Description
Downloaded packages or repository metadata can remain in an image after zypper is used. Caches unnecessary at runtime increase image size and transfer costs.
By default, zypper clean removes downloaded package caches. Use zypper clean --all when repository metadata should also be removed.
Potential impact
- Image transfer and deployment can require more time and storage.
- Deleting caches in a later layer leaves their size in earlier layers.
Remediation
- After a successful installation, run zypper clean in the same RUN; add --all if metadata is unnecessary too.
- Complete installation and cleanup in one layer, then check the final image size and remaining files.
Examples
The existing openSUSE Leap 15.6 examples are preserved. Use supported images and repositories for actual builds. The after example shows default package-cache cleanup only.
Before
dockerfile
FROM opensuse/leap:15.6
RUN zypper install -y nginx
After
dockerfile
FROM opensuse/leap:15.6
RUN zypper install -y nginx \
&& zypper clean
Explanation:
- Before: Caches can remain after installation.
- After: The same RUN removes downloaded package caches. The default command does not also remove all metadata caches.