Jetstack Paranoia: A New Open-Source Tool for Container Image Security
jetstack.io
jetstack.io
In general I think the unidirectional "layered" container image model is a stepping stone. It ought to be easy to replace the "runtime" layer for a container without rebuilding the higher layer holding the application code. I can replace the host's kernel without modifying the code; why can't I upgrade the container's glibc or Python?
This looks great, but it's insane we need to do this: TLS really needs to be a kernel level, global feature. Take it out of the hands of applications, and let's add a pluggable system which extends the socket interface directly since that's theoretically what "transport layer security" is.
Google is moving TCP to user level (QUIC) for a reason.
So we wind up in this space where a transport level protocol is for some reason being handled by the application stack, in a million different places and only somewhat common by convention (which we've gone and broken with containerizing userspace).