3 ms·
> Why is it still necessary to have whole, full-blown OS filesystems inside of our containers, if their purpose is running a single binary? It's not. This is
by pravus 3y ago
> Why is it still necessary to have whole, full-blown OS filesystems inside of our containers, if their purpose is running a single binary?
It's not. This is just the path of least resistance for most container builds since many applications require various supporting files to function properly. Most of my Go containers only contain 2 files: the go binary and ca certificates.
> Dependencies/dynamic libraries are decent reason, sure. But wouldn't it make more sense to do things "bottom-up"?
In theory, yes. With dynamic loading and support for loading plugins and runtime this is virtually impossible to do. That's why starting from a base image that already includes everything you need is generally the chosen method. BSD jails/chroot operate this way and it's an absolute pain to setup for complicated applications.