What to build on.
WHAT THE OPTIONS ARE
A full distribution image A slim variant of one A minimal distribution built for size A distroless image with only the runtime Building from nothing, for compiled binaries
WHAT A FULL DISTRIBUTION PROVIDES
Familiar tools, and packages available.
WHAT IT COSTS
Hundreds of megabytes, and many packages to keep patched.
WHAT SLIM VARIANTS REMOVE
Documentation and rarely used packages.
WHAT MINIMAL DISTRIBUTIONS PROVIDE
Very small images.
WHAT THEY COST
A different standard library in some cases, causing subtle incompatibilities.
WHY THAT MATTERS
Compiled dependencies built for one may not run on the other.
WHAT THE SYMPTOM IS
A binary that will not execute, or crashes oddly.
WHAT TO DO ABOUT IT
Build inside the same base you deploy on.
WHAT DISTROLESS PROVIDES
Only the runtime: no shell, no package manager.
WHAT THAT ACHIEVES
A very small attack surface.
WHAT IT COSTS
Debugging without a shell.
WHAT TO PAIR IT WITH
A debug variant, or ephemeral debug containers.
WHAT TO CHOOSE
The official image for your runtime, slim, at a pinned version.
WHY THAT IS THE SENSIBLE DEFAULT
It balances size, familiarity and maintenance.
WHAT TO REVISIT
The choice, once the application is stable.