Definition. A container-specific Linux distribution (“undistro”) from Chainguard, designed for a minimal footprint, supply-chain-secure builds and fast patch cycles. Wolfi does not ship its own kernel but runs on the host kernel (container/Kubernetes node), is based on glibc and provides SBOMs and signatures for every package. The distribution is rolling and updated daily, without classic release versions.
Why it matters. Wolfi is the foundation of Chainguard Images: hardened, minimally configured container bases that fit well into a reproducible build stack. For mid-sized platforms, Wolfi is mainly interesting when container images are themselves part of the supply chain and need clear provenance.
Related. Immutable Infrastructure, Kubernetes Worker Node, NixOS, Talos Linux, Container Escape