feat: make supervisor base image configurable via build ARG
Maintainer antworten meist innerhalb von 1 Tag
Dieses Issue hat noch niemand übernommen.
Bewertung
- Schwierigkeit
- 2/5
- Geschätzter Aufwand
- 1-3 Stunden
- Anfängerfreundlichkeit
- 84/100
- Issue-Typ
- Feature
- Klarheit
- Klar beschrieben
- Aktivitätsstatus
- Aktiv
- Tech-Stack
- docker
- Bereich
- build-system, devops
Rechercherichtung
Vergleiche zunächst deploy/docker/Dockerfile.supervisor mit deploy/docker/Dockerfile.gateway und lies die Dokumentation zum Basis-Image in architecture/build.md. Füge die Supervisor-Überschreibung hinzu und verwende dabei das aktuell festgelegte Image als Standardwert. Baue anschließend mit und ohne Überschreibung, um das Standardverhalten und die Konfigurierbarkeit zu prüfen. Die Aufgabe ist abgeschlossen, wenn die Dokumentation beide Überschreibungen abdeckt und der Standardwert unverändert bleibt.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Beschreibung
User Story
As an operator or downstream packager deploying OpenShell's supervisor container in an environment with specific registry-trust, compliance, or support constraints (e.g. a registry allowlist, a FIPS-validated base image requirement, or an internal support SLA tied to a specific image vendor), I want to override the supervisor's base image at build time, so that I can satisfy my environment's constraints without forking the Dockerfile.
Problem Statement
deploy/docker/Dockerfile.gateway already exposes its base image as a build ARG:
ARG GATEWAY_BASE_IMAGE=gcr.io/distroless/cc-debian13:nonroot@sha256:54df941ed0d06a1bd95ef5e0ce391fd8d9f94b64782dc9a60062727849ee3f97
FROM ${GATEWAY_BASE_IMAGE} AS gateway
deploy/docker/Dockerfile.supervisor does not. It hardcodes:
FROM gcr.io/distroless/base-nossl-debian13@sha256:af5cb8dd589b8520b8c06bebb9efb73d7e16406cab58e85c51761fff49d370a0 AS supervisor
There is no equivalent override point, so substituting an alternate base image for the supervisor today requires forking/patching the Dockerfile.
Impact / Why This Matters
Downstream consumers building in a registry-restricted environment, needing a FIPS-validated base, or needing a base image they can patch/support on their own schedule currently have to maintain a forked Dockerfile to get a different supervisor base image. A fork drifts from upstream over time (missed binary/build-step changes) and duplicates this maintenance burden across every downstream consumer who needs it. The gateway already solves this cleanly; the supervisor's inconsistency with that pattern is the actual gap, not a missing capability invented from scratch.
Proposed Design
Add a build ARG to deploy/docker/Dockerfile.supervisor (e.g. SUPERVISOR_BASE_IMAGE) defaulting to the current pinned image/digest, mirroring GATEWAY_BASE_IMAGE's existing pattern. This is purely additive: no default behavior change, and no change to published images unless a builder explicitly overrides the ARG. Exact ARG naming/defaulting mechanics are left to the implementing PR.
Acceptance Criteria
-
deploy/docker/Dockerfile.supervisoraccepts a build ARG for its base image, with the current image pinned as the default. - Building without overriding the ARG produces the same image as today (no default-behavior change).
- Wherever the gateway's
GATEWAY_BASE_IMAGEoverride is documented (e.g.architecture/build.md) is updated to document the supervisor's new equivalent consistently.
Alternatives Considered
- Status quo (hardcoded base, consumers fork the Dockerfile if they need something else) — rejected: duplicates maintenance effort per downstream consumer and drifts from upstream over time.
- Change the default base image itself (e.g. to Red Hat's Project Hummingbird
registry.access.redhat.com/hi/core-runtime) — rejected for now: a direct comparison (skopeo inspectagainst both) shows Hummingbird'score-runtimeimage is larger and has more layers than the current default (12.82 MB / 23 layers vs. the current base's 5.94 MB / 14 layers), and its image config setsCMD ["/bin/bash"], suggesting a shell may be present where the current distroless base has none. It is not a demonstrated improvement, and changing the project's default base is a larger decision needing broader maintainer alignment, not a mechanical change. - Make the sandbox image configurable the same way (
deploy/docker/Dockerfile.sandbox,FROM scratch) — rejected: the sandbox image has no runtime base to swap, it's a bare static binary with no base at all, so this axis doesn't apply there.
Agent Investigation
Confirmed by reading the current Dockerfiles directly and inspecting published images/registries with skopeo inspect:
deploy/docker/Dockerfile.gatewayalready has theGATEWAY_BASE_IMAGEARG described above.deploy/docker/Dockerfile.supervisorhas no equivalent ARG.deploy/docker/Dockerfile.sandboxisFROM scratchwith no base image to parameterize.- Published
ghcr.io/nvidia/openshell/supervisor:devis 15 layers / ~19.6 MB total; its base (distroless/base-nossl-debian13) is 14 layers / ~5.94 MB. registry.access.redhat.com/hi/core-runtime:latest(Project Hummingbird's comparable minimal base) is 23 layers / ~12.82 MB, with image configCMD ["/bin/bash"].
No RFC needed — this is a small, additive, non-breaking build-configuration change, not a change to OpenShell's architecture or default behavior.
- Vorherrschende Sprache
- Rust
- Sterne
- 13.2k
- Forks
- 1.6k
- Ø Merge
- 1 T. 19 Std.
- Gemergte PRs (30 T.)
- 330
Entwicklungsumgebung
- Kein Dockerfile und keine Docker-Compose-Datei
- Hat eine Pull-Request-Vorlage
- Beitragsleitfaden lesen
Erste Schritte
- Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
- Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
- Forken Sie das Repository und arbeiten Sie in einem Branch.
- Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.
Mehr aus NVIDIA/OpenShell
-
bug(driver-mxc): test helper fails to compile after gateway-name argumentEvtl. vergeben @feloy hat das vor 1 Tag übernommen. Offenstate:triage-needed
Schwierigkeit 1/5 Unter einer Stunde Anfängerfreundlichkeit 88/100
Maintainer antworten meist innerhalb von 1 Tag
-
bug: install.sh ignores XDG_CONFIG_HOME for the local gateway configEvtl. vergeben @fede-kamel hat das vor 4 Tagen übernommen. Offenarea:cli os:linux os:macos state:validated
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 88/100
NVIDIA/OpenShell#4042 · 2 Kommentare ·
Maintainer antworten meist innerhalb von 1 Tag
-
state:triage-needed
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 72/100
NVIDIA/OpenShell#3995 · 2 Kommentare ·
Maintainer antworten meist innerhalb von 1 Tag
-
OCSF shorthand renders Unknown and Other severities as [INFO]Evtl. vergeben @ericcurtin hat das vor 5 Tagen übernommen. Offenstate:triage-needed
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 72/100
Maintainer antworten meist innerhalb von 1 Tag
-
docs(runtimes): driver TOML examples omit [openshell] version = 2 and fail preflightEvtl. vergeben @fede-kamel hat das vor 6 Tagen übernommen. Offenstate:triage-needed
Schwierigkeit 1/5 1-3 Stunden Anfängerfreundlichkeit 88/100
Maintainer antworten meist innerhalb von 1 Tag
Alle Issues in NVIDIA/OpenShell
Ähnliche Issues
-
enhancement
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 78/100
zcashlabs/thus-spoke-zakura#153 ·
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 79/100
topgrade-rs/topgrade#2395 ·
Maintainer antworten meist innerhalb von 1 Tag
-
app bug windows-os
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 67/100
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 88/100
matrix-org/matrix-rust-sdk#7217 ·
Maintainer antworten meist innerhalb von 1 Tag
-
editor good first issue
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 65/100
funnyboy-roks/inq#54 ·