Tracking image lifecycle
If you were to make a list of every image we’ve built with Packer up until now, what data would you want to retain and for how long? This criterion may depend on some regulatory requirements in your business, or it may be an internal decision for security and best practice. You may need to record only what image names are used and where they are available, including cloud storage regions, local storage pools, image archives, or container registries. Other important attributes may include system packaging metadata, such as which versions of key libraries are installed, or maybe even the results of vulnerability scans, Open Policy Agent profiles, or OpenSCAP scans. Having these on file for your entire image library can be very helpful when important CVE announcements are made, or zero-day vulnerabilities go public. Knowing which images are affected becomes very important, and there are many vendors offering solutions purely to help identify these issues...