# Why doesn't the Elastic Package Registry Docker Image have \`/bin/bash\`?

**URL:** <https://discuss.elastic.co/t/why-doesnt-the-elastic-package-registry-docker-image-have-bin-bash/366138>\
**Category:** Kibana\
**Tags:** docker\
**Created:** [September 6, 2024, 9:07am UTC](https://discuss.elastic.co/t/why-doesnt-the-elastic-package-registry-docker-image-have-bin-bash/366138 "2024-09-06T09:07:17Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![linghengqian](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/linghengqian/32/103651_2.png) [@linghengqian](https://discuss.elastic.co/u/linghengqian)\
**Post date:** [September 6, 2024, 9:07am UTC](https://discuss.elastic.co/t/why-doesnt-the-elastic-package-registry-docker-image-have-bin-bash/366138/1 "2024-09-06T09:07:17Z")

</div>

- Assume there is the following `docker-compose.yml`.

```yaml
services:
  elastic-package-registry:
    image: docker.elastic.co/package-registry/distribution:8.15.0

```

- Start it,

```bash
docker compose pull
docker compose up -d
docker compose exec elastic-package-registry /bin/sh
cat /etc/shells

```

- At this point I'll notice that `/bin/bash` doesn't exist.

```bash
/package-registry # cat /etc/shells
/bin/sh
/bin/ash

```

- This resulted in commands like `docker compose exec elastic-package-registry /bin/bash` not working.
- Why doesn't the Elastic Package Registry Docker Image have `/bin/bash`?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [September 6, 2024, 1:22pm UTC](https://discuss.elastic.co/t/why-doesnt-the-elastic-package-registry-docker-image-have-bin-bash/366138/2 "2024-09-06T13:22:57Z")

</div>

> [@linghengqian](#):
>
> - Why doesn't the Elastic Package Registry Docker Image have `/bin/bash`?

Why it should have?

It is a docker image, there is no need to access the container, if it is required for some reason you already have the `sh` shell.

---

<div class="post-metadata">

**Author:** ![linghengqian](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/linghengqian/32/103651_2.png) [@linghengqian](https://discuss.elastic.co/u/linghengqian)\
**Post date:** [September 6, 2024, 1:28pm UTC](https://discuss.elastic.co/t/why-doesnt-the-elastic-package-registry-docker-image-have-bin-bash/366138/3 "2024-09-06T13:28:27Z")

</div>

- Well, this is just out of my curiosity. Because `docker.elastic.co/beats/elastic-agent:8.15.0` and `docker.elastic.co/elasticsearch/elasticsearch:8.15.0` both have `/bin/bash`. `docker.elastic.co/package-registry/distribution:8.15.0` seems to be designed differently from other Docker Images.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [September 6, 2024, 1:36pm UTC](https://discuss.elastic.co/t/why-doesnt-the-elastic-package-registry-docker-image-have-bin-bash/366138/4 "2024-09-06T13:36:57Z")

</div>

Both Elasticsearch and Elastic Agent image uses a Ubuntu image in the Dockerfile, the Package Registry is a golang image in the Dockerfile, so they are different.

But the reason for that only someone from Elastic can answer.

---

<div class="post-metadata">

**Author:** ![linghengqian](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/linghengqian/32/103651_2.png) [@linghengqian](https://discuss.elastic.co/u/linghengqian)\
**Post date:** [September 7, 2024, 2:00am UTC](https://discuss.elastic.co/t/why-doesnt-the-elastic-package-registry-docker-image-have-bin-bash/366138/5 "2024-09-07T02:00:26Z")

</div>

- Thanks for the clarification, I've opened [Add `/bin/bash` to the Elastic Package Registry Docker Image · Issue #1218 · elastic/package-registry · GitHub](https://github.com/elastic/package-registry/issues/1218) .

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [September 8, 2024, 9:07am UTC](https://discuss.elastic.co/t/why-doesnt-the-elastic-package-registry-docker-image-have-bin-bash/366138/6 "2024-09-08T09:07:13Z")

</div>

Hi!

I am in the team that maintains Package Registry. We recently started to use a [Wolfi](https://github.com/wolfi-dev)-based distribution as the base image for our Docker images. This is a minimalistic distribution focused on security that doesn't include bash by default, to reduce the potential attack surface.

Apart from the base packages we are only including the software we know that is used in common use cases, this basically translates to `curl` for healthchecks, and `/etc/mime.types` for the Go runtime, to be able to properly attach content type headers to HTTP responses.

We would be open to add bash if there are reasons or uses for it. Would you have a use case that requires the use of bash for the Package Registry? Is there any other reason why you think we should include it?

---

<div class="post-metadata">

**Author:** ![linghengqian](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/linghengqian/32/103651_2.png) [@linghengqian](https://discuss.elastic.co/u/linghengqian)\
**Post date:** [September 8, 2024, 9:20am UTC](https://discuss.elastic.co/t/why-doesnt-the-elastic-package-registry-docker-image-have-bin-bash/366138/7 "2024-09-08T09:20:03Z")

</div>

- @jsoriano Thanks for the clarification. There is no known use for bash on my side, except that a container management tool called Portainer CE uses `/bin/bash` by default when connecting to a container via console, and there is no easy way to know in advance if there is `/bin/bash` in the container. This results in an extra step of clicking on the screen to switch to `/bin/sh`.

- The only reason I need to enter the container is when I need to execute `curl` from inside the container to test connectivity to other containers under the same Docker Network, and `curl` is inside the container by default, which is fine.
