Starting in decK v1.65.2, the official kong/deck Docker image uses a distroless base.
This keeps the image small, but the container doesn’t have a shell or package manager.
If these are required, you can build your own image using the steps in this guide.
deck is a CGO_ENABLED=0 static Go binary with no glibc or musl dependency, so you can copy it onto any base image without recompiling anything.
A non-distroless image reintroduces a shell and a package manager into a container that frequently carries Konnect or Kong Gateway admin credentials. That widens the attack surface available to anything that gets code execution inside the container, so prefer the stock distroless image unless you specifically need a shell.