Skip to content

chore: pin ucpd Distroless base image to Debian 13 - #12984

Merged
brooke-hamilton merged 4 commits into
mainfrom
brooke-hamilton-pin-the-ucpd-distroless-base-image-to-de
Sep 18, 2026
Merged

brooke-hamilton merged 4 commits into
mainfrom
brooke-hamilton-pin-the-ucpd-distroless-base-image-to-de

Conversation

@brooke-hamilton

Copy link
Copy Markdown
Member

Summary

  • Pin the ucpd runtime base to the explicitly versioned Debian 13 Distroless image and its immutable multi-platform OCI index digest.
  • Document the tag-plus-index-digest convention and the need to refresh the digest for future base-image security updates.

Reason for change

The unqualified gcr.io/distroless/static:nonroot alias can move to a newer Debian major release without a repository change. The explicit Debian 13 tag preserves the intended operating-system version, while the OCI index digest makes the selected base immutable across supported architectures.

Fixes #12922

How to test

  • Built real ucpd release binaries and images for linux/amd64, linux/arm64, and linux/arm/v7 using the pinned index.
  • Ran ucpd --help successfully on all three architectures under native execution or QEMU.
  • Verified each image retains User=65532:65532, WorkingDir=/, Entrypoint=["/ucpd"], Debian 13 identity, a nonempty CA certificate bundle, and the expected built-in provider manifests.
  • Ran markdown-table-formatter, markdownlint-cli2, cspell, and git diff --check successfully.

File change summary

File Summary of change
deploy/images/ucpd/Dockerfile Pin the Debian 13 nonroot Distroless multi-platform image index digest.
docs/contributing/contributing-code/contributing-code-dockerfiles/README.md Document the pinned runtime-base convention and manual security-update refresh requirement.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Brooke Hamilton <45323234+brooke-hamilton@users.noreply.github.com>
Copilot AI lite review requested due to automatic review settings September 15, 2026 21:01
@brooke-hamilton
brooke-hamilton requested review from a team as code owners September 15, 2026 21:01
@brooke-hamilton brooke-hamilton added the pr:standard Ongoing maintenance, minor improvements, documentation updates, and routine development work label Sep 15, 2026
@brooke-hamilton brooke-hamilton changed the title Pin the ucpd Distroless base image to Debian 13 chore: pin ucpd Distroless base image to Debian 13 Sep 15, 2026
@github-actions

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

Scanned Files

None

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟢 Approval recommended

No unresolved review issues were identified.

Pull request overview

Pins the ucpd runtime image to Debian 13 Distroless with an immutable multi-platform digest and documents the maintenance convention.

Changes:

  • Updates the ucpd Dockerfile base image.
  • Documents digest pinning and refresh requirements.
File summaries
File Description
docs/contributing/contributing-code/contributing-code-dockerfiles/README.md Documents pinned runtime-base usage.
deploy/images/ucpd/Dockerfile Pins the Debian 13 Distroless image index.
Review details
  • Files reviewed: 2/2 changed files
  • Comments generated: 0
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@github-actions

github-actions Bot commented Sep 15, 2026 •

Copy link
Copy Markdown

Unit Tests

    2 files  ±0    459 suites  ±0   8m 16s ⏱️ - 1m 13s
6 618 tests ±0  6 616 ✅ ±0  2 💤 ±0  0 ❌ ±0 
7 926 runs  ±0  7 924 ✅ ±0  2 💤 ±0  0 ❌ ±0 

Results for commit a6d76e2. ± Comparison against base commit 1b0b3da.

♻️ This comment has been updated with latest results.

@codecov

codecov Bot commented Sep 15, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 59.49%. Comparing base (1b0b3da) to head (a6d76e2).

Additional details and impacted files
@@            Coverage Diff             @@
##             main   #12984      +/-   ##
==========================================
- Coverage   59.49%   59.49%   -0.01%     
==========================================
  Files         772      772              
  Lines       45007    45007              
==========================================
- Hits        26778    26777       -1     
- Misses      18229    18230       +1     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

willdavsmith
willdavsmith previously approved these changes Sep 17, 2026
Comment thread docs/contributing/contributing-code/contributing-code-dockerfiles/README.md Outdated
Comment thread docs/contributing/contributing-code/contributing-code-dockerfiles/README.md Outdated
@github-actions

github-actions Bot commented Sep 17, 2026 •

Copy link
Copy Markdown

Functional Tests - kubernetes-noncloud

17 tests  ±0   17 ✅ ±0   4m 55s ⏱️ +7s
 1 suites ±0    0 💤 ±0 
 1 files   ±0    0 ❌ ±0 

Results for commit a6d76e2. ± Comparison against base commit 1b0b3da.

♻️ This comment has been updated with latest results.

brooke-hamilton and others added 2 commits September 18, 2026 08:48
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Brooke Hamilton <45323234+brooke-hamilton@users.noreply.github.com>
…mage-to-de

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Brooke Hamilton <45323234+brooke-hamilton@users.noreply.github.com>
@radius-functional-tests

radius-functional-tests Bot commented Sep 18, 2026 •

Copy link
Copy Markdown

Radius functional test overview

🔍 Go to test action run

Click here to see the test run details
Name Value
Repository radius-project/radius
Commit ref a6d76e2
Unique ID func269817c351
Image tag pr-func269817c351
  • Dapr: 1.14.4
  • Azure KeyVault CSI driver: 1.4.2
  • Azure Workload identity webhook: 1.3.0
  • Bicep recipe location ghcr.io/radius-project/dev/test/testrecipes/test-bicep-recipes/<name>:pr-func269817c351
  • Terraform recipe location http://tf-module-server.radius-test-tf-module-server.svc.cluster.local/<name>.zip (in cluster)
  • applications-rp test image location: ghcr.io/radius-project/dev/applications-rp:pr-func269817c351
  • dynamic-rp test image location: ghcr.io/radius-project/dev/dynamic-rp:pr-func269817c351
  • controller test image location: ghcr.io/radius-project/dev/controller:pr-func269817c351
  • ucp test image location: ghcr.io/radius-project/dev/ucpd:pr-func269817c351
  • deployment-engine test image location: ghcr.io/radius-project/deployment-engine:latest

Test Status

⌛ Building Radius and pushing container images for functional tests...
✅ Container images build succeeded
⌛ Publishing Bicep Recipes for functional tests...
✅ Recipe publishing succeeded
⌛ Starting corerp-cloud functional tests...
⌛ Starting ucp-cloud functional tests...
✅ ucp-cloud functional tests succeeded
✅ corerp-cloud functional tests succeeded

@brooke-hamilton
brooke-hamilton added this pull request to the merge queue Sep 18, 2026
Merged via the queue into main with commit 25b598b Sep 18, 2026
78 checks passed
@brooke-hamilton
brooke-hamilton deleted the brooke-hamilton-pin-the-ucpd-distroless-base-image-to-de branch September 18, 2026 17:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

pr:standard Ongoing maintenance, minor improvements, documentation updates, and routine development work

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Pin the ucpd Distroless base image to Debian 13

6 participants