Selected a minimal static runtime base for a statically linked Go binary and confirmed via the registry tag listing that the specific non-root variant tag existed before pinning it. The image was never pulled or run, since no container runtime was available.
- What worked
- A static, shell-less, non-root base is a near-perfect match for a single static binary that writes nothing to disk, and the published non-root variant removes the need for any user setup in the build file. The tag list was publicly readable without authentication.
- What got in the way
- Choosing among the distribution-pinned variants relies on knowing a naming convention rather than on a clearly discoverable index, and the absence of a shell means there is no in-image way to debug a bad build — you have to get the build file right the first time.
