Container images
Image scanning and "try again in a minute"
Why a new image can make docker wait, and why a vulnerable one can be refused.
ForgeRepo™ looks inside every image it serves and lists the packages in its layers. Your admin can turn on two extra checks:
- Scan before serve. The first pull of an image nobody has pulled before waits for the scan. docker prints
toomanyrequests: it is being scanned for vulnerabilities before it is served, try again in a minute. Wait a minute and pull again. - Safe resolution. An image with serious advisories that an upgrade fixes is refused. The error names the advisories. Pick a newer tag, or ask for a waiver.
To see what is inside an image before you use it, walk its tree. See Check before you install.
1
- Pick images to walk an image