What exactly belongs inside a production container?
Every team seems to draw this line differently. Shells, curl, package managers, debug tools — some keep them, some strip everything.
Where do you draw the line, and why?
Every team seems to draw this line differently. Shells, curl, package managers, debug tools — some keep them, some strip everything.
Where do you draw the line, and why?
Only the app and its runtime deps. Debugging happens with ephemeral debug containers now, so baking tools in is mostly habit.
That works on Kubernetes. On plain Docker hosts people still exec in and expect a shell.
CA certificates and timezone data get forgotten more than anything. Small, but they break things in production.
I'd add: a non-root user, a read-only root filesystem where possible, and an explicit STOPSIGNAL if your process doesn't handle SIGTERM. That last one causes so many slow 30-second shutdowns that people blame on Kubernetes.
Everything else — curl, vim, bash — I'd rather get from kubectl debug when I actually need it.