Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore!: Remove wget from Promtail docker image (backport release-3.2.x) #15145

Merged
merged 1 commit into from
Nov 27, 2024

Commits on Nov 27, 2024

  1. chore!: Remove wget from Promtail docker image (#15101)

    The package has been added to the Docker image with PR #11711 with the intention to support the Docker healthcheck.
    
    However, to reduce the attack surface of our Docker images, we want to keep them as slim as possible. The current version of Promtail (3.3.0) for example contains a wget version with vulnerability [CVE-2024-38428](https://security-tracker.debian.org/tracker/CVE-2024-38428).
    
    The healthcheck can be achieved by other means, e.g.
    
    1. Extend the `grafana/promtail` base image and add `wget` using `apt install wget`
       #11590 (comment)
    3. Use low-level `/dev/tcp/127.0.0.1:9080` to establish a connection and check the exit code
       #11590 (comment)
    
    Original discussion about adding wget #11590
    This may break someone's Docker compose installation, when they require on the `wget` powered health check.
    
    Signed-off-by: Christian Haudum <[email protected]>
    (cherry picked from commit 2eea546)
    chaudum authored and grafana-delivery-bot[bot] committed Nov 27, 2024
    Configuration menu
    Copy the full SHA
    781397f View commit details
    Browse the repository at this point in the history