2026-07-21

Cut bloat, not features: accelerating software delivery with minimal OCI images

Learn how to minimize container footprints without compromising traceability

Register now

For independent software vendors (ISVs), shipping software efficiently means minimizing container footprints to reduce attack surfaces, speed up deployments, and lower infrastructure overhead. However, achieving this has traditionally forced a difficult compromise. Standard container images carry heavy OS dependencies that trigger endless, irrelevant vulnerability alerts. Conversely, popular “distroless” alternatives strip away the OS package manager entirely. While this reduces size, it omits package metadata, resulting in security scanner blind spots, failed customer compliance audits, and severe visibility roadblocks for security teams.

You shouldn’t have to choose between a lean deployment and enterprise-grade traceability. Canonical provides a better path forward with rocks: minimal, OCI-compliant images that deliver the ultra-small footprint of distroless containers while strictly preserving package metadata for accurate CVE scanning.

Join Canonical for our webinar on crafting OCI-compliant, minimal container images.

Discover how Canonical’s Chisel and Rockcraft tooling enables teams to seamlessly deliver distroless-like images without compliance tradeoffs.

Learn about:

  • Chisel: How to slice your way to creating compact, highly secure software by removing everything except exactly what your application needs
  • Technical demo: A live look at our engineers using Chisel and Rockcraft to craft minimal container images
  • The Ubuntu Pro promise: How enterprises can guarantee long-term container security, compliance, and stability backed by Ubuntu Pro

Featuring Canonical speakers Alex Santisteban Corchos, Giulia Lanzafame, Lily Rivers-Klee, and Marcin Konowalczyk.

Learn more about Canonical containers

You can build your own rock, check it out!