Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Build distroless package for better security, smaller size, speed and more

Open
#448 4 comments 0 reactions 1 assignee View on GitHub

@imaffe is already working on this.

Since Oct 24, 2022.

Assessment

This issue has not been assessed yet.

Description

compute/serverless type/feature

As proofed in practice and documented in https://github.com/streamnative/function-mesh/issues/371
there are sometimes (often!) security problems in a container/package whose origin is not the software one build, but in the software which is also situated in this container.

In most cases, there is no use case for this additional software.
This is where the idea of distroless containers comes in and "free" your software:

  1. for better security
  2. fewer bugs
  3. smaller packages
  4. a faster build process
  5. a faster check process (e.g. security scans for CVEs and CWEs)
  6. faster, cheaper and less annoying development process, because of less noise to understand and fix
  7. faster spin-up / faster dynamic scaling on load
  8. less demanding for needed infrastructure = less cost for infrastructure to run on
  9. ...

Traditional, this approach is somehow strenuous to implement and associated with restrictions.

But it looks like 2 new tools makes it pretty easy and straight forward:

good overview on distroless containers
https://dev.to/dansiviter/distroless-alpine-ci8
and
https://blog.chainguard.dev/minimal-container-images-towards-a-more-secure-future/
see last paragraph for how it works

the tools:
source to abk:
https://github.com/chainguard-dev/melange

abk to oci:
https://github.com/chainguard-dev/apko

to debug distroless containers:
official: https://kubernetes.io/docs/concepts/workloads/pods/ephemeral-containers/
detail flow: https://iximiuz.com/en/posts/kubernetes-ephemeral-containers/

Dominant language
Go
Stars
228
Forks
30
Avg merge
2d 8h
Merged PRs (30d)
2

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from streamnative/function-mesh

All issues in streamnative/function-mesh

Similar issues

More Go issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.