Q: Your security team scanned your production container fleet with Grype and Trivy, flagging over 2,400 Common Vulnerabilities and Exposures (CVEs) across utility packages like `bash`, `curl`, `openssl`, `libcrypto`, and `coreutils` bundled inside base images. None of these packages are needed by your compiled application runtimes. The CISO mandates a zero-CVE policy. You must migrate your Go, Node.js, and Java applications to Google Distroless and Scratch base images, resolving static binary dependencies while providing tools for production debugging.
Eliminate CVE attack surfaces by migrating application containers from Ubuntu/Debian/Alpine to Google Distroless and Scratch. Handle glibc/musl linking, TLS certificates, timezone data, and ephemeral debugging.
Want to master this scenario in a live sandbox? KodeKloud's Docker Certified Associate (DCA) Hands-On Lab Course covers this exact problem with hands-on terminal drills.
🛠️ Production Runbook & Step-by-Step Resolution
Analyze the Security Anatomy of Distroless vs Alpine vs Debian
Evaluate attack surfaces: Debian base images contain ~100 packages, a shell, and package manager. Alpine contains musl libc and `apk`. Google Distroless contains strictly your application runtime and minimal shared libraries (glibc, libssl) without a shell, package manager, or system utilities.
Base Image Comparison:
- debian:bookworm-slim -> ~80MB, Package Manager: YES, Shell: YES, CVEs: 15-40
- alpine:3.19 -> ~7MB, Package Manager: YES, Shell: YES, CVEs: 1-5 (musl libc issues)
- gcr.io/distroless/static-debian12 -> ~2MB, Package Manager: NO, Shell: NO, CVEs: 0
- scratch -> 0MB, Package Manager: NO, Shell: NO, CVEs: 0
Configure Static Linking and Library Dependencies
When compiling Go, Rust, or C++ binaries for `scratch` or `distroless/static`, ensure all libraries are statically compiled without dynamic linking against host C libraries (`glibc`).
# Go static build flags
CGO_ENABLED=0 GOOS=linux go build -a -ldflags '-extldflags "-static"' -o /app/server .
# Verify binary has no dynamic library dependencies
file /app/server
# Output: ELF 64-bit LSB executable, x86-64, dynamically linked -> INVALID FOR SCRATCH!
# Correct Output: ELF 64-bit LSB executable, x86-64, statically linked, stripped
Bundle Critical System Assets (CA Certs and Zoneinfo)
Scratch images lack root certificates and timezone databases. If your application verifies HTTPS certificates or parses local times, copy `/etc/ssl/certs/ca-certificates.crt` and `/usr/share/zoneinfo` from the builder stage.
FROM golang:1.22-alpine AS builder
RUN apk add --no-cache ca-certificates tzdata
WORKDIR /src
COPY . .
RUN CGO_ENABLED=0 go build -o /bin/app .
FROM gcr.io/distroless/static-debian12:nonroot
COPY --from=builder /etc/ssl/certs/ca-certificates.crt /etc/ssl/certs/
COPY --from=builder /usr/share/zoneinfo /usr/share/zoneinfo
COPY --from=builder /bin/app /app
USER nonroot:nonroot
ENTRYPOINT ["/app"]
Debug Shell-less Distroless Containers in Production
Because Distroless containers lack `sh` or `bash`, running `docker exec -it
# Debug a running distroless pod in Kubernetes without altering the image
kubectl debug -it pod/payment-api-7b89d-4x8w \
--image=busybox:musl \
--target=payment-api \
-- sh
# Or run distroless debug variant in local Docker
# FROM gcr.io/distroless/base-debian12:debug
- W
- e
- e
- l
- i
- m
- i
- n
- a
- t
- e
- d
- t
- h
- o
- u
- s
- a
- n
- d
- s
- o
- f
- c
- o
- n
- t
- a
- i
- n
- e
- r
- v
- u
- l
- n
- e
- r
- a
- b
- i
- l
- i
- t
- y
- a
- l
- e
- r
- t
- s
- b
- y
- m
- i
- g
- r
- a
- t
- i
- n
- g
- o
- u
- r
- w
- o
- r
- k
- l
- o
- a
- d
- s
- t
- o
- G
- o
- o
- g
- l
- e
- D
- i
- s
- t
- r
- o
- l
- e
- s
- s
- a
- n
- d
- S
- c
- r
- a
- t
- c
- h
- .
- B
- y
- s
- t
- r
- i
- p
- p
- i
- n
- g
- o
- u
- t
- p
- a
- c
- k
- a
- g
- e
- m
- a
- n
- a
- g
- e
- r
- s
- a
- n
- d
- s
- h
- e
- l
- l
- s
- ,
- a
- t
- t
- a
- c
- k
- e
- r
- s
- c
- a
- n
- n
- o
- t
- e
- x
- e
- c
- u
- t
- e
- s
- h
- e
- l
- l
- p
- a
- y
- l
- o
- a
- d
- s
- o
- r
- d
- o
- w
- n
- l
- o
- a
- d
- c
- u
- r
- l
- b
- a
- c
- k
- d
- o
- o
- r
- s
- .
- W
- h
- e
- n
- p
- r
- o
- d
- u
- c
- t
- i
- o
- n
- t
- r
- o
- u
- b
- l
- e
- s
- h
- o
- o
- t
- i
- n
- g
- i
- s
- r
- e
- q
- u
- i
- r
- e
- d
- ,
- w
- e
- a
- t
- t
- a
- c
- h
- e
- p
- h
- e
- m
- e
- r
- a
- l
- d
- e
- b
- u
- g
- c
- o
- n
- t
- a
- i
- n
- e
- r
- s
- w
- i
- t
- h
- `
- k
- u
- b
- e
- c
- t
- l
- d
- e
- b
- u
- g
- `
- w
- i
- t
- h
- o
- u
- t
- m
- o
- d
- i
- f
- y
- i
- n
- g
- t
- h
- e
- h
- a
- r
- d
- e
- n
- e
- d
- r
- u
- n
- t
- i
- m
- e
- i
- m
- a
- g
- e
- .