DUE TO SPAM, SIGN-UP IS DISABLED. Goto Selfserve wiki signup and request an account.
| Table of Contents |
|---|
Status
Current state: Under Discussion Accepted
Discussion thread: here
JIRA: here
...
The Dockerfile for Apache Kafka will continue to be managed by the Apache Kafka community and undergo review by Docker Community. Once approved by Docker community, the Docker Official Image will be built and published by the Docker Community. .
We will recommend using the official images on Docker Hub, as they are reviewed by Docker. The images on apache/kafka will be provided in case of delays in the review process by Docker.
Docker Official Images are considered more secure than OSS sponsored images due to their strict and transparent build processes.
They are maintained through a collaboration between upstream maintainers, community volunteers, and Docker engineers, ensuring adherence to best practices.
The build process is open and transparent, with all changes undergoing public scrutiny through pull requests, and build logs available for inspection.
Each image also comes with a complete Software Bill of Materials (SBOM) and and detailed build provenance as signed attestations, providing users with detailed insight into the image's origins and security.
Regular security audits, updates, and the integration of signature validation in the image pull and build processes further enhance security. Source: https://www.docker.com/blog/enhancing-security-and-transparency-with-docker-official-images/
Its these benefits that the Docker Official Images enjoy, thus making them more a more secure option for users to deploy Apache Kafka. Furthermore, the Docker Official image lowers the barrier to entry for new Apache Kafka users who might not be familiar with Apache or the concept of OSS images. We aim to simplify the process for Kafka beginners on Docker Hub, to discover, find and use the Kafka image.
Apache Kafka Image (already supported) | Docker Official Image (not supported yet) | |
Name | apache/kafka | kafka |
Maintenance | Reviewed, published by Apache Kafka community | Reviewed, published and maintained by Docker community |
Update policy | Only build and push once when specific version release | Actively rebuild for updates and security fixes |
Link | ||
source |
* Unsupported yet.
** To be created.
Public Interfaces
- There will be a new additional artifact i.e. Official Kafka docker image for every Apache Kafka release.
Add public documentation in Official Docker Image Repo.
...
Latest major_version.minor_version.patch_version release:
Once a
major_version.minor_version.patch_versionis officially released and the binary URL for the release is available:For all subsequent steps - use the official binary URL for the latest Apache Kafka
major_version.minor_version.patch_versionrelease, having the Scala version 2.13, since we are only supporting scala version 2.13 for docker images as per KIP-975. For instance, usehttps://downloads.apache.org/kafka/3.7.0/kafka_2.13-3.7.0.tgzfor the 3.7.0 release.
Docker Image Preparation via GitHub Actions:
Implement an automated a GitHub Actions workflow to:
Generate a version-specific folder, following the
major_version.minor_version.patch_versionnaming scheme, under thedocker/docker_official_imagesdirectory, for housing static Dockerfile and scripts. For example3.7.0.This folder will contain all static files necessary for creating the docker image.
The github actions workflow generates this folder which can be downloaded and verified.
The RM puts this folder under the
docker/docker_official_imagesdirectory in their fork of the kafka repo, and merges this change into the official kafka repo by raising a PR.
Docker Build and Release Testing:
Perform Docker Run a GitHub Actions workflow to perform Docker build tests to ensure image integrity. The dockerfiles for the same will be used from the specific folder in the
docker/docker_official_imagesdirectory.
Docker Hub Submission:
Remove unsupported version folders from the
docker_official_imagesdirectory to maintain repository cleanliness.Run a script from trunk to automate the creation of a file which contains all the necessary information for submission to the Docker Hub official images library.
The RM will manually raise the final PR to Docker Hub’s official images repository using the contents of the generated file. Following PR approval, it is now Docker’s responsibility to build and publish the Docker Official Images. For example
kafka:3.8.0.
Post Release Process - if Dockerhub folks suggest changes to the Dockerfiles:
- Important:- Make sure the change suggested by Dockerhub is only specific to build and not a functionality change. In case it's a functionality change request then it would require a new KIP and the below mentioned steps will not be applicable.
Make the same changes in the Dockerfile present in
docker/jvm/Dockerfile, so that the changes are propagated to newer RC releases and new major, minor and patch releases. This ensures that the source of truth is kept updated. Additionally, update the Dockerfile in the docker official image for that specific release. Commit these changes.The RM will cherry pick these changes into the branch of that particular release.
Run the build and test workflow to test the images with the latest changes.
If the image builds successfully, and passes all tests, follow step 4 again to raise a new PR in the docker official images repo.
...