Skip to content

Evaluate system package lists for Workbench images #89

Description

@ianpittwood

Summary

The package lists used in this repository are largely lifted from rstudio-docker-products which may not have up-to-date dependencies. We should evaluate our system dependency lists to determine if any packages should be removed, moved between required and optional, or added.

Methodology

Required packages should include system dependencies that are...

  • Required by what is installed into the minimal image
  • Not subject to a user's specific environment or opinions (like Python or R versions)

Optional packages should include system dependencies that are...

  • Used by nearly all users
  • Dependencies of popular R and Python packages
  • Used for advanced configurations for subcomponents like authentication
  • Required for things to "just work"

Activity

  1. added theissue type on Apr 29, 2026
  2. ianpittwood commented on Apr 29, 2026

    @ianpittwood
    ContributorAuthor

    Package list review — findings

    Generated by Claude (Opus 4.7) at the request of @ianpittwood. Treat as a starting point for human review and verification, not as authoritative.

    Reviewed workbench/template/deps/{ubuntu-22.04,ubuntu-24.04}_{,optional_}packages.txt.jinja2 against the Containerfile, install_workbench.sh, and the Bakery apt.j2 macros. The 22.04 and 24.04 required lists are byte-identical; the optional lists differ only on libfreetype-dev vs libfreetype6-dev (correct transitional naming).

    Context that shapes the recommendations

    • The required list is installed for both Standard and Minimal — every entry is opinionated bundling that Minimal customers cannot opt out of.
    • apt.run_setup() already installs curl, ca-certificates, gnupg, tar.
    • install_workbench.sh extracts the rstudio-server deb's Depends: and installs them, so anything pulled by the deb is already covered.
    • All installs use --no-install-recommends, so anything normally pulled via Recommends must be explicit.

    Highest-priority findings

    1. libpam-sss / libnss-sss are likely missing. With --no-install-recommends, the sssd metapackage may not pull these reliably across releases. Without them, SSSD cannot integrate with PAM/NSS — login lookups silently fall back. Verify presence in the current Standard image; if they exist, it's transitive luck. Add explicitly to optional.
    2. default-jdk → default-jre-headless. Saves ~250–400 MB and reduces CVE surface. Most users with rJava / RJDBC / Spark / H2O need only the JRE. Customers needing javac can layer it back in.
    3. build-essential, libssl-dev, libclang-dev should leave the required list. None are runtime requirements of rstudio-server itself; they're source-compilation conveniences. Putting them in required forces them into Minimal, which contradicts Minimal's purpose.
    4. libc6 in required is a no-op. Guaranteed present in the base image and pulled by the deb's Depends:. Remove.

    Required list — recommended trim

    Package Recommendation Reason
    libc6 Remove Already in base image + deb depends
    libclang-dev Move to optional Not a server runtime dep; ~150 MB
    libxkbcommon-x11-0 Investigate, likely remove X11 keyboard lib in a headless server image
    libssl-dev Move to optional Headers only needed for compilation; runtime libssl3 already pulled by deb
    lsb-release Move to optional or remove /etc/os-release covers most needs
    build-essential Move to optional ~400 MB compiler chain doesn't belong in Minimal
    libsqlite3-0 Verify against deb depends Likely already pulled
    libpq5, psmisc, rrdtool, sudo, supervisor Keep Core runtime

    Consider adding tzdata and locales (with a locale-gen en_US.UTF-8) — UTF-8 / time-zone issues are recurring user pain points.

    Optional list — recommended changes

    Add (advanced auth — directly called out in the issue scope):

    • libpam-sss, libnss-sss — see priority finding Refactor repo for bakery tool compatbility #1
    • krb5-user — Kerberos client (kinit, klist) for AD/GSSAPI
    • libsasl2-modules-gssapi-mit — SASL GSSAPI mechanism for Kerberos-backed LDAP binds
    • libsasl2-dev, libldap2-dev — for R/Python LDAP/SASL bindings

    Add (Quarto / rendering):

    • librsvg2-bin — SVG → PDF for Quarto/RMarkdown PDF pipelines
    • fonts-dejavu-core, fonts-liberation — currently only gsfonts ships; ggplot/Quarto PDF output benefits from common fallbacks (~30–80 MB total)

    Add (developer ergonomics — commonly assumed present):

    • openssh-client — git over SSH, scp/sftp (notable omission)
    • unzip, zip, rsync, jq, vim-tiny, htop

    Remove or downgrade:

    Package Action Reason
    default-jdk → default-jre-headless Size + CVE surface; most users need only JRE
    imagemagick Remove (keep libmagick++-dev) Long CVE history; R magick package only needs the library
    oddjob-mkhomedir Remove Containerfile already wires pam_mkhomedir.so directly; redundant mechanism
    python3 Remove Workbench uses uv-managed Python in /opt/python; system Python invites version drift
    tk-table Remove Very niche; bare tcl/tk is sufficient for tcltk
    gdb Optional candidate Useful but easily added on demand if image size matters

    Suggested verification before merging any change

    1. Run dpkg -I against the published rstudio-server deb to enumerate Depends: precisely — drop anything from packages.txt that's already there.
    2. Build Minimal with the trimmed required list and run bakery run dgoss --image-name workbench.
    3. For SSSD additions, check /lib/*/security/pam_sss.so and /lib/*/libnss_sss.so.2 exist in the current Standard image to confirm whether the additions are correctness fixes vs explicit pinning.
    4. Build Standard with default-jre-headless and smoke-test rJava / RJDBC workflows before committing.

    Biggest wins, in priority order

    1. Explicit libpam-sss / libnss-sss (correctness for SSSD-based auth)
    2. default-jdk → default-jre-headless (size + CVE surface)
    3. Move build-essential / libssl-dev / libclang-dev out of required (Minimal slimming)
    4. Drop libc6 from required (cosmetic, but signals carefulness)
  3. self-assigned this
    on May 27, 2026
  4. added
    cvp:0Necessary projects we are undertaking that don’t directly deliver value to the customer
    tdp:1The individual working on it notices.
    on Jul 22, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

cvp:0Necessary projects we are undertaking that don’t directly deliver value to the customerdependenciesUpdates to dependency filesdockerRelated to container images we producetdp:1The individual working on it notices.tech debtTechnical debt we should address

Type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions