# distroless

Distroless is a project providing minimal container images that contain an application and its runtime dependencies without package managers, shells, or other standard Linux distribution programs.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Chainguard OS and the Next Generation of Distroless Software Delivery

DevFeed: [Chainguard OS and the Next Generation of Distroless Software Delivery](<https://devfeed.tech/articles/the-distroless-revolution-will-be-chainguarded-13249.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/the-distroless-revolution-will-be-chainguarded>)

Published: 2025-03-20T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard os](<https://devfeed.tech/topics/chainguard-os.md>), [distroless](<https://devfeed.tech/topics/distroless.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>)

Tags: [beyond-distro](<https://devfeed.tech/tags/beyond-distro.md>), [chainguard-os](<https://devfeed.tech/tags/chainguard-os.md>), [chainguard-your-os](<https://devfeed.tech/tags/chainguard-your-os.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [distroless](<https://devfeed.tech/tags/distroless.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [security](<https://devfeed.tech/tags/security.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

This article proposes a next generation of open source software delivery centered on distroless, purpose-built container images and upstream-maintained software packages. It introduces Chainguard OS, which Chainguard describes as continuously rebuilding packages from upstream sources to incorporate security fixes and performance improvements.

### Source excerpt

Chainguard OS is the next generation in open source software delivery. Learn all about the principles and technology that make it possible.

## Have We Reached a Distroless Tipping Point?

DevFeed: [Have We Reached a Distroless Tipping Point?](<https://devfeed.tech/articles/have-we-reached-a-distroless-tipping-point-13080.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/have-we-reached-a-distroless-tipping-point>)

Published: 2025-03-18T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [distroless](<https://devfeed.tech/topics/distroless.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Cloud Native Ecosystem](<https://devfeed.tech/topics/cloud-native-ecosystem.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Linux](<https://devfeed.tech/topics/linux.md>)

Tags: [beyond-distro](<https://devfeed.tech/tags/beyond-distro.md>), [cgroups](<https://devfeed.tech/tags/cgroups.md>), [chainguard-os](<https://devfeed.tech/tags/chainguard-os.md>), [chainguard-your-os](<https://devfeed.tech/tags/chainguard-your-os.md>), [cloud-native](<https://devfeed.tech/tags/cloud-native.md>), [containers](<https://devfeed.tech/tags/containers.md>), [distroless](<https://devfeed.tech/tags/distroless.md>), [kernel](<https://devfeed.tech/tags/kernel.md>), [linux](<https://devfeed.tech/tags/linux.md>), [oci](<https://devfeed.tech/tags/oci.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [secure-by-design](<https://devfeed.tech/tags/secure-by-design.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

The article argues that containerization and cloud-native software development have created an inflection point in open source software delivery. It presents the evolution from Linux Containers to Docker and the Open Container Initiative as milestones supporting a shift from traditional Linux distributions toward distroless, secure-by-design, continuously updated software.

### Source excerpt

The world is at an inflection point in open source software delivery. See where the software distribution status quo is at, and what is next.

## Check out Chainguard at KubeCon NA in Salt Lake City on November 12-15!

DevFeed: [Check out Chainguard at KubeCon NA in Salt Lake City on November 12-15!](<https://devfeed.tech/articles/check-out-chainguard-at-kubecon-na-in-salt-lake-city-on-november-12-15-13006.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/check-out-chainguard-at-kubecon-na-in-salt-lake-city-on-november-12-15>)

Published: 2024-10-16T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>), [distroless](<https://devfeed.tech/topics/distroless.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Security](<https://devfeed.tech/topics/security.md>), [devrel](<https://devfeed.tech/topics/devrel.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cloud-native-rejekts](<https://devfeed.tech/tags/cloud-native-rejekts.md>), [conference](<https://devfeed.tech/tags/conference.md>), [container](<https://devfeed.tech/tags/container.md>), [debug](<https://devfeed.tech/tags/debug.md>), [developers](<https://devfeed.tech/tags/developers.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [devsecops](<https://devfeed.tech/tags/devsecops.md>), [distroless](<https://devfeed.tech/tags/distroless.md>), [event](<https://devfeed.tech/tags/event.md>), [kubecon](<https://devfeed.tech/tags/kubecon.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [multi-arch](<https://devfeed.tech/tags/multi-arch.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [security](<https://devfeed.tech/tags/security.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [sigstorecon](<https://devfeed.tech/tags/sigstorecon.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>)

### AI overview

Chainguard announces its participation in KubeCon North America 2024 in Salt Lake City, including product demonstrations of Chainguard Images and appearances at Cloud-Native Rejekts and SigstoreCon.

### Source excerpt

Chainguard is going to be at KubeCon North America 2024 in Salt Lake City. See where we'll be and how you can meet us to learn more about Chainguard Images.

## Images as Code: The pursuit of declarative image builds

DevFeed: [Images as Code: The pursuit of declarative image builds](<https://devfeed.tech/articles/images-as-code-the-pursuit-of-declarative-image-builds-13101.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/images-as-code-the-pursuit-of-declarative-image-builds>)

Published: 2024-01-22T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Code](<https://devfeed.tech/topics/code.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Dockerfile](<https://devfeed.tech/topics/dockerfile.md>), [bazel](<https://devfeed.tech/topics/bazel.md>), [distroless](<https://devfeed.tech/topics/distroless.md>), [Docker](<https://devfeed.tech/topics/docker.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Terraform](<https://devfeed.tech/topics/terraform.md>), [Infrastructure as code](<https://devfeed.tech/topics/infrastructure-as-code.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [apk](<https://devfeed.tech/tags/apk.md>), [apko](<https://devfeed.tech/tags/apko.md>), [bazel](<https://devfeed.tech/tags/bazel.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [code](<https://devfeed.tech/tags/code.md>), [container-image](<https://devfeed.tech/tags/container-image.md>), [containers](<https://devfeed.tech/tags/containers.md>), [declarative](<https://devfeed.tech/tags/declarative.md>), [distroless](<https://devfeed.tech/tags/distroless.md>), [docker](<https://devfeed.tech/tags/docker.md>), [infrastructure-as-code](<https://devfeed.tech/tags/infrastructure-as-code.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [reproducibility](<https://devfeed.tech/tags/reproducibility.md>), [terraform](<https://devfeed.tech/tags/terraform.md>)

### AI overview

The article traces the pursuit of declarative container image builds. It critiques imperative Dockerfile-based builds for making multi-tenant, multi-architecture, and reproducible builds difficult, then discusses Bazel and distroless images as steps toward expressing intended build state. Kubernetes and Terraform are presented as examples of declarative systems, inspiring the idea of "Images as Code."

### Source excerpt

Chainguard's CTO Matt Moore describes the process of creating a declarative container image build for Chainguard Images.

## Announcing Bazel rules for extending Chainguard Images

DevFeed: [Announcing Bazel rules for extending Chainguard Images](<https://devfeed.tech/articles/announcing-bazel-rules-for-extending-chainguard-images-12875.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/announcing-bazel-rules-for-extending-chainguard-images>)

Published: 2023-10-24T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [distroless](<https://devfeed.tech/topics/distroless.md>), [Package manager](<https://devfeed.tech/topics/package-manager.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [apk](<https://devfeed.tech/tags/apk.md>), [apko](<https://devfeed.tech/tags/apko.md>), [bazel](<https://devfeed.tech/tags/bazel.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [distroless](<https://devfeed.tech/tags/distroless.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [secure-software-supply-chain](<https://devfeed.tech/tags/secure-software-supply-chain.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Chainguard and Aspect.Dev announce the general availability of rules_apko, an open source Bazel plugin for building secure, minimal Wolfi-based OCI container images. The article explains how rules_apko integrates APK packages and Wolfi-base images into existing Bazel workflows, supports reproducible builds, and provides dependency locking, integrity verification, and SBOM generation.

### Source excerpt

Explore Bazel rules for Chainguard Images, your pathway to secure, effortless image extension.

## Understanding attacker techniques in distroless containers

DevFeed: [Understanding attacker techniques in distroless containers](<https://devfeed.tech/articles/understanding-attacker-techniques-in-distroless-containers-13300.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/understanding-attacker-techniques-in-distroless-containers>)

Published: 2023-10-05T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [distroless](<https://devfeed.tech/topics/distroless.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Security](<https://devfeed.tech/topics/security.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [containers](<https://devfeed.tech/tags/containers.md>), [distroless](<https://devfeed.tech/tags/distroless.md>), [distroless-containers](<https://devfeed.tech/tags/distroless-containers.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [rce](<https://devfeed.tech/tags/rce.md>), [remote-code-execution](<https://devfeed.tech/tags/remote-code-execution.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article examines attacker techniques relevant to distroless containers, drawing on a DEFCON 31 talk and an example involving PHP remote code execution, reverse shells, and injected spam content. It emphasizes keeping software up to date and using defense in depth.

### Source excerpt

Explore DEFCON 31 insights on Distroless container security. Delve into RCE vulnerabilities and Chainguard's robust defense strategies for up-to-date software.

## How to use Dockerfiles with wolfi-base images

DevFeed: [How to use Dockerfiles with wolfi-base images](<https://devfeed.tech/articles/how-to-use-dockerfiles-with-wolfi-base-images-13097.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/how-to-use-dockerfiles-with-wolfi-base-images>)

Published: 2023-09-14T00:00:00Z

Content type: tutorial

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Dockerfile](<https://devfeed.tech/topics/dockerfile.md>), [Docker](<https://devfeed.tech/topics/docker.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [distroless](<https://devfeed.tech/topics/distroless.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [Go](<https://devfeed.tech/topics/go.md>)

Tags: [apko](<https://devfeed.tech/tags/apko.md>), [base-images](<https://devfeed.tech/tags/base-images.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [distroless](<https://devfeed.tech/tags/distroless.md>), [docker](<https://devfeed.tech/tags/docker.md>), [docker-hub](<https://devfeed.tech/tags/docker-hub.md>), [dockerfiles](<https://devfeed.tech/tags/dockerfiles.md>), [go](<https://devfeed.tech/tags/go.md>), [guide](<https://devfeed.tech/tags/guide.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [melange](<https://devfeed.tech/tags/melange.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

This tutorial explains how to use Dockerfiles with Chainguard wolfi-base and other Chainguard Images. It covers minimal static images, glibc-dynamic images, multi-stage builds, package management, and selecting image variants based on application dependencies and runtime needs.

### Source excerpt

Your guide to leveraging Dockerfiles with Wolfi-base images for hardened container images.

## It all started with a commit: Celebrating 6 years of Distroless

DevFeed: [It all started with a commit: Celebrating 6 years of Distroless](<https://devfeed.tech/articles/it-all-started-with-a-commit-celebrating-6-years-of-distroless-13129.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/it-all-started-with-a-commit-celebrating-6-years-of-distroless>)

Published: 2023-04-12T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [distroless](<https://devfeed.tech/topics/distroless.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [sigstore](<https://devfeed.tech/topics/sigstore.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [bazel](<https://devfeed.tech/topics/bazel.md>), [Debian](<https://devfeed.tech/topics/debian.md>), [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [Go](<https://devfeed.tech/topics/go.md>)

Tags: [bazel](<https://devfeed.tech/tags/bazel.md>), [c-plus-plus](<https://devfeed.tech/tags/c-plus-plus.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [debian](<https://devfeed.tech/tags/debian.md>), [digital-signatures](<https://devfeed.tech/tags/digital-signatures.md>), [distroless](<https://devfeed.tech/tags/distroless.md>), [distroless-containers](<https://devfeed.tech/tags/distroless-containers.md>), [go](<https://devfeed.tech/tags/go.md>), [java](<https://devfeed.tech/tags/java.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [python](<https://devfeed.tech/tags/python.md>), [release-engineering](<https://devfeed.tech/tags/release-engineering.md>), [sigstore](<https://devfeed.tech/tags/sigstore.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [verify](<https://devfeed.tech/tags/verify.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

The article commemorates six years of Distroless, describing its goal of creating more secure and efficient container images by removing non-essential components. It covers the Bazel-based build tooling, language runtimes, Kubernetes adoption, vulnerability-management benefits, and later integration with Sigstore for container signing and authenticity verification. It also introduces the subsequent development of Chainguard Images.

### Source excerpt

The goal of Distroless is to provide a more secure and efficient way to package and run software in containers by using only essential components.