Proposal: Add ReadOnlyFs option to default execution parameters config
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 25/100
- Issue type
- Feature
- Clarity
- Mostly clear
- Activity status
- Stale
- Tech stack
- docker, go, helm, kubernetes
- Domain
- devops, infrastructure
Research direction
Start by reading the OCI image-spec definition of default execution parameters and compare how Docker's --read-only option is represented and how Helm or Kubernetes deployment settings consume it. Done means the specification clearly defines a ReadOnlyFs field that image authors can declare during image build and runtimes can apply consistently.
Written by the indexing model from the issue text.
Description
It would be nice to extend the default execution parameters config with a ReadOnlyFs field. Currently it is only possible to declare that option explicitly on container start (e.g. with docker run --read-only). It would be better if the image author could declare this option already during the image build as the author has more knowledge about the fact if the container needs a writable filesystem at runtime or not.
Another problem with declaring the read-only option separately from the image (e.g. in a Helm chart for Kubernetes deployment) is that the requirement for a writable filesystem may change with a new image release.
- Dominant language
- Go
- Stars
- 4.5k
- Forks
- 891
- Avg merge
- 27d 2h
- Merged PRs (30d)
- 1
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from opencontainers/image-spec
-
Difficulty 5/5 Over a week Newbie friendliness 35/100
opencontainers/image-spec#1333 · 2 comments · 2 reactions ·
-
Difficulty 5/5 Over a week Newbie friendliness 35/100
opencontainers/image-spec#1310 · 4 comments ·
-
Difficulty 5/5 Over a week Newbie friendliness 42/100
opencontainers/image-spec#1308 · 5 comments · 1 reaction ·
-
Difficulty 5/5 Over a week Newbie friendliness 30/100
opencontainers/image-spec#1283 · 5 comments ·
-
Difficulty 5/5 Over a week Newbie friendliness 15/100
opencontainers/image-spec#1270 · 29 comments ·
All issues in opencontainers/image-spec
Similar issues
-
optimization optimization:agents-md-curator
Difficulty 2/5 1-3 hours Newbie friendliness 86/100
githubnext/gh-aw-cao#13143 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
blinklabs-io/bursa#904 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
yanet-platform/ipfw-go#129 ·
-
bug confmap/provider/googlesecretmanagerprovider needs triage
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
open-telemetry/opentelemetry-collector-contrib#51273 · 2 comments ·
-
bug: AI Gateway client filter lists "Unknown" twice when NULL and literal Unknown clients coexist Openbug
Difficulty 2/5 1-3 hours Newbie friendliness 90/100