You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AzureML Kubernetes部署中OpenSSL旧版本残留问题求助

Azure ML Docker镜像OpenSSL版本问题解决方法

问题背景

基于ubuntu:18.04构建Azure ML部署镜像时,执行apt-get install openssl后镜像仍保留存在安全漏洞的旧版本,怀疑是安装流程问题或Azure ML自动安装了旧包。

排查步骤

先在镜像中确认当前OpenSSL版本,定位问题根源:

RUN openssl version

解决方案

方案1:通过APT强制更新并替换旧版本

Ubuntu 18.04的官方源中,openssl包会包含安全补丁,但如果旧版本未被彻底替换,可执行以下步骤:

  1. 彻底卸载现有OpenSSL相关包:
RUN apt-get update && apt-get -y purge openssl libssl-dev libssl1.1
  1. 清理残留依赖与缓存:
RUN apt-get autoremove -y && apt-get clean && rm -rf /var/lib/apt/lists/*
  1. 重新安装最新可用版本:
RUN apt-get update && apt-get -y install openssl libssl-dev

方案2:从源码编译安装最新稳定版

若官方源提供的版本仍无法满足安全要求,可直接从源码编译最新版OpenSSL:

  1. 安装编译依赖:
RUN apt-get update && apt-get -y install build-essential wget
  1. 下载并解压最新OpenSSL源码(以3.0.12为例,可替换为当前稳定版):
RUN wget https://www.openssl.org/source/openssl-3.0.12.tar.gz && tar -xzf openssl-3.0.12.tar.gz && cd openssl-3.0.12
  1. 编译并安装:
RUN ./config --prefix=/usr/local/openssl --openssldir=/usr/local/openssl && make && make install
  1. 替换系统默认OpenSSL路径:
RUN mv /usr/bin/openssl /usr/bin/openssl.old && ln -s /usr/local/openssl/bin/openssl /usr/bin/openssl
RUN echo "/usr/local/openssl/lib" >> /etc/ld.so.conf.d/openssl.conf && ldconfig
  1. 验证安装结果:
RUN openssl version

针对Azure ML自动安装的应对

若Azure ML部署过程中自动安装了旧版本OpenSSL,可在Dockerfile末尾添加版本校验命令,确保镜像构建完成后版本符合要求;同时检查Azure ML部署配置,禁用不必要的自动依赖安装逻辑。

内容的提问来源于stack exchange,提问作者shafee ul kabir Fahim

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.21 12:54:21