Skip to main content

Sudo access for package installation in worker images

Private worker images currently block access to apk, which makes it impossible to install additional packages at runtime. Not every deployment justifies maintaining a custom image.

From time to time, it is useful to install a small number of packages via hooks for a single stack or execution context. There is no supported way to do this when using private workers, which forces teams towards heavier image customisation than is really necessary.

Allowing limited sudo access, restricted specifically to apk, would address this gap.

Problem
Status: ❌ Rejected1 comment

Log in to comment and vote

Comments1

  • Black Breeze

    •

    Jan 13

    Sudo access in containers, even restricted, significantly expands the attack surface and breaks container immutability principles. Custom images are the industry-standard approach for this use case and ensure your environments are reproducible and version-controlled.

    Custom images aren't as heavyweight as they might seem - you can use multi-stage builds and automated CI/CD to maintain them efficiently. This approach also ensures your package dependencies are tracked in version control and consistently deployed across environments.