learninfra · Linux · Networking · Kubernetes · System Design · AI Infrastructure · Exam blueprints · Drills

Image Footprint & Scanning (CKS)

Smaller images, scanned images, and manifests checked before they ship.

An interactive Kubernetes lesson: 21 steps, about 35 minutes, on a live simulation in your browser.

The shop's payments api is a small Go program. Its Dockerfile was written in a hurry: start from the official golang image, install a few tools that were handy while debugging, copy the source in, compile.

It works. Two replicas are serving requests from the frontend. Now read the layers on the left. The compiled program is about 14 MB. The image is close to 1 GB.

What you will learn

  1. What is in the image

    • A one-gigabyte api: An image is everything an attacker finds already installed. What your program does not need, only they will use.
    • Whose vulnerabilities are these?: Most CVEs in an image are inherited from its base. Change the base and they leave without a single code change.
  2. A smaller base

    • Build in one stage, ship another: Every FROM is a fresh start. Only what you COPY into the last stage ships.
    • Down the ladder of base images
    • Break it: runAsNonRoot on a root image: runAsNonRoot is an assertion, not a setting. The image, or runAsUser, has to supply the non-root user.
    • Distroless, with a non-root USER: The safest base image is the one with nothing in it that you would not miss.
    • Try to get a shell: An attacker works with the tools in the image. No shell and no package manager means every next step has to be brought in.
    • Pin versions and digests: A tag is a label someone else can move. A digest is the content itself.
  3. Scan, rebuild, rescan

    • What a scan can and cannot see: A scanner compares a package list with a CVE list. Fewer packages, fewer matches, fewer things to patch.
    • Drill: scan an image
    • A new dependency arrives: Your dependencies are part of the image too. A minimal base removes the OS findings, not the ones you compile in.
    • Break it: ship the vulnerable build: Admission judges new pods at the door. It never goes back to check the ones already inside.
    • Rebuild, rescan, redeploy
  4. Know your supply chain

    • An SBOM: the list of ingredients: An SBOM is the ingredients label. You write it once at build time and search it every time a new CVE lands.
    • One road from commit to cluster: Build, scan, record, store, admit. Every image should reach the cluster by that one road and no other.
  5. Check before you ship

    • Lint the Dockerfile: hadolint
    • Score the manifest: kubesec: kubesec turns a manifest into a number. The number matters less than the list of fields it tells you to set.
    • Pass or fail: KubeLinter: Image scanners check what you built. Manifest linters check how you run it. A release needs both to pass.
    • Drill: scan a manifest
  6. Recap & playground

    • Cheat sheet
    • Playground