Skip to content

Commit 953ed15

Browse files
committed
fix(images): update gateway base and allow supervisor base override
Signed-off-by: Adrien Langou <alangou@nvidia.com>
1 parent e9271cb commit 953ed15

5 files changed

Lines changed: 31 additions & 2 deletions

File tree

‎CONTRIBUTING.md‎

Lines changed: 16 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -279,6 +279,22 @@ each worktree. Cache reuse therefore depends on the compiler inputs: outputs
279279
that embed absolute paths, including Rust dependencies in some builds, can
280280
still miss across worktrees.
281281

282+
## Container Image Base Overrides
283+
284+
The gateway and supervisor Dockerfiles accept `GATEWAY_BASE_IMAGE` and
285+
`SUPERVISOR_BASE_IMAGE` build arguments. Omitting them keeps the pinned
286+
distroless defaults. To build with your own bases, pass the argument through
287+
the corresponding task:
288+
289+
```shell
290+
mise run build:docker:gateway -- --build-arg GATEWAY_BASE_IMAGE=registry.example.com/gateway-base:tag
291+
mise run build:docker:supervisor -- --build-arg SUPERVISOR_BASE_IMAGE=registry.example.com/supervisor-base:tag
292+
```
293+
294+
Choose bases that provide the GNU runtime libraries required by the binaries
295+
and CA certificates for the target architecture. Validate the resulting images
296+
with your deployment. The sandbox image uses `scratch` and has no base override.
297+
282298
## Main Tasks
283299

284300
These are the primary `mise` tasks for day-to-day development:

‎deploy/docker/Dockerfile.gateway‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@
88
#
99
# Distroless Debian provides the glibc runtime required by the binary.
1010

11-
ARG GATEWAY_BASE_IMAGE=gcr.io/distroless/cc-debian13:nonroot@sha256:54df941ed0d06a1bd95ef5e0ce391fd8d9f94b64782dc9a60062727849ee3f97
11+
ARG GATEWAY_BASE_IMAGE=gcr.io/distroless/cc-debian13:nonroot@sha256:e792ab3d241a468a4fd7519ddbbebe66b49b5f365771716ea688ad40b6c6f1c2
1212
FROM ${GATEWAY_BASE_IMAGE} AS gateway
1313

1414
ARG TARGETARCH

‎deploy/docker/Dockerfile.supervisor‎

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,8 @@
88

99
# Keep the GNU runtime and CA roots without a shell or unused native TLS libraries.
1010
# The default variant preserves UID 0 and /; compute drivers set the runtime UID.
11-
FROM gcr.io/distroless/base-nossl-debian13@sha256:af5cb8dd589b8520b8c06bebb9efb73d7e16406cab58e85c51761fff49d370a0 AS supervisor
11+
ARG SUPERVISOR_BASE_IMAGE=gcr.io/distroless/base-nossl-debian13@sha256:af5cb8dd589b8520b8c06bebb9efb73d7e16406cab58e85c51761fff49d370a0
12+
FROM ${SUPERVISOR_BASE_IMAGE} AS supervisor
1213

1314
ARG TARGETARCH
1415

‎docs/how-it-works/sandboxes/runtimes.mdx‎

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -44,6 +44,11 @@ driver TOML overrides the compiled release defaults. Helm renders Kubernetes
4444
image fields into TOML, so they apply when these environment variables are
4545
unset. Sandbox requests cannot override either trusted image.
4646

47+
When building your own gateway or supervisor image, the `GATEWAY_BASE_IMAGE`
48+
and `SUPERVISOR_BASE_IMAGE` build arguments override their pinned bases. See
49+
[Container Image Base Overrides](https://github.com/NVIDIA/OpenShell/blob/main/CONTRIBUTING.md#container-image-base-overrides)
50+
for build commands and base compatibility requirements.
51+
4752
For TLS-enabled Docker, Podman, and MicroVM gateways, set `guest_tls_ca` in
4853
`[openshell.gateway]` or use the package-managed local CA. Remove the retired
4954
`guest_tls_cert` and `guest_tls_key` fields. Supervisors receive only the

‎skills/debug-openshell-cluster/SKILL.md‎

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -93,6 +93,11 @@ Use gateway metadata, deployment values, or the user's setup notes to identify t
9393

9494
Before debugging the compute platform, inspect gateway logs for failures in dependencies initialized before the listener becomes ready.
9595

96+
The gateway container uses a Distroless Debian runtime. For OS-library
97+
vulnerability findings, check the deployed image digest and package version;
98+
deploy a rebuilt gateway image with the patched base. Updating the gateway
99+
binary alone does not update the libraries supplied by its container image.
100+
96101
For resource-admission failures, distinguish disabled caller driver config from
97102
missing resource approval. Helm defaults `server.drivers.kubernetes.allowDriverConfig`
98103
to false and `resourceAdmission.enabled` to true. Existing PVCs, RuntimeClasses,
@@ -213,6 +218,8 @@ rationale, configured and effective modes, active generation, and the explicit
213218
`previous_policy_active` state.
214219

215220
The published supervisor image uses a shell-free distroless Debian 13 base.
221+
For custom builds using `SUPERVISOR_BASE_IMAGE`, check the selected base's GNU
222+
runtime libraries, CA certificates, and inherited user and working directory.
216223
Use container logs, engine inspection and the configured exec health probe for
217224
diagnostics; `exec ... sh`, package installation and in-container shell scripts
218225
are unavailable. Workload shells belong to the separate sandbox image. Preserve

0 commit comments

Comments
 (0)