UNCLASSIFIED

You need to sign in or sign up before continuing.
Commit cb6c5396 authored by Christopher Vernooy's avatar Christopher Vernooy
Browse files

Update hardening_manifest.yaml, Dockerfile files

parent 9b923397
Pipeline #100672 passed with stage
in 7 seconds
......@@ -4,13 +4,10 @@ ARG BASE_IMAGE=ubi8
ARG BASE_TAG=8.3
FROM kubeflow-images-public/admission-webhook:v20190520-v0-139-gcee39dbc-dirty-0d8f4c AS base
FROM ${BASE_REGISTRY}/${BASE_IMAGE}:${BASE_TAG}
# Label
ENV LANG C.UTF-8
RUN mkdir -p /app
COPY --from=base /webhook /app
RUN dnf upgrade -y && \
dnf clean all && \
rm -rf /var/cache/dnf
......@@ -20,6 +17,4 @@ RUN find / -path /proc -prune -o -perm /2000 -exec chmod g-s {} \;
RUN chown -R kf /app
USER kf
WORKDIR /app
ENTRYPOINT [ "./webhook" ]
HEALTHCHECK CMD ps | grep webhook | grep -v grep
\ No newline at end of file
......@@ -3,10 +3,6 @@ apiVersion: v1
# The repository name in registry1, excluding /ironbank/
name: "kubeflow/admission-webhook/admission-webhook-82f41fd8878e"
# List of tags to push for the repository in registry1
# The most specific version should be the first tag and will be shown
# on ironbank.dsop.io
tags:
- "82f41fd8878e"
- "latest"
......@@ -19,37 +15,22 @@ args:
# Docker image labels
labels:
org.opencontainers.image.title: "admission-webhook-82f41fd8878e"
## Human-readable description of the software packaged in the image
# org.opencontainers.image.description: "FIXME"
## License(s) under which contained software is distributed
# org.opencontainers.image.licenses: "FIXME"
## URL to find more information on the image
# org.opencontainers.image.url: "FIXME"
## Name of the distributing entity, organization or individual
# org.opencontainers.image.vendor: "FIXME"
org.opencontainers.image.description: "admission-webhook container for kubeflow 1.0.2 based on UBI 8 baase imaage"
org.opencontainers.image.licenses: "Apache-2.0"
org.opencontainers.image.url: "gcr.io/kubeflow-images-public/admission-webhook@sha256:82f41fd8878ead19616b577c537d2ff83ea576b78478b2f8819caa83eeac0ee0"
org.opencontainers.image.vendor: "kubeflow"
org.opencontainers.image.version: "82f41fd8878e"
## Keywords to help with search (ex. "cicd,gitops,golang")
# mil.dso.ironbank.image.keywords: "FIXME"
## This value can be "opensource" or "commercial"
# mil.dso.ironbank.image.type: "FIXME"
## Product the image belongs to for grouping multiple images
# mil.dso.ironbank.product.name: "FIXME"
mil.dso.ironbank.image.keywords: "kubeflow,admission-webhook,"
mil.dso.ironbank.image.type: "opensource"
mil.dso.ironbank.product.name: "kubeflow"
# List of resources to make available to the offline build context
resources:
- tag: kubeflow-images-public/admission-webhook:v20190520-v0-139-gcee39dbc-dirty-0d8f4c
url: docker://gcr.io/kubeflow-images-public/admission-webhook@sha256:82f41fd8878ead19616b577c537d2ff83ea576b78478b2f8819caa83eeac0ee0
# List of project maintainers
# FIXME: Fill in the following details for the current container owner in the whitelist
# FIXME: Include any other vendor information if applicable
maintainers:
- email: "cvernooy@oteemo.com"
# # The name of the current container owner
# name: "FIXME"
# # The gitlab username of the current container owner
# username: "FIXME"
# cht_member: true # FIXME: Uncomment if the maintainer is a member of CHT
# - name: "FIXME"
# username: "FIXME"
# email: "FIXME"
name: "Christopher Vernooy"
username: "cvernooy"
cht_member: true
Markdown is supported
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment