ืฉื—ืจื•ืจ Bottlerocket 1.1, ื”ืคืฆื” ื”ืžื‘ื•ืกืกืช ืขืœ ืžื›ื•ืœื•ืช ืžื‘ื•ื“ื“ื•ืช

ื”ื”ืคืฆื” ืฉืœ ื”ืคืฆืช ืœื™ื ื•ืงืก Bottlerocket 1.1.0 ื–ืžื™ื ื”, ืฉืคื•ืชื—ื” ื‘ื”ืฉืชืชืคื•ืช ืืžื–ื•ืŸ ืœืฆื•ืจืš ื”ืฉืงื” ื™ืขื™ืœื” ื•ืžืื•ื‘ื˜ื—ืช ืฉืœ ืžื›ื•ืœื•ืช ืžื‘ื•ื“ื“ื•ืช. ื”ื›ืœื™ื ื•ืจื›ื™ื‘ื™ ื”ื‘ืงืจื” ืฉืœ ื”ื”ืคืฆื” ื ื›ืชื‘ื™ื ื‘-Rust ื•ืžื•ืคืฆื™ื ืชื—ืช ืจื™ืฉื™ื•ื ื•ืช MIT ื•-Apache 2.0. ื”ื•ื ืชื•ืžืš ื‘ื”ืคืขืœืช Bottlerocket ื‘ืืฉื›ื•ืœื•ืช Amazon ECS ื•-AWS EKS Kubernetes, ื›ืžื• ื’ื ื‘ื™ืฆื™ืจืช ื‘ื ื™ื™ื” ื•ืžื”ื“ื•ืจื•ืช ืžื•ืชืืžื•ืช ืื™ืฉื™ืช ื”ืžืืคืฉืจื•ืช ืฉื™ืžื•ืฉ ื‘ื›ืœื™ ืชื–ืžื•ืจ ื•ื–ืžืŸ ืจื™ืฆื” ืฉื•ื ื™ื ืขื‘ื•ืจ ืงื•ื ื˜ื™ื™ื ืจื™ื.

ื”ื”ืคืฆื” ืžืกืคืงืช ืชืžื•ื ืช ืžืขืจื›ืช ื‘ืœืชื™ ื ื™ืชื ืช ืœื—ืœื•ืงื” ืžืขื•ื“ื›ื ืช ื‘ืื•ืคืŸ ืื˜ื•ืžื™ ื•ืื•ื˜ื•ืžื˜ื™ ื”ื›ื•ืœืœืช ืืช ืœื™ื‘ืช ืœื™ื ื•ืงืก ื•ืกื‘ื™ื‘ืช ืžืขืจื›ืช ืžื™ื ื™ืžืœื™ืช, ื”ื›ื•ืœืœืช ืจืง ืืช ื”ืจื›ื™ื‘ื™ื ื”ื“ืจื•ืฉื™ื ืœื”ืคืขืœืช ืงื•ื ื˜ื™ื™ื ืจื™ื. ื”ืกื‘ื™ื‘ื” ื›ื•ืœืœืช ืืช ืžื ื”ืœ ื”ืžืขืจื›ืช systemd, ืกืคืจื™ื™ืช Glibc, ื›ืœื™ ื”ื‘ื ื™ื™ื” Buildroot, ื˜ื•ืขืŸ ื”ืืชื—ื•ืœ GRUB, Configurator ื”ืจืฉืช ื”ืžืจื•ืฉืขืช, ื–ืžืŸ ื”ืจื™ืฆื” ืฉืœ containerd ืขื‘ื•ืจ ืงื•ื ื˜ื™ื™ื ืจื™ื ืžื‘ื•ื“ื“ื™ื, ืคืœื˜ืคื•ืจืžืช ืชื–ืžื•ืจ ื”ืงื•ื ื˜ื™ื™ื ืจื™ื Kubernetes, aws-iam-authenticator ื•-Amazon. ืกื•ื›ืŸ ECS.

ื›ืœื™ ืชื–ืžื•ืจ ืžื™ื›ืœ ืžื’ื™ืขื™ื ื‘ืžื™ื›ืœ ื ื™ื”ื•ืœ ื ืคืจื“ ื”ืžื•ืคืขืœ ื›ื‘ืจื™ืจืช ืžื—ื“ืœ ื•ืžื ื•ื”ืœ ื‘ืืžืฆืขื•ืช ื”-API ื•-AWS SSM Agent. ืชืžื•ื ืช ื”ื‘ืกื™ืก ื—ืกืจื” ืžืขื˜ืคืช ืคืงื•ื“ื”, ืฉืจืช SSH ื•ืฉืคื•ืช ืžืคื•ืจืฉื•ืช (ืœื“ื•ื’ืžื”, ืœืœื Python ืื• Perl) - ื›ืœื™ ื ื™ื”ื•ืœ ื•ื›ืœื™ ื ื™ืคื•ื™ ื‘ืื’ื™ื ืžืžื•ืงืžื™ื ื‘ืžื™ื›ืœ ืฉื™ืจื•ืช ื ืคืจื“, ื”ืžื•ืฉื‘ืช ื›ื‘ืจื™ืจืช ืžื—ื“ืœ.

ื”ื”ื‘ื“ืœ ื”ืขื™ืงืจื™ ืžื”ืคืฆื•ืช ื“ื•ืžื•ืช ื›ื’ื•ืŸ Fedora CoreOS, CentOS/Red Hat Atomic Host ื”ื•ื ื”ื”ืชืžืงื“ื•ืช ื”ืขื™ืงืจื™ืช ื‘ืžืชืŸ ืื‘ื˜ื—ื” ืžืงืกื™ืžืœื™ืช ื‘ื”ืงืฉืจ ืฉืœ ื—ื™ื–ื•ืง ื”ื’ื ืช ื”ืžืขืจื›ืช ืžืคื ื™ ืื™ื•ืžื™ื ืืคืฉืจื™ื™ื, ืžื” ืฉืžืงืฉื” ืขืœ ื ื™ืฆื•ืœ ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื‘ืจื›ื™ื‘ื™ ืžืขืจื›ืช ื”ื”ืคืขืœื” ื•ื”ื’ื‘ืจืช ื‘ื™ื“ื•ื“ ื”ืงื•ื ื˜ื™ื™ื ืจื™ื . ืงื•ื ื˜ื™ื™ื ืจื™ื ื ื•ืฆืจื™ื ื‘ืืžืฆืขื•ืช ืžื ื’ื ื•ื ื™ ืœื™ื‘ืช ืœื™ื ื•ืงืก ืกื˜ื ื“ืจื˜ื™ื™ื - cgroups, ืžืจื—ื‘ื™ ืฉืžื•ืช ื•-seccomp. ืœื‘ื™ื“ื•ื“ ื ื•ืกืฃ, ื”ื”ืคืฆื” ืžืฉืชืžืฉืช ื‘-SELinux ื‘ืžืฆื‘ "ืื›ื™ืคื”".

ืžื—ื™ืฆืช ื”ืฉื•ืจืฉ ืžื•ืชืงื ืช ืœืงืจื™ืื” ื‘ืœื‘ื“, ื•ืžื—ื™ืฆืช ื”ื”ื’ื“ืจื•ืช /etc ื ื˜ืขื ืช ื‘-tmpfs ื•ืžืฉื•ื—ื–ืจืช ืœืžืฆื‘ื” ื”ืžืงื•ืจื™ ืœืื—ืจ ื”ืคืขืœื” ืžื—ื“ืฉ. ืฉื™ื ื•ื™ ื™ืฉื™ืจ ืฉืœ ืงื‘ืฆื™ื ื‘ืกืคืจื™ื™ืช /etc, ื›ื’ื•ืŸ /etc/resolv.conf ื•-/etc/containerd/config.toml, ืื™ื ื• ื ืชืžืš - ื›ื“ื™ ืœืฉืžื•ืจ ื”ื’ื“ืจื•ืช ืœืฆืžื™ืชื•ืช, ืขืœื™ืš ืœื”ืฉืชืžืฉ ื‘-API ืื• ืœื”ืขื‘ื™ืจ ืืช ื”ืคื•ื ืงืฆื™ื•ื ืœื™ื•ืช ืœืงื•ื ื˜ื™ื™ื ืจื™ื ื ืคืจื“ื™ื. ืžื•ื“ื•ืœ dm-verity ืžืฉืžืฉ ืœืื™ืžื•ืช ืงืจื™ืคื˜ื•ื’ืจืคื™ืช ืฉืœ ืชืงื™ื ื•ืช ืžื—ื™ืฆืช ื”ืฉื•ืจืฉ, ื•ืื ืžื–ื•ื”ื” ื ื™ืกื™ื•ืŸ ืœืฉื ื•ืช ื ืชื•ื ื™ื ื‘ืจืžืช ื”ืชืงืŸ ื”ื‘ืœื•ืง, ื”ืžืขืจื›ืช ืžื•ืคืขืœืช ืžื—ื“ืฉ.

ืจื•ื‘ ืจื›ื™ื‘ื™ ื”ืžืขืจื›ืช ื›ืชื•ื‘ื™ื ื‘-Rust, ื”ืžืกืคืง ืชื›ื•ื ื•ืช ื‘ื˜ื•ื—ื•ืช ืœื–ื™ื›ืจื•ืŸ ื›ื“ื™ ืœืžื ื•ืข ืคื’ื™ืขื•ื™ื•ืช ื”ื ื’ืจืžื•ืช ืขืœ ื™ื“ื™ ื’ื™ืฉื” ื—ื•ืคืฉื™ืช ืœื–ื™ื›ืจื•ืŸ, ื”ืคื ื™ื™ืช ืžืฆื‘ื™ืข null ื•ื—ืจื™ืคื•ืช ืžืื’ืจ. ื‘ืขืช ื‘ื ื™ื™ื” ื›ื‘ืจื™ืจืช ืžื—ื“ืœ, ืžืฆื‘ื™ ื”ืงื•ืžืคื™ืœืฆื™ื” "-enable-default-pie" ื•-"-enable-default-ssp" ืžืฉืžืฉื™ื ื›ื“ื™ ืœืืคืฉืจ ืืงืจืื™ืช ืฉืœ ืžืจื—ื‘ ื”ื›ืชื•ื‘ื•ืช ืฉืœ ืงื•ื‘ืฅ ื”ื”ืคืขืœื” (PIE) ื•ื”ื’ื ื” ืžืคื ื™ ื”ืฆืคืช ืžื—ืกื ื™ืช ื‘ืืžืฆืขื•ืช ื”ื—ืœืคื” ืงื ืจื™ืช. ืขื‘ื•ืจ ื—ื‘ื™ืœื•ืช ืฉื ื›ืชื‘ื• ื‘-C/C++, ื”ื“ื’ืœื™ื "-Wall", "-Werror=format-security", "-Wp,-D_FORTIFY_SOURCE=2", "-Wp,-D_GLIBCXX_ASSERTIONS" ื•-"-fstack-clash" ื”ื ื‘ื ื•ืกืฃ -ื”ื’ื ื” ืžื•ืคืขืœืช".

ื‘ืžื”ื“ื•ืจื” ื”ื—ื“ืฉื”:

  • ื”ื•ืฆืขื• ืฉืชื™ ืืคืฉืจื•ื™ื•ืช ื”ืคืฆื” ื—ื“ืฉื•ืช aws-k8s-1.20 ื•-vmware-k8s-1.20 ืขื ืชืžื™ื›ื” ื‘-Kubernetes 1.20. ื’ืจืกืื•ืช ืืœื”, ื›ืžื• ื’ื ื”ื’ืจืกื” ื”ืžืขื•ื“ื›ื ืช aws-ecs-1, ืžืฉืชืžืฉื™ื ื‘ืžื”ื“ื•ืจืช ืœื™ื‘ืช ืœื™ื ื•ืงืก ื”ื—ื“ืฉื” 5.10. ืžืฆื‘ ื”ื ืขื™ืœื” ืžื•ื’ื“ืจ ืœ"ืฉืœืžื•ืช" ื›ื‘ืจื™ืจืช ืžื—ื“ืœ (ื™ื›ื•ืœื•ืช ื”ืžืืคืฉืจื•ืช ืœื‘ืฆืข ืฉื™ื ื•ื™ื™ื ื‘ืงืจื ืœ ื”ืคื•ืขืœ ืžืžืจื—ื‘ ื”ืžืฉืชืžืฉ ื—ืกื•ืžื•ืช). ื”ืชืžื™ื›ื” ื‘ื’ืจืกื” aws-k8s-1.15 ื”ืžื‘ื•ืกืกืช ืขืœ Kubernetes 1.15 ื”ื•ืคืกืงื”.
  • Amazon ECS ืชื•ืžืš ื‘ืžืฆื‘ ืจืฉืช awsvpc, ื”ืžืืคืฉืจ ืœืš ืœื”ืงืฆื•ืช ืžืžืฉืงื™ ืจืฉืช ื ืคืจื“ื™ื ื•ื›ืชื•ื‘ื•ืช IP ืคื ื™ืžื™ื•ืช ืœื›ืœ ืžืฉื™ืžื”.
  • ื ื•ืกืคื• ื”ื’ื“ืจื•ืช ืœืฉืœื™ื˜ื” ื‘ืคืจืžื˜ืจื™ื ืฉื•ื ื™ื ืฉืœ Kubernetes, ื›ื•ืœืœ QPS, ืžื’ื‘ืœื•ืช ืžืื’ืจ ื•ื™ื›ื•ืœืช ืœื”ืชื—ื‘ืจ ืœืกืคืงื™ ืขื ืŸ ืžืœื‘ื“ AWS.
  • ืžื™ื›ืœ ื”-bootstrap ืžืกืคืง ื”ื’ื‘ืœืช ื’ื™ืฉื” ืœื ืชื•ื ื™ ืžืฉืชืžืฉ ื‘ืืžืฆืขื•ืช SELinux.
  • ื ื•ืกืฃ ืชื•ื›ื ื™ืช ื”ืฉื™ืจื•ืช resize2fs.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”