/performing-container-image-hardening
Harden container images by reducing attack surface, enforcing non-root and immutable runti.
Harden container images by reducing attack surface, enforcing non-root and immutable runtime constraints, and validating security posture with repeatable checks.
Category
Security
Execution
8 steps, sequential + gated
Goal
Harden container images by reducing attack surface, enforcing non-root and immutable runtime constraints, and validating security posture with repeatable checks.
Scope
Applies to
- +Harden container image for production
- +Reduce image CVE surface
- +Apply non-root/read-only/container hardening best practices
Does not cover
- −Trivial changes outside the workflow domain
Triggers
"Harden container image for production""Reduce image CVE surface""Apply non-root/read-only/container hardening best practices""Implement multi-stage secure Docker builds"
Inputs
- →Context: environment/system affected
- →Scope: change boundary
- →Constraints: policy or hard rules
Invariants
- 01Production images must avoid unnecessary packages and tooling.
- 02Images must run as non-root unless explicitly justified.
- 03Base images should be pinned by digest for reproducibility and trust.
- 04Security validation must include vulnerability and configuration checks.
- 05Hardening cannot break application runtime requirements without mitigation plan.
Procedure
- Step 1Step 1 — **Assess current image posture**
- Step 2Step 2 — **Apply multi-stage build design**
- Step 3Step 3 — **Minimize runtime footprint**
- Step 4Step 4 — **Enforce identity and privilege controls**
- Step 5Step 5 — **Apply filesystem and process hardening**
- Step 6Step 6 — **Pin trust anchors**
- Step 7Step 7 — **Validate hardening outcomes**
- Step 8Step 8 — **Publish hardening report**
Outputs
- ▸Hardened Dockerfile/image build spec.
- ▸Before/after hardening report (size and vulnerability delta).
- ▸Validation evidence for non-root, filesystem policy, and scanner results.
- ▸Residual risk register with follow-up actions.
Review Gate
- [ ]Final image uses minimized trusted base strategy.
- [ ]Non-root and least-privilege settings are enforced.
- [ ]Read-only/root-hardening controls are validated where applicable.
- [ ]Vulnerability/config checks meet policy thresholds.
- [ ]Hardening changes preserve required application behavior.