Uploaded image for project: 'Multiple Architecture Enablement'
  1. Multiple Architecture Enablement
  2. MULTIARCH-5645

Trim the container images file systems

XMLWordPrintable

    • Icon: Story Story
    • Resolution: Unresolved
    • Icon: Major Major
    • None
    • None
    • None
    • None
    • False
    • Hide

      None

      Show
      None
    • False
    • None
    • None
    • None

      We can create a final runtime layer in the Dockerfile for the images where we only stores the binaries, libraries and configurations actually needed to run the operator's binaries.

      This would reduce the surface of attack and limit malicious users from exploiting a shell in the operator pods to attack the cluster. This is especially critical for the eBPF program ran by the execFormatError plugin as it runs in a privileged container.

      After a discussion with Product Security, we agreed on targeting this enhancement/fix for MTO 1.3

              rhn-support-adistefa Alessandro Di Stefano
              rhn-support-adistefa Alessandro Di Stefano
              Matthias Weckbecker
              None
              None
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated: