Panda Layer

For platform engineering teams

Koala Base Container Images

Drop-in replacement with a familiar Debian-like toolchain. Built with precise SBOM control for security and transparency.

The Minimal Container Dilemma

While Hardened distroless container images may have been a much talked about buzzword in the last few years, changing your infrastructure to move to hardened images has been a hard challenge across the industry.

Primary challenge stems from the lack of familiarity with newer toolchain (most hardened images are built on some fork of alpine ↗) and/or missing toolchain to work with base container images (in case of distroless ↗).

KoalaLab understood these issues and tackled on modernising legacy linux distro(debian) for a container-first design to provide same security(of distroless containers) with a familiar toolchain(apt) ↗

Understanding the container bloat problem

KoalaLab started with understanding where the container bloat stemmed from & those issue came from

1

Bloated Package Universe

Debian's package creation includes unnecessary maintainer scripts

2

Package Manager Footprint

APT leaves behind significant overhead

3

Non-Essential "Essentials"

Many packages marked as essential aren't actually needed in containers

This bloat creates a larger attack surface with more CVEs, while consuming extra resources and slowing deployments.

Container Bloat Problem Diagram

Koala's container-first approach, reimagined Debian for a container-first world:

Bootstrapped Debian-like Distro

Created with only essential base packages

DebFlow

Modernized OSS deb package creation process

Minimal Package Universe

Proprietary repository where all packages are minimal by design

C(APT)ain

A portable Go-based package manager that's fully compatible with Debian

Optimized Container Creation

Using the bootstrapped distro and minimal package universe

How It Works

Customize your image. Your way

The combination of C(APT)ain & minimal package universe allows for a very precise control over the SBOM of the containers; enabling security and allowing for custom use-cases when required.

Koala's enterprise plans offer C(CAPT)ain and our minimal package universe along with the Hardened "out-of-the-box" base container images. This combination helps with any enteprise-centric custom use-case your teams might have.

Engineering container security.
from first principles

From OpenSSF to top security podcasts, hear how we built 0-deb
to reimagine secure containers.

Need a good headline here

Ready to onboard your enteprise onto koala's hardened container images. Ready to onboard your enteprise onto koala's hardened container imagesReady to onboard your enteprise onto koala's hardened container images

Ask, plug in, collaborate

Let us know how we can help you reduce CVEs, meet compliance, and ship safer code.

Let's chat. Click here to grab a quick slot and we'll take it from there.
Contact illustration