Skip to main content

Distroless Deployments - In Progress

 



“Distroless” images contain only your application and its runtime dependencies. They do not contain package managers, shells or any other programs you would expect to find in a standard Linux distribution.


A distroless image is a slimmed down Linux distribution image plus the application runtime, resulting in the minimum set of binary dependencies required for the application to run.

You don't have Shell in Distroless distribution.

A typical container consists of:

  • Distro base layer - linux distribution files (Ubuntu, CentOS, Debian)
  • Runtime layer (JRE for Java, Python runtime, glibc for C++)
  • Application layer - actual application binaries 

Why should I use distroless images?

w

Distroless images are very small. The smallest distroless image, gcr.io/distroless/static-debian11, is around 2 MiB. That's about 50% of the size of alpine (~5 MiB), and less than 2% of the size of debian (124 MiB).



The general syntax involves adding FROM additional times within your Dockerfile - whichever is the last FROM statement is the final base image. To copy artifacts and outputs from intermediate images use COPY --from=<base_image_number>.


https://github.com/GoogleContainerTools/distroless/blob/main/examples/java/Dockerfile


javac HelloJava.java

jar cfe main.jar HelloJava HelloJava.class

java -jar main.jar



FROM openjdk:11-jdk-slim-bullseye AS build-env

COPY HelloJava.java /app

WORKDIR /app

RUN javac HelloJava.java

RUN jar cfe main.jar HelloJava HelloJava.class


FROM gcr.io/distroless/java11-debian11

COPY --from=build-env /app /app

WORKDIR /app

CMD ["main.jar"]

=====

FROM openjdk:11-jdk-slim-bullseye AS build-env

COPY . /app/examples

WORKDIR /app

RUN javac examples/*.java

RUN jar cfe main.jar examples.HelloJava examples/*.class 


FROM gcr.io/distroless/java11-debian11

COPY --from=build-env /app /app

WORKDIR /app

CMD ["main.jar"]


==================

package examples;


public class HelloJava {

    public static void main(String[] args) {

        System.out.println("Hello world");

    }

}

====================
















Comments

Popular posts from this blog

PIANO MUSIC THEORY

  Time signature The time signature of a piece of music indicates how many beats are in each bar. A time signature allows a musician to count a steady beat while playing a piece. The time signature is written at the beginning of the  staff . It comes after the  clef  and key signatures. You may find certain pieces of music have include changes to different time signatures. This will be marked on the sheet music, so always check through a piece of music to ensure you are aware of any changes of time signature it might have. Metronome mark A composer may include a  metronome  mark to indicate the  tempo  - how fast or slow the music should be played. For example, the metronome mark above tells you there are 80 crotchet beats per minute. Key signatures The key signature tells you which notes should be played as  sharps  or  flats  throughout a piece of music and therefore what key the piece should be played in. The examples above ...

Apple Provisioning

  Common Reasons for App Signing on Both Platforms: Authentication: App signing provides a mechanism for authenticating the source of the app. Users and systems can trust that the app comes from the stated developer. Preventing Tampering: App signing helps prevent unauthorized modifications to the app. If the app's binary or resources are altered, the signature won't match, and the system will reject the app. Ensuring Updates: With app signing, updates can be delivered securely. The platform can verify that the update is signed by the same entity that signed the original app. APP SIGNING PROCESS IN IOS App signing in iOS involves the use of digital signatures to verify the authenticity and integrity of an app. This process is an integral part of the code signing mechanism in iOS development. Here are the key steps involved in app signing for iOS: Create a Certificate Signing Request (CSR): Before you can sign your app, you need a certificate. To obtain a certificate, you start ...