apisix 카탈로그 CVE 게이트 완전 해소 (차단 165건 → 0건)
etcd(bitnamilegacy 동결 미러) → etcd.enabled=false + 카탈로그 자체 etcd 차트를 externalEtcd 기본값으로 연결. adc·apisix-ingress-controller·apisix(paasup/apisix) 세 이미지는 SUSE BCI 자체 빌드로 교체 — 전부 벤더 등급만으로는 안 보이던 벤더 하향 등급 CVE(NVD 재평가 시 드러남)가 원인이었다. - images/apisix-ingress-controller: 정적 링크 Go 모듈 취약 버전만 강제 업그레이드 - images/apisix: APISIX-Runtime(WASM·dubbo 등 커스텀 모듈 포함) 전체를 SUSE BCI 위에서 소스로 재현, keycloak-authz 플러그인 오버레이 - images/adc: 업스트림 빌더 스테이지는 그대로 두고 distroless 최종 베이스만 SUSE BCI+nodejs24 로 교체 scripts/build/patch-catalog-tag.py 의 TAG_BLOCK 이 점 구분 중첩 경로를 지원하도록 확장(apisix 서브차트 alias 때문에 필요). 세 이미지 모두 게이트 PASS(실효 CRITICAL/HIGH 0/0)와 배포 검증(테스트 클러스터)을 마쳤다. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,64 @@
|
||||
#!/usr/bin/env bash
|
||||
#
|
||||
# Licensed to the Apache Software Foundation (ASF) under one or more
|
||||
# contributor license agreements. See the NOTICE file distributed with
|
||||
# this work for additional information regarding copyright ownership.
|
||||
# The ASF licenses this file to You under the Apache License, Version 2.0
|
||||
# (the "License"); you may not use this file except in compliance with
|
||||
# the License. You may obtain a copy of the License at
|
||||
#
|
||||
# http://www.apache.org/licenses/LICENSE-2.0
|
||||
#
|
||||
# Unless required by applicable law or agreed to in writing, software
|
||||
# distributed under the License is distributed on an "AS IS" BASIS,
|
||||
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
# See the License for the specific language governing permissions and
|
||||
# limitations under the License.
|
||||
#
|
||||
|
||||
set -eo pipefail
|
||||
|
||||
PREFIX=${APISIX_PREFIX:=/usr/local/apisix}
|
||||
|
||||
if [[ "$1" == "docker-start" ]]; then
|
||||
if [ "$APISIX_STAND_ALONE" = "true" ]; then
|
||||
# If the file is not present then initialise the content otherwise update relevant keys for standalone mode
|
||||
if [ ! -f "${PREFIX}/conf/config.yaml" ]; then
|
||||
cat > ${PREFIX}/conf/config.yaml << _EOC_
|
||||
deployment:
|
||||
role: data_plane
|
||||
role_data_plane:
|
||||
config_provider: yaml
|
||||
_EOC_
|
||||
fi
|
||||
|
||||
if [ ! -f "${PREFIX}/conf/apisix.yaml" ]; then
|
||||
cat > ${PREFIX}/conf/apisix.yaml << _EOC_
|
||||
routes:
|
||||
-
|
||||
#END
|
||||
_EOC_
|
||||
fi
|
||||
/usr/bin/apisix init
|
||||
else
|
||||
/usr/bin/apisix init
|
||||
/usr/bin/apisix init_etcd
|
||||
fi
|
||||
|
||||
# For versions below 3.5.0 whose conf_server has not been removed.
|
||||
if [ -e "/usr/local/apisix/conf/config_listen.sock" ]; then
|
||||
rm -f "/usr/local/apisix/conf/config_listen.sock"
|
||||
fi
|
||||
|
||||
if [ -e "/usr/local/apisix/logs/worker_events.sock" ]; then
|
||||
rm -f "/usr/local/apisix/logs/worker_events.sock"
|
||||
fi
|
||||
|
||||
if [ -e "/usr/local/apisix/logs/stream_worker_events.sock" ]; then
|
||||
rm -f "/usr/local/apisix/logs/stream_worker_events.sock"
|
||||
fi
|
||||
|
||||
exec /usr/local/openresty/bin/openresty -p /usr/local/apisix -g 'daemon off;'
|
||||
fi
|
||||
|
||||
exec "$@"
|
||||
Reference in New Issue
Block a user