bazel-contrib / bazel-contrib/rules_python
Support native binary-based stage1 bootstrap
- Lingua principale
- Starlark
- Stelle
- 688
- Fork
- 721
- Merge medio
- 15h 7m
- PR unite (30g)
- 76
Descrizione
# 🚀 feature request
### Relevant Rules
`py_binary`
### Description
With a similar motivation as #691, we would like to package a `py_binary` (including runfiles) into an `oci_image` and run it within a minimum base image like [distroless_base](https://github.com/GoogleContainerTools/distroless/tree/main/base) in order to minimize the attack surface. This does not come with a shell and other tools which are required by #1929 so this unfortunately doesn't help us.
### Describe the solution you'd like
Use a statically linked executable as loader.
### Describe alternatives you've considered
Add more stuff to the base image. This is suboptimal as this does not only increase the size but also the attack surface.
Guida per i contributori
Apri la guida per i contributori
Direzione di ricerca
Start by reviewing the existing py_binary and oci_image integration, then read the related discussions in #691 and #1929. No source files or tests are named in the issue. Done means a py_binary, including its runfiles, can run from a minimal distroless_base image using a statically linked executable as its loader.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Valutazione
- Stack tecnologico
- python
- Ambito
- build-system
- Tipo di issue
- Funzionalità
- Difficoltà
- 5/5
- Tempo stimato
- Più di una settimana
- Stato di attività
- Ferma
- Chiarezza
- Abbastanza chiara
- Idoneità per principianti
- 30/100