Hardening a Container Image thumbnail

Hardening a Container Image

By Richard Augenti

Take a bloated application image that runs as root and rebuild it as a minimal, non-root, reproducible image, measuring the vulnerability count at every step.

Browse
Skill Level: Beginner Duration: 45 min ContainersDevSecOps
Sign in to start

Free to browse. Takes about 45 minutes once you start.

Lab Overview

The receipts-api service ships a container built from python:3.12, running as root, with the entire build toolchain baked into the production image.

In this lab you measure that image's attack surface, rewrite the Dockerfile as a minimal non-root multi-stage build, and then prove the surface actually shrank: fewer vulnerabilities, no shell, no root, and no ability to write outside its own directory. Hardening you cannot measure is hardening you are guessing at.

Docker builds run locally on your lab machine and Trivy runs as a container. Nothing is pushed anywhere and no registry credentials are involved.

What to Expect

  • Environment: a single Ubuntu machine you connect to over SSH, with Docker installed and the application repository in place. Trivy runs as a container. No cluster required.
  • Access: SSH credentials are generated for your session and shown in the workspace. They are destroyed when the lab ends.
  • Timing: verify.sh builds the image as part of checking your work, so it takes longer than a plain check.
  • Progress: your work is not saved. If the lab expires or you quit, the machine and everything on it is destroyed.

What are hands-on labs?

A lab is a real environment, not a simulation. You get a live machine with the tooling already installed, a task taken from production work, and root access to take it apart. Nothing is mocked, nothing is multiple choice. It either works or it doesn't.

Real tooling

The same commands you would run at work, on a machine that is already set up for them. No screenshots, no sandboxed toy version.

Break it freely

Everything is disposable. When the clock runs out the environment is destroyed with everything in it, so there is no reason to be careful.

Useful on Monday

Built by engineers who run these systems in production. Skills you can apply to your own stack the same week, not exam preparation.

Browse labs