Skip to content

Float the base images and update packages at build time - #1

Merged
aaaaaaaalex merged 3 commits into
mainfrom
cve/image-build-hardening
Sep 30, 2026
Merged

aaaaaaaalex merged 3 commits into
mainfrom
cve/image-build-hardening

Conversation

@aaaaaaaalex

@aaaaaaaalex aaaaaaaalex commented Sep 28, 2026 •

Copy link
Copy Markdown
Collaborator

Brings the image up to date and keeps it there.

  • oc now comes from origin-must-gather:4.22. The 4.18 image it came from has not been rebuilt since August 2025.
  • The runtime base names its floating tag explicitly (ubi9-minimal:latest), and its packages are updated at build time, so the image picks up errata released since the base was last rebuilt.
  • The update would otherwise be served from the build cache whenever the base is unchanged, shipping updates as old as the cached layer. The Makefile now passes a per-build BUILD_DATE, declared ahead of the update so it re-runs.

Only build/Dockerfile, which the Makefile builds, and the Makefile change; build/Dockerfile-downstream is untouched.

Verification

  • Builds; oc (4.22) and gather run, and the collection tools are present.
  • No package updates are pending in the built image.
  • Compared with the image shipped today (a mirror of an upstream build): RHEL 9.8 with 114 packages, against RHEL 9.4 with 327.
  • Cache behaviour: the same BUILD_DATE twice leaves the update cached; a new value makes it re-run.

🤖 Generated with Claude Code

aaaaaaaalex and others added 3 commits September 28, 2026 11:10
The shipped oc comes from the 4.18 must-gather image, which is no longer
rebuilt; take it from 4.22 instead. The runtime base now names its
floating tag explicitly.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: Alex O'Regan <alex.oregan@tigera.io>
A floating base only helps once the registry rebuilds it; updating at
build time also picks up errata released since. The image runs as root,
so no ownership needs restoring afterwards.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: Alex O'Regan <alex.oregan@tigera.io>
The update layer was served from the build cache whenever the base image
was unchanged, so the image could ship updates days old. The Makefile
now passes a per-build BUILD_DATE, declared ahead of the update so it
re-runs.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: Alex O'Regan <alex.oregan@tigera.io>
Copilot AI lite review requested due to automatic review settings September 28, 2026 11:49

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The build must pull refreshed mutable base tags and use BUILD_DATE in the package-update instruction to invalidate its cache.

Review effort: Lite
Findings: 1 Medium severity

Open (1)
What changed in this PR

Updates the image build to use newer OpenShift tooling and refresh runtime packages.

Changes:

  • Uses origin-must-gather:4.22 and ubi9-minimal:latest.
  • Adds build-time package updates and a BUILD_DATE argument.
  • Updates the Makefile-driven image build.
File Summary
Makefile Passes BUILD_DATE; does not force pulling mutable base tags.
build/​Dockerfile Updates base images and packages; BUILD_DATE is not used to invalidate the update layer.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread build/Dockerfile
Comment on lines +7 to +10
ARG BUILD_DATE=unknown
RUN microdnf -y update && \
microdnf -y install rsync tar gzip jq findutils && \
microdnf -y clean all
@aaaaaaaalex
aaaaaaaalex merged commit 960b72a into main Sep 30, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants