4 ms·
To provide a real-life use-case for such a tiny container image: With Kubernetes one may want to run the service container as a random or at least non-root user
by El_RIDO 5y ago
To provide a real-life use-case for such a tiny container image: With Kubernetes one may want to run the service container as a random or at least non-root user id and store data in an attached volume. That volume will usually be attached as owned by root. So often an init-container is used, which runs once, before the service container is started, to change the permissions.
Here is an image with a statically linked chown binary from the busybox tools cowering this use case: https://hub.docker.com/r/privatebin/chown https://hub.docker.com/r/privatebin/chown (I am the author of that image)
Benefits of using a small image are less attack surface and faster operation (less data to download, lower startup time, less memory, etc.).
- spalas 5y agoHi! Author here! My (somewhat silly) use case for the tiny container was trying to cram 10,000 pods onto a k8s cluster without breaking the bank: https://www.youtube.com/watch?v=1y2nRNexRVk https://www.youtube.com/watch?v=1y2nRNexRVk