Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

Build distroless package for better security, smaller size, speed and more

オープン
#448 コメント 4 件 リアクション 0 件 担当者 1 名 GitHub で見る

@imaffe がすでに取り組んでいます。

2022年10月24日 から。

評価

この issue はまだ評価されていません。

説明

compute/serverless type/feature

As proofed in practice and documented in https://github.com/streamnative/function-mesh/issues/371
there are sometimes (often!) security problems in a container/package whose origin is not the software one build, but in the software which is also situated in this container.

In most cases, there is no use case for this additional software.
This is where the idea of distroless containers comes in and "free" your software:

  1. for better security
  2. fewer bugs
  3. smaller packages
  4. a faster build process
  5. a faster check process (e.g. security scans for CVEs and CWEs)
  6. faster, cheaper and less annoying development process, because of less noise to understand and fix
  7. faster spin-up / faster dynamic scaling on load
  8. less demanding for needed infrastructure = less cost for infrastructure to run on
  9. ...

Traditional, this approach is somehow strenuous to implement and associated with restrictions.

But it looks like 2 new tools makes it pretty easy and straight forward:

good overview on distroless containers
https://dev.to/dansiviter/distroless-alpine-ci8
and
https://blog.chainguard.dev/minimal-container-images-towards-a-more-secure-future/
see last paragraph for how it works

the tools:
source to abk:
https://github.com/chainguard-dev/melange

abk to oci:
https://github.com/chainguard-dev/apko

to debug distroless containers:
official: https://kubernetes.io/docs/concepts/workloads/pods/ephemeral-containers/
detail flow: https://iximiuz.com/en/posts/kubernetes-ephemeral-containers/

主要言語
Go
スター
228
フォーク
30
平均マージ
2日 8時間
マージ済み PR(30日)
2

コントリビューションガイド

このリポジトリのコントリビューションガイドは索引されていません

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

streamnative/function-mesh のほかの issue

streamnative/function-mesh の issue をすべて見る

似ている issue

Go の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。