βNEW JOB OPPORTUNITIES
- βJunior DevOps Engineer, Remoteβ
- βJunior DevOps Engineer, Hybridβ
- βDevOps Engineer, Microsoft, Remoteβ
For more opportunities, click here to open the full post (free)
βFROM BLOATED TO BULLETPROOF
β
When I scanned one of my early Python containers, I nearly spit out my coffee:
π 750+ low, 500+ medium, 93 high, and 5 critical vulnerabilities.β
And the image was over 1GB.
Just by changing the base image, I eliminated 99% of those vulnerabilities. But I didnβt stop there.
What follows is a concise guide to optimize your container images for security and size.
β
π§ 1. Choose the right base image
β
Most devs reach for python:latest out of habit. But that image is bloated and loaded with vulnerabilities.
Switching to python:3.13-alpine dropped our image to ~113MB and removed hundreds of CVEs instantly.
*Itβs not always possible to use Alpine, but you should always try.*β
πͺ 2. Use multi-stage builds for clean final images
β
We install everything in a separate stage, then copy only the runtime environment: no pip, no cache, no bloat.
This technique slashed build time, cut attack surface, and made our containers production-ready.
(We deep-dive this in the masterclass with examples.)
β
π οΈ 3. Run only what you need
β
I recommend using UV to manage your packages in Python. By building your Python package using uv sync you can keep it very lean by excluding development dependencies.
Finally, you just copy the .venv into your final image:
COPY –from=builder –chown=app:app /app/.venv /app/.venvOur final image includes just the binary and dependencies. No package managers, no tooling.
That one move cut dozens of MBs and made our security scanner smile.
β
π‘ Final Result:
- β 55MB image (down from 1GB)
- β 99% fewer CVEs
- β Faster deploys, reduced cloud costs, hardened containers
βIf youβre building for production, this is the standard.
β
If you only include exactly what you need at run time, you reduce your attack surface and the image size. This leads to more secure deployments and much faster deployment times. I go much deeper into many more of these techniques in my new DevOps Masterclass. Click here if you want to learn more. β
β
That’s it for this week.
Keep automating,
β
Mischa
βP.S. Donβt just learn Docker tricks, master the entire pipeline. Inside KubeCraft, Iβll show you how to build a complete, production-grade CI/CD system based on GitOps. From code to cluster.
β βπ βClick here to join and start building it todayβ
β
β
β
β