This repo builds hardened, statically-linked Go binaries from kubernetes-csi/external-attacher and packages them in a minimal SLE BCI (bci-nano) based image.
Binaries are compiled against rancher/hardened-build-base,
which provides the latest supported Go toolchain (FIPS/BoringCrypto-enabled on amd64).
rancher/hardened-csi-attacher— CSI Attacher Sidecar
make build-image-all # build for the host architecture
make image-scan # run Trivy against the built image(s)The upstream version is controlled by the TAG file.
A -buildYYYYMMDD suffix (BUILD_META) is appended automatically and is required on
release tags.
Updatecli keeps two things current via daily PRs:
- the upstream
external-attacherversion (TAG), and - the
rancher/hardened-build-baseversion (DockerfileGO_IMAGE).
- Build: builds every image and runs a Trivy scan
(
CRITICAL,HIGH) on each on every PR/push. - Release: on a published GitHub release, builds multi-arch images and pushes them to
the Rancher Prime registry (
<prime-registry>/rancher/hardened-*).