How to Build Hardened Container Images (Wolfi, apko, melange)
Rabbit Holes With Freddy
0:00 / 0:00
How to Build Hardened Container Images (Wolfi, apko, melange)
5 просмотров · 5 дней назад
Rabbit Holes With Freddy
14 подписчиков
5 просмотров · 5 дней назад
Your container images are probably full of vulnerabilities you don't need. In this video, I show you how to build a hardened container image from scratch using Wolfi, apko, and melange, then scan it before and after to see how far the CVE count drops.
A hardened image contains only what your app needs to run: no shell, no package manager, no leftover tools, and it runs as non-root. Fewer packages means a smaller attack surface and fewer vulnerabilities to patch.
In this video you'll learn:
✅ What a hardened container image is
✅ Why hardened images matter for security and compliance
✅ Who uses them (DevOps, platform, and security teams)
✅ Where to get them: Chainguard, Docker Hardened Images (DHI), Google Distroless
✅ When to use hardened images, and when not to
✅ How to build your own with Wolfi, apko, and melange
✅ Before-and-after vulnerability scans
🔗 Resources
Wolfi: https://wolfi.dev
apko: https://github.com/chainguard-dev/apko
melange: https://github.com/chainguard-dev/melange
[Scanner you used, e.g. Grype or Trivy, with link]
[Link to your demo repo, if you have one]
💬 Are you using hardened images in production yet? Let me know in the comments. If this helped, like and subscribe for more DevOps and container security content.
#Docker #ContainerSecurity #DevSecOps #Kubernetes #Chainguard