Scratch vs. Distroless Images
Question Variations
- "What is a 'distroless' image, and why would you use one?"
- "What is the `scratch` base image, and what kind of applications can use it?"
- "How do minimal base images improve the security posture of a container?"
- "What are the challenges of debugging an application running in a distroless container?"
Why This Is Asked
This is a deep-dive question into container security and optimization. It tests if the candidate knows how to build “enterprise-grade” images that are not just small, but also hardened against common attacks by removing every unnecessary binary.
Key Concepts
- Attack Surface: How removing shells and package managers improves security.
- Static vs. Dynamic Linking: Why
scratchonly works for some languages. - Debugging: The trade-off between security and ease of troubleshooting.
- CA Certificates: A common pitfall when using ultra-minimal images.
Question Variations
- “What is a ‘distroless’ image, and why would you use one?”
- “What is the
scratchbase image, and what kind of applications can use it?” - “How do minimal base images improve the security posture of a container?”
- “What are the challenges of debugging an application running in a distroless container?”