Skip to content

Harden Nitro parent helper images and add ARM64 validation - #1068

Merged
AnthonyRonning merged 2 commits into
masterfrom
fix/nitro-helper-image-refresh
Oct 3, 2026
Merged

AnthonyRonning merged 2 commits into
masterfrom
fix/nitro-helper-image-refresh

Conversation

@AnthonyRonning

@AnthonyRonning AnthonyRonning commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Summary\n\n- Refresh the two host-side Nitro helpers (credential requester and CloudWatch logger) to a digest-pinned Python 3.13.16 Bookworm base with a verified Linux ARM64 manifest.\n- Replace floating dependencies with complete hash-locked, wheel-only closures; update boto3/botocore and urllib3, remove unused iproute2, and remove pip plus its ensurepip bootstrap after installation.\n- Add offline contract tests and PR CI that builds both Linux ARM64 images, runs the tests without network access, and scans each finished image for fixable high/critical vulnerability matches. Helper-only source changes do not select measured EIF checks.\n\n## Research and validation\n\n- The October 2 parent inventory found existing helper images on Python 3.9 and older urllib3. Python 3.9 is end-of-life; the refreshed boto3/botocore closure supports urllib3 2.8.\n- Both dependency closures installed with wheel-only hash verification, passed pip check and 8 offline contract tests in isolated Python 3.13 environments. pip-audit found no known matches in either lock.\n- Repository pre-commit passed 370 tests; root nix flake check passed on aarch64-darwin.\n- On exact PR head 5565b87, both GitHub ARM64 jobs built their images, ran 5 requester and 3 logger tests inside the images, and passed Trivy v0.75.0 scans with zero fixable HIGH/CRITICAL matches in Debian and installed Python packages. The scanner gate intentionally excludes unfixed and lower-severity matches.\n- Local Docker builds were unavailable because this machine has no working daemon; the CI jobs above supply actual image-build evidence. Synthetic tests still do not establish live VSOCK/IMDS/AWS behavior on a Nitro parent.\n\n## Scope boundary\n\nThis PR does not publish, copy, or deploy images. No dev/prod parent, EIF, PCR approval, KMS policy, or running service is changed. A later rollout requires separate review and live validation. EIF kernel/dependency updates remain a separate follow-up.

@AnthonyRonning
AnthonyRonning merged commit 9713c11 into master Oct 3, 2026
23 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant