-
Notifications
You must be signed in to change notification settings - Fork 7.6k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
distroless: move to apko/wolfi images #50925
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM - one comment:
if we do not ship both iptables
and iptables-legacy
in our iptables
image, we effectively will never put our CNI rules into legacy
tables, even if the host node primarily uses legacy
tables, and this would not work on any boxes that only have legacy
support.
IDK if we care about that, though.
... the |
@bleggett I am not sure I fully grok the question but old one:
new one:
|
That's good enough yep. I was looking at https://github.com/wolfi-dev/os/blob/main/iptables.yaml and it wasn't clear if they were packaging the |
for future reference on how to get the contents |
/retest |
6498362
to
025a6e1
Compare
/retest |
Fixes #44510
This moves our images over to the new images added in #50545.
This has 2 commits: 1 replaces just our iptables one, the second replaces the other
static
ones.The main value is on the
iptables
one, since that is our fork and has maintenance benefits. I changedstatic
as well to align there (why depend on 2 things when we can depend on 1).