loopbackio / loopbackio/loopback-next

Use FQIN in Dockerfile

Đang mở
#9,841 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Một pull request liên quan đã được merge.

  • #9842 của @achrinza — đã merge
Ngôn ngữ chính
TypeScript
Star
5.1k
Fork
1.1k
Merge trung bình
2 ngày 21 giờ
Pull request đã merge (30 ngày)
27

Mô tả

Historically, we have used Unqualified Image Names. However, this is insecure as it is ambiguous on registry to use. Fully Qualified Image Names (FQIN) make explicit the domain name of the registry to pull from.

## Change details

For `Dockerfile`s, the general update will be:

```diff
+ FROM docker.io/library/node:18-slim
- FROM node:18-slim
```

Although there is special-handling for the `docker.io` registry that allows omission of `/library` namespace path prefix for "no-namespace" images, we should use the full FQIN so as to be consistent with the output of other utilities such as `podman image ls`.

## Impact

Other than updated `Dockerfile`s, there should be no other noticeable impact.

## Files to update

- `loopback-next`
- [docs/site/Application-generator.md](https://github.com/loopbackio/loopback-next/blob/553cfb173ece664e0d25f029f2ac27eeaef89897/docs/site/Application-generator.md?plain=1#L118)
- [examples/access-control-migration/Dockerfile](https://github.com/loopbackio/loopback-next/blob/553cfb173ece664e0d25f029f2ac27eeaef89897/examples/access-control-migration/Dockerfile#L2)
- [examples/multi-tenancy/Dockerfile](https://github.com/loopbackio/loopback-next/blob/553cfb173ece664e0d25f029f2ac27eeaef89897/examples/multi-tenancy/Dockerfile#L2)
- [examples/references-many/Dockerfile](https://github.com/loopbackio/loopback-next/blob/553cfb173ece664e0d25f029f2ac27eeaef89897/examples/references-many/Dockerfile#L2)
- [examples/rest-crud/Dockerfile](https://github.com/loopbackio/loopback-next/blob/553cfb173ece664e0d25f029f2ac27eeaef89897/examples/rest-crud/Dockerfile#L2)
- [examples/socketio/Dockerfile](https://github.com/loopbackio/loopback-next/blob/553cfb173ece664e0d25f029f2ac27eeaef89897/examples/socketio/Dockerfile#L2)
- [examples/todo/Dockerfile](https://github.com/loopbackio/loopback-next/blob/553cfb173ece664e0d25f029f2ac27eeaef89897/examples/todo/Dockerfile#L2)
- [examples/todo-jwt/Dockerfile](https://github.com/loopbackio/loopback-next/blob/553cfb173ece664e0d25f029f2ac27eeaef89897/examples/todo-jwt/Dockerfile#L2)
- [examples/todo-list/Dockerfile](https://github.com/loopbackio/loopback-next/blob/553cfb173ece664e0d25f029f2ac27eeaef89897/examples/todo-list/Dockerfile#L2)
- [packages/cli/generators/app/templates/Dockerfile](https://github.com/loopbackio/loopback-next/blob/553cfb173ece664e0d25f029f2ac27eeaef89897/packages/cli/generators/app/templates/Dockerfile#L4)
- `create-loopback`
- [templates/app/Dockerfile](https://github.com/loopbackio/create-loopback/blob/650ce5fe7d021b53e461af2994c9f0669aa3b23d/templates/app/Dockerfile#L2)
- `loopback4-example-shopping`
- [bin/dockerize.js](https://github.com/loopbackio/loopback4-example-shopping/blob/af15cf5e6a5d309c61da2ee9e522533ee9def980/bin/dockerize.js#L69-L107)
- [Dockerfile.monorepo](https://github.com/loopbackio/loopback4-example-shopping/blob/af15cf5e6a5d309c61da2ee9e522533ee9def980/Dockerfile.monorepo#L4)
- [Dockerfile.recommender](https://github.com/loopbackio/loopback4-example-shopping/blob/af15cf5e6a5d309c61da2ee9e522533ee9def980/Dockerfile.recommender#L6)
- [Dockerfile.shopping](https://github.com/loopbackio/loopback4-example-shopping/blob/af15cf5e6a5d309c61da2ee9e522533ee9def980/Dockerfile.shopping#L5)
- `loopback-blog`
- [blog/2019/2019-07-24-building-an-online-game-with-loopback-4-pt5.md](https://github.com/loopbackio/loopback-blog/blob/e7043a3870b8c58c22883f5608b1e2d5e5cd630a/blog/2019/2019-07-24-building-an-online-game-with-loopback-4-pt5.md?plain=1#L58)
- `starter`
- [Dockerfile](https://github.com/loopbackio/starter/blob/1861e2284ad3bb054fa69f2e7dba3e7c9153ed85/Dockerfile#L2)

## References

- https://github.com/search?q=org%3Aloopbackio%20language%3ADockerfile&type=code
- https://github.com/search?q=org%3Aloopbackio+%22FROM+node%3A%22&type=code
- https://github.com/containers/image/blob/95a2847696c8583d5bed0ce71fed3a32276aa870/docs/containers-registries.conf.5.md#note-risk-of-using-unqualified-image-names

### Similar changes in other projects

- https://github.com/NetApp/trident/pull/690
- https://github.com/ceph/ceph-csi/pull/1715
- https://github.com/hedgedoc/container/pull/437

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Hướng nghiên cứu

Xem xét các Dockerfile, template Dockerfile, tài liệu và bin/dockerize.js được liệt kê trong các repository đã nêu, bắt đầu từ các dòng được tham chiếu và các liên kết tìm kiếm trên toàn repository. Cập nhật nhất quán từng tham chiếu image bị ảnh hưởng, sau đó tìm kiếm lại trong các repository được liệt kê để xác nhận rằng các tham chiếu không đủ định danh được nhắm đến đã biến mất; issue nêu rõ rằng không được thay đổi hành vi nào khác.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Đánh giá

Công nghệ
docker, dockerfile
Lĩnh vực
devops, infrastructure
Loại issue
Tái cấu trúc
Độ khó
4/5
Thời gian dự kiến
3-5 ngày
Mức độ hoạt động
Đình trệ
Độ rõ ràng
Đặc tả rõ ràng
Mức phù hợp với người mới
38/100

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.