VIRTUAL MACHINE IMAGE UPDATE MANAGEMENT PLATFORM
A system and method for virtual machine image management. A method includes generating a plurality of software packages, wherein each software package is generated using a respective set of code; building a plurality of VM images based on a plurality of files, wherein building each VM image further comprises combining a subset of the plurality of software packages according to a corresponding file of the plurality of files, wherein each file includes a set of instructions for combining the subset of the plurality of software packages in order to build the corresponding VM image; and pushing the plurality of VM images in a repository.
1 . A method for virtual machine (VM) image management, comprising:
generating a plurality of software packages, wherein each software package is generated using a respective set of code;
building a plurality of VM images based on a plurality of files, wherein building each VM image further comprises combining a subset of the plurality of software packages according to a corresponding file of the plurality of files, wherein each file includes a set of instructions for combining the subset of the plurality of software packages in order to build the corresponding VM image;
pushing the plurality of VM images in a repository;
detecting an upstream change to a first software package of the plurality of software packages, wherein the upstream change is detected as a change to a portion of code from which the first software package depends; and
rebuilding a first VM image of the plurality of VM images based on a first file of the plurality of files using a new version of the portion of code from which the first software package depends.
2 . The method of claim 1 , further comprising:
configuring each of the plurality of VM images based on the plurality of files, wherein the set of instructions for each file further defines a configuration for the corresponding VM image.
3 . The method of claim 1 , further comprising:
monitoring for changes to a plurality of portions of code among the plurality of software packages;
identifying an update based on the monitoring, wherein the update includes a change in at least one portion of code of the plurality of portions of code among the plurality of software packages; and
rebuilding at least one VM image of the plurality of VM images using a new version of the at least one portion of code.
4 . The method of claim 3 , wherein the plurality of portions of code among the plurality of software packages is a plurality of first portions of code, wherein monitoring for the changes to the plurality of portions of code among the plurality of software packages further comprises:
establishing a pipeline with respect to the plurality of software packages, wherein the pipeline is defined such that a software package of the plurality of software packages containing a dependency to a second portion of code is downstream of the second portion of code, wherein the upstream change is detected based further on the pipeline.
5 . The method of claim 3 , further comprising:
classifying the identified update into a classification; and
selecting the at least one VM image to be rebuilt based on the classification.
6 . The method of claim 5 , wherein the classification indicates that the change in the at least one portion of code is a change to patch a vulnerability.
7 . The method of claim 1 , wherein the plurality of VM images corresponds to a plurality of virtual machines, further comprising:
ingesting cybersecurity data from a computing environment in which the plurality of virtual machines is deployed;
identifying a vulnerability being exploited based on the ingested cybersecurity data; and
rebuilding at least one VM image of the plurality of VM images, wherein the rebuilt at least one VM image include a vulnerable software package of the plurality of software packages, wherein the vulnerable software package has the identified vulnerability.
8 . The method of claim 7 , further comprising:
redeploying the rebuilt at least one VM image.
9 . The method of claim 1 , wherein each software package is a unit of code defined with respect to at least one function.
10 . A non-transitory computer-readable medium having stored thereon instructions for causing a processing circuitry to execute a process, the process comprising:
generating a plurality of software packages, wherein each software package is generated using a respective set of code;
building a plurality of VM images based on a plurality of files, wherein building each VM image further comprises combining a subset of the plurality of software packages according to a corresponding file of the plurality of files, wherein each file includes a set of instructions for combining the subset of the plurality of software packages in order to build the corresponding VM image;
pushing the plurality of VM images in a repository;
detecting an upstream change to a first software package of the plurality of software packages, wherein the upstream change is detected as a change to a portion of code from which the first software package depends; and
rebuilding a first VM image of the plurality of VM images based on a first file of the plurality of files using a new version of the portion of code from which the first software package depends.
11 . A system for virtual machine image management, comprising:
a processing circuitry; and
a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:
generate a plurality of software packages, wherein each software package is generated using a respective set of code;
build a plurality of VM images based on a plurality of files, wherein building each VM image further comprises combining a subset of the plurality of software packages according to a corresponding file of the plurality of files, wherein each file includes a set of instructions for combining the subset of the plurality of software packages in order to build the corresponding VM image;
push the plurality of VM images in a repository;
detect an upstream change to a first software package of the plurality of software packages, wherein the upstream change is detected as a change to a portion of code from which the first software package depends; and
rebuild a first VM image of the plurality of VM images based on a first file of the plurality of files using a new version of the portion of code from which the first software package depends.
12 . The system of claim 11 , wherein the system is further configured to:
configure each of the plurality of VM images based on the plurality of files, wherein the set of instructions for each file further defines a configuration for the corresponding VM image.
13 . The system of claim 11 , wherein the system is further configured to:
monitor for changes to a plurality of portions of code among the plurality of software packages;
identify an update based on the monitoring, wherein the update includes a change in at least one portion of code of the plurality of portions of code among the plurality of software packages; and
rebuild at least one VM image of the plurality of VM images using a new version of the at least one portion of code.
14 . The system of claim 13 , wherein the plurality of portions of code among the plurality of software packages is a plurality of first portions of code, wherein the system is further configured to:
establish a pipeline with respect to the plurality of software packages, wherein the pipeline is defined such that a software package of the plurality of software packages containing a dependency to a second portion of code is downstream of the second portion of code, wherein the upstream change is detected based further on the pipeline.
15 . The system of claim 13 , wherein the system is further configured to:
classify the identified update into a classification; and
select the at least one VM image to be rebuilt based on the classification.
16 . The system of claim 15 , wherein the classification indicates that the change in the at least one portion of code is a change to patch a vulnerability.
17 . The system of claim 11 , wherein the plurality of VM images corresponds to a plurality of virtual machines, wherein the system is further configured to:
ingest cybersecurity data from a computing environment in which the plurality of virtual machines is deployed;
identify a vulnerability being exploited based on the ingested cybersecurity data; and
rebuild at least one VM image of the plurality of VM images, wherein the rebuilt at least one VM image include a vulnerable software package of the plurality of software packages, wherein the vulnerable software package has the identified vulnerability.
18 . The system of claim 17 , wherein the system is further configured to:
redeploy the rebuilt at least one VM image.
19 . The system of claim 11 , wherein each software package is a unit of code defined with respect to at least one function.