Conversation
vcf-sdk is a meta package that pulls every VMware Cloud Foundation binding (NSX, SDDC Manager, Operations, Fleet LCM, Installer, vSAN data protection). netbox-sync only needs create_vsphere_client and the tagging client, which come from vmware-vcenter and the vapi runtime and common client it depends on. Install vmware-vcenter pinned to the version vcf-sdk resolves to today, so a rebuild of the same tag gets the same SDK, and drop the apt-get line that installed nothing. Built from the same development commit: 339 MB -> 248 MB uncompressed, 58 MB -> 52 MB gzipped. All 552 Python files under vmware/ and com/ in the new image are byte-identical to the current one; the 155 files that are no longer installed belong to SDDC Manager, the VCF installer and snapservice. pyvmomi, vmware-vapi-runtime, vmware-vapi-common-client and vmware-vcenter stay at 9.1.1.0, --help works and the process still runs as uid 1000.
The application files were copied with the service user as owner, so the running process could rewrite its own code, while /app itself stayed owned by root, so the default cache directory (/app/cache) could not be created and every container run logged "NetBox caching DISABLED" and fetched all objects from NetBox again. Copy the code as root, read-only for the service user, and create /app/cache owned by the service user and group 0 with mode 0770, which also covers platforms that run the image with an arbitrary uid in group 0. Checked with --read-only --cap-drop ALL --security-opt no-new-privileges and a volume on /app/cache: the cache is writable, the code is not, --help works, and an arbitrary uid in group 0 can write the cache. Before this change the same checks failed on the cache and succeeded on writing the code.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Two changes to the image, both checked by running the image against NetBox, not only by building it.
Caching was off in every container.
/appbelongs to root, so the service user cannot create the default cache directory/app/cache, and every run logsError writing to cache directory: /app/cache/NetBox caching DISABLEDand fetches all objects from NetBox again. The code itself was copied with the service user as owner, so the process could rewrite it. Now the code is copied as root and read-only for the service user, and/app/cacheis created owned by the service user and group 0 with mode 0770 (group 0 covers platforms that run images with an arbitrary uid).Smaller, pinned SDK.
vcf-sdkis a meta package that pulls every VMware Cloud Foundation binding (NSX, SDDC Manager, Operations, Fleet LCM, Installer, vSAN data protection). netbox-sync only usescreate_vsphere_clientand the tagging client fromvmware-vcenter, which is now installed pinned to the versionvcf-sdkresolves to today (9.1.1.0), so rebuilding a tag gives the same SDK. All 552 Python files undervmware/andcom/are byte-identical to the current image; the 155 that are gone belong to SDDC Manager, the VCF installer and snapservice. Also drops theapt-get updateline that installed nothing.developmentimageFunctional check, both images the same way, under a rootless Docker daemon (Docker 29.1.3 on Ubuntu 26.04,
docker inforeportsname=rootless): NetBox 4.4.5 in containers, two vcsim instances replaying the captured vCenters fromtests/fixtures/vcsim(vchvr 6.7 with 28 VMs, vc001 8.0.3 with 34 VMs) as two sources in one config, netbox-sync run with--read-only --cap-drop ALL --security-opt no-new-privileges, settings mounted read-only, a volume on/app/cache, two passes each:NetBox caching DISABLEDon every runRootless mode needs nothing from the image beyond what this keeps: it runs as a non-root user, opens no ports and writes only to
/app/cache.--helpworks and the process runs as uid 1000 in both. vCenter tag sync cannot be exercised against vcsim (it does not implement the vAPI endpoint the SDK talks to), which is why the SDK files are compared byte for byte instead.This is independent of the release; fine to merge before or after v1.9.0.