Skip to content

Document using distroless. - #394

Merged
bgravenorst merged 8 commits into
Consensys-Incorporated:mainfrom
bgravenorst:DOC-388
Oct 5, 2026
Merged

bgravenorst merged 8 commits into
Consensys-Incorporated:mainfrom
bgravenorst:DOC-388

Conversation

@bgravenorst

@bgravenorst bgravenorst commented Sep 9, 2026 •

Copy link
Copy Markdown
Contributor

Documents the published distroless Docker image (consensys/web3signer:<version>-distroless) for operators.

Preview

Fixes

Closes #388


Note

Low Risk
Documentation-only changes with no runtime, security, or deployment code modifications.

Overview
Documents the distroless Web3Signer image (consensys/web3signer:<version>-distroless) alongside the existing Ubuntu image and replaces hard-coded develop tags with <version> in Docker examples.

Get started (use-docker.md) now describes both images (Temurin JRE 25, shell vs distroless, UID 65532) and uses Docusaurus tabs for Ubuntu vs distroless docker run examples; it points operators to a dedicated how-to for advanced distroless usage.

Adds run-distroless-docker.md: optional --read-only / readOnlyRootFilesystem, volume and UID 65532 permissions, JDK_JAVA_OPTIONS / JAVA_TOOL_OPTIONS instead of JAVA_OPTS, and --Xkey-manager-skip-keystore-storage for key manager imports on a read-only root.

manage-keys.md and logging.md are updated with cross-links and distroless-specific notes (keystore writes vs read-only containers; custom Log4j2 via env vars in distroless).

Reviewed by Cursor Bugbot for commit 44b0448. Bugbot is set up for automated code reviews on this repo. Configure here.

Signed-off-by: bgravenorst <byron.gravenorst@consensys.net>
Signed-off-by: bgravenorst <byron.gravenorst@consensys.net>
Signed-off-by: bgravenorst <byron.gravenorst@consensys.net>
@bgravenorst
bgravenorst marked this pull request as ready for review September 10, 2026 01:23
Signed-off-by: bgravenorst <byron.gravenorst@consensys.net>
@vercel

vercel Bot commented Sep 10, 2026

Copy link
Copy Markdown

@bgravenorst is attempting to deploy a commit to the Consensys Incorporated Team on Vercel.

A member of the Team first needs to authorize it.

@vercel

vercel Bot commented Sep 10, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
doc-web3signer Ready Ready Preview Oct 5, 2026 9:24pm UTC

Request Review

@bgravenorst
bgravenorst marked this pull request as draft September 10, 2026 03:36
@bgravenorst
bgravenorst marked this pull request as ready for review September 10, 2026 03:36
Comment thread docs/how-to/run-distroless-docker.md Outdated
Comment thread docs/how-to/run-distroless-docker.md
Comment thread docs/how-to/run-distroless-docker.md Outdated
Comment thread docs/how-to/run-distroless-docker.md Outdated
Signed-off-by: bgravenorst <byron.gravenorst@consensys.net>
Comment thread docs/how-to/run-distroless-docker.md
usmansaleem
usmansaleem previously approved these changes Oct 2, 2026

@usmansaleem usmansaleem left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Signed-off-by: bgravenorst <byron.gravenorst@consensys.net>
alexandratran
alexandratran previously approved these changes Oct 2, 2026

@alexandratran alexandratran left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Minor suggestions, LGTM

Comment thread docs/get-started/use-docker.md Outdated
Comment thread docs/get-started/use-docker.md Outdated
Signed-off-by: bgravenorst <byron.gravenorst@consensys.net>
@bgravenorst
bgravenorst merged commit 3eff60a into Consensys-Incorporated:main Oct 5, 2026
14 checks passed
@github-actions github-actions Bot locked and limited conversation to collaborators Oct 5, 2026

This branch was successfully deployed

1 active deployment
Preview — 44b0448f Deployed Oct 5, 2026 by vercel[bot]
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Document distroless Docker image and read-only root filesystem

3 participants