Shrink to Secure: Kubernetes and Secure Compact Containers
gsantoro.dev
gsantoro.dev
Re: security, defining security contexts for containers and pods are quite important, the container should not run as root, you should drop all capabilities, ...etc. For example
securityContext:
runAsNonRoot: true
runAsGroup: 1000
runAsUser: 1000
privileged: false
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
capabilities:
drop:
- ALL
You should also use something like kubescape[1] to regularly scan your cluster (or helm files or yaml files). Furthermore, you should use an admission controller[2] like Gatekeeper[3] to enforce certain policies in your clusters e.g. containers should always have a securityContext.[0] https://cloud.google.com/artifact-registry/docs/analysis
[1] https://github.com/kubescape/kubescape
[2] https://kubernetes.io/docs/reference/access-authn-authz/admi...
The post also doesn't mention SlimToolkit (aka DockerSlim), which is now a CNCF Sandbox project. It represents another major way to create minimal container images.
i used dockerslim in the past and i was impressed. i didn't add to the article since i wasn't aware it became a CNCF protect. I wasn't sure who was using it.