← docsSecurity

/performing-container-image-hardening

Harden container images by reducing attack surface, enforcing non-root and immutable runti.

Harden container images by reducing attack surface, enforcing non-root and immutable runtime constraints, and validating security posture with repeatable checks.

Category

Security

Execution

8 steps, sequential + gated

Goal

Harden container images by reducing attack surface, enforcing non-root and immutable runtime constraints, and validating security posture with repeatable checks.

Scope

Applies to

  • +Harden container image for production
  • +Reduce image CVE surface
  • +Apply non-root/read-only/container hardening best practices

Does not cover

  • −Trivial changes outside the workflow domain

Triggers

"Harden container image for production""Reduce image CVE surface""Apply non-root/read-only/container hardening best practices""Implement multi-stage secure Docker builds"

Inputs

  • →Context: environment/system affected
  • →Scope: change boundary
  • →Constraints: policy or hard rules

Invariants

  • 01Production images must avoid unnecessary packages and tooling.
  • 02Images must run as non-root unless explicitly justified.
  • 03Base images should be pinned by digest for reproducibility and trust.
  • 04Security validation must include vulnerability and configuration checks.
  • 05Hardening cannot break application runtime requirements without mitigation plan.

Procedure

  1. Step 1Step 1 — **Assess current image posture**
  2. Step 2Step 2 — **Apply multi-stage build design**
  3. Step 3Step 3 — **Minimize runtime footprint**
  4. Step 4Step 4 — **Enforce identity and privilege controls**
  5. Step 5Step 5 — **Apply filesystem and process hardening**
  6. Step 6Step 6 — **Pin trust anchors**
  7. Step 7Step 7 — **Validate hardening outcomes**
  8. Step 8Step 8 — **Publish hardening report**

Outputs

  • ▸Hardened Dockerfile/image build spec.
  • ▸Before/after hardening report (size and vulnerability delta).
  • ▸Validation evidence for non-root, filesystem policy, and scanner results.
  • ▸Residual risk register with follow-up actions.

Review Gate

  • [ ]Final image uses minimized trusted base strategy.
  • [ ]Non-root and least-privilege settings are enforced.
  • [ ]Read-only/root-hardening controls are validated where applicable.
  • [ ]Vulnerability/config checks meet policy thresholds.
  • [ ]Hardening changes preserve required application behavior.