-
Notifications
You must be signed in to change notification settings - Fork 54
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
REQUEST: Use distroless image in final stage #103
Comments
Hi @xunholy, thanks for raising this. The 0.3.0 release was initially pushed to docker based on alpine 3.13.2 in error, and it has now been updated with the same binary layered on 3.13.5 as it should have been based on our Dockerfile. I believe this should address the CVEs of concern? Separately, on the question of a distro-less image, could you explain a little more about the motivation for this request please? |
Hi @tomhjp thanks for informing me about the image error. Our ask for distroless is to avoid several exploits and to help harden our implementation in GKE. With this plugin we were able to surface a few attack vectors that we can completely mitigate if there was no shell that could be used to exploit. Obviously we have the default position that things like pods/exec and other RBAC controls are in place, but this is also helping protect from lateral privilege escalation from other compromised workloads that might be used to bleed into this particular workload. We're using the GSM plugin among others and these are all based on distroless images in final stages, my ask would be to keep it aligned with that to help reduce the attack surface seeing as secret management is such a critical asset. **Sorry for being slightly cryptic 😅 |
@tomhjp any further consideration or context required? |
Would this still be considered for a future release? |
vault-csi-provider/Dockerfile
Line 1 in 425b31c
I'd like the request we move the final stage of the image to a distroless image - or even an image that has no shell.
It would also be great to do some image scanning for known CVE vulnerabilities as it appears there are some in this image that are marked HIGH and CRITICAL respectively.
The text was updated successfully, but these errors were encountered: