• Run as a non-root userOnly include necessary packages
  • Scan the images continuously and rebuild for security updates
  • Use a hardened compiler and non-default security settings, like FORTIFY_SOURCE=3.