Minimus container images are now free

(images.minimus.io)

111 points | by dimastopel 6 hours ago

18 comments

  • charukiewicz 5 hours ago

    Completely blocking the image information page to mobile user agents is completely unnecessary. I'd much rather look at your non optimized page than be told to come back on desktop.

    Moreover, even after switching to desktop mode on my phone, there's nothing I see that precludes you from employing a little bit of CSS to make those pages render more nicely on mobile screens.

    • hobofan 6 hours ago

      Asking the very obvious question (as it's not apparent from the website): Why would I use this over DHI (Docker Hardened Images) or Chainguard Images, both of which also have a set of free hardened images?

      • indigodaddy 37 minutes ago

        I'm interested in using these images on exe.dev. exe supports any oci images and stands it up as a microvm, in which it would be used non-ephemerally from that point. I'm assuming the images don't have any rc/services. How hard would it be to pull that back in after image deployment? (Also looks like I'd want to use the -dev images which include shell/apk, etc)

        • euph0ria 24 minutes ago

          Thank you for this! Super valuable for contribution to all businesses. Suppose I want to add a custom PHP extension such as NewRelic, how would I go about adding that on your distroless images?

          • csnoob 19 minutes ago

            Is the cli open source? What about the images themselves?

            An easy comparison is wolfi, which is completely open source.

            • zufallsheld 5 hours ago

              Where are these built? Can I see the Dockerfiles? How are they licensed? I get that they are free as in beer, but not libre/FLOSS?

              • NoNameProvided 1 hour ago

                In the risk reduction tab, it should compare the vulnerability count against the node-slim image. In my eyes, it takes away from the offering when they try to prop up the vuln count for the official images, and nobody deploys `node:latest`.

                • biimugan 2 hours ago

                  What's the availability story? Docker Hub has pretty severe rate-limiting even if you're not an anonymous user.

                  • cedws 5 hours ago

                    Since we started paying for Chainguard I’ve become super sold on the benefits of minimal and continually patched images. It’s just a shame that the open source community only gets to benefit from the limited free library DHI and Chainguard offer. I understand it costs money though and that needs to come from somewhere.

                    • morellonet 6 hours ago

                      John here (CTO and Co-Founder)… we’d be happy to answer any questions anyone has!

                      • figassis 5 hours ago

                        The free tiers always go away, after they're deep in our infra. I would prefer to price it from the start.

                        • crabique 5 hours ago

                          Is their ingress-nginx-controller image similar to that of Chainguard: a drop-in replacement with the CVEs fixed?

                          • 2OEH8eoCRo0 4 hours ago

                            Supply chain attack waiting to happen

                            • alfanick 4 hours ago

                              I truly don't get this. What is the security policy here? Why should I trust images built by minimus.io? How do I know they don't contain malicious software? What's the point?

                              • concerned_ctzn 4 hours ago

                                good job!

                                • tuananh 4 hours ago

                                  this space is too crowded now. everyone is copying whatever Chainguard is doing

                                  - Chainguard Images

                                  - Chainguard Libraries

                                  - Chainguard VM

                                  ...

                                  • tamimio 4 hours ago

                                    I have no idea what the heck is this, maybe it’s a great product but a very poor website in telling what I am getting into, is this better than the usual containers? How? Supported platforms? Can I run it on arm? The usuals

                                    • qwer123vbtf 6 hours ago

                                      noice!