Sitelet https://github.com/kubernetes/kops/pull/18554
Skip to content

pkg/assets: keep container registry clients out of runtime binaries - #18554

Merged
kubernetes-prow[bot] merged 1 commit into
kubernetes:masterfrom
hakman:slim-pkg-assets
Jul 8, 2026
Merged

kubernetes-prow[bot] merged 1 commit into
kubernetes:masterfrom
hakman:slim-pkg-assets

Conversation

@hakman

@hakman hakman commented Jul 8, 2026

Copy link
Copy Markdown
Member

pkg/assets is linked into kops-controller and nodeup, but it also carried two CLI-only pieces that pull in go-containerregistry and, transitively, docker/cli:

  • the kops get assets --copy image/file copy machinery
  • the crane.Digest() call that pins images by digest

This moves the copy machinery into a new pkg/assets/assetcopy package (imported only by the CLI) and turns digest resolution into an injectable hook that only cmd/kops wires up. When no resolver is set, RemapImage skips digest pinning, which already matched behavior whenever ImageDigest was off or KOPS_BASE_URL was set.

Result: go-containerregistry and docker/cli are gone from the kops-controller and nodeup binaries and their SBOMs, so registry client CVEs (e.g. CVE-2025-15558 in docker/cli) stop showing up in scans of binaries that never talk to a registry. Binaries shrink about 1.5MB (kops-controller) and 1.2MB (nodeup).

/cc @rifelpet @ameukam

Assisted by Claude Fable

@kubernetes-prow
kubernetes-prow Bot requested review from ameukam and rifelpet July 8, 2026 05:58
@kubernetes-prow kubernetes-prow Bot added cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. size/M Denotes a PR that changes 30-99 lines, ignoring generated files. labels Jul 8, 2026
@hakman

hakman commented Jul 8, 2026

Copy link
Copy Markdown
Member Author

/approve

@kubernetes-prow

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: hakman

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@kubernetes-prow kubernetes-prow Bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Jul 8, 2026
@ameukam

ameukam commented Jul 8, 2026

Copy link
Copy Markdown
Member

/lgtm

@kubernetes-prow kubernetes-prow Bot added the lgtm "Looks good to me", indicates that a PR is ready to be merged. label Jul 8, 2026
@kubernetes-prow
kubernetes-prow Bot merged commit da75ff4 into kubernetes:master Jul 8, 2026
26 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. lgtm "Looks good to me", indicates that a PR is ready to be merged. size/M Denotes a PR that changes 30-99 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants