My Python service image is 1.2 GB. The code is maybe 400 KB. Where does it all go?
Almost always the base image plus build tooling that never gets removed. Check the layer breakdown first:
docker history --no-trunc --format "{{.Size}}\t{{.CreatedBy}}" myimage:latest | head -20
The usual suspects are python:3.12 instead of python:3.12-slim, a pip install that keeps its cache, and build dependencies like gcc left in the final layer.
That first layer at 980 MB is the whole story. A multi-stage build moves compilation into a throwaway stage:
FROM python:3.12-slim AS build
RUN pip install --no-cache-dir --prefix=/install -r requirements.txt
FROM python:3.12-slim
COPY --from=build /install /usr/local
COPY . /app
Typical result for a service like yours is 180 to 220 MB, most of which is the interpreter itself.
Does it matter beyond disk space?
Pull time on cold nodes, mostly. A 1.2 GB image on a fresh autoscaled node adds roughly 20 to 40 seconds before the container starts, which is exactly when you least want it. It also widens the CVE surface: every package in the image gets scanned and reported, including the compiler you no longer use.
