Skip to content

notebooks-downstream: Security

Secrets

Kubernetes secrets referenced by this component. Only names and types are shown, not values.

Deployment Security Controls

SecurityContext settings on pod and container specs. These control privilege escalation, filesystem access, and user identity.

Container Security Contexts

Deployment Container RunAsNonRoot ReadOnlyFS Privileged Source
notebook notebook ? ? ? jupyter/datascience/ubi9-python-3.11/kustomize/base/statefulset.yaml
notebook notebook ? ? ? jupyter/datascience/ubi9-python-3.12/kustomize/base/statefulset.yaml
notebook notebook ? ? ? jupyter/minimal/ubi9-python-3.11/kustomize/base/statefulset.yaml
notebook notebook ? ? ? jupyter/minimal/ubi9-python-3.12/kustomize/base/statefulset.yaml
notebook notebook ? ? ? jupyter/pytorch/ubi9-python-3.11/kustomize/base/statefulset.yaml
notebook notebook ? ? ? jupyter/pytorch/ubi9-python-3.12/kustomize/base/statefulset.yaml
notebook notebook ? ? ? jupyter/rocm/pytorch/ubi9-python-3.11/kustomize/base/statefulset.yaml
notebook notebook ? ? ? jupyter/rocm/pytorch/ubi9-python-3.12/kustomize/base/statefulset.yaml
notebook notebook ? ? ? jupyter/rocm/tensorflow/ubi9-python-3.11/kustomize/base/statefulset.yaml
notebook notebook ? ? ? jupyter/tensorflow/ubi9-python-3.11/kustomize/base/statefulset.yaml
notebook notebook ? ? ? jupyter/tensorflow/ubi9-python-3.12/kustomize/base/statefulset.yaml
notebook notebook ? ? ? jupyter/trustyai/ubi9-python-3.11/kustomize/base/statefulset.yaml
notebook notebook ? ? ? jupyter/trustyai/ubi9-python-3.12/kustomize/base/statefulset.yaml

Build Security

Dockerfile patterns and base image analysis. Covers supply chain security: base images, build stages, runtime user, FIPS compliance.

Path Base Image Stages User Ports Architectures FIPS Issues
codeserver/ubi9-python-3.11/Dockerfile.cpu base 2 1001 multi-arch Unpinned base image: registry.access.redhat.com/ubi9/python-311:latest; Unpinned base image: base
codeserver/ubi9-python-3.12/Dockerfile.cpu base 2 1001 multi-arch Unpinned base image: registry.access.redhat.com/ubi9/python-312:latest; Unpinned base image: base
jupyter/datascience/ubi9-python-3.11/Dockerfile.cpu jupyter-minimal 4 1001 Unpinned base image: registry.access.redhat.com/ubi9/go-toolset:latest; Unpinned base image: registry.access.redhat.com/ubi9/python-311:latest; Unpinned base image: base; Unpinned base image: jupyter-minimal
jupyter/datascience/ubi9-python-3.12/Dockerfile.cpu jupyter-minimal 4 1001 Unpinned base image: registry.access.redhat.com/ubi9/go-toolset:latest; Unpinned base image: registry.access.redhat.com/ubi9/python-312:latest; Unpinned base image: base; Unpinned base image: jupyter-minimal
jupyter/minimal/ubi9-python-3.11/Dockerfile.cpu base 2 1001 Unpinned base image: registry.access.redhat.com/ubi9/python-311:latest; Unpinned base image: base
jupyter/minimal/ubi9-python-3.11/Dockerfile.cuda cuda-base 5 1001 multi-arch Unpinned base image: registry.access.redhat.com/ubi9/python-311:latest; Unpinned base image: base; Unpinned base image: base; Unpinned base image: cuda-base-${TARGETARCH}; Unpinned base image: cuda-base
jupyter/minimal/ubi9-python-3.11/Dockerfile.rocm rocm-base 3 1001 Unpinned base image: registry.access.redhat.com/ubi9/python-311:latest; Unpinned base image: base; Unpinned base image: rocm-base
jupyter/minimal/ubi9-python-3.12/Dockerfile.cpu base 2 1001 Unpinned base image: registry.access.redhat.com/ubi9/python-312:latest; Unpinned base image: base
jupyter/minimal/ubi9-python-3.12/Dockerfile.cuda cuda-base 5 1001 multi-arch Unpinned base image: registry.access.redhat.com/ubi9/python-312:latest; Unpinned base image: base; Unpinned base image: base; Unpinned base image: cuda-base-${TARGETARCH}; Unpinned base image: cuda-base
jupyter/minimal/ubi9-python-3.12/Dockerfile.rocm rocm-base 3 1001 Unpinned base image: registry.access.redhat.com/ubi9/python-312:latest; Unpinned base image: base; Unpinned base image: rocm-base
jupyter/pytorch/ubi9-python-3.11/Dockerfile.cuda cuda-jupyter-datascience 8 1001 multi-arch Unpinned base image: registry.access.redhat.com/ubi9/go-toolset:latest; Unpinned base image: registry.access.redhat.com/ubi9/python-311:latest; Unpinned base image: base; Unpinned base image: base; Unpinned base image: cuda-base-${TARGETARCH}; Unpinned base image: cuda-base; Unpinned base image: cuda-jupyter-minimal; Unpinned base image: cuda-jupyter-datascience
jupyter/pytorch/ubi9-python-3.12/Dockerfile.cuda cuda-jupyter-datascience 8 1001 multi-arch Unpinned base image: registry.access.redhat.com/ubi9/go-toolset:latest; Unpinned base image: registry.access.redhat.com/ubi9/python-312:latest; Unpinned base image: base; Unpinned base image: base; Unpinned base image: cuda-base-${TARGETARCH}; Unpinned base image: cuda-base; Unpinned base image: cuda-jupyter-minimal; Unpinned base image: cuda-jupyter-datascience
jupyter/rocm/pytorch/ubi9-python-3.11/Dockerfile.rocm rocm-jupyter-datascience 6 1001 Unpinned base image: registry.access.redhat.com/ubi9/go-toolset:latest; Unpinned base image: registry.access.redhat.com/ubi9/python-311:latest; Unpinned base image: base; Unpinned base image: rocm-base; Unpinned base image: rocm-jupyter-minimal; Unpinned base image: rocm-jupyter-datascience
jupyter/rocm/pytorch/ubi9-python-3.12/Dockerfile.rocm rocm-jupyter-datascience 6 1001 Unpinned base image: registry.access.redhat.com/ubi9/go-toolset:latest; Unpinned base image: registry.access.redhat.com/ubi9/python-312:latest; Unpinned base image: base; Unpinned base image: rocm-base; Unpinned base image: rocm-jupyter-minimal; Unpinned base image: rocm-jupyter-datascience
jupyter/rocm/tensorflow/ubi9-python-3.11/Dockerfile.rocm rocm-jupyter-datascience 6 1001 Unpinned base image: registry.access.redhat.com/ubi9/go-toolset:latest; Unpinned base image: registry.access.redhat.com/ubi9/python-311:latest; Unpinned base image: base; Unpinned base image: rocm-base; Unpinned base image: rocm-jupyter-minimal; Unpinned base image: rocm-jupyter-datascience
jupyter/tensorflow/ubi9-python-3.11/Dockerfile.cuda cuda-jupyter-datascience 8 1001 multi-arch Unpinned base image: registry.access.redhat.com/ubi9/go-toolset:latest; Unpinned base image: registry.access.redhat.com/ubi9/python-311:latest; Unpinned base image: base; Unpinned base image: base; Unpinned base image: cuda-base-${TARGETARCH}; Unpinned base image: cuda-base; Unpinned base image: cuda-jupyter-minimal; Unpinned base image: cuda-jupyter-datascience
jupyter/tensorflow/ubi9-python-3.12/Dockerfile.cuda cuda-jupyter-datascience 8 1001 multi-arch Unpinned base image: registry.access.redhat.com/ubi9/go-toolset:latest; Unpinned base image: registry.access.redhat.com/ubi9/python-312:latest; Unpinned base image: base; Unpinned base image: base; Unpinned base image: cuda-base-${TARGETARCH}; Unpinned base image: cuda-base; Unpinned base image: cuda-jupyter-minimal; Unpinned base image: cuda-jupyter-datascience
jupyter/trustyai/ubi9-python-3.11/Dockerfile.cpu jupyter-datascience 5 1001 Unpinned base image: registry.access.redhat.com/ubi9/go-toolset:latest; Unpinned base image: registry.access.redhat.com/ubi9/python-311:latest; Unpinned base image: base; Unpinned base image: jupyter-minimal; Unpinned base image: jupyter-datascience
jupyter/trustyai/ubi9-python-3.12/Dockerfile.cpu jupyter-datascience 5 1001 Unpinned base image: registry.access.redhat.com/ubi9/go-toolset:latest; Unpinned base image: registry.access.redhat.com/ubi9/python-312:latest; Unpinned base image: base; Unpinned base image: jupyter-minimal; Unpinned base image: jupyter-datascience
rstudio/c9s-python-3.11/Dockerfile.cpu base 2 1001 Unpinned base image: base
rstudio/c9s-python-3.11/Dockerfile.cuda cuda-base 5 1001 multi-arch Unpinned base image: base; Unpinned base image: base; Unpinned base image: cuda-base-${TARGETARCH}; Unpinned base image: cuda-base
rstudio/rhel9-python-3.11/Dockerfile.cpu base 2 1001 Unpinned base image: registry.redhat.io/rhel9/python-311:latest; Unpinned base image: base
rstudio/rhel9-python-3.11/Dockerfile.cuda cuda-base 5 1001 multi-arch Unpinned base image: registry.redhat.io/rhel9/python-311:latest; Unpinned base image: base; Unpinned base image: base; Unpinned base image: cuda-base-${TARGETARCH}; Unpinned base image: cuda-base
runtimes/datascience/ubi9-python-3.11/Dockerfile.cpu base 2 1001 Unpinned base image: registry.access.redhat.com/ubi9/python-311:latest; Unpinned base image: base
runtimes/datascience/ubi9-python-3.12/Dockerfile.cpu base 2 1001 Unpinned base image: registry.access.redhat.com/ubi9/python-312:latest; Unpinned base image: base
runtimes/minimal/ubi9-python-3.11/Dockerfile.cpu base 2 1001 Unpinned base image: registry.access.redhat.com/ubi9/python-311:latest; Unpinned base image: base
runtimes/minimal/ubi9-python-3.12/Dockerfile.cpu base 2 1001 Unpinned base image: registry.access.redhat.com/ubi9/python-312:latest; Unpinned base image: base
runtimes/pytorch/ubi9-python-3.11/Dockerfile.cuda cuda-base 5 1001 multi-arch Unpinned base image: registry.access.redhat.com/ubi9/python-311:latest; Unpinned base image: base; Unpinned base image: base; Unpinned base image: cuda-base-${TARGETARCH}; Unpinned base image: cuda-base
runtimes/pytorch/ubi9-python-3.12/Dockerfile.cuda cuda-base 5 1001 multi-arch Unpinned base image: registry.access.redhat.com/ubi9/python-312:latest; Unpinned base image: base; Unpinned base image: base; Unpinned base image: cuda-base-${TARGETARCH}; Unpinned base image: cuda-base
runtimes/rocm-pytorch/ubi9-python-3.11/Dockerfile.rocm rocm-base 3 1001 Unpinned base image: registry.access.redhat.com/ubi9/python-311:latest; Unpinned base image: base; Unpinned base image: rocm-base
runtimes/rocm-pytorch/ubi9-python-3.12/Dockerfile.rocm rocm-base 3 1001 Unpinned base image: registry.access.redhat.com/ubi9/python-312:latest; Unpinned base image: base; Unpinned base image: rocm-base
runtimes/rocm-tensorflow/ubi9-python-3.11/Dockerfile.rocm rocm-base 3 1001 Unpinned base image: registry.access.redhat.com/ubi9/python-311:latest; Unpinned base image: base; Unpinned base image: rocm-base
runtimes/rocm-tensorflow/ubi9-python-3.12/Dockerfile.rocm rocm-base 3 1001 Unpinned base image: registry.access.redhat.com/ubi9/python-312:latest; Unpinned base image: base; Unpinned base image: rocm-base
runtimes/tensorflow/ubi9-python-3.11/Dockerfile.cuda cuda-base 5 1001 multi-arch Unpinned base image: registry.access.redhat.com/ubi9/python-311:latest; Unpinned base image: base; Unpinned base image: base; Unpinned base image: cuda-base-${TARGETARCH}; Unpinned base image: cuda-base
runtimes/tensorflow/ubi9-python-3.12/Dockerfile.cuda cuda-base 5 1001 multi-arch Unpinned base image: registry.access.redhat.com/ubi9/python-312:latest; Unpinned base image: base; Unpinned base image: base; Unpinned base image: cuda-base-${TARGETARCH}; Unpinned base image: cuda-base