The end of free public images does not mean the end of innovation. On the contrary, it represents a necessary maturity.

CTO
João Brito

The announcement of the end of public image distribution by Bitnami marks more than just an operational change. It is a clear sign that the cloud native world is acknowledging a technical debt accumulated over years: the neglect of security at the foundation of container infrastructure.
For a long time, public images were used as the de facto standard. Docker Hub, Bitnami, and other providers facilitated access to packaged, ready-to-use, and seemingly reliable applications. This model offered convenience and speed but masked an invisible cost. There was no clarity on who built these images, what packages were included, how they were maintained, or how often they were patched. By delegating this responsibility, many companies took on significant risks without realizing it.
Supply chain as a critical point
Recent years have made it clear that the software supply chain is one of the main attack vectors. Cases of malicious code injection in packages, cryptocurrency mining in clusters, and sensitive data leaks have shown that blindly trusting public images compromises security and governance. The problem is not limited to known vulnerabilities. It extends to the lack of traceability and robust controls over every component that reaches production.
Keeping images secure, free of vulnerabilities, and continuously updated is a complex and costly process. It is estimated that more than 130 new vulnerabilities are registered daily across different technologies. For each fix, triage, rebuilding, and validation are required. This effort is continuous and consumes time and resources from specialized teams.
The real cost of images
With the end of public images, reality sets in: either companies invest in internal teams to maintain and harden their own images, or they hire specialized vendors who offer this service in a controlled and auditable manner. Both paths have costs, but they differ in the scale of investment. Internally sustaining the update of complex stacks such as Prometheus, Grafana, Istio, Nginx, RabbitMQ, Redis, or Elasticsearch is not feasible for most organizations. The alternative is to rely on companies that assume this responsibility and guarantee consistent, secure, and audited images.
This shift is not just about Bitnami. It is about the entire container ecosystem. The era where security was left in the background in the name of scalability is over. Now, governance over container images and operating systems must be treated as a strategic priority.
Conclusion
The end of free public images does not mean the end of innovation. On the contrary, it represents a necessary maturity. The community took a decade to realize that convenience cannot come at the expense of security. From now on, the debate is no longer about whether we should invest in maintaining secure images, but how to do so efficiently.
Companies that understand this movement and adjust their practices will come out ahead. Those that insist on treating images as an operational detail run the risk of turning vulnerabilities into serious incidents. The message is clear: the future of containers goes through the conscious control of the entire software chain.
Want to dive deep into this topic? Access: getup.io/zerocve
Newsletter Getup.
Atualizações sobre Kubernetes e Software Supply Chain Security todos os meses.
Operating Kubernetes in production for more than 13 years. With Quor, this experience extends to software supply chain security as well.
GET UP
© Getup · 2026

