Elastic trusts Chainguard to harden the foundation its entire artifact portfolio ships on
Elastic is the company behind the Elasticsearch Platform, serving tens of thousands of organizations with search, observability, and security solutions, including in highly regulated environments. Open source is core to Elastic’s ethos: Elasticsearch itself is open source, and its broader stack relies heavily on open source components. That's both a strength and a continuous responsibility.
The challenge
At Elastic's scale, container security is an operational discipline. With thousands of engineers globally and a published artifact portfolio that carries open source in its DNA, keeping every container image free of known vulnerabilities was an ever-growing burden. And as Elastic accelerated its push toward FedRAMP High accreditation, the stakes got higher.
Three challenges were converging at once. First, CVE remediation was consuming a meaningful share of platform engineering capacity. Second, FIPS-validated cryptographic modules, a hard requirement for regulated environments, were non-trivial to maintain in-house. And finally, vulnerability work was increasingly slipping to the final stages of the release cycle, causing repeated Elastic Stack release delays.
As Maha Alsayasneh, Senior Engineering Manager at Elastic, described it: "We were spending too much time on the back foot. Every release cycle, we'd find ourselves chasing CVEs into the final days before GA. That's not a sustainable place to operate when you're shipping at our scale and into our regulatory environments."
The team mapped out what it would take to build and maintain their own hardened, FIPS-validated image foundation at scale. The conclusion was that scaling Elastic’s internal approach was structurally untenable: it would require a dedicated team working full-time on image hardening alone, plus a significant planned investment to stand up FIPS-validated builds internally.
These challenges had real business consequences. For commercial customers, the release delays meant slower access to new features. For public sector customers, the absence of mature supply chain controls and FIPS-validated images was a hard barrier. FedRAMP High wasn't accessible without solving this properly.
The solution
When Elastic ran the build-vs-buy math honestly, the answer was clear. Elastic turned to Chainguard Containers as the base layer for its published artifacts.
Rather than standing up an internal hardened image factory, Elastic recognized that Chainguard had already built one with the Chainguard Factory, continuous CVE remediation built in, and FIPS-validated variants included.
The integration fit cleanly into Elastic's existing infrastructure: Chainguard Containers flow through its Buildkite-based CI and ArgoCD-driven GitOps workflows, are scanned by Snyk, validated by automated quality gates, and ship to downstream registries without disruption.
The results
Engineering capacity reclaimed
The most immediate impact was felt by Elastic's Platform Engineering Productivity team, which is responsible for the frameworks, tooling, and infrastructure that allow all of Elastic's product teams to build, test, and release at scale. CVE remediation toil dropped significantly, and the capacity previously absorbed by image hardening work was redirected toward platform innovation.
Product teams saw fewer late-cycle CVE scrambles disrupting their delivery plans, and Release Engineering gained a more predictable release cadence with CVE compliance built into the base layer rather than patched in at the end.
FedRAMP High unlocked
The ability to point to hardened, FIPS-validated, continuously updated container images removed a hard blocker on Elastic's path to regulated markets. For security and compliance teams, it created a stronger, audit-ready baseline. For public sector customers, it meant Elastic could now credibly compete for and serve accounts where supply chain integrity is a real procurement criterion, markets that simply weren't accessible before.
Increased speed and confidence
Perhaps the most durable change inspired by bringing on Chainguard was cultural. Before Chainguard, every new open source dependency triggered a security review and a remediation plan. Now, if it's available through the Chainguard Repository, it's already trusted. As Maha described it, the team has shifted "from a defensive posture to a confident one," building with confidence rather than caution. And for Maha, the broader lesson is one any engineering leader will recognize: supply chain security isn't a problem you solve once and walk away from. It's a continuous discipline—the question is whether you staff for it internally or outsource to a dedicated partner.