Open blairdrummond opened 3 years ago
CC @brendangadd , this is from a newish usecase; I think @ben-santos wants to make this service accessible to governments/institutions overseas as a proof-of-concept
Thanks @blairdrummond , here is an extract of the proposal of one of the goals we want to accomplish:
"Each member of the task team who works at/with an NSO will secure a server which can be attached to a public network (can be a cloud machine). The UN Global Platform will also procure a machine to facilitate network services between NSO machines where relevant. We will then, on an ongoing basis, coordinate experiments on public data using a variety of privacy enhancing technology software stacks. It is our goal to use these 0-risk (public data, single-machine, separate from any secure networks) experiments to increase awareness and certainty around what current PET technologies are capable of in the context of NSO-relevant use cases. We want to go through the exercise of working with private data without needing to actually work with private data so that we can all learn more about the constraints of such systems relevant to statistical use cases NSOs care about."
The yamls above are the first attempts to deploy such service. They are provided by the UN (network node) and OpenMined. As a domain node we will host some public data. This is a WIP they are trying to test this with another NSO (I think ONS).
I communicated our concerns about the vulnerabilities on this image. I'll keep you posted.
@blairdrummond UN-OpenMined changed the images and the services. I was told that now they splitted the services into 7 containers wrapped on a VM. They are working on a one command line deployment... I do not have the details yet. They are willing to remediate the issues.
Thanks Blair, I think neither of us knew about trivy.
They are pushing this for next week to start the deployment. I told that your team has the last word for the approval for the images and instructions.
I requested invitations to the repo and slack channel for @sylus @brendangadd and @blairdrummond
OpenMined's IT expert is in Brisbane, so to schedule a meeting will be difficult. It has to be around 5pm (7am there) because there is another collaborator in the UK. they suggest as early as possible in the morning... please @sylus @brendangadd @blairdrummond let me know what do you think...
From @ben-santos
@Ben Santos that image seems to have 5 critical cves atm
One is a pretty recent glibc vulnerability, which will hopefully get patched soon. Also the docker image runs as root
Project here https://github.com/OpenMined/PyGrid/blob/dev/apps/domain/Dockerfile
They were also given a Postgres thing