Docker Zombie Layers: Why Deleted Layers Can Still Haunt You

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

Unreferenced Docker image layers, known as 'zombie layers', persist in registries even after being removed from a manifest, potentially posing security risks if they contain sensitive data. These layers can linger for weeks before being removed by registry garbage collectors. While tools exist to remove such layers, the persistence of these layers highlights the importance of vigilant monitoring and immediate revocation of exposed secrets.

8m read timeFrom blog.gitguardian.com
Post cover image
Table of contents
TL;DRWhat's inside a Docker image?What if a layer is removed from an image?What happens to the layer that was removed?How long does a zombie layer stay in a registry?Take Away Messages

Sort: