← All images

kong Web Servers & Proxies

Kong API Gateway built on Nginx and OpenResty.

Arch x86_64, aarch64 User kong (65532) Upstream konghq.com

Pull this image

docker pull ghcr.io/rtvkiz/minimal-kong:latest

Details

Repository
ghcr.io/rtvkiz/minimal-kong
Architectures
x86_64, aarch64
Primary package
kong

Some data was unavailable for this build: partial.

Entrypoint
/usr/local/bin/kong start --prefix /usr/local/kong
User
kong (65532)
Working dir
/usr/local/kong
Architectures
x86_64, aarch64
Environment
PATH=/usr/local/bin:/usr/bin:/binLD_LIBRARY_PATH=/usr/local/openresty/luajit/libKONG_PREFIX=/usr/local/kongKONG_DATABASE=offKONG_NGINX_DAEMON=off
Labels
org.opencontainers.image.titleminimal-kong
org.opencontainers.image.descriptionHardened shell-less Kong API Gateway built on Wolfi with CVE patches on every rebuild
org.opencontainers.image.urlhttps://github.com/rtvkiz/minimal
org.opencontainers.image.sourcehttps://github.com/rtvkiz/minimal/tree/main/images/kong
org.opencontainers.image.licensesApache-2.0
TagPullPublished
3 ghcr.io/rtvkiz/minimal-kong:3 2026-09-29
3.9 ghcr.io/rtvkiz/minimal-kong:3.9 2026-09-29
3.9.2-r1 ghcr.io/rtvkiz/minimal-kong:3.9.2-r1 2026-09-29
3.9.2-r1-20260929 ghcr.io/rtvkiz/minimal-kong:3.9.2-r1-20260929 2026-09-29
latest ghcr.io/rtvkiz/minimal-kong:latest 2026-09-29
3-dev ghcr.io/rtvkiz/minimal-kong:3-dev 2026-09-29
3.9-dev ghcr.io/rtvkiz/minimal-kong:3.9-dev 2026-09-29
3.9.2-r1-20260929-dev ghcr.io/rtvkiz/minimal-kong:3.9.2-r1-20260929-dev 2026-09-29
3.9.2-r1-dev ghcr.io/rtvkiz/minimal-kong:3.9.2-r1-dev 2026-09-29
latest-dev ghcr.io/rtvkiz/minimal-kong:latest-dev 2026-09-29

The resolved SBOM isn't available for this build yet — showing the packages requested in the apko build recipe (without resolved versions). The full SBOM appears after the next scheduled build.

wolfi-baselayoutkongcoreutilsbusyboxca-certificates-bundle

No scan data for this build. Advisories appear after the next scheduled CVE scan.

Everything is verifiable without an account. Copy and run:

Build provenance (SLSA v1.0, Build L2)

gh attestation verify oci://ghcr.io/rtvkiz/minimal-kong:latest --owner rtvkiz

Cosign signature

cosign verify \
  --certificate-identity-regexp='https://github.com/rtvkiz/minimal/' \
  --certificate-oidc-issuer='https://token.actions.githubusercontent.com' \
  ghcr.io/rtvkiz/minimal-kong:latest

SBOM attestation (SPDX)

cosign verify-attestation --type spdxjson \
  --certificate-identity-regexp='https://github.com/rtvkiz/minimal/' \
  --certificate-oidc-issuer='https://token.actions.githubusercontent.com' \
  ghcr.io/rtvkiz/minimal-kong:latest \
  | jq -r '.payload | @base64d | fromjson | .predicate'

Signatures are logged in the public Rekor transparency log.

More Web Servers & Proxies images

Weighing this against another provider? The comparison pages publish head-to-head scan data with the raw dataset, including the images where Minimal comes off worse — or read the migration guide for what actually breaks when you switch.