Hands-on Lab·Certified Kubernetes Security Specialist
Minimizing the Base Image Footprint
The first supply-chain competency is the one with the best return: most of what a scanner finds in your image was never yours. This guide measures four base images the same way, looks at what the findings actually are, and is honest about what a minimal image costs you.
Supply Chain Security Guide 25 of 40 Intermediate
- Kubernetesapiserver v1.36.4, kubelet v1.36.3
- Runtimecontainerd 2.2.6
- CNICilium 1.18.1 - tunnel/VXLAN, with Hubble relay and UI
- Host OSUbuntu 26.04 LTS, kernel 7.0.0-29
- Built withkubeadm v1.36.3 - podSubnet 10.244.0.0/16, serviceSubnet 10.96.0.0/12
- TimeAbout 16 min
- Reviewed25 August 2026
Written against the versions above. Trivy 0.73.0, installed on the cluster. Component counts come from a CycloneDX SBOM and finding counts from the vulnerability scan, so both are the scanner's own numbers.
| Server Name | IP Address | OS | Roles | CPU | RAM | HDD |
|---|---|---|---|---|---|---|
| CKA6001 | 192.168.0.46 | Ubuntu 26.04 LTS | Control Plane Node (tainted NoSchedule) | 2 Core | 4 GB | 50 GB |
| CKA6001-NODE01 | 192.168.0.47 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
| CKA6001-NODE02 | 192.168.0.48 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
Before you start
- guide 8 - the same discipline, one layer up.
-
Four base images, measured the same way
-
What the findings in the largest one actually are
-
The trade you are making