AzureML Kubernetes部署中OpenSSL旧版本残留问题求助
Azure ML Docker镜像OpenSSL版本问题解决方法
问题背景
基于ubuntu:18.04构建Azure ML部署镜像时,执行apt-get install openssl后镜像仍保留存在安全漏洞的旧版本,怀疑是安装流程问题或Azure ML自动安装了旧包。
排查步骤
先在镜像中确认当前OpenSSL版本,定位问题根源:
RUN openssl version
解决方案
方案1:通过APT强制更新并替换旧版本
Ubuntu 18.04的官方源中,openssl包会包含安全补丁,但如果旧版本未被彻底替换,可执行以下步骤:
- 彻底卸载现有OpenSSL相关包:
RUN apt-get update && apt-get -y purge openssl libssl-dev libssl1.1
- 清理残留依赖与缓存:
RUN apt-get autoremove -y && apt-get clean && rm -rf /var/lib/apt/lists/*
- 重新安装最新可用版本:
RUN apt-get update && apt-get -y install openssl libssl-dev
方案2:从源码编译安装最新稳定版
若官方源提供的版本仍无法满足安全要求,可直接从源码编译最新版OpenSSL:
- 安装编译依赖:
RUN apt-get update && apt-get -y install build-essential wget
- 下载并解压最新OpenSSL源码(以3.0.12为例,可替换为当前稳定版):
RUN wget https://www.openssl.org/source/openssl-3.0.12.tar.gz && tar -xzf openssl-3.0.12.tar.gz && cd openssl-3.0.12
- 编译并安装:
RUN ./config --prefix=/usr/local/openssl --openssldir=/usr/local/openssl && make && make install
- 替换系统默认OpenSSL路径:
RUN mv /usr/bin/openssl /usr/bin/openssl.old && ln -s /usr/local/openssl/bin/openssl /usr/bin/openssl RUN echo "/usr/local/openssl/lib" >> /etc/ld.so.conf.d/openssl.conf && ldconfig
- 验证安装结果:
RUN openssl version
针对Azure ML自动安装的应对
若Azure ML部署过程中自动安装了旧版本OpenSSL,可在Dockerfile末尾添加版本校验命令,确保镜像构建完成后版本符合要求;同时检查Azure ML部署配置,禁用不必要的自动依赖安装逻辑。
内容的提问来源于stack exchange,提问作者shafee ul kabir Fahim
相关产品推荐
相关产品推荐

