Skip to content

Update the baseimage to debian:stretch-slim for node:slim image #821

Description

@mkumatag

Now security patches are limited to certain architectures for jessie release.

Refer following links for more information:
https://lists.debian.org/debian-security-announce/2018/msg00132.html
debuerreotype/docker-debian-artifacts#44 (comment)
vicamo/docker_buildpack-deps#33

Because of the above reason, we'll have to move to the next release of debian to build it on all different archs and works fine.

Activity

  1. mkumatag commented on Jul 19, 2018

    @mkumatag
    Author

    I got a recommendation of adding Dockerfile template in root directory by @PeterDaveHello. But in this case, I need to change the content of Dockerfile-slim.template to accommodate the changes needed for the stretch release.

    We have 2 ways of doing this:

    1. Create Dockerfile-slim-stretch.template and mantain the changes for stretch-slim release
    2. Modify the content to Dockerfile-slim.template file which will enforce everyone to start using stretch as baseimage(one way it will make sure every damn image will work properly on all the arch)

    So I need @PeterDaveHello and your team's opinion here to make the changes.

  2. mkumatag commented on Jul 19, 2018

    @mkumatag
    Author

    /cc @nodejs/docker

  3. kbirger commented on Aug 8, 2018

    @kbirger

    This would be wonderful. I have a requirement to be using Stretch for my base images for the security fixes, etc, and a requirement for slim to conserve space.

    @mkumatag I would think Option 2 is better. Stretch is considered stable now.

    Is there an eta on when this issue might be addressed?

  4. mkumatag commented on Aug 8, 2018

    @mkumatag
    Author

    @kbirger I already have a working PR ready, I'm just waiting for nodejs team to merge it.

    @PeterDaveHello @LaurentGoderre @chorrell

  5. LaurentGoderre commented on Sep 5, 2018

    @LaurentGoderre
    Member

    To minimize disruption I created an alternate PR that gives users the choice between jessie or stretch for the slim variant.

    I don't think we should switch the slim variant without also changing the default variant.

  6. lag-linaro commented on Nov 1, 2018

    @lag-linaro

    Is there an update on this please?

    The Docker Official Images build for Node is currently broken on ARM64.

  7. PeterDaveHello commented on Nov 2, 2018

    @PeterDaveHello
    Member

    We've changed default & slim variant to Stretch in the base image, and applied to the latest v11 release, would migrate v6, v8 & v10 to Stretch in future.

  8. PeterDaveHello commented on Nov 2, 2018

    @PeterDaveHello
    Member

    @lag-linaro I think we have ARM64 builds for these tags:

    Tags: 8.12.0-alpine, 8.12-alpine, 8-alpine, carbon-alpine
    Tags: 8.12.0-stretch, 8.12-stretch, 8-stretch, carbon-stretch
    Tags: 6.14.4-stretch, 6.14-stretch, 6-stretch, boron-stretch
    Tags: 11.0.0-alpine, 11.0-alpine, 11-alpine, alpine
    Tags: 11.0.0-slim, 11.0-slim, 11-slim, slim
    Tags: 11.0.0-stretch, 11.0-stretch, 11-stretch, stretch, 11.0.0, 11.0, 11, latest
    Tags: 10.13.0-alpine, 10.13-alpine, 10-alpine, dubnium-alpine
    Tags: 10.13.0-stretch, 10.13-stretch, 10-stretch, dubnium-stretch

    Ref: https://github.com/docker-library/official-images/blob/master/library/node

  9. lag-linaro commented on Nov 2, 2018

    @lag-linaro

    @PeterDaveHello the trouble is, we have a dependency for Ghost:

    https://github.com/docker-library/ghost/blob/master/2/debian/Dockerfile

    Will the default 8-slim repo be moved to 8-stretch?

  10. lag-linaro commented on Nov 2, 2018

    @lag-linaro

    Another reference/request: TryGhost/docker-library-ghost#157 (comment)

    It would be good if you could move all of your default images to Stretch.

    Jessie is no longer receiving updates.

  11. PeterDaveHello commented on Nov 2, 2018

    @PeterDaveHello
    Member

    Jessie has LTS support until June 30, 2020, from the last discussion, we may transfer to Stretch about 1 month later.

    cc @chorrell

  12. chorrell commented on Nov 2, 2018

    @chorrell
    Contributor

    Maybe we need a slim-stretch variant for 8.x.x and 10.x.x for the Ghost image to use?

  13. PeterDaveHello commented on Nov 2, 2018

    @PeterDaveHello
    Member

    maybe

  14. chorrell commented on Nov 2, 2018

    @chorrell
    Contributor

    But...I’m not sure it’s worth the effort. I’d rather just switch the slim variant for the next v8.x.x release

  15. PeterDaveHello commented on Nov 2, 2018

    @PeterDaveHello
    Member

    maybe open an issue for more formal discussion?

  16. kbirger commented on Nov 2, 2018

    @kbirger

    I don't understand - has there been any movement on this issue or not?

  17. PeterDaveHello commented on Nov 7, 2018

    @PeterDaveHello
    Member

    No, we haven't made any decision yet.

  18. PeterDaveHello commented on Nov 7, 2018

    @PeterDaveHello
    Member

    Ping @nodejs/docker for suggestions ;)

  19. chorrell commented on Nov 7, 2018

    @chorrell
    Contributor

    I think at this point we should just start switching over to stretch when we update each v10 and v8 image. The required changes are already in the repo. I think we can proabbly skip v6 since it will be gone soon and I don't see it being updated in the near future (but I could be wrong).

    This would technically be a breaking change, but given the current situation, things are broken already. In the future we should create stretch-slim variant to set the groundwork for the next Debian release.

  20. LaurentGoderre commented on Nov 7, 2018

    @LaurentGoderre
    Member

    That's what I tried to do with #850

  21. chorrell commented on Nov 7, 2018

    @chorrell
    Contributor

    Can we revisit the approach in #850 with what we have now?

  22. LaurentGoderre commented on Nov 8, 2018

    @LaurentGoderre
    Member

    Absolutely. I am very busy until end of week but I should have more time to dedicate to this next week.

  23. LaurentGoderre commented on Nov 16, 2018

    @LaurentGoderre
    Member

    @chorrell I updated my PR #850

  24. LaurentGoderre commented on Nov 16, 2018

    @LaurentGoderre
    Member

    Something is wrong with the build. It can't fetch any of the keys

  25. tianon commented on Nov 16, 2018

    @tianon
    Contributor
  26. chorrell commented on Nov 16, 2018

    @chorrell
    Contributor

    --> #912

  27. chorrell commented on Dec 4, 2018

    @chorrell
    Contributor

    Closing as stretch is now the default, and we provide a jessie and jessie-slim options for those who need it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions