awesome-repositories.com
Blog
awesome-repositories.com

Découvrez les meilleurs dépôts open-source grâce à notre recherche par IA.

ExplorerRecherches sélectionnéesAlternatives open sourceLogiciels auto-hébergésBlogPlan du site
ProjetÀ proposNotre méthodologiePresseServeur MCP
Mentions légalesConfidentialitéConditions d'utilisation
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
hexops-graveyard avatar

hexops-graveyard/dockerfile

0
View on GitHub↗
4,085 stars·155 forks·Dockerfile·7 vues

Dockerfile

Ce projet est une collection de bonnes pratiques et de templates curés pour créer des images Docker sécurisées, stables et prêtes pour la production. Il fournit des standards pour l'optimisation des images OCI et un guide pour implémenter des configurations conformes aux standards de l'industrie dans les environnements de conteneurs.

Le dépôt propose des modèles spécifiques pour le durcissement de la sécurité, comme l'implémentation de l'exécution par un utilisateur non-root avec des ID statiques pour empêcher l'élévation de privilèges sur l'hôte. Il fournit également des templates structurels pour les builds multi-étapes afin de séparer les dépendances de build de l'environnement d'exécution final.

Des capacités supplémentaires couvrent la gestion des processus de conteneurs en utilisant des systèmes init légers pour gérer les signaux système et empêcher les processus zombies. Le projet inclut également des méthodes pour assurer la reproductibilité des builds via des images de base versionnées et des configurations réseau pour résoudre les échecs DNS sur les runtimes Linux et macOS hérités.

Features

  • Container Image Building - Provides a comprehensive set of standards and templates for building secure and optimized production container images.
  • Docker Image Building - Provides a comprehensive set of standards and templates for building secure, production-ready Docker images.
  • Multi-Stage Container Builds - Provides structural patterns for multi-stage builds to reduce attack surface and final image size.
  • Multi-Stage Build Pipelines - Ships curated multi-stage build templates that separate build-time dependencies from the final runtime environment.
  • Image Optimization Standards - Establishes guidelines for pinning base images and structuring entrypoints to ensure efficient and reproducible OCI builds.
  • Hardened Container Images - Provides patterns for creating pre-configured, secure container images designed for production environments.
  • Non-Root Process Identities - Implements non-privileged user identities with static IDs to prevent host privilege escalation.
  • Container Security Hardening - Hardens container security by restricting application privileges and implementing non-root execution.
  • Reproducible Build Environments - Ensures consistent container builds by pinning base image versions and managing dependency updates.
  • Base Image Pinning - Locks specific base image tags to ensure consistent builds and prevent breaking changes from upstream updates.
  • OCI Container Process Management - Manages process lifecycles and signal propagation within OCI compliant container runtimes.
  • Reproducible Build Systems - Ensures consistent and deterministic image builds across environments by pinning base image versions.
  • Process Signal Forwarding - Implements mechanisms to propagate termination signals from the container init process to child processes.
  • Container Init Process - Uses a lightweight init system as PID 1 to handle system signals and manage zombie processes.

Historique des stars

Graphique de l'historique des stars pour hexops-graveyard/dockerfileGraphique de l'historique des stars pour hexops-graveyard/dockerfile

Recherche par IA

Explorez plus de dépôts awesome

Décrivez vos besoins en langage naturel — l'IA classe des milliers de projets open source sélectionnés par pertinence.

Start searching with AI

Collections incluant Dockerfile

Sélections manuelles où Dockerfile apparaît.
  • Linters de bonnes pratiques pour Dockerfile

Questions fréquentes

Que fait hexops-graveyard/dockerfile ?

Ce projet est une collection de bonnes pratiques et de templates curés pour créer des images Docker sécurisées, stables et prêtes pour la production. Il fournit des standards pour l'optimisation des images OCI et un guide pour implémenter des configurations conformes aux standards de l'industrie dans les environnements de conteneurs.

Quelles sont les fonctionnalités principales de hexops-graveyard/dockerfile ?

Les fonctionnalités principales de hexops-graveyard/dockerfile sont : Container Image Building, Docker Image Building, Multi-Stage Container Builds, Multi-Stage Build Pipelines, Image Optimization Standards, Hardened Container Images, Non-Root Process Identities, Container Security Hardening.

Quelles sont les alternatives open-source à hexops-graveyard/dockerfile ?

Les alternatives open-source à hexops-graveyard/dockerfile incluent : collabnix/dockerlabs — dockerlabs is a collection of educational labs and technical tutorials designed to teach the fundamentals of… docker-library/official-images — This project is a collection of curated and standardized Docker base images that serve as reliable starting points for… krallin/tini — Tini is a lightweight process management tool designed to act as the entrypoint for OCI compliant containers. It… bitnami/containers — This project is a cloud-native software distribution and an OCI container image library. It provides a collection of… yeasy/docker_practice — This project is a Docker educational resource and a collection of practical examples designed for learning… yelp/dumb-init — dumb-init is a lightweight process supervisor and minimal init system designed to run as the primary process in a…

Alternatives open source à Dockerfile

Projets open source similaires, classés selon le nombre de fonctionnalités partagées avec Dockerfile.
  • collabnix/dockerlabsAvatar de collabnix

    collabnix/dockerlabs

    8,008Voir sur GitHub↗

    dockerlabs is a collection of educational labs and technical tutorials designed to teach the fundamentals of containerization and microservice architecture. It provides instructional material and hands-on exercises covering image optimization, security training, infrastructure setup, and cluster orchestration. The project features specific courses and guides focused on reducing image size through multi-stage builds, securing workloads via vulnerability scanning and encrypted networks, and deploying multi-node clusters with high availability using Swarm orchestration. The materials cover a br

    PHPadvancebeginnersdocker
    Voir sur GitHub↗8,008
  • docker-library/official-imagesAvatar de docker-library

    docker-library/official-images

    6,972Voir sur GitHub↗

    This project is a collection of curated and standardized Docker base images that serve as reliable starting points for building containerized applications. It functions as an OCI container image repository and a build template library, providing a central source of truth for images that adhere to Open Container Initiative standards for portability. The project utilizes an automated image lifecycle pipeline to build, tag, and push images, ensuring that dependencies remain current and security patches are applied. It specifically supports cross-platform distribution by providing a multi-archite

    Shell
    Voir sur GitHub↗6,972
  • krallin/tiniAvatar de krallin

    krallin/tini

    11,129Voir sur GitHub↗

    Tini is a lightweight process management tool designed to act as the entrypoint for OCI compliant containers. It functions as a minimal init process that manages the lifecycle of a primary child process, preventing the root process from ignoring critical termination signals. The project focuses on signal proxying and zombie process reaping. It forwards system signals from the container runtime to child processes and process groups to ensure graceful shutdowns. Additionally, it automatically collects terminated child processes to prevent the process table from filling with defunct entries. Ti

    Ccdockerinit
    Voir sur GitHub↗11,129
  • bitnami/containersAvatar de bitnami

    bitnami/containers

    4,441Voir sur GitHub↗

    This project is a cloud-native software distribution and an OCI container image library. It provides a collection of pre-configured, hardened container images and Docker Compose application stacks designed for consistent deployment across cloud and on-premises environments. The images are production-ready and compiled using standardized security configurations and vulnerability scanning to reduce attack surfaces. These hardened application images are designed to minimize manual setup and security risks during deployment. The project covers container vulnerability management, production-ready

    Shellbitnamicontainersdocker
    Voir sur GitHub↗4,441
  • Voir les 30 alternatives à Dockerfile→