@@ -93,6 +93,11 @@ Use gateway metadata, deployment values, or the user's setup notes to identify t
9393
9494Before debugging the compute platform, inspect gateway logs for failures in dependencies initialized before the listener becomes ready.
9595
96+ The gateway container uses a Distroless Debian runtime. For OS-library
97+ vulnerability findings, check the deployed image digest and package version;
98+ deploy a rebuilt gateway image with the patched base. Updating the gateway
99+ binary alone does not update the libraries supplied by its container image.
100+
96101For resource-admission failures, distinguish disabled caller driver config from
97102missing resource approval. Helm defaults ` server.drivers.kubernetes.allowDriverConfig `
98103to false and ` resourceAdmission.enabled ` to true. Existing PVCs, RuntimeClasses,
@@ -213,6 +218,8 @@ rationale, configured and effective modes, active generation, and the explicit
213218` previous_policy_active ` state.
214219
215220The published supervisor image uses a shell-free distroless Debian 13 base.
221+ For custom builds using ` SUPERVISOR_BASE_IMAGE ` , check the selected base's GNU
222+ runtime libraries, CA certificates, and inherited user and working directory.
216223Use container logs, engine inspection and the configured exec health probe for
217224diagnostics; ` exec ... sh ` , package installation and in-container shell scripts
218225are unavailable. Workload shells belong to the separate sandbox image. Preserve
0 commit comments