Review zypper cache cleanup

Complete installation and zypper cache cleanup in the same RUN.

Description

Downloaded packages or repository metadata can remain in an image after zypper is used. Caches unnecessary at runtime increase image size and transfer costs.

By default, zypper clean removes downloaded package caches. Use zypper clean --all when repository metadata should also be removed.

Potential impact

  • Image transfer and deployment can require more time and storage.
  • Deleting caches in a later layer leaves their size in earlier layers.

Remediation

  • After a successful installation, run zypper clean in the same RUN; add --all if metadata is unnecessary too.
  • Complete installation and cleanup in one layer, then check the final image size and remaining files.

Examples

The existing openSUSE Leap 15.6 examples are preserved. Use supported images and repositories for actual builds. The after example shows default package-cache cleanup only.

Before

dockerfile
FROM opensuse/leap:15.6

RUN zypper install -y nginx

After

dockerfile
FROM opensuse/leap:15.6

RUN zypper install -y nginx \
    && zypper clean

Explanation:

  • Before: Caches can remain after installation.
  • After: The same RUN removes downloaded package caches. The default command does not also remove all metadata caches.

References