@cryptotaxi247 / netdata-1 / commits / e50881f36

Scramble packages in docker images with polymorphic linux (#5137)

Paweł Krupa committed Jan 9, 2019 at 18:43 UTC e50881f363d78188d9eaadef1340f5ec68c045c9
3 files changed +17 -1
packaging/docker/Dockerfile
+6 -1
@@ -58,7 +58,7 @@ RUN mkdir -p /app/usr/sbin/ \
58 ARG ARCH
59 FROM multiarch/alpine:${ARCH}
60
61 -# Reinstall some prerequisites
61 +# Install some prerequisites
62 RUN apk --no-cache add curl \
63 fping \
64 jq \
@@ -71,6 +71,11 @@ RUN apk --no-cache add curl \
71 py-yaml \
72 python
73
74 +# Subscribe to Polyverse's Polymorphic Linux repositories and reinstall all packages, so they are scrambled
75 +RUN curl https://sh.polyverse.io | sh -s install gcxce5byVQbtRz0iwfGkozZwy support+netdata@polyverse.io && \
76 + sed -n -i '/repo.polyverse.io/p' /etc/apk/repositories && \
77 + apk upgrade --update-cache --available
78 +
79 # Copy files over
80 COPY --from=builder /app /
81
packaging/docker/README.md
+6
@@ -8,6 +8,12 @@
8
9 Running netdata in a container for monitoring the whole host, can limit its capabilities. Some data is not accessible or not as detailed as when running netdata on the host.
10
11 +## Package scrambling in runtime (x86_64 only)
12 +
13 +By default on x86_64 architecture our docker images use Polymorphic Polyverse Linux package scrambling. For increased security you can enable rescrambling of packages during runtime. To do this set environment variable `RESCRAMBLE=true` while starting netdata docker container.
14 +
15 +For more information go to [Polyverse site](https://polyverse.io/how-it-works/)
16 +
17 ## Run netdata with docker command
18
19 Quickly start netdata with the docker command line.
packaging/docker/run.sh
+5
@@ -2,6 +2,11 @@
2
3 #set -e
4
5 +if [ ${RESCRAMBLE+x} ]; then
6 + echo "Reinstalling all packages to get the latest Polymorphic Linux scramble"
7 + apk upgrade --update-cache --available
8 +fi
9 +
10 if [ ${PGID+x} ]; then
11 echo "Adding user netdata to group with id ${PGID}"
12 addgroup -g "${PGID}" -S hostgroup 2>/dev/null