Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Spike: Investigate options for transferring software dependencies into airgap/egress-limited/controlled environments #54

Open
Racer159 opened this issue Jun 3, 2024 · 2 comments
Labels
enhancement ✨ New feature or request

Comments

@Racer159
Copy link
Contributor

Racer159 commented Jun 3, 2024

Is your feature request related to a problem? Please describe.

This is a proof of concept of different ways we can manage dependencies for software development in an airgapped environment focused on using open source tools. Scope includes just efficiently managing transferring the dependencies over the airgap along with an SBOM of the packages being moved across the airgap (#47 covers transfer). It could involve writing a custom tool to facilitate this. It could also involve collating multiple lightweight OSS tools together. Each of the following options should be evaluate based on the criteria for success defined below.

Output of this ticket should be working proof of concept and a followup ADR.

As there are so many different programming languages, this POC will focus on only a few, common ones:

  1. golang
  2. javascript/typescript/npm
  3. python/pypi

Describe the solution you'd like

Any solution that will be picked should be the following:

  1. Performant to the end user (and scalable)
  2. Performant to transfer. The less of a heavy lift this process is the less difficult it will be to do multiple times/regularly
  3. Sustainable
  4. Have little to no impact of provenance, interaction with the repositories with package managers, etc
  5. Positive UX
@Racer159
Copy link
Contributor Author

Racer159 commented Jun 3, 2024

Marking this as blocked on #47 since it is likely best done serially

@oates
Copy link
Contributor

oates commented Nov 4, 2024

not actively working on this right now. It will depend on future registry discussion/decision. Moving to icebox

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement ✨ New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants