Scramble packages in docker images with polymorphic linux (#5137)
Paweł Krupa committed
Jan 9, 2019 at 18:43 UTC
e50881f363d78188d9eaadef1340f5ec68c045c9
3 files changed
+17
-1
packaging/docker/Dockerfile
+6
-1
@@ -58,7 +58,7 @@ RUN mkdir -p /app/usr/sbin/ \
58
ARG ARCH
59
FROM multiarch/alpine:${ARCH}
60
61
-# Reinstall some prerequisites
61
+# Install some prerequisites
62
RUN apk --no-cache add curl \
63
fping \
64
jq \
@@ -71,6 +71,11 @@ RUN apk --no-cache add curl \
71
py-yaml \
72
python
73
74
+# Subscribe to Polyverse's Polymorphic Linux repositories and reinstall all packages, so they are scrambled
75
+RUN curl https://sh.polyverse.io | sh -s install gcxce5byVQbtRz0iwfGkozZwy support+netdata@polyverse.io && \
76
+ sed -n -i '/repo.polyverse.io/p' /etc/apk/repositories && \
77
+ apk upgrade --update-cache --available
78
+
79
# Copy files over
80
COPY --from=builder /app /
81
packaging/docker/README.md
+6
@@ -8,6 +8,12 @@
8
9
Running netdata in a container for monitoring the whole host, can limit its capabilities. Some data is not accessible or not as detailed as when running netdata on the host.
10
11
+## Package scrambling in runtime (x86_64 only)
12
+
13
+By default on x86_64 architecture our docker images use Polymorphic Polyverse Linux package scrambling. For increased security you can enable rescrambling of packages during runtime. To do this set environment variable `RESCRAMBLE=true` while starting netdata docker container.
14
+
15
+For more information go to [Polyverse site](https://polyverse.io/how-it-works/)
16
+
17
## Run netdata with docker command
18
19
Quickly start netdata with the docker command line.
packaging/docker/run.sh
+5
@@ -2,6 +2,11 @@
2
3
#set -e
4
5
+if [ ${RESCRAMBLE+x} ]; then
6
+ echo "Reinstalling all packages to get the latest Polymorphic Linux scramble"
7
+ apk upgrade --update-cache --available
8
+fi
9
+
10
if [ ${PGID+x} ]; then
11
echo "Adding user netdata to group with id ${PGID}"
12
addgroup -g "${PGID}" -S hostgroup 2>/dev/null