Sign inSign up

detoxd/alpine

By detoxd

•Updated 6 months ago

Image
0

1.5K

detoxd/alpine repository overview

⁠Alpine Linux - Detoxd Hardened Image

⁠Overview

Alpine Linux is a security-oriented, lightweight Linux distribution based on musl libc and busybox. Created in 2005, Alpine is known for its exceptionally small footprint (~5MB base image) and security features, making it the de facto standard for minimal Docker images.

⁠Common Use Cases

  • Base Images - Foundation for application containers
  • Microservices - Minimal resource footprint
  • Security-Focused Containers - Default security features
  • CI/CD Runners - Fast image pull times
  • Edge Computing - Constrained environments
  • Embedded Systems - Limited storage/memory

⁠Security Features (Built-in)

Alpine Linux includes several security features by default:

  • musl libc - Lighter, cleaner implementation than glibc
  • Stack-Smashing Protection - Compile-time buffer overflow protection
  • Position-Independent Executables - ASLR support
  • No glibc vulnerabilities - Different codebase, different bugs
  • Minimal attack surface - Only essential packages

⁠Security Concerns

Even minimal images have risks:

  • Outdated Packages - Old versions with known CVEs
  • Shell Access - busybox provides many utilities
  • Root User - Default operation as root
  • Setuid Binaries - Privilege escalation vectors
  • Unnecessary Users - Legacy system accounts

⁠What Detoxd Does

⁠Package Updates
  • Updates all packages to latest versions via apk upgrade
  • Removes package cache to minimize image size
⁠Setuid/Setgid Removal

Removes special permissions from ALL binaries:

find / -perm /6000 -type f -exec chmod a-s {} \;

This prevents privilege escalation through:

  • /bin/su
  • /usr/bin/passwd
  • /bin/ping
  • Any other setuid binaries
⁠User Cleanup

Removes unnecessary system accounts:

  • games - Legacy gaming account
  • news - Usenet news account
  • uucp - UUCP services
  • proxy - Proxy services
  • www-data - Web server (if not needed)
  • list - Mailing list
  • irc - IRC services
  • gnats - Bug reporting
⁠File Cleanup
  • Removes cron directories and configurations
  • Removes init scripts and runlevels
  • Cleans temporary files
  • Secures file permissions
⁠Create Non-Root User
FROM detoxd/alpine:3.21-detox.1

# Create application user
RUN adduser -D -H -u 1000 -s /sbin/nologin appuser

# Set working directory
WORKDIR /app

# Copy application files
COPY --chown=appuser:appuser . .

# Switch to non-root user
USER appuser

CMD ["/app/myapp"]
⁠Read-Only Filesystem
docker run --read-only \
    --tmpfs /tmp:rw,noexec,nosuid \
    detoxd/alpine:3.21-detox.1
⁠Drop Capabilities
docker run --cap-drop=ALL \
    --security-opt=no-new-privileges:true \
    detoxd/alpine:3.21-detox.1
⁠Minimal Shell Access
# Remove shell if not needed
RUN rm -rf /bin/sh /bin/ash /bin/busybox 2>/dev/null || true

⁠Comparison with Standard Alpine

FeatureStandard AlpineDetoxd Alpine
Setuid binariesPresentRemoved
Legacy usersPresentRemoved
Package cachePresentRemoved
CronConfiguredRemoved
Init scriptsPresentRemoved
CVE patchesManualApplied

⁠References

Tag summary

Content type

Image

Digest

sha256:b0effd523…

Size

3.7 MB

Last updated

6 months ago

docker pull detoxd/alpine:3.23.3-detox.1