We have been working on tools for safe debloating of software for a few years now at the university. BLAFS is one of our first tools to release for file debloating, a bloat-aware filesystem for container debloating. It detects the files used by the container, and the debloats the container removing the unused files. The debloated containers are fully functional and can run the same workload as the original containers, but with a much smaller size and faster deployment.
Check the paper for more details: https://arxiv.org/abs/2305.04641
Beginning with the Container Security, I suggest NIST Special Publication 800-190 for Container Security to be adopted; "https://csrc.nist.gov/pubs/sp/800/190/final" While NIST publications/standards are extremely recognized and followed in the US, they are considered an industry best practice worldwide.
Thanks, Waleed Waheed. SR Mgr GRC, RSA Security.
reply