3 ms·
In production it can be better to bind-mount the host's CA store, instead of relying on each container to have a correct and current CA database. This is espec
by tedchs 4y ago
In production it can be better to bind-mount the host's CA store, instead of relying on each container to have a correct and current CA database. This is especially needed if an enterprise CA is in use.
In general I think the unidirectional "layered" container image model is a stepping stone. It ought to be easy to replace the "runtime" layer for a container without rebuilding the higher layer holding the application code. I can replace the host's kernel without modifying the code; why can't I upgrade the container's glibc or Python?
- jacobr1 4y agoTake a look at buildpack layer model and caching options: https://buildpacks.io/docs/buildpack-author-guide/caching-strategies/ https://buildpacks.io/docs/buildpack-author-guide/caching-st...