UNCLASSIFIED
Skip to content
GitLab
Projects
Groups
Snippets
Help
Loading...
Help
Help
Support
Community forum
Keyboard shortcuts
?
Submit feedback
Sign in
Toggle navigation
Open sidebar
Ironbank Containers
A
aiml
airflow
airflow-scheduler
Commits
7036970d
Commit
7036970d
authored
Aug 31, 2021
by
Al Fontaine
Browse files
Merge branch 'development' into 'master'
Update for new findings See merge request
!21
parents
0796d9f9
ba8d3b64
Pipeline
#453233
failed with stages
in 95 minutes and 44 seconds
Changes
3
Pipelines
1
Expand all
Hide whitespace changes
Inline
Side-by-side
Showing
3 changed files
with
938 additions
and
306 deletions
+938
-306
Dockerfile
Dockerfile
+30
-4
gpg/RPM-GPG-KEY-CentOS-Official
gpg/RPM-GPG-KEY-CentOS-Official
+30
-0
hardening_manifest.yaml
hardening_manifest.yaml
+878
-302
No files found.
Dockerfile
View file @
7036970d
...
@@ -8,9 +8,15 @@ ARG BITNAMI_DIR=/bitnami
...
@@ -8,9 +8,15 @@ ARG BITNAMI_DIR=/bitnami
USER
root
USER
root
RUN
dnf update
-y
--nodocs
&&
\
RUN
mkdir
-p
/local/rpms
COPY
gpg/RPM-GPG-KEY-CentOS-Official /etc/pki/rpm-gpg/
COPY
*.rpm /local/rpms
RUN
rpm
--import
/etc/pki/rpm-gpg/RPM-GPG-KEY-CentOS-Official
&&
\
dnf update
-y
--nodocs
&&
\
# Needed for pycocotools
# Needed for pycocotools
dnf -y install gcc && \
dnf -y install gcc
gcc-c++ libstdc++-devel /local/rpms/libstdc++-static-8.4.1-1.el8.x86_64.rpm
&& \
dnf clean all && \
dnf clean all && \
rm -rf /var/cache/dnf && \
rm -rf /var/cache/dnf && \
mkdir -p /local/wheels
mkdir -p /local/wheels
...
@@ -18,11 +24,31 @@ RUN dnf update -y --nodocs && \
...
@@ -18,11 +24,31 @@ RUN dnf update -y --nodocs && \
COPY
*.whl *.tar.gz /local/wheels/
COPY
*.whl *.tar.gz /local/wheels/
RUN
source
/opt/bitnami/airflow/venv/bin/activate
&&
\
RUN
source
/opt/bitnami/airflow/venv/bin/activate
&&
\
for
f
in
$(
ls
-l
/local/wheels |
awk
'{print $9}'
|sed
'/^$/d'
)
;
do
pip
install
--no-index
--no-deps
/local/wheels/
$f
;
done
&&
\
python3
-m
pip
install
--upgrade
--no-index
--find-links
/local/wheels/ pip
&&
\
python3
-m
pip
install
--no-index
--find-links
/local/wheels/ cython setuptools_scm
&&
\
python3
-m
pip
install
--no-index
--find-links
/local/wheels/ matplotlib
\
numpy
\
pandas
\
dask
\
kafka-python
\
sklearn
\
apache-beam
\
notebook
\
papermill
\
keras
\
tfx
\
tensorflow_ranking
\
tensorflow_text
\
tf_utils
\
cryptography
\
PyYAML
\
nltk
\
spacy
\
gensim
&&
\
find /opt/bitnami/airflow/venv/lib/python3.8/site-packages
-name
"*.pem"
-o
-name
"*.key"
| egrep
".*test.*/.*
\.
pem|.*test.*/.*
\.
key"
| xargs
rm
-f
&&
\
find /opt/bitnami/airflow/venv/lib/python3.8/site-packages
-name
"*.pem"
-o
-name
"*.key"
| egrep
".*test.*/.*
\.
pem|.*test.*/.*
\.
key"
| xargs
rm
-f
&&
\
rm
/opt/bitnami/airflow/venv/lib/python3.8/site-packages/tensorflow/include/external/local_config_python/python_include/patchlevel.h
&&
\
rm
/opt/bitnami/airflow/venv/lib/python3.8/site-packages/tensorflow/include/external/local_config_python/python_include/patchlevel.h
&&
\
rm
-rf
/local/
*
&&
\
rm
-rf
/local/
*
&&
\
dnf
-y
remove gcc
&&
\
dnf
-y
remove gcc
gcc-c++ libstdc++-devel libstdc++-static
&&
\
dnf clean all
&&
\
dnf clean all
&&
\
rm
-rf
/var/cache/dnf
rm
-rf
/var/cache/dnf
...
...
gpg/RPM-GPG-KEY-CentOS-Official
0 → 100644
View file @
7036970d
-----BEGIN PGP PUBLIC KEY BLOCK-----
Version: GnuPG v2.0.22 (GNU/Linux)
mQINBFzMWxkBEADHrskpBgN9OphmhRkc7P/YrsAGSvvl7kfu+e9KAaU6f5MeAVyn
rIoM43syyGkgFyWgjZM8/rur7EMPY2yt+2q/1ZfLVCRn9856JqTIq0XRpDUe4nKQ
8BlA7wDVZoSDxUZkSuTIyExbDf0cpw89Tcf62Mxmi8jh74vRlPy1PgjWL5494b3X
5fxDidH4bqPZyxTBqPrUFuo+EfUVEqiGF94Ppq6ZUvrBGOVo1V1+Ifm9CGEK597c
aevcGc1RFlgxIgN84UpuDjPR9/zSndwJ7XsXYvZ6HXcKGagRKsfYDWGPkA5cOL/e
f+yObOnC43yPUvpggQ4KaNJ6+SMTZOKikM8yciyBwLqwrjo8FlJgkv8Vfag/2UR7
JINbyqHHoLUhQ2m6HXSwK4YjtwidF9EUkaBZWrrskYR3IRZLXlWqeOi/+ezYOW0m
vufrkcvsh+TKlVVnuwmEPjJ8mwUSpsLdfPJo1DHsd8FS03SCKPaXFdD7ePfEjiYk
nHpQaKE01aWVSLUiygn7F7rYemGqV9Vt7tBw5pz0vqSC72a5E3zFzIIuHx6aANry
Gat3aqU3qtBXOrA/dPkX9cWE+UR5wo/A2UdKJZLlGhM2WRJ3ltmGT48V9CeS6N9Y
m4CKdzvg7EWjlTlFrd/8WJ2KoqOE9leDPeXRPncubJfJ6LLIHyG09h9kKQARAQAB
tDpDZW50T1MgKENlbnRPUyBPZmZpY2lhbCBTaWduaW5nIEtleSkgPHNlY3VyaXR5
QGNlbnRvcy5vcmc+iQI3BBMBAgAhBQJczFsZAhsDBgsJCAcDAgYVCAIJCgsDFgIB
Ah4BAheAAAoJEAW1VbOEg8ZdjOsP/2ygSxH9jqffOU9SKyJDlraL2gIutqZ3B8pl
Gy/Qnb9QD1EJVb4ZxOEhcY2W9VJfIpnf3yBuAto7zvKe/G1nxH4Bt6WTJQCkUjcs
N3qPWsx1VslsAEz7bXGiHym6Ay4xF28bQ9XYIokIQXd0T2rD3/lNGxNtORZ2bKjD
vOzYzvh2idUIY1DgGWJ11gtHFIA9CvHcW+SMPEhkcKZJAO51ayFBqTSSpiorVwTq
a0cB+cgmCQOI4/MY+kIvzoexfG7xhkUqe0wxmph9RQQxlTbNQDCdaxSgwbF2T+gw
byaDvkS4xtR6Soj7BKjKAmcnf5fn4C5Or0KLUqMzBtDMbfQQihn62iZJN6ZZ/4dg
q4HTqyVpyuzMXsFpJ9L/FqH2DJ4exGGpBv00ba/Zauy7GsqOc5PnNBsYaHCply0X
407DRx51t9YwYI/ttValuehq9+gRJpOTTKp6AjZn/a5Yt3h6jDgpNfM/EyLFIY9z
V6CXqQQ/8JRvaik/JsGCf+eeLZOw4koIjZGEAg04iuyNTjhx0e/QHEVcYAqNLhXG
rCTTbCn3NSUO9qxEXC+K/1m1kaXoCGA0UWlVGZ1JSifbbMx0yxq/brpEZPUYm+32
o8XfbocBWljFUJ+6aljTvZ3LQLKTSPW7TFO+GXycAOmCGhlXh2tlc6iTc41PACqy
yy+mHmSv
=kkH7
-----END PGP PUBLIC KEY BLOCK-----
hardening_manifest.yaml
View file @
7036970d
This diff is collapsed.
Click to expand it.
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
.
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment