Hey everyone, im trying to get druid deployed on o...
# general
n
Hey everyone, im trying to get druid deployed on our prod env and this requires to run ECR security scanning on the official druid images were using latest (
29.0.1
) • https://hub.docker.com/r/apache/druid • docker file: https://github.com/apache/druid/blob/master/distribution/docker/Dockerfile and security scans showing
35 Critical
and
84 High
wanted to ask how did you manage to deploy this on an enterprise / prod env that wont allow critical findings, or is there any other image we can use?
j
hi @Nimrod Lahav I believe the official Druid image bundles all the extensions. If you want to reduce the number of CVEs in the image you use in production, the easiest path imo is to build druid yourself with only the extensions you need for your use-case. I don't think you will be able to get the CVE count to 0, but you should be able to drastically reduce it.
n
thanks @Jan Werner my main concern is that the critical ones are mostly JVM CVE (which indicates that core druid parts might be using old jackson libs for example)
j
my recollection is that the current most problematic issue is with netty3, there are some efforts to uproot it from the codebase, but it's a big task (check the issues in github). To my best knowledge, no vulnerabilities currently present in druid core code are exploitable, there are some more details in the suppression file, so that might be useful for preparing deviation requests