Public Docker image quality-of-life improvements
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 25/100
- Issue type
- Feature
- Clarity
- Needs clarification
- Activity status
- Quiet
- Tech stack
- docker, github-actions
- Domain
- build-system, ci-cd, devops, infrastructure, security
Research direction
This is an umbrella issue rather than a single implementation task. Start by reviewing the unchecked items, especially the linked image-signing issue #183, and inspect the existing CI and image-build workflows in rstudio-docker-products and r-docker. Done requires narrowing one improvement into a concrete plan with defined image, workflow, or security outcomes.
Written by the indexing model from the issue text.
Description
[!NOTE]
Moved from rstudio/platform-team#188
This came out of conversations with @colearendt and @bschwedler. Essentially, there are some things we'd like to improve about our public Docker images -- for the products especially but also their upstream base images -- but that are scattered across various people's heads or some isolated issues.
Items we've discussed as potential improvements:
-
Image rebuilds automatically triggered by updates to the base image. Ideally we'd like a holistic update cycle so it's clear how changes to
r-dockerbase images and evenr-buildOS packages trigger updates up the stack. This should also catch security patches to the OS base images we use. -
More efficient continuous integration. Currently CI for
rstudio-docker-products(which runs on every commit and PR) takes about an hour, which really cuts into iteration time. Most of this is due to rebuilding all images even when a commit only touches one of them. Cole has some work in progress to improve this. -
More layer optimisation (and, related, "as small as possible" images). We can potentially use tools like
divefor analysis here. -
Image signing (see #183) and signature verification of upstream components (GPG for packages, maybe Sigstore for base images).
-
Whether we can produce minimalist/distroless builds for Connect and Package Manager (for dramatically smaller images and improved image security).
-
Whether
r-dockershould be moved from Jenkins to GitHub Actions. It's a public project, so that seems like a reasonable choice and is consistent withrstudio-docker-products.
- Dominant language
- Python
- Stars
- 2
- Forks
- 0
- Avg merge
- 4d 11h
- Merged PRs (30d)
- 24
Getting set up
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from posit-dev/images-shared
-
cvp:0 docker tdp:1
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
posit-dev/images-shared#757 · 2 comments ·
Maintainers usually reply within 1 day
-
bug cvp:0 docker priority/medium python tdp:1
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
posit-dev/images-shared#685 ·
Maintainers usually reply within 1 day
-
slack-build-notify: no persisted alert state — causes suppressed repeat-failure and recovery alertsOpenbug cicd cvp:0 docker needs discussion observability tdp:2
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
posit-dev/images-shared#677 ·
Maintainers usually reply within 1 day
-
cvp:0 docker tdp:2 tech debt
Difficulty 4/5 3-5 days Newbie friendliness 48/100
posit-dev/images-shared#795 ·
Maintainers usually reply within 1 day
-
cicd cvp:0 docker enhancement tdp:2
Difficulty 5/5 Over a week Newbie friendliness 35/100
posit-dev/images-shared#773 ·
Maintainers usually reply within 1 day
All issues in posit-dev/images-shared
Similar issues
-
pydanty:is-working
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
pydantic/pydantic-ai#8843 ·
Maintainers usually reply within 1 day
-
breaking change enhancement server
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
Maintainers usually reply within 1 day
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
sktime/sktime#11310 · 1 comment ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
Maintainers usually reply within 1 day
-
needs-triage
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
Maintainers usually reply within 1 day