New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
images: start building an apko-general iptables image #50545
Conversation
Skipping CI for Draft Pull Request. |
89b3dd2
to
38549dd
Compare
38549dd
to
95911ca
Compare
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Great idea.
Few suggestions ( we can do that in separate PRs):
- add envoy user too, 1337
- can use use /home/istio-proxy as home ?
As a larger topic, should we maybe explore a base image for sidecars without iptables - for istio-CNI users ? As we move towards ambient and sandwitched sidecars, plus sidecar containers - it may be worth having a more secure and constrained image - would also be good for waypoints/gateways.
For istio#44510 This will need a PR to istio/tools to add `apko`, so putting a hold. Note this doesn't yet change Istio to use it, only to build it.
afebaa0
to
49b1182
Compare
For #44510
This will need a PR to istio/tools to add
apko
, so putting a hold.Note this doesn't yet change Istio to use it, only to build it.