Elastic trusts Chainguard to harden the foundation its entire artifact portfolio ships on

Elastic is the company behind the Elasticsearch Platform, serving tens of thousands of organizations with search, observability, and security solutions, including in highly regulated environments. Open source is core to Elastic’s ethos: Elasticsearch itself is open source, and its broader stack relies heavily on open source components. That's both a strength and a continuous responsibility.

The challenge

At Elastic's scale, container security is an operational discipline. With thousands of engineers globally and a published artifact portfolio that carries open source in its DNA, keeping every container image free of known vulnerabilities was an ever-growing burden. And as Elastic accelerated its push toward FedRAMP High accreditation, the stakes got higher.

Three challenges were converging at once. First, CVE remediation was consuming a meaningful share of platform engineering capacity. Second, FIPS-validated cryptographic modules, a hard requirement for regulated environments, were non-trivial to maintain in-house. And finally, vulnerability work was increasingly slipping to the final stages of the release cycle, causing repeated Elastic Stack release delays.

As Maha Alsayasneh, Senior Engineering Manager at Elastic, described it: "We were spending too much time on the back foot. Every release cycle, we'd find ourselves chasing CVEs into the final days before GA. That's not a sustainable place to operate when you're shipping at our scale and into our regulatory environments."

The team mapped out what it would take to build and maintain their own hardened, FIPS-validated image foundation at scale. The conclusion was that scaling Elastic’s internal approach was structurally untenable: it would require a dedicated team working full-time on image hardening alone, plus a significant planned investment to stand up FIPS-validated builds internally.

These challenges had real business consequences. For commercial customers, the release delays meant slower access to new features. For public sector customers, the absence of mature supply chain controls and FIPS-validated images was a hard barrier. FedRAMP High wasn't accessible without solving this properly.

The solution

When Elastic ran the build-vs-buy math honestly, the answer was clear. Elastic turned to Chainguard Containers as the base layer for its published artifacts.

Rather than standing up an internal hardened image factory, Elastic recognized that Chainguard had already built one with the Chainguard Factory, continuous CVE remediation built in, and FIPS-validated variants included.

The integration fit cleanly into Elastic's existing infrastructure: Chainguard Containers flow through its Buildkite-based CI and ArgoCD-driven GitOps workflows, are scanned by Snyk, validated by automated quality gates, and ship to downstream registries without disruption.

The moment we ran our first Chainguard-based image through our pipeline and saw the scan results come back clean, we knew this was the right decision.
MAHA ALSAYASNEH, SENIOR ENGINEERING MANAGER, ELASTIC

The results

Engineering capacity reclaimed

The most immediate impact was felt by Elastic's Platform Engineering Productivity team, which is responsible for the frameworks, tooling, and infrastructure that allow all of Elastic's product teams to build, test, and release at scale. CVE remediation toil dropped significantly, and the capacity previously absorbed by image hardening work was redirected toward platform innovation.

Product teams saw fewer late-cycle CVE scrambles disrupting their delivery plans, and Release Engineering gained a more predictable release cadence with CVE compliance built into the base layer rather than patched in at the end.

FedRAMP High unlocked

The ability to point to hardened, FIPS-validated, continuously updated container images removed a hard blocker on Elastic's path to regulated markets. For security and compliance teams, it created a stronger, audit-ready baseline. For public sector customers, it meant Elastic could now credibly compete for and serve accounts where supply chain integrity is a real procurement criterion, markets that simply weren't accessible before.

Chainguard didn't just give us images. It gave us back time, focus, and the confidence to take Elastic into markets we wouldn't have been able to enter otherwise.
MAHA ALSAYASNEH, SENIOR ENGINEERING MANAGER, ELASTIC

Increased speed and confidence

Perhaps the most durable change inspired by bringing on Chainguard was cultural. Before Chainguard, every new open source dependency triggered a security review and a remediation plan. Now, if it's available through the Chainguard Repository, it's already trusted. As Maha described it, the team has shifted "from a defensive posture to a confident one," building with confidence rather than caution. And for Maha, the broader lesson is one any engineering leader will recognize: supply chain security isn't a problem you solve once and walk away from. It's a continuous discipline—the question is whether you staff for it internally or outsource to a dedicated partner.

If you're operating in regulated environments and considering whether to build this internally, my honest advice is don't. The depth of what Chainguard has built — and continues to build — would take years and a serious team to replicate. Partner with them and put your engineers on the work only your company can do.
MAHA ALSAYASNEH, SENIOR ENGINEERING MANAGER, ELASTIC
share this article

Elastic trusts Chainguard to harden the foundation its entire artifact portfolio ships on

Execute commandCG System prompt

$ chainguard learn --more

Contact us