Small and secure Docker images for Rust: Alpine vs Debian vs Scratch
Was recently somewhat surprised that you can't just copy a Rust executable into a ´scratch´ container and have it work, so this is a cool blog post to find in my RSS feed.
I'm guessing, if you're doing something less complex, then you just need the ´musl´ target and the allocator...
https://kerkour.com/rust-dockerOpen linkView original on lemmy.ml
4 replies
Personally, I settled on
wolfi-base, which feels a lot like Alpine, but is based on glibc, so there's fewer compatibility issues. I also considereddebian-slim, but there's just too many CVEs in Debian, and I was fed up with it being so outdated all the time. What I really wanted was something like wolfi, but more open, i.e., not associated with paid images. We need a glibc-based Alpine!Thanks, I hadn't heard of Wolfi, nor of Chainguard. They are by a for-profit company, which isn’t an automatic deal-breaker by any means—it could even be a net-positive—but I do have some more homework to do before jumping onboard.
Because most images from Chainguard are paid, apart from the base image, the way I use it is through multi-stage builds, where I simply copy what I need from other images into the wolfi base, unless of course it's just easier to install what I want using apk. If I could do that with plain Alpine, I would, but most stuff is compiled for glibc, so it's a no-go.
If security is the main factor for your, I'd recommend you scan the image with grype, so you can get a grasp of how many CVEs you're working with.
What about nix2container?