Hardened Images?! #4112
-
We've been playing with RKE2 as a potential replacement for K3s. During our investigations, we've noticed RKE2 is pulling in a bunch of 'hardened' images: rancher/hardened-etcd Amongst others... What constituents these images as hardened, what has been done? I can't see to find anything to explain what has gone into that process. After a quick Snyk scan against some of these images, the results don't look overly pretty, with many various libraries needing to be bumped. Any info would be appreciated, tks! |
Beta Was this translation helpful? Give feedback.
Replies: 2 comments 4 replies
-
As linked on Slack, this is covered in the docs: https://docs.rke2.io/security/about_hardened_images Note that we don’t ever re-release existing images, so you will never see them updated in-place to “fix” a vulnerability. Updates are delivered in newer image builds. |
Beta Was this translation helpful? Give feedback.
-
All of the above images have proof of concept exploits against them? |
Beta Was this translation helpful? Give feedback.
As linked on Slack, this is covered in the docs: https://docs.rke2.io/security/about_hardened_images
Note that we don’t ever re-release existing images, so you will never see them updated in-place to “fix” a vulnerability. Updates are delivered in newer image builds.