# How to patch eck-operator image

**URL:** <https://discuss.elastic.co/t/how-to-patch-eck-operator-image/243187>\
**Category:** Elastic Cloud on Kubernetes (ECK)\
**Created:** [July 30, 2020, 8:55am UTC](https://discuss.elastic.co/t/how-to-patch-eck-operator-image/243187 "2020-07-30T08:55:59Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![CHU\_XU](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chu_xu/32/45946_2.png) [@CHU\_XU](https://discuss.elastic.co/u/CHU_XU)\
**Post date:** [July 30, 2020, 8:55am UTC](https://discuss.elastic.co/t/how-to-patch-eck-operator-image/243187/1 "2020-07-30T08:55:59Z")

</div>

Hi there,

I need to do some security update of the eck-operator image.  
Usually I run a docker image and with --entrypoint /bin/bash, just like  
`docker run -it --entrypoint /bin/bash image`  
and do the update there. Then commit the updated container as a patched image.  
But when I do this to eck-operator, I got a error here:  
"Error response from daemon: OCI runtime create failed: container\_linux.go:349: starting container process caused "exec: "/usr/bin/sh": stat /usr/bin/sh: no such file or directory": unknown."

I exec into a running operator, there **is** /bin/bash, but why do I get such error.  
Any idea about it or is there other ways to do the update?  
Thanks

---

<div class="post-metadata">

**Author:** ![CHU\_XU](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chu_xu/32/45946_2.png) [@CHU\_XU](https://discuss.elastic.co/u/CHU_XU)\
**Post date:** [July 30, 2020, 9:10am UTC](https://discuss.elastic.co/t/how-to-patch-eck-operator-image/243187/2 "2020-07-30T09:10:59Z")

</div>

Is that because eck-operator is using distroless base?

---

<div class="post-metadata">

**Author:** ![Thibault\_Richard](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thibault_richard/32/50513_2.png) [@Thibault\_Richard](https://discuss.elastic.co/u/Thibault_Richard)\
**Post date:** [July 30, 2020, 10:00am UTC](https://discuss.elastic.co/t/how-to-patch-eck-operator-image/243187/3 "2020-07-30T10:00:22Z")

</div>

Yes!

Since 1.2.0, the ECK operator container image is much smaller and more secure thanks to switching to [Distroless](https://github.com/GoogleContainerTools/distroless) as the base image.

This should save you from having to perform security updates to the ECK operator container image.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 8:08am UTC](https://discuss.elastic.co/t/how-to-patch-eck-operator-image/243187/4 "2022-11-04T08:08:17Z")

</div>


