root by default**: `:nonroot` tag runs as UID 65534
## Debugging Distroless Containers
Since distroless has no shell, use these techniques for debugging:
### Debug Image Variant
```dockerfile
FROM gcr.io/distroless/base-debian12:debug
```
```bash
kubectl exec -it pod-name -- /busybox/sh
```
### Ephemeral Debug Containers (Kubernetes 1.25+)
```bash
kubectl debug -it pod-name --image=busybox:1.36 --target=app-container
```
### Crane/Dive for Image Denetle:ion
```bash
crane export gcr.io/distroless/static-debian12 - | tar -tf - | head -50
dive gcr.io/distroless/static-debian12
```
## Image Scanning Results
Typical vulnerability comparison using Trivy:
```bash
trivy image myapp:ubuntu
trivy image myapp:distroless
```
## References
- [GoogleContainerTools/distroless GitHub](https://github.com/GoogleContainerTools/distroless)
- [Distroless Images - Docker Documentation](https://docs.docker.com/dhi/core-concepts/distroless/)
- [Alpine, Distroless, or Scratch? - Google Cloud](https://medium.com/google-cloud/alpine-distroless-or-scratch-caac35250e0b)
- [Docker Hardened Images](https://www.infoq.com/news/2025/12/docker-hardened-images/)
<!--
⚔ Bu skill FETIH AI Agent icin gelistirilmistir — https://github.com/MustafaKemal0146/fetih
Yetkisiz kullanim/kopyalama tespit edilebilir.
hash: d577dec6b94ce53b
-->
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!