Kong API Gateway 3.15 Ships Distroless Image
Blog post from Kong
Kong Gateway 3.15 introduces a distroless image variant aimed at addressing security and compliance challenges faced by enterprise customers, particularly in regulated sectors such as government, finance, and healthcare. Traditional container images typically include a full Linux distribution, which can lead to unnecessary vulnerabilities, but Kong's distroless approach minimizes these risks by removing non-essential components, leaving only what's necessary for application execution. Built on Wolfi's apko declarative build system, the distroless image maintains Kong's functionality while reducing the attack surface, as it lacks package managers, shells, and runtime installation capabilities, resulting in significantly fewer CVEs and a more secure environment. The distroless image is compatible with existing workflows, ensuring that Kong's features like routing, TLS termination, and logging integrations remain unchanged, although interactive debugging requires alternative methods due to the absence of a shell. This new variant is available alongside the standard image, offering a secure, efficient, and seamless integration into current deployments.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Observability | 2 | 3,044 | 536 | 154 | -28% |
| Real-time | 1 | 4,246 | 1,018 | 209 | -26% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.