Uploaded image for project: 'OpenShift Service Mesh'
  1. OpenShift Service Mesh
  2. OSSM-8188

Move build of istioctl out of istio-pilot container

XMLWordPrintable

    • Icon: Story Story
    • Resolution: Done
    • Icon: Major Major
    • OSSM 3.0-TP2
    • None
    • Sail Operator
    • None

      It would be better if the istioctl binary was created as part of a different container image than istio-pilot.

      Having it contained within istio-pilot:

      1. Increases the footprint of the container, which is undesirable, and
      2. Introduces a potential security risk by an additional package being shipped in the container that could be exploited.

      It is recognized that it would be a lot of work to create a whole new container image just for this one binary, and it would be pointless to publish such an image. Thus, instead, it has been suggested that perhaps we instead build istioctl and distribute it as part of the must-gather image.

      This Jira represents researching what would be the best solution, and then implementing it. It is recognized that this change will probably mean having to make updates in the subsequent distribution systems which are involved.

              _bmangoen Brian Mangoenpawiro
              dward-se-jboss David Ward
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: