← all discussions

What exactly belongs inside a production container?

mhmhoffman7 hours ago4 replies

Every team seems to draw this line differently. Shells, curl, package managers, debug tools — some keep them, some strip everything.

Where do you draw the line, and why?

Discussion

srsre_lena6 hours ago

Only the app and its runtime deps. Debugging happens with ephemeral debug containers now, so baking tools in is mostly habit.

Reply
mhmhoffman5 hours ago

That works on Kubernetes. On plain Docker hosts people still exec in and expect a shell.

Reply
cocoldboot4 hours ago

CA certificates and timezone data get forgotten more than anything. Small, but they break things in production.

Reply
vmvmkernel3 hours ago

I'd add: a non-root user, a read-only root filesystem where possible, and an explicit STOPSIGNAL if your process doesn't handle SIGTERM. That last one causes so many slow 30-second shutdowns that people blame on Kubernetes.

Everything else — curl, vim, bash — I'd rather get from kubectl debug when I actually need it.

Reply