Skip to content

Most secure search engine container images, ranked by isolation score

How isolated are the most-pulled search engine container images when you docker run them with plain defaults, no hardening flags? This page ranks 9 search and indexing engines (Elasticsearch, OpenSearch, Solr, Meilisearch, Typesense) on IronClaw's seven-dimension container containment scale (0-100), best-isolated first. Scores run 48/100 to 63/100 (average 58/100). Higher is safer. Every score comes from ironctl scan, a credential-free audit you can run on your own containers in ten seconds.

No search engine image ships fully isolated by default: the leaders still leave capabilities, egress, or a writable root filesystem open. The gap between any image here and a clean 100/100 grade A is a handful of docker run flags, shown on every scorecard.

Ranked best to worst

Rank Image Score Grade Top gaps (default config)
๐Ÿฅ‡ 1 elasticsearch:8.16.1 63/100 ๐ŸŸก C Dropped capabilities, Network isolation / egress, Read-only root filesystem
๐Ÿฅˆ 2 opensearchproject/opensearch:2 63/100 ๐ŸŸก C Dropped capabilities, Network isolation / egress, Read-only root filesystem
๐Ÿฅ‰ 3 opensearchproject/opensearch-dashboards:2.18.0 63/100 ๐ŸŸก C Dropped capabilities, Network isolation / egress, Read-only root filesystem
4 solr:9 63/100 ๐ŸŸก C Dropped capabilities, Network isolation / egress, Read-only root filesystem
5 apache/tika:latest 63/100 ๐ŸŸก C Dropped capabilities, Network isolation / egress, Read-only root filesystem
6 vespaengine/vespa:8.453.24 63/100 ๐ŸŸก C Dropped capabilities, Network isolation / egress, Read-only root filesystem
7 manticoresearch/manticore:6.3.6 48/100 ๐ŸŸ  D Dropped capabilities, Non-root user (uid != 0), Network isolation / egress
8 getmeili/meilisearch:v1.11 48/100 ๐ŸŸ  D Dropped capabilities, Non-root user (uid != 0), Network isolation / egress
9 typesense/typesense:27.1 48/100 ๐ŸŸ  D Dropped capabilities, Non-root user (uid != 0), Network isolation / egress

Scan your own search engine container

These grades come from ironctl scan, one credential-free command that audits any running container, docker-compose service, or Kubernetes manifest, not just the search engine images ranked above:

# install (Homebrew)
brew install ironsecco/ironclaw/ironclaw

# grade your own container the same way this page was generated
ironctl scan my-container

Part of the Container Isolation Scores directory. Generated from a reproducible survey by examples/isolation-survey/gen_scorecards.py and refreshed weekly, so this ranking never goes stale. Grades reflect each image's default configuration, not a limit of the image itself: every one reaches grade A with the right docker run flags.