This repo intents to provide a general way to create minimal docker containers. By reducing the amount of software included in a container image, the container is less susceptible to attacks. Plus, a small container requires less storage and downloads faster.
There is a subdirectory for each minimal container image. Each subdirectory includes these files:
| File | Purpose |
|---|---|
EXTRA_PACKAGES |
List of extra packages to install |
BINARIES |
List of binaries to copy to final image |
ENTRYPOINT |
The line (or lines) used as ENTRYPOINT (and optionally CMD) for the Dockerfile |
extra_steps.sh |
Extra collection steps needed to make the respective container work |
get_version.sh |
A script that outputs the version of the created container image |
So far there are directories for these containers:
| Directory | Purpose |
|---|---|
| mosquitto | An MQTT server |
| opensshd | The OpenSSH ssh server (sftp-only, key-only, chroot to user's home) |
| opensshd-unpriv | Like opensshd, but running unprivileged (beware of some caveats ) |
| wsddn | Web Service (or Web Socket?) Discovery Daemon (native) - C++ implementation of the WS-Discovery protocol to get rid of NetBIOS |
- First, based on
debian:stable-slimpackages are updated to latest versions andEXTRA_PACKAGES(see table above) are installed. - Then, based on the
BINARIES, the libraries needed for the respective executable are (recursively) searched for and collected, including the dynamic loader library. - As an optional step (using
extra_steps.sh), some additional files are collected (in case of mosquitto,/etc/passwdand/etc/groupare copied, because otherwise mosquitto complains about a missing mosquitto user) or created. - Finally, all collected files are copied into an empty (
scratch) container and the entrypoint and cmd are set according toENTRYPOINT. - Once the image is created (docker automatically tags it as
:latest), theget_version.shscript is executed and the output is used to add another tag with the correct version number.
While I do upload the image(s) to alestrix/minimal-<container> (link to docker hub), I haven't set up a pipeline that
keeps the image(s) updated and by the time you want to use it, I might have abandoned this whole idea and the image could be completely outdated and full of
vulnerabilities.
Therefore, I encourage everyone to build their own images. You shouldn't trust a random guy on the internet anyway!
The created images might not be able to be properly scanned by tools like trivy, grype, or xray as they do not include any package information.