{"repo":"sredevopsorg/ghost-on-kubernetes","free":true,"listed":false,"github":"https://github.com/sredevopsorg/ghost-on-kubernetes","clone":"git clone https://github.com/sredevopsorg/ghost-on-kubernetes.git","description":"Deploy the leading open-source publishing platform, Ghost, on Kubernetes and Docker with maximum security and efficiency using a hardened, multi-arch container image.","language":"Dockerfile","stars":90,"topics":["ghost","ghost-cms","k3s","k8s","kubernetes","kubernetes-deployment","container-image","dockerfile","containers","gke"],"license":"MIT","category":"deployment-docker-iac","readme_excerpt":"Ghost on Kubernetes (v6.x) by SREDevOps.Org Deploy the leading open-source publishing platform, Ghost, on Kubernetes with maximum security and efficiency using a hardened, multi-arch container image. Maintained by SREDevOps.org : SRE, DevOps, Linux, Ethical Hacking, AI, ML, Open Source, Cloud Native, Platform Engineering in English, Español, and Portugués (Brasil). Key Highlights: Security & Efficiency This repository implements Ghost CMS v6.xx.x from @TryGhost (Official) on Kubernetes with a custom built image, which delivers significant improvements for production use and security features in Kubernetes. Enhanced Security Non-Root Execution: Both the Ghost and MySQL components run exclusively as a non-root user (UID/GID 65532) in Kubernetes, preventing potential privilege escalation attacks. Distroless Runtime: We utilize Google Container Tools Distroless Debian 13 - NodeJS 22 as the final runtime environment. Distroless images contain only the required application and language dependencies, excluding shells and package managers , making them substantially more secure and reducing the attack surface. Vulnerability Reduction: By replacing gosu with a native container execution flow and adopting Distroless, we removed several critical vulnerabilities reported in the original Ghost image: Result: This change alone reduced 6 critical vulnerabilities and 34 high vulnerabilities reported by Docker Scout in the official image. Example Security Reports: Ghost Official Image Ghost o","default_branch":null,"files":null,"tree":[],"storefront":"/r/sredevopsorg","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/sredevopsorg/ghost-on-kubernetes/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}