Skip to content

Provide guidance for using update-ca-certificates in distroless images #5045

@lbussell

Description

@lbussell

Describe the Problem

Our Ubuntu Chiseled images only includes the ca-certificates_data slice, which excludes tools like update-ca-certificates in order to reduce image size (this utility isn't typically needed at container runtime). However, if users want to add certificates at container build time, there's no documented way to do so in Ubuntu Chiseled.

Describe the Solution

There should be a documented way to run the update-ca-certificates tool in the image's build layer, and copy the results to the runtime layer.

Other Information

Context: https://devblogs.microsoft.com/dotnet/announcing-dotnet-chiseled-containers/comment-page-2/#comment-20182

Metadata

Metadata

Assignees

Projects

Status

Current Release

Relationships

None yet

Development

No branches or pull requests

Issue actions