Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Reduce container attack surface by building application images on Google distroless base images that contain only the application runtime with no shell, package manager, or unnecessary OS utilities.
.claude/skills/implementing-container-image-minimal-base-with-distroless/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-07 | ✗→✓ | ▲ Improved | — | — |
| case-17 | ✗→✓ | ▲ Improved | — | — |
| case-04 | ✗→✓ | ▲ Improved | — | — |
| case-10 | ✗→✓ | ▲ Improved | — | — |
| case-16 | ✗→✓ | ▲ Improved | — | — |
Google distroless images contain only your application and its runtime dependencies, without package managers, shells, or other programs found in standard Linux distributions. By eliminating unnecessary OS components, distroless images achieve up to 95% reduction in attack surface compared to traditional base images like ubuntu or debian. Major projects including Kubernetes itself, Knative, and Tekton use distroless images in production. As of 2025, Docker also offers Hardened Images (DHI) as an open-source alternative for minimal container bases.
| Image | Use Case | Size | |-------|----------|------| | gcr.io/distroless/static-debian12 | Statically compiled binaries (Go, Rust) | ~2MB | | gcr.io/distroless/base-debian12 | Dynamically linked binaries needing glibc | ~20MB | | gcr.io/distroless/cc-debian12 | C/C++ applications needing libstdc++ | ~25MB | | gcr.io/distroless/java21-debian12 | Java 21 applications | ~220MB | | gcr.io/distroless/python3-debian12 | Python 3 applications | ~50MB | | gcr.io/distroless/nodejs22-debian12 | Node.js 22 applications | ~130MB |
dockerfile# Build stage FROM golang:1.22-bookworm AS builder WORKDIR /app COPY go.mod go.sum ./ RUN go mod download COPY . . RUN CGO_ENABLED=0 GOOS=linux go build -ldflags="-s -w" -o /server ./cmd/server # Runtime stage - static distroless FROM gcr.io/distroless/static-debian12:nonroot COPY --from=builder /server /server USER nonroot:nonroot ENTRYPOINT ["/server"]
dockerfile# Build stage FROM maven:3.9-eclipse-temurin-21 AS builder WORKDIR /app COPY pom.xml . RUN mvn dependency:go-offline COPY src ./src RUN mvn package -DskipTests # Runtime stage - Java distroless FROM gcr.io/distroless/java21-debian12:nonroot COPY --from=builder /app/target/app.jar /app.jar USER nonroot:nonroot ENTRYPOINT ["java", "-jar", "/app.jar"]
dockerfile# Build stage FROM python:3.12-bookworm AS builder WORKDIR /app COPY requirements.txt . RUN pip install --no-cache-dir --target=/deps -r requirements.txt COPY . . # Runtime stage - Python distroless FROM gcr.io/distroless/python3-debian12:nonroot WORKDIR /app COPY --from=builder /deps /deps COPY --from=builder /app /app ENV PYTHONPATH=/deps USER nonroot:nonroot ENTRYPOINT ["python3", "/app/main.py"]
dockerfile# Build stage FROM node:22-bookworm AS builder WORKDIR /app COPY package*.json ./ RUN npm ci --production COPY . . # Runtime stage - Node distroless FROM gcr.io/distroless/nodejs22-debian12:nonroot WORKDIR /app COPY --from=builder /app . USER nonroot:nonroot CMD ["server.js"]
| Component | Ubuntu | Alpine | Distroless | |-----------|--------|--------|-----------| | Shell (bash/sh) | Yes | Yes | No | | Package manager | apt | apk | No | | coreutils | Full | BusyBox | No | | curl/wget | Yes | Yes | No | | User management | Yes | Yes | No | | Known CVEs (typical) | 50-200+ | 5-20 | 0-5 | | Image size (base) | ~77MB | ~7MB | ~2-20MB |
cat, ls, find, curl for reconnaissance:nonroot tag runs as UID 65534Since distroless has no shell, use these techniques for debugging:
dockerfile# Use debug variant in non-production environments only FROM gcr.io/distroless/base-debian12:debug # Includes busybox shell at /busybox/sh
bash# Exec into debug variant kubectl exec -it pod-name -- /busybox/sh
bash# Attach a debug container with full tooling kubectl debug -it pod-name --image=busybox:1.36 --target=app-container
bash# Inspect image layers without running crane export gcr.io/distroless/static-debian12 - | tar -tf - | head -50 # Analyze image layers dive gcr.io/distroless/static-debian12
Typical vulnerability comparison using Trivy:
bash# Scan Ubuntu-based image trivy image myapp:ubuntu # Result: 47 vulnerabilities (3 CRITICAL, 12 HIGH) # Scan Distroless-based image trivy image myapp:distroless # Result: 2 vulnerabilities (0 CRITICAL, 0 HIGH)
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-07 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-01 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-06 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-17 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-12 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-09 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-04 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-10 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-05 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-13 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-11 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-22 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-14 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-18 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-08 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-03 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-19 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-02 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-15 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-16 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-20 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-21 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted. The headline lift of +23 percentage points is the difference between those two pass rates over the 22 comparable cases.
The per-case answers from this run were removed by the retention sweep, so the case table below shows the verdicts without the text either arm produced. The counts above were recorded at the time and are unaffected. Answers are now kept for 180 days.
Other measured skills in the registry, with their headline benchmark lift.