Below you will find pages that utilize the taxonomy term “Containers”
Distroless Was the Easy Part
Last year I wrote about distroless containers and finished with a small brag: I build my own minimal base image with apko and Wolfi, look how tiny it is, look how few packages it has.
This year I held that image against the standards that serious hardened-image vendors compete on. It failed.
Not because of what was inside the image. The contents were fine. Six packages, no shell, non-root user, signed with Cosign. It failed because of everything around the image and that is exactly where the state of the art has moved.
Distroless Containers
If you’ve been in the container game for a while, you’ve probably seen a lot of buzz around “distroless” containers. The first time I heard the term, I pictured a container floating off into the void - no OS, no shell, just… code. Turns out, that’s not too far from the truth, but just like Serverless, Distroless is a misleading term!
Let’s break down what distroless containers are, why you might want them in your stack, what they’re great at (and not-so-great at), plus how to actually debug one.