Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Switching to a bare-based image will reduce the overall image size and reduces attack surface area.
The original Dockerfile uses
gcr.io/distroless/static:latest
, which has only a few packages. We can add those packages and switch to a bare-based image.Helm charts may expect the speaker image to be able to copy some files.
The
frr
rock base is not switched to bare as it has quite a few runtime dependencies and it is a bit more complex.We can no longer use
ensure_image_contains_paths
to check if files exist in the rock images, since they are now bare-based. Instead, we can useensure_image_contains_paths_bare
, which checks the image layers instead. Because of this, we need sufficient permissions to check the/var/lib/docker
folder.