4 ms·
> - Straightforward upgrades of the environment to incorporate security patches How do you ensure that your exposed containers have all the relevant security p
by cookiecaper 7y ago
> - Straightforward upgrades of the environment to incorporate security patches
How do you ensure that your exposed containers have all the relevant security patches, especially if the images aren't uniform? Are you using something like Watchtower to monitor for vulnerable packages and automatically rebuild and redeploy the containers when e.g. the underlying Ubuntu or Alpine image uses a vulnerable library?
Lots of people have the mistaken impression that containerization inherently protects their application from running vulnerable code. If you already have this built in to your pipeline, I'll be impressed!
- allochthon 7y agoIt's a side project. :) The "environment" in this case would be k8s. My (small) point was that that component is straightforward to upgrade if needed.