Project Lightning Talk: Project Copacetic - Jeremy Rickard, Maintainer
Jeremy Rickard, Maintainer
KubeCon + CloudNativeCon Europe 2025 · Project Lightning Talk
Overview
In the dynamic and often perilous landscape of cloud-native security, managing vulnerabilities within container images remains a perennial challenge for organizations. Jeremy Rickard, a maintainer of Project Copacetic, delivered a lightning talk at KubeCon EU, introducing a novel approach to this critical problem. Project Copacetic, or Copa, is a BuildKit-based CLI tool designed to directly patch vulnerabilities in container images, circumventing many of the complexities associated with traditional remediation methods.

Key moments
- 0:00 Introduction: Patching CVEs in container images
- 0:20 Copacetic's core mechanism: BuildKit, scanners, patch layers
- 1:10 Two modes of operation: scanner-driven vs. bulk updates
- 2:00 Detailed workflow of generating and applying patch layers
- 2:50 Recent improvements: Alma Linux, scanner plugins, GCHR mirroring
- 4:00 Upcoming features: Multi-architecture and bulk image patching
- 4:25 Where to find more information and connect
Project Lightning Talk: Project Copacetic
Speakers: Jeremy Rickard, Maintainer
Conference: KubeCon EU
YouTube: https://www.youtube.com/watch?v=Q9m7eGoBaMA
Overview
In the dynamic and often perilous landscape of cloud-native security, managing vulnerabilities within container images remains a perennial challenge for organizations. Jeremy Rickard, a maintainer of Project Copacetic, delivered a lightning talk at KubeCon EU, introducing a novel approach to this critical problem. Project Copacetic, or Copa, is a BuildKit-based CLI tool designed to directly patch vulnerabilities in container images, circumventing many of the complexities associated with traditional remediation methods.
The core innovation of Copa lies in its ability to interpret vulnerability scanner reports, identify vulnerable packages, and then generate and apply a new patch layer on top of an existing container image. Crucially, it achieves this without requiring the underlying package management tooling to be present within the container itself, making it particularly effective for distroless containers which are intentionally minimalistic and lack such utilities. This talk highlighted Copa's capabilities, recent advancements, and its burgeoning role as a CNCF sandbox project aimed at streamlining vulnerability management for containerized applications.
The significance of Copa stems from its direct attack on the inefficiencies and security risks posed by unpatched container images. By offering a surgical, automated, and non-invasive method for applying security updates, Copa empowers development and operations teams to maintain a more secure and compliant container environment. Rickard's presentation underscored the project's commitment to addressing a widespread pain point, making container vulnerability remediation faster, more reliable, and less disruptive to existing CI/CD pipelines.
Background
▶ Watch: Introduction: Patching CVEs in container images (0:00)
The proliferation of containers and immutable infrastructure has revolutionized software deployment, offering unparalleled speed, consistency, and scalability. However, this paradigm shift also introduced new security challenges, particularly concerning Common Vulnerabilities and Exposures (CVEs) found within container images. Traditional software patching often involves updating packages within a running system or rebuilding an entire application from source. For container images, especially those deployed in production, both approaches present significant hurdles.
One primary method for addressing vulnerabilities in container images is to rebuild the image from scratch, incorporating updated base layers or package versions. While effective, this process can be time-consuming, resource-intensive, and may break the principle of immutability if not managed carefully within a robust CI/CD pipeline. It also necessitates maintaining a comprehensive build history and ensuring all dependencies are consistently available. Furthermore, the rapid pace of vulnerability discovery means that images can become outdated and vulnerable shortly after deployment, requiring frequent rebuilds that can disrupt development workflows and release cycles.
A specific challenge arises with distroless containers. These lean images are designed to contain only the application and its runtime dependencies, intentionally omitting package managers (like apt or yum), shells, and other utilities commonly found in full operating system distributions. While this significantly reduces the attack surface and image size, it simultaneously renders traditional in-container patching impossible. If a CVE is discovered in a library within a distroless image, the only conventional recourse is to rebuild the entire image with a patched version of the library, which can be a slow process, especially when dealing with a large number of images or urgent zero-day vulnerabilities.
Project Copacetic emerges as a direct response to these limitations. Recognizing the need for a more agile and less disruptive patching mechanism, Copa was conceived to bridge the gap between vulnerability detection and remediation in containerized environments. Instead of rebuilding or modifying the original image's layers, Copa leverages advanced container build technologies to inject necessary updates as a new, distinct layer. This approach maintains the integrity of the original image while applying critical security patches, offering a surgical solution that is particularly advantageous for immutable and distroless container strategies, thereby addressing a long-standing pain point in cloud-native security.
Key Findings
▶ Watch: Two modes of operation: scanner-driven vs. bulk updates (1:10)
Project Copacetic fundamentally redefines how organizations can approach vulnerability management in container images by introducing a direct patching mechanism. The talk highlighted several key findings and capabilities that underpin Copa's innovative approach:
First and foremost, Copa is a BuildKit-based CLI tool that specializes in interpreting vulnerability scanner results. It seamlessly integrates with popular scanning tools like Trivy (its default), Gripe, and Docker Scout, allowing it to parse their reports and pinpoint specific vulnerable packages within a container image. This integration ensures that patching efforts are targeted and efficient, focusing only on identified threats.
A cornerstone of Copa's design is its ability to generate a new patch layer and apply it directly on top of an existing container image. This method is crucial because it avoids the need to rebuild the entire image from scratch, significantly reducing the operational overhead and time associated with vulnerability remediation. This approach maintains the integrity of the original image's lower layers, effectively creating a "patched" version without altering its fundamental structure.
Perhaps one of the most significant contributions of Copa is its support for patching distroless containers. By utilizing the underlying distribution's package manager (e.g., apt for Ubuntu, RPM for Alma Linux) outside the target container and then injecting the updates as a new layer, Copa bypasses the requirement for package management tooling to be present within the distroless image itself. This capability addresses a critical security blind spot for highly minimized container images.
Copa offers two distinct operational modes: a scanner-driven approach, where patches are applied based on specific vulnerability reports, and a broader "update all" mode, which installs all available package updates for the underlying OS, akin to a system-wide upgrade. While the latter is less surgical, it can be useful for maintaining general package hygiene.
Recent improvements to Project Copacetic further enhance its utility and adoption. These include support for Alma Linux, expanding its compatibility with a broader range of RPM-based distributions alongside existing support for Ubuntu and other systems. The introduction of community scanner plugins for tools like Gripe and Docker Scout demonstrates a commitment to ecosystem integration. Other notable enhancements include customizable tag suffix support for patched images (moving beyond the default _patched suffix), mirroring of tooling images to GCHR (GitHub Container Registry) to alleviate Docker Hub rate limits, and better logging support for held packages, providing more granular control over specific package upgrades.
Looking ahead, the project is actively developing features for multi-architecture and bulk image patching. This will significantly improve the developer experience by allowing users to patch multiple images or images across different architectures (e.g., amd64, arm64) with a single Copa command, addressing current limitations where each image and architecture requires a separate run.
Technical Deep Dive
▶ Watch: Detailed workflow of generating and applying patch layers (2:00)
Project Copacetic's technical prowess lies in its intelligent utilization of BuildKit and its understanding of container image layers and underlying operating system package management principles. The tool operates primarily in two distinct modes: a precise, scanner-driven patching approach and a more comprehensive "update all" strategy.
In the scanner-driven mode, the process begins with an external vulnerability scanning tool, such as Trivy, generating a detailed report. This report enumerates specific CVEs and the vulnerable packages associated with them within a target container image. Copa then ingests and parses this report, meticulously identifying the exact packages that require updating.
Once the vulnerable packages are identified, Copa determines the underlying operating system distribution of the container image (e.g., Ubuntu, Alma Linux, other RPM-based systems). It then leverages the appropriate package manager for that distribution – apt (or dpkg) for Debian-based systems like Ubuntu, or RPM for systems like Alma Linux. Crucially, Copa executes these package manager operations outside the target container environment. It fetches the updated versions of the identified packages from their respective repositories.
The core of Copa's innovation then comes into play with BuildKit. BuildKit is a next-generation toolkit for building container images, offering advanced caching, parallel execution, and a flexible frontend. Copa uses BuildKit to construct a new file system layer. This layer is not built by modifying the existing layers of the target image directly. Instead, Copa takes the original image's layers as a base and, within a BuildKit environment, installs the newly fetched, updated packages into this pristine new layer. This process is analogous to creating a new RUN instruction in a Dockerfile that installs updates, but without modifying the original Dockerfile or requiring a full rebuild from the source.
After installing the updated packages into this temporary layer, Copa calculates the difference between the state of the file system with the original vulnerable packages and the state with the newly installed patched versions. This difference is then encapsulated into a brand new patch layer. This patch layer is then stacked on top of the existing layers of the original container image. The result is a new image manifest that references the original base layers plus this newly generated, thin patch layer containing only the security fixes. This ensures that the original image's immutability is respected, and only the necessary changes are applied. For example, if libssl-dev version 1.1.1u was vulnerable and 1.1.1v is available, Copa would install 1.1.1v into the new layer, and this layer would effectively override or supersede the older version present in the lower layers of the image.
The "update all" mode follows a similar technical path but with a broader scope. Instead of relying on a specific vulnerability report, Copa instructs the package manager to look for all available updates for all installed packages in the underlying OS distribution. It then proceeds to fetch and install these updates into a new BuildKit-generated layer, ultimately producing a patched image with all packages brought up to their latest available versions. While less precise, this mode offers a quick way to ensure general package freshness.
The ability to operate without requiring package management tooling within the container itself is a critical technical differentiator. This is achieved because BuildKit allows Copa to mount and manipulate the container's filesystem externally. Copa effectively "pretends" to be the package manager for the target image, performing the update operations in a controlled BuildKit environment and then packaging the results into a new layer. This mechanism is what enables Copa to effectively patch distroless images, which by design lack apt, yum, or apk, making traditional in-container patching impossible.
Copa's support for various distributions like Alma Linux, Ubuntu, and other RPM-based systems underscores its adaptability. The tool intelligently adapts its internal logic to interact with RPM commands, apt-get commands, or other relevant package management binaries based on the detected base image. This makes Copa a versatile tool for diverse container environments.
Demo / Proof of Concept
▶ Watch: Upcoming features: Multi-architecture and bulk image patching (4:00)
While Jeremy Rickard's presentation was structured as a lightning talk and therefore did not include a live, step-by-step demonstration of Project Copacetic in action, the detailed technical explanation and description of its operational modes effectively served as a conceptual Proof of Concept (PoC). The talk outlined the entire workflow, from integrating with vulnerability scanners like Trivy to the final output of a patched container image.
Rickard explicitly mentioned the availability of demos: "If you'd like to talk more about Copa, please come see us at the Project Pavilion kiosk number 20B... We'd love to talk to you, give you some demos and and answer any questions you have." This indicates that functional demonstrations of Copa's capabilities are readily available and showcased at the conference, even if not part of this specific lightning talk. The description of how Copa parses scanner reports, leverages BuildKit to generate new layers, and applies patches to various distributions, including distroless images, provides a clear understanding of its practical application and effectiveness.
Defensive Implications
▶ Watch: Where to find more information and connect (4:25)
Project Copacetic introduces a paradigm shift in how organizations can approach the defense against container vulnerabilities, offering several profound implications for security teams and practitioners.
Firstly, Copa significantly enhances vulnerability remediation speed and agility. In traditional workflows, discovering a CVE in a container image often necessitates a full rebuild of the image, which can be a time-consuming process involving source code changes, CI/CD pipeline execution, and re-deployment. Copa's ability to directly patch existing images by adding a new layer drastically reduces the time from vulnerability detection to remediation. This speed is critical for responding to zero-day exploits or high-severity CVEs, minimizing the window of exposure.
Secondly, it provides a viable and efficient solution for patching distroless and immutable container images. These images, while offering a reduced attack surface, pose a challenge for traditional patching methods due to their lack of package managers. Copa's external patching mechanism ensures that even these highly optimized images can receive critical security updates without requiring a complete rebuild or compromising their minimalist design. This is a significant boon for organizations adopting hardened, minimal base images.
Thirdly, Copa facilitates proactive security posture management. By integrating with vulnerability scanners like Trivy, it allows for automated patching workflows. This means that as new vulnerabilities are identified, Copa can be configured to automatically generate and deploy patched versions of images, shifting security from a reactive to a more proactive stance. This automation reduces manual effort and ensures a consistently updated and secure container fleet.
Fourthly, the "patch layer" approach promotes supply chain security by maintaining the integrity of the original base image layers. Instead of altering existing layers, Copa adds a new, traceable layer containing only the security fixes. This clear separation of concerns makes it easier to audit changes, understand the provenance of patches, and roll back if necessary. It also means that the original, potentially validated and signed, base layers remain untouched, adding an extra layer of trust.
Fifthly, Copa can help organizations achieve and maintain compliance requirements. Many industry regulations and security standards mandate timely patching of known vulnerabilities. By automating and accelerating the patching process, Copa helps organizations demonstrate due diligence and maintain a compliant security posture across their containerized applications, reducing the risk of audit failures or regulatory penalties.
Finally, the customizable tag suffix and GCHR mirroring enhancements address operational friction. By allowing custom tagging, Copa integrates more smoothly into existing image naming conventions, and by mitigating Docker Hub rate limits, it ensures that the patching process remains reliable and uninterrupted, even under heavy usage. This focus on developer experience directly contributes to better security outcomes by making the secure path the easiest path. Defenders should integrate Copa into their CI/CD pipelines to automatically scan, patch, and re-deploy container images, ensuring a continuously hardened and up-to-date container environment.
Key Takeaways
- Direct Vulnerability Patching: Project Copacetic (Copa) directly patches vulnerabilities in container images by interpreting scanner reports and applying updates as a new layer.
- BuildKit-Based Innovation: Copa leverages BuildKit to generate and apply these patch layers, critically enabling patching without requiring package management tooling inside the target container.
- Distroless Container Support: A key strength of Copa is its ability to patch distroless containers, addressing a significant security challenge for highly minimized images.
- Flexible Remediation Modes: It supports both targeted patching based on specific vulnerability reports (e.g., from Trivy) and a broader "update all" mode for general package hygiene.
- Enhanced Ecosystem Integration: Recent improvements include support for Alma Linux, community scanner plugins (Gripe, Docker Scout), customizable tag suffixes, and mirroring tooling images to GCHR to bypass Docker Hub rate limits.
- Future-Proofing: Upcoming features like multi-architecture and bulk image patching promise to further streamline the developer experience and operational efficiency for large-scale deployments.
About the Speaker(s)
Jeremy Rickard is a Maintainer of Project Copacetic, a CNCF sandbox project. His work involves the ongoing development, enhancement, and community engagement for this innovative tool designed to patch vulnerabilities in container images. His role as a maintainer signifies his deep technical expertise and commitment to advancing the project's mission within the cloud-native ecosystem.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
Project Copacetic (Copa) presents a genuinely novel and highly impactful solution for patching container vulnerabilities, particularly for distroless images. By leveraging BuildKit to inject updates as a new layer externally, it bypasses the need for in-container package managers, drastically improving remediation speed and efficiency. This is a critical defensive innovation that addresses a significant pain point in cloud-native security, making it a valuable contribution to the field.
Heather Calloway (CISO) — STRONG ACCEPT
Project Copacetic presents a pragmatic and impactful solution to a long-standing challenge in container security: patching vulnerabilities in an agile and non-disruptive manner, especially for distroless images. By leveraging BuildKit to apply targeted updates as new layers, Copa significantly accelerates remediation cycles and reduces the operational overhead traditionally associated with image rebuilding. This tool offers clear value for improving an organization's security posture, enabling faster response to CVEs, and strengthening supply chain integrity within containerized environments. It is a necessary advancement for any CISO managing a significant cloud-native footprint.