1"use strict";(globalThis.webpackChunkshipwright_io_website=globalThis.webpackChunkshipwright_io_website||[]).push([[7120],{3850(e,t,i){i.r(t),i.d(t,{assets:()=>h,contentTitle:()=>s,default:()=>c,frontMatter:()=>r,metadata:()=>n,toc:()=>l});var n=i(6078),o=i(4848),a=i(8453);const r={title:"Bringing Shipwright to Beta - and Beyond!",date:new Date("2022-10-25T21:00:00.000Z"),slug:"bringing-shipwright-to-beta-and-beyond",authors:["adambkaplan"],tags:["shipwright","community","roadmap"]},s=void 0,h={authorsImageUrls:[void 0]},l=[{value:"What Should Shipwright Become?",id:"what-should-shipwright-become",level:2},{value:"Core Values",id:"core-values",level:2},{value:"Bringing Shipwright to Beta",id:"bringing-shipwright-to-beta",level:2}];function d(e){const t={a:"a",code:"code",h2:"h2",p:"p",...(0,a.R)(),...e.components};return(0,o.jsxs)(o.Fragment,{children:[(0,o.jsxs)(t.p,{children:["Recently, the Shipwright community came together to define a beta API for the\n",(0,o.jsx)(t.a,{href:"https://github.com/shipwright-io/build",children:"Build project"}),' with stronger support\nguarantees.\nWe have come a long way since our launch two years ago, as "a framework for\nbuilding container images on Kubernetes."\nDuring the workshop, the community found itself coming back to a fundamental\nquestion, "What is Shipwright?"\nAnd more importantly, "What do we want Shipwright to be?"']}),"\n",(0,o.jsx)(t.h2,{id:"what-should-shipwright-become",children:"What Should Shipwright Become?"}),"\n",(0,o.jsxs)(t.p,{children:["We concluded that Shipwright is and should remain a framework for building\ncontainer images.\nShipwright will continue to make it simple to build a container image from\nsource, using tools that are actively maintained by a community of experts.\nOur separation of ",(0,o.jsx)(t.a,{href:"/docs/build/buildstrategies",children:"build strategy"}),"\nfrom build definition and execution will remain a cornerstone of the Shipwright\nframework."]}),"\n",(0,o.jsxs)(t.p,{children:["However, we realized that building the image is just the starting point to\ndelivering software on the cloud.\nSoftware supply chain security is a topmost concern of teams large and small.\nArtifacts like image scans, signatures,\n",(0,o.jsx)(t.a,{href:"https://www.cisa.gov/sbom",children:"software bill of materials"}),", and\n",(0,o.jsx)(t.a,{href:"https://in-toto.io/in-toto/",children:"provenance"})," are needed to build modern software\nfor the cloud.\nShipwright can, and should, rise up to meet these demands."]}),"\n",(0,o.jsxs)(t.p,{children:["We also decided that Shipwright will continue to run on cloud-native\ninfrastructure, powered by ",(0,o.jsx)(t.a,{href:"https://kubernetes.io",children:"Kubernetes"})," and\n",(0,o.jsx)(t.a,{href:"https://tekton.dev",children:"Tekton"}),".\nWe can go further, though, and plug Shipwright into the vast cloud-native\necosystem, through integrations with ",(0,o.jsx)(t.a,{href:"https://cdevents.dev",children:"CDEvents"}),",\n",(0,o.jsx)(t.a,{href:"https://argo-cd.readthedocs.io/en/stable/",children:"ArgoCD"}),", and more.\nShipwright is just getting started in this effort through the\n",(0,o.jsx)(t.a,{href:"https://github.com/shipwright-io/triggers",children:"Triggers"})," and\n",(0,o.jsx)(t.a,{href:"https://github.com/shipwright-io/image",children:"Image"})," sub-projects."]}),"\n",(0,o.jsx)(t.h2,{id:"core-values",children:"Core Values"}),"\n",(0,o.jsx)(t.p,{children:"Over the past two years, the Shipwright community has coalesced around three\ncore values: simplicity, flexibility, and security."}),"\n",(0,o.jsx)(t.p,{children:"Simplicity means that we provide an experience that is intuitive and\nconsistent.\nIt also means that we shouldn't be afraid to take an opinionated stance on\ncommon tasks, or features that we want to add to the project.\nWe discovered in the Beta API workshop areas where our APIs were not consistent\nor intuitive, and we identified changes to fix these problem areas.\nThese include single sources for builds and maintaining our opinionated steps\nto obtain source code."}),"\n",(0,o.jsx)(t.p,{children:"Flexibility means that we provide space for teams to bend Shipwright to fit\ntheir needs.\nThis started with the build strategy model itself, which we are keeping at the\ncore of the API.\nWe continued with the Parameters API, which provides avenues for customization\nbetween build strategies and build executions.\nWe also took steps in our beta workshop to ensure our API is tool agnostic,\nsuch that we can help grow the ecosystem of build tools.\nThis meant that some fields that were only used by specific build tools were\ndropped."}),"\n",(0,o.jsxs)(t.p,{children:['Lastly, Shipwright aims to meet the security needs for cloud-native\napplications.\nSecurity for Shipwright starts with the transparent pod security contexts built\ninto the build strategy API.\nThis encourages the continued evolution of tooling away from privileged and\n"root" containers, both of which are potential security risks.\nAs a community, we have started experimenting with tools like\n',(0,o.jsx)(t.a,{href:"https://github.com/aquasecurity/trivy",children:"Trivy"})," to make the security of\nShipwright-built images more transparent.\nWe hope to continue these efforts with emerging software security tools in the\nfuture."]}),"\n",(0,o.jsx)(t.h2,{id:"bringing-shipwright-to-beta",children:"Bringing Shipwright to Beta"}
1),"\n",(0,o.jsxs)(t.p,{children:["Starting in version 0.12, Shipwright will introduce the beta ",(0,o.jsx)(t.a,{href:"/docs/build/",children:"Build API"}),"\nand begin phasing out the current alpha API.\nWe encourage current and future users to provide feedback as we roll this new\nAPI out.\nYou can provide feedback by filing an issue on ",(0,o.jsx)(t.a,{href:"https://github.com/shipwright-io/build/issues",children:"GitHub"}),",\nsending an email to our ",(0,o.jsx)(t.a,{href:"mailto:[email protected]",children:"mailing list"}),",\nor posting a message to the ",(0,o.jsx)(t.code,{children:"#shipwright"})," channel on ",(0,o.jsx)(t.a,{href:"https://kubernetes.slack.com/archives/C019ZRGUEJC",children:"Kubernetes Slack"}),".\nWe look forward to hearing from you!"]})]})}function c(e={}){const{wrapper:t}={...(0,a.R)(),...e.components};return t?(0,o.jsx)(t,{...e,children:(0,o.jsx)(d,{...e})}):d(e)}},8453(e,t,i){i.d(t,{R:()=>r,x:()=>s});var n=i(6540);const o={},a=n.createContext(o);function r(e){const t=n.useContext(a);return n.useMemo(function(){return"function"==typeof e?e(t):{...t,...e}},[t,e])}function s(e){let t;return t=e.disableParentContext?"function"==typeof e.components?e.components(o):e.components||o:r(e.components),n.createElement(a.Provider,{value:t},e.children)}},6078(e){e.exports=JSON.parse('{"permalink":"/blog/bringing-shipwright-to-beta-and-beyond","editUrl":"https://github.com/facebook/docusaurus/tree/main/blog/blog/2022-10-25-bringing-shipwright-to-beta-and-beyond.md","source":"@site/blog/2022-10-25-bringing-shipwright-to-beta-and-beyond.md","title":"Bringing Shipwright to Beta - and Beyond!","description":"Recently, the Shipwright community came together to define a beta API for the","date":"2022-10-25T21:00:00.000Z","tags":[{"inline":true,"label":"shipwright","permalink":"/blog/tags/shipwright"},{"inline":false,"label":"Community","permalink":"/blog/tags/community","description":"Community related content"},{"inline":true,"label":"roadmap","permalink":"/blog/tags/roadmap"}],"readingTime":3.23,"hasTruncateMarker":true,"authors":[{"name":"Adam Kaplan","title":"Shipwright Maintainer","url":"https://github.com/adambkaplan","socials":{"github":"https://github.com/adambkaplan"},"imageURL":"https://github.com/adambkaplan.png","key":"adambkaplan","page":null}],"frontMatter":{"title":"Bringing Shipwright to Beta - and Beyond!","date":"2022-10-25T21:00:00.000Z","slug":"bringing-shipwright-to-beta-and-beyond","authors":["adambkaplan"],"tags":["shipwright","community","roadmap"]},"unlisted":false,"prevItem":{"title":"Hacktoberfest 2023","permalink":"/blog/hacktoberfest-2023"},"nextItem":{"title":"Hacktoberfest 2022","permalink":"/blog/hacktoberfest-2022"}}')}}]);
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.