4 ms·
It's best practice not to have any shell tools in your app container, including package managers. It bloats the image and can be a security vulnerability if a
by qbasic_forever 4y ago
It's best practice not to have any shell tools in your app container, including package managers. It bloats the image and can be a security vulnerability if a zero day exploit hits the app. Ideally a container is something like distroless which just has the libc and dependencies you care about and nothing else, not even bash.
- Steltek 4y agoBut where do your dependencies come from? Your compiler? Are you building everything from source after libc?
- qbasic_forever 4y agoIf you're shipping modern code like go or rust you have a static build with no real dependencies. If you're shipping a scripting language like python you're probably going to use their base images, and if you're shipping native C/C++ you have to figure out your risk tolerance for trusting a distro to ship good dependencies vs. just building them yourself. It's not hard to build all your deps in a container, and arguably is the best security practice so you have total control and knowledge of their versions.
- m4rtink 4y agoWouldn't something like that be really hard to debug in real world scenarios ?