Sudo access for package installation in worker images
Private worker images currently block access to apk, which makes it impossible to install additional packages at runtime. Not every deployment justifies maintaining a custom image.
From time to time, it is useful to install a small number of packages via hooks for a single stack or execution context. There is no supported way to do this when using private workers, which forces teams towards heavier image customisation than is really necessary.
Allowing limited sudo access, restricted specifically to apk, would address this gap.
- Problem
Log in to comment and vote
Comments1
Black Breeze
Jan 13
Sudo access in containers, even restricted, significantly expands the attack surface and breaks container immutability principles. Custom images are the industry-standard approach for this use case and ensure your environments are reproducible and version-controlled.
Custom images aren't as heavyweight as they might seem - you can use multi-stage builds and automated CI/CD to maintain them efficiently. This approach also ensures your package dependencies are tracked in version control and consistently deployed across environments.