Description
dnf install can leave package metadata and cache files in an image layer. Caches that are unnecessary at runtime increase image size and storage or transfer costs.
Deleting them in a later RUN does not shrink earlier layers. Complete installation and cleanup in one layer to avoid retaining that cache in the resulting layer.
Potential impact
- Images can require more storage and take longer to transfer or deploy.
- Unnecessary caches increase image-management overhead.
Remediation
- Run dnf clean all after dnf install in the same RUN instruction.
- Check the remaining cache and final image size. Cache cleanup does not replace security updates for installed packages.
Examples
The existing Fedora 40 examples compare commands. For actual builds, choose a supported base and repositories and verify that the nginx package is available.
Before
dockerfile
FROM fedora:40
RUN dnf install -y nginx
After
dockerfile
FROM fedora:40
RUN dnf install -y nginx \
&& dnf clean all
Explanation:
- Before: Installation caches can remain in the image.
- After: After a successful installation, the same RUN cleans the dnf cache. This does not shrink files already stored in earlier layers.