TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Let Google do the patching with new managed base images

120 点作者 cimnine超过 6 年前

8 条评论

dlor超过 6 年前
I'm Tech Lead/maintainer for these images. Happy to answer any questions!
评论 #18725411 未加载
评论 #18717878 未加载
评论 #18720073 未加载
评论 #18718063 未加载
评论 #18719640 未加载
评论 #18719201 未加载
评论 #18718983 未加载
评论 #18718169 未加载
评论 #18718407 未加载
评论 #18717914 未加载
评论 #18745690 未加载
评论 #18723079 未加载
评论 #18721182 未加载
rob-olmos超过 6 年前
&quot;The CentOS managed base image uses `yum` and `rpm` for package management, and these pull RPM files only over HTTPS connections.&quot;<p>That&#x27;s interesting. Is there a reason for that?<p>IIRC the stock CentOS doesn&#x27;t use HTTPS for its yum&#x2F;rpm repos and I figured it wasn&#x27;t necessary to use HTTPS since the package signature is verified.
评论 #18720526 未加载
评论 #18718966 未加载
coder543超过 6 年前
The Ubuntu base image is Ubuntu 16.04, which is an interesting choice. 18.04 LTS has been out for <i>awhile</i> now, so I would have expected it to at least be an option.
评论 #18717884 未加载
paaaaaaaaaa超过 6 年前
What&#x27;s the difference between this and pulling an official image from dockerhub? For example <a href="https:&#x2F;&#x2F;hub.docker.com&#x2F;_&#x2F;ubuntu&#x2F;" rel="nofollow">https:&#x2F;&#x2F;hub.docker.com&#x2F;_&#x2F;ubuntu&#x2F;</a>
评论 #18718032 未加载
nad7vx超过 6 年前
This is awesome - is there any thing similar for Azure? Or possible 3rd party solutions that do the same? We don’t leverage GCP but I am very envious of this feature. Would love the community to help point me in the right direction to get same functionality - mainly not having to maintain and patch Ubuntu 16.0.4 images
评论 #18718692 未加载
评论 #18718776 未加载
评论 #18717876 未加载
tmdk超过 6 年前
Does Google (or any of the other cloud vendors) audit&#x2F;review the actual source code of packages used in the images? such as apache, nginx, openjdk, etc? or do they just run a scanner that test for known vulnerabilities?
jiveturkey超过 6 年前
wow. why would anyone want this? in a production environment you want tight control over software versions, not surprise updates.
评论 #18721333 未加载
LaGrange超过 6 年前
&quot;Let Google do the patching&quot;<p>Also replace your shepherd dogs with wolves, wolves are bigger, faster, and will do it for free[*].
评论 #18718179 未加载
评论 #18718165 未加载