Slim down product images
维护者通常 2 天内回复
还没有人认领这个 Issue。
评估
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 新手友好度
- 35/100
- Issue 类型
- 重构
- 描述清晰度
- 基本清楚
- 活跃度
- 停滞
- 技术栈
- docker, dockerfile
- 领域
- build-system, devops, security
调研方向
首先检查 Hive Dockerfile 注释以及 Trino、Hive 和 HBase 的构建流程,然后比较复制到各自最终镜像中的组件。使用 pull request 814 作为组件 SBOM 的参考。完成的标准是记录可移除的组件及其影响,并记录无法移除的组件及其原因。
由索引模型根据 Issue 内容生成。
描述
We might have some potential to slim down product images. This can reduce build time, image size and attack surface. For example, the Hive Dockerfile has a comment about Hadoop: https://github.com/stackabletech/docker-images/blob/1965d50dc436552d4c7e06363f4b1ed46deac29c/hive/Dockerfile#L102
Now that we build from source, it might be worth digging into the build processes to:
a) Limit which components we build. It doesn't make sense to build stuff that's never copied to the final image.
b) Revalidate if all the components that are copied into the final image are really needed in production. With Hive, for example, we switched the build to only build the metastore, which significantly reduced the attack surface. Some products consist of multiple components and plugins, which might not all be needed to run the platform.
c) While we're at it, try to generate an SBOM for each component that is copied into the final image (next to the component itself). For most components that should already be the case, see https://github.com/stackabletech/docker-images/pull/814
We want to focus on products that are mostly affected by vulnerabilities right now:
- Trino
- Hive
- HBase
Acceptance criteria:
- Document what could be removed and the impacts of the removal
- Document what can't be removed and why it can't be removed
- 主要语言
- Dockerfile
- 星标
- 22
- 派生
- 7
- 平均合并
- 3 天 15 小时
- 30 天内合并 PR
- 33
环境准备
- 没有 Dockerfile 或 Docker Compose 文件
- 有 Pull Request 模板
- 没有贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
stackabletech/docker-images 的其他 Issue
-
release-note/action-required scheduled-for/26.11.0
难度 4/5 3-5 天 新手友好度 35/100
stackabletech/docker-images#1657 · 1 条评论 · 已指派 1 人 ·
维护者通常 2 天内回复
-
scheduled-for/26.11.0
难度 4/5 3-5 天 新手友好度 48/100
stackabletech/docker-images#1655 ·
维护者通常 2 天内回复
-
scheduled-for/26.11.0
难度 4/5 3-5 天 新手友好度 52/100
stackabletech/docker-images#1652 ·
维护者通常 2 天内回复
-
scheduled-for/26.11.0
难度 4/5 3-5 天 新手友好度 45/100
stackabletech/docker-images#1649 ·
维护者通常 2 天内回复
-
chore(hbase-phoenix-omid): Update major/minor versions for 26.11.0可能已有人在做 @adwk67 于 17 天前认领。 未关闭scheduled-for/26.11.0
难度 4/5 3-5 天 新手友好度 55/100
stackabletech/docker-images#1647 · 已指派 1 人 ·
维护者通常 2 天内回复
查看 stackabletech/docker-images 的全部 Issue
相似的 Issue
-
难度 2/5 1-3 小时 新手友好度 78/100
JoviDeCroock/pracht#432 ·
维护者通常 1 天内回复
-
fix(ci): check-changed-skills.sh fails a stale branch on skills only main changed可能已有人在做 关联的 PR 仍在进行中或已合并。 未关闭good first issue needs-triage priority: medium
难度 2/5 1-3 小时 新手友好度 72/100
melodic-software/claude-code-plugins#7014 · 1 条评论 ·
维护者通常 1 天内回复
-
[Bug]: atlauncher fails to install due to invalid requires (libpulseaudio, libudev)可能已有人在做 @Owen-sz 今天认领。 未关闭
难度 2/5 1-3 小时 新手友好度 84/100
维护者通常 1 天内回复
-
chore(build): TxCoordinator.cpp uses the deprecated shared_ptr atomic free functions可能已有人在做 @w5jwp 今天认领。 未关闭
难度 1/5 1 小时以内 新手友好度 84/100
aethersdr/AetherSDR#6368 · 1 条评论 ·
维护者通常 1 天内回复
-
Typings import `react` and `react-dom`, but `@types/react` and `@types/react-dom` are not declared as peer dependencies可能已有人在做 @lazerg 今天认领。 未关闭react
难度 2/5 1-3 小时 新手友好度 78/100
维护者通常 1 天内回复