k8s-sidecar
Secure by Design, Built for Speed, Hardened Container Images on a minimal base CleanStart OS.
10K+
The CleanStart K8S-Sidecar image provides a production-ready, security-hardened container optimized for enterprise environments. Built on a minimal base OS with comprehensive security hardening, this image delivers reliable application execution with advanced security features.
š Base Foundation: Production-ready container from cleanstart.
Image Path: cleanstart/k8s-sidecar
Registry: cleanstart Registry
Download the container image from the registry
docker pull cleanstart/k8s-sidecar:latest
docker pull cleanstart/k8s-sidecar:latest-dev
Note: cleanstart/k8s-sidecar:latest is a Python-based Kubernetes sidecar that watches ConfigMaps and Secrets cluster-wide (via NAMESPACE=ALL) and syncs their data as files into a shared volume; it requires both the FOLDER_ANNOTATION env var and a matching annotation on each ConfigMap/Secret to specify the target directory, and with UNIQUE_FILENAMES=true writes files as namespace_._. to prevent cross-namespace collisions.
Run the container with basic configuration
docker run -it --name k8s-sidecar cleanstart/k8s-sidecar:latest
Deploy with production security settings
docker run -d --name k8s-sidecar-prod \
--security-opt=no-new-privileges \
--user 1000:1000 \
--restart unless-stopped \
cleanstart/k8s-sidecar:latest
Volume Mount Mount local directory for persistent data
docker run -v /app:/app cleanstart/k8s-sidecar:latest
Port Forwarding Run with custom port mappings
docker run -p 8080:8080 cleanstart/k8s-sidecar:latest
Recommended security context for Kubernetes deployments
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
readOnlyRootFilesystem: true
runAsUser: 1000
runAsGroup: 1000
Essential links and resources for further information
Vulnerability Disclaimer
CleanStart offers Docker images that include third-party open-source libraries and packages maintained by independent contributors. While CleanStart maintains these images and applies industry-standard security practices, it cannot guarantee the security or integrity of upstream components beyond its control.
Users acknowledge and agree that open-source software may contain undiscovered vulnerabilities or introduce new risks through updates. CleanStart shall not be liable for security issues originating from third-party libraries, including but not limited to zero-day exploits, supply chain attacks, or contributor-introduced risks.
Security remains a shared responsibility: CleanStart provides updated images and guidance where possible, while users are responsible for evaluating deployments and implementing appropriate controls.
Content type
Image
Digest
sha256:bbd1b5868ā¦
Size
270 Bytes
Last updated
1 day ago
docker pull cleanstart/k8s-sidecar:sha256-a3e3bf5d01e28a723e49ed2f1ea6479d49e6d5fd7548bd3fceacc8a15a0fbe66.sig