3 ms·
Chris from Kinvolk here. We're happy to talk about what you need on the security front. Some of the folks working on Flatcar Container Linux have a very strong
by blixtra 7y ago
Chris from Kinvolk here.
We're happy to talk about what you need on the security front. Some of the folks working on Flatcar Container Linux have a very strong security background; worked on AWS' EC2 security team, do regular pentesting for distributed systems[1], have reported dozens of security issues to upstream projects packaged in Flatcar Container Linux, including the kernel.
We've just now started breaking away from the upstream project, and updating packages. Addressing any open security issues is front and center in our efforts. If you have concerns we'd love to hear them.
We worked with CoreOS team for years (was our founding project) and they trusted us on the security front. We feel that if you trusted CoreOS and know our team + background, you should have just as much trust in Kinvolk.
[1] https://www.youtube.com/watch?v=ze1vgh8sjlE https://www.youtube.com/watch?v=ze1vgh8sjlE
- hunta2097 7y agoHi Chris, Thanks for the informed response. To be honest I hope Flatcar does well, I notice the Docker version has been updated on your edge release - long overdue from the upstream project! I will let you know if our security team has any issues if and when they look at it. Thanks for giving everyone the option of staying on Container Linux!
- blixtra 7y agoThe whole point of CoreOS Container Linux was to deliver a steady stream of security/software updates. We've been eager to update packages for Flatcar Container Linux but have wanted to maintain as much compatibility as possible for as long as possible. Fairly soon, however, we'll be introducing an updated kernel and user space (systemd, Docker, etc.) into the alpha channel. For us, this will mark the point where we feel like we're fully taking the reins from CoreOS and carrying forward the original objectives.