TGViewer
TechLead Bits TechLead Bits @techleadbits · 517 subscribers
Post #49 202
Distroless Images

The concept of distroless images was initially presented at the swampUP conference in 2017.

So what does it mean?
"Distroless" images contain only your application and its runtime dependencies. They do not contain package managers, shells or any other programs you would expect to find in a standard Linux distribution.


That’s how Google deploys software in production. But what problem does it solve? Why is a small distro image like alpine not enough?

So let’s start with what application actually needs to run:
- Compiled sources
- Dependencies
- Language runtime

It doesn’t need any package manager, shell utilities or other tools from OS distribution. But their existence increases image size and image download time, extends scope of compliance (security hardening, CVE scans). That's the problem Google tried to solve.

Initially Google used alpine as the smallest available distro. But Alpine contains an unnecessary package manager, BusyBox and it is based on musl libc that makes glibc usage mostly impossible. So Google decided to create images that contain only what is really needed. That’s how distroless was created.

Distroless images are based on Debian Linux distribution and have a variety of language support: go, python, java, cpp, nodejs. The smallest distroless image, gcr.io/distroless/static-debian11, is around 2 MiB. That's about 50% of the size of alpine (~5 MiB), and less than 2% of the size of debian (124 MiB).

Since March 2023, Distroless images are based on oci manifests and support multiple architectures (more about multi-arch images in the post ).

We have been using distroless for some time already, and the experience is really positive. Of course, in some cases I regret about bash absence in runtime 😃, but it drives us to improve other debug and observability tools. Additionally, I want to highlight that distros are actively supported by Google and they have regular updates including actual security patches.

#engineering
GitHub GitHub - GoogleContainerTools/distroless: 🥑 Language focused docker images, minus the operating system. 🥑 Language focused docker images, minus the operating system. - GoogleContainerTools/distroless
  • 👍 4
  • ❤ 2
More from @techleadbits
  1. Oct 7, 2026AI & Repository Strategy For many years, there has been an ongoing debate between monorepo…
  2. Oct 1, 2026Tracer Bullets Continuing the topic from the previous post, let's talk in more detail abou…
  3. Sep 28, 2026Why Software Factories Fail "Read the Code!" is one of the key ideas from Dex Horthy's tal…
  4. Sep 21, 2026Illustrations from The Culture Map showing how different cultures compare on the scales. #…
  5. Sep 21, 2026The Culture Map Have you ever worked in international distributed teams? Or collaborated w…
  6. Sep 10, 2026Loop Engineering from First Principles Continuing the topic of Loop Engineering, I'd like…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →