steve_clarke
12/06/2021, 3:55 AMpython:3.8.12-slim-bullseye
I'm wonder if it is possible to have alternative Meltano Docker builds which I could pull from with a more hardened base image? I can't comment however whether this image will run Meltano correctly or not. I do know however that my security team would be a lot happier 😀.
I also have another related security question regarding best practices for environment variables. Really keen to get a steer on that too. https://meltano.slack.com/archives/C01UTUSP34M/p1638488867102100
Thanks
Stevesteve_clarke
12/07/2021, 7:24 AMedgar_ramirez_mondragon
12/07/2021, 6:35 PMpython:3.8.12-slim-bullseye
? If the slim images work this may be something we want to implement on the Meltano images in dockerhubsteve_clarke
12/08/2021, 5:03 AMpython:3.8.12-slim-bullseye
image has reduced the number of vulnerabilities by quite a bit. I do think these slim images might be good, they also make smaller images which is good.
I shaved off 200MB with the slim image. I probably could improved this with refactoring my docker image a bit. See the attached table for the scan difference. If you were able to use the slim python images for the base that would be much appreciated.
Thanks
Stevesteve_clarke
02/22/2022, 10:29 PMaaronsteers
02/22/2022, 11:12 PMsteve_clarke
02/23/2022, 7:58 AMaaronsteers
02/23/2022, 4:44 PMaaronsteers
02/23/2022, 6:02 PM