惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Microsoft Azure Blog
Microsoft Azure Blog
爱范儿
爱范儿
大猫的无限游戏
大猫的无限游戏
T
The Exploit Database - CXSecurity.com
K
Kaspersky official blog
Apple Machine Learning Research
Apple Machine Learning Research
雷峰网
雷峰网
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
www.infosecurity-magazine.com
www.infosecurity-magazine.com
C
Cyber Attacks, Cyber Crime and Cyber Security
Recent Commits to openclaw:main
Recent Commits to openclaw:main
WordPress大学
WordPress大学
SecWiki News
SecWiki News
S
Schneier on Security
酷 壳 – CoolShell
酷 壳 – CoolShell
人人都是产品经理
人人都是产品经理
C
Cybersecurity and Infrastructure Security Agency CISA
V
Vulnerabilities – Threatpost
宝玉的分享
宝玉的分享
Google Online Security Blog
Google Online Security Blog
T
Troy Hunt's Blog
博客园 - 聂微东
Hacker News - Newest:
Hacker News - Newest: "LLM"
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
月光博客
月光博客
博客园 - 司徒正美
S
Security Affairs
The Cloudflare Blog
T
Threat Research - Cisco Blogs
L
LINUX DO - 最新话题
The Last Watchdog
The Last Watchdog
Help Net Security
Help Net Security
PCI Perspectives
PCI Perspectives
博客园 - 三生石上(FineUI控件)
T
Tailwind CSS Blog
T
Tenable Blog
Latest news
Latest news
Hacker News: Ask HN
Hacker News: Ask HN
The Hacker News
The Hacker News
Jina AI
Jina AI
Schneier on Security
Schneier on Security
博客园 - 叶小钗
小众软件
小众软件
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
S
SegmentFault 最新的问题
IT之家
IT之家
Vercel News
Vercel News

Open Container Initiative

OCI Runtime Spec v1.3 - Open Container Initiative OCI Image and Distribution Specs v1.1 Releases OCI Runtime Spec v1.2 - Open Container Initiative OCI in 2024 and TOB Election Results OCI at The Container Plumbing Conference OCI in 2023 and TOB Election Results OCI in 2022 and TOB Election Results OCI Member Spotlight – Chainguard Calling All Registries to Submit OCI Conformance! OCI Summit 2021 - Open Container Initiative Introducing fuzzing for runC and Umoci OCI in 2021 and TOB Election Results Consuming Public Content - Open Container Initiative OCI accepts new project, umoci Introducing and open sourcing the OCI Icon Set Open Sourcing runc Security Audit Container Journal – “OCI Launches Artifacts Project to Reduce Registries Required” New OCI Artifacts Project - Open Container Initiative Open Container Initiative Explained…with Dolls! OCI 2019 Elections and New TOB Lineup 2018’s Biggest Moments + What’s Coming for OCI in 2019 Bringing OCI images to the desktop with Flatpak OCI Image Support Comes to Open Source Docker Registry Open Container Initiative Welcomes Alibaba Cloud as Newest Member PouchContainer – How OCI Specifications Power Alibaba CRI-O – How Standards Power a Container Runtime OCI Member Spotlight – OpenStack (Kata Containers) Teaming up with Docker to Support a Diverse Container Ecosystem The New Stack – “Open Container Initiative Creates a Distribution Specification for Registries” SDxCentral – “OCI Standardizes Container Image Distribution Based on Docker Registry” ZDNet – “​Open Container Initiative nails down container image distribution standard” Container Journal – “OCI Standardizes Container Registry Protocol” Distribution-Spec is Here! - Open Container Initiative OCI Announces 2018 TOB Election Results OCI Member Spotlight – Kontena Windows ITPro – Using Containers? Look for the OCI Seal of Approval SiliconAngle - Why the new Open Container Initiative standard is a milestone for software OCI Welcomes New Project Maintainers OCI Member Spotlight – EasyStack SDxCentral – Open Container Initiative Marks Success, Looks for What’s Next Fostering Diversity and Inclusivity at DockerCon Europe eWeek – Open Container Initiative Specifications Reach 1.0 Milestone GeekWire – Cloud computing’s Open Container Initiative hits the 1.0 release milestone InformationWeek – Unity Rules As OCI Launches 1.0 Container Spec OCI v1.0 – Bringing Containers Closer to Standardization TechCrunch – The Open Container Initiative launches version 1.0 of its container specs The New Stack – OCI’s Long-Awaited Container Runtime and Image Specifications Hit the Streets The Register – Contain(er) your enthusiasm, nerds – Docker-backed OCI runtime spec hits 1.0 ZDNet – Containers consolidation – Open Container Initiative 1.0 released Open Container Initiative (OCI) Releases v1.0 of Container Standards OCI Member Spotlight – CoreOS OCI Member Spotlight – Cycle.io Join OCI for OSCON’s Open Container Day Innovative Cloud Organizations Join the Open Container Initiative to Help Shape Industry Container Standards OCI Member Spotlight – Mesosphere OCI Member Spotlight – Univa OCI Member Spotlight – Wercker OCI Member Spotlight – IBM OCI Member Spotlight – Rancher Labs OCI Moves into 2017 - Open Container Initiative The OCI Applauds containerd and rkt to CNCF OCI Member Spotlight – ContainerShip OCI Member Spotlight – SUSE OCI Member Spotlight – Apcera OCI Member Spotlight – Portworx OCI Member Spotlight – Huawei OCI Member Spotlight – Pivotal OCI Member Spotlight – Fujitsu OCI Member Spotlight – Weaveworks OCI Member Spotlight – Red Hat OCI Member Spotlight – Google help-guide-the-future-of-container-technology-through-the-open-container-initiative - Open Container Initiative developerWorks Webcast Recap – Open Container Initiative at 12 months OCI Member Spotlight – Intel OCI Member Spotlight – Microsoft Docker 1.11 – The first runtime built on containerd and based on OCI technology Celebrating the Open Container Initiative Image Specification New Image Specification Project for Container Images Open Container Initiative Launches a Container Image Format Spec Open Container Format Progress Report Community Rallies Behind Open Container Initiative Industry Leaders Unite to Create Project for Open Container Standards About the Open Container Initiative Community Overview - Open Container Initiative Contact us - Open Container Initiative FAQ - Open Container Initiative Join - Open Container Initiative Leadership - Open Container Initiative OCI Certified - Open Container Initiative OCI distribution-spec v 1.0.0 release notice OCI distribution-spec v 1.0.1 release notice OCI distribution-spec v. 1.1.0 release notice OCI distribution-spec v. 1.1.1 release notice OCI image-spec v. 1.0.1 release notice OCI image-spec v. 1.0.2 release notice OCI image-spec v. 1.1.0 release notice OCI image-spec v. 1.1.1 release notice OCI runtime-spec v. 1.0.1 release notice OCI runtime-spec v. 1.0.2 release notice OCI Runtime Spec v1.1 - Open Container Initiative
Summary of Upcoming Changes in OCI Image and Distribution Specs v1.1
map[name:Open Container Initiative tag:oci] · 2023-07-07 · via Open Container Initiative

As mentioned in an earlier post, the OCI Reference Types Working Group delivered a suggested set of changes in the OCI Image and Distribution specs to enable the creation and discovery of relationships between objects stored in an OCI registry.

These changes (with some subsequent modifications) will be included in upcoming minor releases of both OCI Image and Distribution spec.

Notes on Versioning and the Term “OCI 1.1”

The version of the upcoming minor releases of both OCI Image and Distribution spec happens to be the same: v1.1.0.

This has undoubtedly led to the term “OCI 1.1” which is a bit vague and incorrect since these changes do not affect the Runtime spec. These versions of the individual specifications are all technically independent of each other.

However, when dealing with clients responsible with pushing/pulling from registries, or registries themselves, hearing claims of “support for OCI 1.1” can be assumed to be relating to reference types and the changes outlined in this post.

List of Major Changes (3)

1. Official Guidance on How to Create and Store Alternative (Even Non-Container) Artifacts

For several years, people have been coming up with different ways to specify alternative (non-image) artifacts in the registry.

One such method relied on using a custom value for the config.mediaType field on the image manifest. This is the same method used by tools such as Helm, OPA, WASM etc.

In the new OCI releases, this behavior has been finally codified as a valid way of specifying this information.

If you look at change #3 below, in the sample JSON response from the registry API, you will notice the new field artifactType on descriptors. The value of this field is either a.) the artifactType provided on the manifest when it is pushed or b.) the value of config.mediaType if the artifactType field is missing.

TLDR; for new clients pushing artifacts, there is a new top-level field called artifactType which can be used to denote a custom, non-image artifact. If an object is instead pushed with a custom artifact type in the config.mediaType field (the old way), this value will be surfaced in the artifactType field in the API response.

For more information, please see our Guidelines for Artifact Usage.

2. New Manifest Field for Establishing Relationships

A new field called subject can now be included on manifests (including on an index) which points to another object in the registry:

{
...
  "subject": {
    "mediaType": "application/vnd.oci.image.manifest.v1+json",
    "digest": "sha256:5b0bca...",
    "size": 7682
  },
...
}

This is the primary mechanism for linking objects to one another. This is what is used to determine the proper list returned by the registry API endpoint described in #3 below.

If the registry supports the processing of the subject field, it is required to respond with a header in the following form: OCI-Subject: sha256:5b0bca... (the value being the digest field in the subject JSON object).

3. New Registry API Endpoint for Querying Relationships

The following HTTP API endpoint has been added to enable querying for relationships between objects in the registry: GET /v2/<name>/referrers/<digest>

The contents of a valid response to this request is a valid OCI image index containing a list of descriptors which point to the provided digest:

{
  "schemaVersion": 2,
  "mediaType": "application/vnd.oci.image.index.v1+json",
  "manifests": [
    {
      "mediaType": "application/vnd.oci.image.manifest.v1+json",
      "size": 1234,
      "digest": "sha256:a1a1a1...",
      "artifactType": "application/vnd.example.sbom.v1",
      "annotations": {
        "org.opencontainers.artifact.created": "2022-01-01T14:42:55Z",
        "org.example.sbom.format": "json"
      }
    },
    {
      "mediaType": "application/vnd.oci.image.manifest.v1+json",
      "size": 1234,
      "digest": "sha256:a2a2a2...",
      "artifactType": "application/vnd.example.signature.v1",
      "annotations": {
        "org.opencontainers.artifact.created": "2022-01-01T07:21:33Z",
        "org.example.signature.fingerprint": "abcd"
      }
    }
  ]
}

If the response contains a Link header (see RFC5988), this indicates that there is another page of results which the client should fetch.

In addition, clients may provide a filter in querystring in the form ?artifactType=<mediaType>. Registries may or may not support this server-side filtering mechanism. If supported, however, the registry is required to respond with a header indicating the filter(s) applied: OCI-Filters-Applied: artifactType.

Note: the only filter defined at this time is artifactType.

Closing Thoughts

This post attemts to cover all of the major changes involved in adopting OCI Image and Distribution specs v1.1, however there are several other fine-grained details which can only be understood by carefully reading through the specifications.

Some other notable changes include the following:

  • data field in the descriptor
  • non-distributable layers are deprecated
  • zstd compression support
  • extension support in distribution-spec
  • support for resuming chunked blob push
  • anonymous blob mount support in distribution-spec
  • a Warning header for surfacing user-facing client warnings

We encourage you to take a look at both of the latest specs to see for yourself:

As always, if you need assistance, please reach out to the OCI community via GitHub, Slack, or the mailing list. You can find more info on how to get in touch with the OCI community here.