3 ms·
Off-topic, but pertains to Docker images: Do people usually roll out their own images from source/based on verified binaries from the parent distribution's rep
by consonants 13y ago
Off-topic, but pertains to Docker images:
Do people usually roll out their own images from source/based on verified binaries from the parent distribution's repositories or are base images provided by the community?
- mpasternacki 13y agoI've seen both; Docker's main registry provides some base images (the most used is named `ubuntu` and has base system for Precise and Raring), and I've seen many imaged descending from author's own base - it's quite easy to prepare a base image using debuild or other distros' equivalents. Can't talk about not debian-ish distributions, but debuild does verify its downloads. The place of trust here is the registry - usually, for convenience, tags are used rather than hashes (and I'm still quite not sure whether the long hex IDs are hashes, or just unique random names). The registry returns hex id for a given tag, and is trusted to deliver correct files for an ID. I believe that the main index/registry runs over https and provides basic security, but it would be a huge issue if it was compromised. It's quite easy to run your own registry, too. What I'd love to see on top of that is some kind of GPG-based verification of downloaded images (Debian got the problem basically solved in Apt).