Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

Build distroless package for better security, smaller size, speed and more

Aperta
#448 4 commenti 0 reazioni 1 assegnatario Vedi su GitHub

@imaffe ci sta già lavorando.

Dal 24/10/2022.

Valutazione

Questa issue non è ancora stata valutata.

Descrizione

compute/serverless type/feature

As proofed in practice and documented in https://github.com/streamnative/function-mesh/issues/371
there are sometimes (often!) security problems in a container/package whose origin is not the software one build, but in the software which is also situated in this container.

In most cases, there is no use case for this additional software.
This is where the idea of distroless containers comes in and "free" your software:

  1. for better security
  2. fewer bugs
  3. smaller packages
  4. a faster build process
  5. a faster check process (e.g. security scans for CVEs and CWEs)
  6. faster, cheaper and less annoying development process, because of less noise to understand and fix
  7. faster spin-up / faster dynamic scaling on load
  8. less demanding for needed infrastructure = less cost for infrastructure to run on
  9. ...

Traditional, this approach is somehow strenuous to implement and associated with restrictions.

But it looks like 2 new tools makes it pretty easy and straight forward:

good overview on distroless containers
https://dev.to/dansiviter/distroless-alpine-ci8
and
https://blog.chainguard.dev/minimal-container-images-towards-a-more-secure-future/
see last paragraph for how it works

the tools:
source to abk:
https://github.com/chainguard-dev/melange

abk to oci:
https://github.com/chainguard-dev/apko

to debug distroless containers:
official: https://kubernetes.io/docs/concepts/workloads/pods/ephemeral-containers/
detail flow: https://iximiuz.com/en/posts/kubernetes-ephemeral-containers/

Lingua principale
Go
Stelle
228
Fork
30
Merge medio
2g 8h
PR unite (30g)
2

Guida per i contributori

Nessuna guida per i contributori indicizzata per questo repository

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di streamnative/function-mesh

Tutte le issue di streamnative/function-mesh

Issue simili

Altre issue su Go

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.