• ikidd@lemmy.worldOPM
    link
    fedilink
    English
    arrow-up
    4
    ·
    6 days ago

    Sounds like they’re used as a template and it’s now a regular LXC that you can treat like a running distro.

    • FlexibleToast@lemmy.world
      link
      fedilink
      English
      arrow-up
      5
      ·
      6 days ago

      Right, but these containers are usually not designed to be updated like that. It totally defeats the nature of the OCI image and delivering something that has been tested to work. I’m sure there is a use case for this, but it seems more like a gimmick than a useful feature.

      • ikidd@lemmy.worldOPM
        link
        fedilink
        English
        arrow-up
        1
        ·
        5 days ago

        Actually, I could see myself using this for development if there were an easy way to package it back into a container image.

        • FlexibleToast@lemmy.world
          link
          fedilink
          English
          arrow-up
          2
          ·
          5 days ago

          Back into an OCI image? I don’t know if lxc can do that, but podman can. I think it is podman save that allows you to save your current container as an image. Or, even better would be to use buildah. With buildah your expected workflow is to kind of run a container, run a script against that container, then save it at the end. In fact I’m specifically thinking of images I’ve created with buildah as being almost completely useless with this LXC technique. I’ve used the RHEL UBI micro image before and it doesn’t even have a package manager. You actually mount the container to the host and use the host’s package manager to install what is needed and then unmount it to save. It makes a super slim image with as little attack surface as possible.

            • FlexibleToast@lemmy.world
              link
              fedilink
              English
              arrow-up
              1
              ·
              5 days ago

              With buildah you can take it even farther and build a container “from scratch.” So, no packages at all. Then use your package manager to install the bare minimum to get things done.