4 ms·
Yes. Works great with Haskell statically compiled binaries. Running the binary through UPX i've managed to get small HTTP microservices down to a 2MB docker im
by ek5Jf 9y ago
Yes.
Works great with Haskell statically compiled binaries. Running the binary through UPX i've managed to get small HTTP microservices down to a 2MB docker image with just Scratch.
- Intermernet 9y agoWorks just as well for Go binaries. It's pretty much the recommended base image for distribution of Go apps on Docker. I assume that it would be just as effective for any statically compiled binary. Edit: I really should have read the article first. It uses Go binaries as the example. Good to know Haskell folks are also using it.
- rmoriz 9y agoMassive downside: You run your app as root or you have to do nasty mounts of /etc/passwd and /etc/group from your host
- Intermernet 9y agoYou can run a Docker container as a particular user. https://docs.docker.com/engine/reference/builder/#user https://docs.docker.com/engine/reference/builder/#user You can use `setcap` to grant capabilities to the binary or the `pam_cap` module if you need to do capabilities per user. I haven't run across the need to run most containers as root for a while now.
- embano1 9y agoYup, in the end it´s an OS process and all rules apply. I did not care too much about Dockerfile best practices in my article. Good point, should at least have used "user <!root>".
- lizxrice 9y agoYou don't have to mount the host versions - you can create container-specific ones. See https://medium.com/@lizrice/non-privileged-containers-based-on-the-scratch-image-a80105d6d341 https://medium.com/@lizrice/non-privileged-containers-based-...