# Isolated environments for coding agents

Govern agents and Claws across every team

Your AI Agent across Docker

Local-first LLM inference made easy

Connect and manage MCP tools

Ship with secure, enterprise-ready images

Simplify the software supply chain

Containerize your applications

Discover and share container images

Break free of local constraints

Find guides for Docker products

Learn the Docker basics

Search a library of helpful materials

Skill up your Docker knowledge

Create and share your own extensions

Connect with other Docker developers

Explore open source projects

Help shape the future of Docker

Get inspired with customer stories

## Docker Hardened Images

**NOW FREE**

### The new standard for building securely

Minimal and hardened images you can trust.

[Get started with DHI](https://hub.docker.com/hardened-images/catalog) [Try enterprise](https://hub.docker.com/hardened-images/start-free-trial) [Compare plans](https://www.docker.com/products/hardened-images/#compare)

#### Multi-distro compatibility

#### Near-zero CVEs

#### Transparent SBOMs

#### Provenance you can trust

### What makes DHI different

#### Drop-in Adoption

Swap the base image and get instant security gains.

#### Apache 2.0 on Open Distros

You can migrate to and from with freedom and without surprises. Pay when you need stronger SLAs, compliance, or to leverage our build service.

#### Easiest path to secure supply chain

Drop-in replacements that require minimal changes. Our event-driven build system keeps images continuously updated, and secure customization allows you to tailor hardened images without breaking provenance.

#### Built with Docker-Maintained Packages

Every DHI image is built with system packages that Docker builds, patches, and maintains directly from upstream source.

#### Full Transparency

Signed SBOMs and SLSA Level 3 provenance, with complete CVE data.

#### Built for Developers, hardened for security

When upstream stops, your protection continues. Up to 5 extra years of hardened patching, SBOMs and provenance.

## Security that outlasts upstream

When a software version reaches end-of-life, patches stop but vulnerabilities don’t. DHI ELS gives you up to five more years of hardened coverage.

#### CVE patching continues after upstream EOL

#### SBOMs and provenance maintained throughout

#### Covers the images you rely on most: Node, Python, PostgreSQL, and more

## Up and running in seconds

Drop-in migration with minimal workflow changes.

[Documentation](https://docs.docker.com/dhi/) [Browse 1000+ images](https://hub.docker.com/hardened-images/catalog) [Migration guide](https://docs.docker.com/dhi/migration/) [GitHub discussions](https://github.com/orgs/docker-hardened-images/discussions)

“For the first time, I don’t have to worry about what’s hiding in our base images. That mental overhead is gone, and we can finally focus on the security challenges that are unique to Attentive.”  
**Jacob Rickerd**  
Principal Security Engineer at Attentive

## A complete security model

A secure starting point for every developer and a secure, sustainable path forward for organizations operating at scale.

## Free for every developer

Secure, transparent, and no-cost for everyone.

[Start building](https://hub.docker.com/hardened-images/catalog)

#### What’s included:

- Hardened, minimal images
- Near-zero CVEs
- Verifiable SBOMs & SLSA Build L3 provenance
- Full, unsuppressed CVE visibility
- Drop-in adoption, no workflow changes
- Full catalog of open source images under Apache 2.0
- Built with Docker Hardened System Packages
- Upstream cadence for Docker-released patches

## Starting at $5k/repo

Production-ready security with compliance support

#### Everything in community, plus:

- FIPS/STIG variants
- Critical CVE fixes < 7 days with SLA-backed continuous patching
- Up to 5 customizations

## Contact us for pricing

Advanced security controls and unlimited customization

#### Everything in select, plus:

- Unlimited customizations, including system packages
- Access to Hardened System Packages repo
- Full catalog access available
- ELS add-on available
- Extended Lifecycle Support

## FAQ

### What are Docker Hardened Images?

Docker Hardened Images are near-zero CVE, secure-by-default, minimal container images designed to serve as a trusted, verifiable upstream for modern software supply chains. Each image is continuously rebuilt from source, reducing attack surface while patching known CVEs as fixes become available rather than on a manual schedule.

### Are Docker Hardened Images free?

Yes. The full Docker Hardened Images catalog is free and open source under the Apache 2.0 license. Any developer can pull and use hardened images from Docker Hub at no cost, with no usage restrictions.

### What is the difference between DHI Community, DHI Select, DHI Enterprise, and DHI ELS?

- **DHI Community** is free and open under the Apache 2.0 license. It includes the full hardened image catalog with near-zero CVEs.
- **DHI Select** adds SLA-backed CVE remediation (critical fixes within 7 days) and limited image customization.
- **DHI Enterprise** expands on Select with unlimited customization capabilities and eligibility for Extended Lifecycle Support.
- **DHI ELS** provides five additional years of security coverage beyond a software version’s end-of-life.

### What distributions do Docker Hardened Images support?

Docker Hardened Images support both Alpine and Debian, allowing teams to choose the distribution that matches their existing environment.

### How do Docker Hardened Images compare to other hardened image providers?

Docker Hardened Images take a fundamentally different approach by hardening the distributions developers already use rather than requiring migration to proprietary or unfamiliar operating systems.
