Software security teams can face an overwhelming influx of vulnerability alerts, often stemming from non-essential packages bundled inside traditional container base images. When developers inherit base images packed with unneeded tools, shells, and package managers, security teams end up triaging noise, and developers end up burdened with Common Vulnerabilities and Exposures (CVE) remediations. To ease this friction and help organizations move toward a zero-CVE strategy, container infrastructure requires a purpose-built starting point that cuts away unnecessary attack surface from day one.
To address this challenge and strengthen defense-in-depth across the hybrid cloud, support for Red Hat Hardened Images is live in the AWS InspectorScan API and ECR Basic scanning. By further expanding Red Hat’s collaboration with AWS, we’re delivering a smoother way to verify software supply chain integrity and maintain cleaner security profiles directly within native AWS workflows. Red Hat Hardened Images and AWS scanning gives security and developer teams the flexibility to choose the technology that best fits their project's needs, while strengthening security standards.
Easing workflows for developers and security engineers
Red Hat Hardened Images is a catalog of essential container images built for deployment across vendor-agnostic infrastructure, containing only the specific files required for an application to run. Built using Red Hat’s trusted software pipeline, these pre-hardened images are rigorously tested for operational functionality and optimized to mitigate as many known security vulnerabilities as possible at release. By removing unnecessary software that increases attack surface and security noise, this minimalist approach provides a purpose-built path toward a zero-CVE environment.
Red Hat’s collaboration with AWS addresses the unique needs of both security engineers and developers. Security engineers benefit from a secure-by-default posture, cleaner security scans, faster CVE remediations, and standardized security profiles that support compliance certifications like CIS, STIG, and OpenSCAP. Developers gain freedom of choice across components and versions, easier adoption through drop-in compatibility, and comprehensive documentation.
From build to registry: Layering container security
Amazon ECR Basic scanning is built-in vulnerability detection for container images stored in Amazon Elastic Container Registry (ECR). It uses AWS-native technology sourcing more than 50 data feeds, including vendor security advisories, threat intelligence feeds, and the National Vulnerability Database (NVD), to identify known CVEs in operating system packages. Teams can configure scanning to run automatically on image push or trigger it manually, receiving findings directly within their ECR console and through Amazon EventBridge for downstream alerting and automation.
The AWS InspectorScan API extends vulnerability analysis into CI/CD pipelines and automated build workflows. It accepts a Software Bill of Materials (SBOM)–generated by the Amazon Inspector SBOM Generator from container images, archives, or compiled binaries–and returns a detailed vulnerability report scored with NVD and CVSS ratings. This lets development teams shift security left by scanning images for vulnerabilities during the build process, before they ever reach a registry, enabling gate checks that block insecure images from progressing to production.
Together, these services provide layered coverage. The InspectorScan API catches vulnerabilities early in the pipeline, while ECR Basic scanning provides ongoing detection for images already stored in your registry.
Purpose-built variants for multi-stage builds
Red Hat Hardened Images offers security engineers a minimal attack surface while also giving developers the tooling needed for innovation. By offering distinct image variants, teams can implement multi-stage builds without compromising on compliance or usability.
- Default: The lean, distroless runtime image built for production deployments. It includes no shell or package manager by default, minimizing attack surface while keeping container sizes small.
- Builder: Designed for development and multi-stage build pipelines. It contains package managers and shells to compile code and install build-time dependencies before passing only the final binary into a clean default runtime image.
- FIPS: Designed for regulated environments, enforcing Federal Information Processing Standards (FIPS) 140-2/3 validated cryptography modules when running on FIPS-enabled host clusters.
The Red Hat Hardened Images catalog offers nearly 60 core images and over 150 variants designed to provide a resilient foundation for organizations pursuing zero-CVE strategies. To explore, visit images.redhat.com or the Amazon ECR User Guide.
저자 소개
Red Hat is the world’s leading provider of enterprise open source software solutions, using a community-powered approach to deliver reliable and high-performing Linux, hybrid cloud, container, and Kubernetes technologies.
Red Hat helps customers integrate new and existing IT applications, develop cloud-native applications, standardize on our industry-leading operating system, and automate, secure, and manage complex environments. Award-winning support, training, and consulting services make Red Hat a trusted adviser to the Fortune 500. As a strategic partner to cloud providers, system integrators, application vendors, customers, and open source communities, Red Hat can help organizations prepare for the digital future.
유사한 검색 결과
Red Hat Enterprise Linux Long-Life Add-On: 지원 종료 걱정 없는 RHEL 소개
인프라를 Red Hat Lightspeed에 어떻게 연결해야 할까요?
Can Compliance Be A Piece Of Cake? | Compiler
Scaling with Orchestrators | Compiler
자세히 알아보기
백서: 하이브리드 클라우드 환경을 위한 보안 접근 방식영어 (English) 버전으로 제공됩니다 (한국어 미지원) - 컨테이너와 쿠버네티스 보안에 대한 계층화된 접근 방식
채널별 검색
오토메이션
기술, 팀, 인프라를 위한 IT 자동화 최신 동향
인공지능
고객이 어디서나 AI 워크로드를 실행할 수 있도록 지원하는 플랫폼 업데이트
오픈 하이브리드 클라우드
하이브리드 클라우드로 더욱 유연한 미래를 구축하는 방법을 알아보세요
보안
환경과 기술 전반에 걸쳐 리스크를 감소하는 방법에 대한 최신 정보
엣지 컴퓨팅
엣지에서의 운영을 단순화하는 플랫폼 업데이트
인프라
세계적으로 인정받은 기업용 Linux 플랫폼에 대한 최신 정보
애플리케이션
복잡한 애플리케이션에 대한 솔루션 더 보기
가상화
온프레미스와 클라우드 환경에서 워크로드를 유연하게 운영하기 위한 엔터프라이즈 가상화의 미래