4 ms·
I haven't seen ubuntu's version of distroless but the general term implies a container image with an empty shell of what a linux distro provides. Leaving behind
by mhio 2y ago
I haven't seen ubuntu's version of distroless but the general term implies a container image with an empty shell of what a linux distro provides. Leaving behind only the minimum files for running your app rather than all the cruft around running and maintaining a distro, which is normally all done at container build time.
From the Debian based https://github.com/GoogleContainerTools/distroless/blob/main/base/README.md https://github.com/GoogleContainerTools/distroless/blob/main...
Statically compiled applications (Go) that do not require libc can use the gcr.io/distroless/static image, which contains:
- ca-certificates
- A /etc/passwd entry for a root user
- A /tmp directory
- tzdata
Applications that require libc but do not need libssl can use the gcr.io/distroless/base-nossl, which contains all of the packages in gcr.io/distroless/static, and
- glibc
Most other applications (and Go apps that require libc/cgo) should start with gcr.io/distroless/base, which contains all of the packages in gcr.io/distroless/static, and
- glibc
- libssl
- newman314 2y agoWhat I have found is that at least Google's distroless images do not get updated frequently enough to handle security issues. Because of this, I ended up switching to Ubuntu images and doing apt-get dist-upgrade before anything else to try to pick up fixed binaries. If Ubuntu truly is able to keep an up to date cadence for its distroless images, then I'd definitely want to investigate to see if I should switch.
- lolinder 2y agoLooking at the dependency listing I'm trying to figure out why this would be. There are like 4 dependencies here in the largest of these containers, so why is it so difficult to keep them up to date?
- mhio 2y agoThe issues I've seen are around updating the run times to point to new release versions in a timely manner. The project maintainers don't actively work on (the endless) security updates and defer people to commercial projects that can spend the time doing that.
- lokar 2y agoThe images are tiny, and trivial to update. You don’t really need theirs, just take the bazel rules and build it yourself.
- laz 2y agoI'm using rules_distroless+rules_oci with bazel to build small Ubuntu based images. It takes some effort, but ends up being pretty nice.