10 ms·
Let Google do the patching with new managed base images
- nad7vx 8y agoThis is awesome - is there any thing similar for Azure? Or possible 3rd party solutions that do the same? We don’t leverage GCP but I am very envious of this feature. Would love the community to help point me in the right direction to get same functionality - mainly not having to maintain and patch Ubuntu 16.0.4 images
- stefan_ 8y agoI think they call it "serverless"
- nad7vx 8y agoMy understanding is that those are more for “functions” or business logic. How can I leverage that for pointing my docker image to a 3rd party mainted base image?
- TheIronYuppie 8y agoThe good news is you don't have to use GCP! The very nice people over there have made them available for anyone - https://cloud.google.com/container-registry/docs/managed-base-images https://cloud.google.com/container-registry/docs/managed-bas... So, to be clear, no matter what cloud you use, if you create a Dockerfile like the following: FROM launcher.gcr.io/google/ubuntu16_04:latest CMD echo "foobar" This should work fine. Disclosure: I work at Microsoft on Azure.
- puzzle 8y agoYou moved to MS?!? Your about section still mentions your Google address. Good luck!
- TheIronYuppie 8y agoWhoops! Updated :) Thanks!
- ElijahLynn 8y agoThanks for pointing this out! Great news!
- fatherlinnux 8y agoYeah, it's called Red Hat Enterprise Linux ;-) It's available on all the cloud providers and has a better API/ABI guarantee as well as very, very well defined commitments to patching and lifecycle :-)
- dlor 8y agoI'm Tech Lead/maintainer for these images. Happy to answer any questions!
- Operyl 8y agoWhy is 18.04 not an available-at-launch image choice?
- stingraycharles 8y agoI think Ubuntu 16.04 is used internally a lot with Google, as they have hardened it themselves. I believe GKE On-Prem will also be based on Ubuntu 16.04 for this reason.
- ssambros 8y agoNot that much anymore. https://www.zdnet.com/article/google-moves-to-debian-for-in-house-linux-desktop/ https://www.zdnet.com/article/google-moves-to-debian-for-in-...
- dlor 8y agoThis was a mistake - we have it ready and just forgot to publish it. I'll get it out ASAP!
- Someone1234 8y agoDo you think this strategy could be successful/have a future for non-container based Operating Systems?
- scarface74 8y agoFor AWS: https://docs.aws.amazon.com/systems-manager/latest/userguide/systems-manager-patch.html https://docs.aws.amazon.com/systems-manager/latest/userguide...
- alwaysdoit 8y agoWhat's the difference between this and say: FROM ubuntu:16.04 Won't that pull the latest official Ubuntu image with that tag?
- coder543 8y agoThe Ubuntu base image is Ubuntu 16.04, which is an interesting choice. 18.04 LTS has been out for awhile now, so I would have expected it to at least be an option.
- dlor 8y agoWhoops, that looks like an oversight. 18.04 is definitely available as well.
- LaGrange 8y ago"Let Google do the patching" Also replace your shepherd dogs with wolves, wolves are bigger, faster, and will do it for free[*].
- andybak 8y agoThis doesn't make any sense. What motives would Google have for providing an insecure service on their cloud hosting. I'm all for Google-bashing in areas that actually make some sense but this is nonsensical.
- siffland 8y agoIf you are into conspiracy theory's and such, then you can question if google and NSA really have a partnership and PRISM and mass surveillance and all that stuff, then question if the images are tainted or whatnot. I am not saying it is so by any stretch. I am just saying how i can understand the paranoid not trusting this 100%.
- magicalist 8y agoStill makes no sense. If you're paranoid about it, why are you running on google's cloud?
- dlor 8y agoSidestepping the conspiracy questions, these images are built reproducibly, from sources available on GitHub. You can clone the repo, audit the build tools and inputs, and build the image yourself. You'll get the exact same sha256 as the one on our registry.
- paaaaaaaaaa 8y agoWhat's the difference between this and pulling an official image from dockerhub? For example https://hub.docker.com/_/ubuntu/ https://hub.docker.com/_/ubuntu/
- LaGrange 8y agoIt's betting that Google are better package maintainers than Debian/CentOS/Ubuntu, especially when it comes to maintaining container images. From a purely technical, and financial, point of view, it's likely true. Of course, they could have bolstered the distro teams. And the fact that the repositories are within GCR, not Docker, is just convenience. It brings you closer into Googles warm, technototalitarian embrace, is what I mean.
- ramses0 8y agoI would suggest you look a little deeper into Debian's history and work on reproducible builds: https://wiki.debian.org/ReproducibleBuilds https://wiki.debian.org/ReproducibleBuilds They've been at it (looks like) since ~2014, and their goals and motivations seem 100% in line with google, but at the package/distro level, not the container-base-image level (highly related): https://tests.reproducible-builds.org/debian/unstable/amd64/stats_pkg_state.png https://tests.reproducible-builds.org/debian/unstable/amd64/...
- LaGrange 8y ago> goals and motivations seem 100% in line with google, It's been a long time since I've believed in their idealism, yes, but I still think accusing Debian of being in the advertising and surveillance business is a bit harsh.
- ramses0 8y ago> Google are better package maintainers than Debian My intent was to challenge your statement that google are better package maintainers than Debian, specifically w.r.t. reproducibility of builds. It's disrespectful to Debian to think that they haven't been pushing for secure, auditable, trusted software running on trusted computers. It's practically their reason for existing: taking open, auditable software, packaging it in reproducible fashion for use by anyone who wants it. https://www.debian.org/social_contract.html#guidelines https://www.debian.org/social_contract.html#guidelines Imagine if Debian had similar financial support available compared to Google/RedHat? The best info I could find is here: https://www.spi-inc.org/corporate/annual-reports/2017.pdf https://www.spi-inc.org/corporate/annual-reports/2017.pdf `This covers the Period January 1, 2017 – December 31, 2017` `Gross Income -------- 635,311.59` ...and in that way, yes: google can afford more package maintainers, more scrutiny, but if they are "better package maintainers" it's at those margins and due to economics rather than ability or desire.
- rob-olmos 8y ago"The CentOS managed base image uses `yum` and `rpm` for package management, and these pull RPM files only over HTTPS connections." That's interesting. Is there a reason for that? IIRC the stock CentOS doesn't use HTTPS for its yum/rpm repos and I figured it wasn't necessary to use HTTPS since the package signature is verified.
- blaike 8y agoSome orgs have requirements for using encryption in transit for everything.
- TurningCanadian 8y agoa MITM can trick your server into thinking there are no updates, and no error will be raised
- skj 8y agoThat, and an attacker could do a replay attack, and potentially send you to an earlier (vulnerable) version.
- jiveturkey 8y agowow. why would anyone want this? in a production environment you want tight control over software versions, not surprise updates.
- jacques_chester 8y agoI generally agree with you. However I also feel that the ABI guarantees by Red Hat, Canonical and the Debian project are fairly trustworthy. Rolling forward automatically is much less risky, taken overall, than a rotting pin.
- deleted 8y ago[deleted]
- tmdk 8y agoDoes Google (or any of the other cloud vendors) audit/review the actual source code of packages used in the images? such as apache, nginx, openjdk, etc? or do they just run a scanner that test for known vulnerabilities?
- recipient 8y ago966556925437@mms.net.sa