4 ms·
not to be pedantic but why should containers be patched for security issues? the entire point of containers (and orchestration systems) is the ability to push
by sonaltr 8y ago
not to be pedantic but why should containers be patched for security issues?
the entire point of containers (and orchestration systems) is the ability to push updates without downtime.
Just update with a newer container....am I missing something?
Also about container security - a strict process internally can easily help counter that (I believe Shopify had a nice talk about it at the Google Cloud Platform event in Toronto - everything from using trusted images, running only signed images and going through a security check for each layer).
EDIT: To add to it, please don't patch containers - the entire point of an "image" is that if I run it locally and on my datacenter - it should behave the same - live patching them just voids this concept.
- claviola 8y agoHow many people do you see setting up a deploy pipeline that includes pulling security updates into the base image and redeploying as needed? In my experience, it's much more common to see docker images that have been untouched for months with zero accountability of what exactly is running there.
- secabeen 8y agoThat's my real concern: old, out of date images. How will we handle another OpenSSL-level vulnerability in 7 years, with bad code buried in containers that haven't been updated in 4, and for which the build infrastructure is no longer functional?
- Spivak 8y agoThis really isn't that different from having some pre-built statically liked app still kicking on your system with the source and/or build tooling long gone. There aren't really easy answers here. You can't fix bad software with more tooling.
- sonaltr 8y agoI blame that on docker hub. It's the fault of Docker - the company. They have a security scanning software that they decided was an enterprise feature. This sort of issue is to be expected if you claim that security to be an enterprise feature.