Build distroless package for better security, smaller size, speed and more
@imaffe ya está trabajando en esto.
Desde el 24/10/2022.
Evaluación
Este issue todavía no se ha evaluado.
Descripción
As proofed in practice and documented in https://github.com/streamnative/function-mesh/issues/371
there are sometimes (often!) security problems in a container/package whose origin is not the software one build, but in the software which is also situated in this container.
In most cases, there is no use case for this additional software.
This is where the idea of distroless containers comes in and "free" your software:
- for better security
- fewer bugs
- smaller packages
- a faster build process
- a faster check process (e.g. security scans for CVEs and CWEs)
- faster, cheaper and less annoying development process, because of less noise to understand and fix
- faster spin-up / faster dynamic scaling on load
- less demanding for needed infrastructure = less cost for infrastructure to run on
- ...
Traditional, this approach is somehow strenuous to implement and associated with restrictions.
But it looks like 2 new tools makes it pretty easy and straight forward:
good overview on distroless containers
https://dev.to/dansiviter/distroless-alpine-ci8
and
https://blog.chainguard.dev/minimal-container-images-towards-a-more-secure-future/
see last paragraph for how it works
the tools:
source to abk:
https://github.com/chainguard-dev/melange
abk to oci:
https://github.com/chainguard-dev/apko
to debug distroless containers:
official: https://kubernetes.io/docs/concepts/workloads/pods/ephemeral-containers/
detail flow: https://iximiuz.com/en/posts/kubernetes-ephemeral-containers/
- Lenguaje dominante
- Go
- Estrellas
- 228
- Forks
- 30
- Merge medio
- 1 d 14 h
- PR fusionados (30 d)
- 3
Preparar el entorno
Aún no hemos revisado los archivos de configuración de este proyecto. Empieza por su README y consulta nuestra guía para la primera contribución para los pasos generales.
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de streamnative/function-mesh
-
support `BatchingConfig` for Function and SourceQuizá libre de nuevo @freeznet la tomó hace 452 días y no hay ningún pull request abierto. Abierto
streamnative/function-mesh#811 · 1 asignado ·
-
Dificultad 2/5 Medio día Aptitud para principiantes 45/100
streamnative/function-mesh#806 ·
-
upgrade `autoscaler/vertical-pod-autoscaler` to v1.3.0Quizá libre de nuevo @jiangpengcheng la tomó hace 538 días y no hay ningún pull request abierto. Abierto
streamnative/function-mesh#801 · 1 asignado ·
-
Dificultad 4/5 3-5 días Aptitud para principiantes 35/100
streamnative/function-mesh#796 ·
-
Dificultad 3/5 1-2 días Aptitud para principiantes 25/100
streamnative/function-mesh#769 ·
Todos los issues de streamnative/function-mesh
Issues similares
-
bug needs triage
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
netdata/netdata#24062 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100
meshery/meshery#22119 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
Los mantenedores suelen responder en 1 día
-
automation documentation
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
Los mantenedores suelen responder en 1 día
-
[BUG] 安装向导生成了两个 rate_limit 无效参数Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
Los mantenedores suelen responder en 1 día