The concept of distroless images was initially presented at the swampUP conference in 2017.
So what does it mean?
"Distroless" images contain only your application and its runtime dependencies. They do not contain package managers, shells or any other programs you would expect to find in a standard Linux distribution.
That’s how Google deploys software in production. But what problem does it solve? Why is a small distro image like alpine not enough?
So let’s start with what application actually needs to run:
- Compiled sources
- Dependencies
- Language runtime
It doesn’t need any package manager, shell utilities or other tools from OS distribution. But their existence increases image size and image download time, extends scope of compliance (security hardening, CVE scans). That's the problem Google tried to solve.
Initially Google used alpine as the smallest available distro. But Alpine contains an unnecessary package manager, BusyBox and it is based on musl libc that makes glibc usage mostly impossible. So Google decided to create images that contain only what is really needed. That’s how distroless was created.
Distroless images are based on Debian Linux distribution and have a variety of language support: go, python, java, cpp, nodejs. The smallest distroless image,
gcr.io/distroless/static-debian11, is around 2 MiB. That's about 50% of the size of alpine (~5 MiB), and less than 2% of the size of debian (124 MiB).Since March 2023, Distroless images are based on oci manifests and support multiple architectures (more about multi-arch images in the post ).
We have been using distroless for some time already, and the experience is really positive. Of course, in some cases I regret about bash absence in runtime 😃, but it drives us to improve other debug and observability tools. Additionally, I want to highlight that distros are actively supported by Google and they have regular updates including actual security patches.
#engineering