Docker Engine 25 rootful¶
Upstream Docker Engine 25.0.5 static payload on maintained Alpine, rootful daemon
Image: ghcr.io/strukturpiloten/docker-25-rootful
Declared image version: v25.0.5
Family: Docker Engine
Architecture: amd64, arm64
Inner mode: rootful
Declared runtime base: docker.io/library/alpine:3.24@sha256:294b683cb724975bec92580e1e685676bd4b50bda910ddb8c51d4cabeaec77e6
Image source and metadata · GHCR package · Detailed guide
Choose and inspect¶
Declared upstream software: 25.0.5
Declared tags: v25.0.5, v25.0, v25, main, latest. These are publication policy aliases, not proof that any tag exists in GHCR. Even the exact SemVer tag can move after a reviewed rebuild.
Registry status: observed; checked at 2026-09-28T10:15:40.909298+00:00.
Observed latest index digest: sha256:832b07eb78a996802e2ef790f71deae02f856bb6d24ba8ea0b755662ab98cd48.
Pull the observed immutable artifact:
podman pull ghcr.io/strukturpiloten/docker-25-rootful@sha256:832b07eb78a996802e2ef790f71deae02f856bb6d24ba8ea0b755662ab98cd48
For an isolated Linux nested-Docker test, the outer Podman boundary runs rootfully and privileged. Use a trusted runner and keep its image store separate from other tests:
sudo podman run --rm --detach --name nested-docker --privileged --device /dev/fuse --security-opt label=disable ghcr.io/strukturpiloten/docker-25-rootful@sha256:832b07eb78a996802e2ef790f71deae02f856bb6d24ba8ea0b755662ab98cd48
ready=0
for attempt in $(seq 1 30); do
if sudo podman exec nested-docker docker info >/dev/null 2>&1; then ready=1; break; fi
sleep 2
done
if [ "$ready" -eq 1 ]; then sudo podman exec nested-docker docker info; else sudo podman logs nested-docker; fi
sudo podman stop nested-docker
test "$ready" -eq 1
This fixture does not use the host Docker socket. Read the detailed guide for nested workloads.
Support and runtime contract¶
Lifecycle: legacy; admission: isolated-test; review after: 2026-10-27.
Pinned static Engine and bundled dependencies are not patched by Alpine OS rebuilds; isolated compatibility fixture only.
Declared runtime profiles: docker. Declared test settings are in the metadata source. Admission is policy, not evidence of a passed test.
Declared runtime test contract:
{
"docker": {
"mode": "rootful",
"nestedRuntime": true,
"outerPrivilege": "privileged"
}
}
Registry aliases and history¶
Aliases resolved to the observed current digest: latest, main, v25, v25.0, v25.0.5.
Listed without digest resolution: run-36338188065-1-sha-237848af5481e58c6b0fec3ee0944d644eb59867, run-36346260768-1-sha-0b136a13a8bb612d91960ae5d07e72f449c89ec1, sha-0b136a13a8bb612d91960ae5d07e72f449c89ec1, sha-237848af5481e58c6b0fec3ee0944d644eb59867, sha256-02d3dbd987017ea4bcd48f149b96968cfee8af0462cad962f30db2d28afe67d0, sha256-23e81e247bbd77e2702eedcc2a0af244fe8073bc967977f798ffa8ef3b56d896, sha256-35c34926b1f511a2d2e1f48f61e41e52e81f86ff098febb0335a97fc7ce58169, sha256-46f6ad8f636740329d5425384fca73ea60b2c23d1eaa2c968e7299c08b5cc2e2, sha256-75d9fadea8dbc4533a2116a97999e2f4e58a48a84695b92a997483058d9a33f5, sha256-832b07eb78a996802e2ef790f71deae02f856bb6d24ba8ea0b755662ab98cd48.
Evidence and timestamps¶
| Field | Observed value |
|---|---|
| Source revision | 0b136a13a8bb612d91960ae5d07e72f449c89ec1 |
| Build succeeded | 2026-09-27T20:21:37.079021+00:00 |
| Published | unknown |
| Registry checked | 2026-09-28T10:15:40.909298+00:00 |
| Evidence | verified |
| Compared with current declarations | matched |
Matching release asset verified the build record and per-architecture runtime and scan evidence. Signature and provenance remain unverified in this snapshot.
Maintenance release · Evidence asset
amd64 OCI config and labels
Manifest: sha256:02d3dbd987017ea4bcd48f149b96968cfee8af0462cad962f30db2d28afe67d0
Config: sha256:36fe2af2bcd6b4c380548edb1235d08816e5a6aad4f66d894590cc45b29411f5
Config created: 2026-09-27T19:57:58Z
| Label | Value |
|---|---|
| org.opencontainers.image.base.digest | sha256:294b683cb724975bec92580e1e685676bd4b50bda910ddb8c51d4cabeaec77e6 |
| org.opencontainers.image.base.name | docker.io/library/alpine:3.24 |
| org.opencontainers.image.created | 2026-09-27T19:57:58Z |
| org.opencontainers.image.description | Upstream Docker Engine 25.0.5 static payload on maintained Alpine, rootful daemon |
| org.opencontainers.image.documentation | https://github.com/Strukturpiloten/containers/tree/0b136a13a8bb612d91960ae5d07e72f449c89ec1/images/docker/docker-25-rootful |
| org.opencontainers.image.licenses | AGPL-3.0-only |
| org.opencontainers.image.revision | 0b136a13a8bb612d91960ae5d07e72f449c89ec1 |
| org.opencontainers.image.source | https://github.com/Strukturpiloten/containers |
| org.opencontainers.image.title | Docker Engine 25 rootful |
| org.opencontainers.image.url | https://github.com/Strukturpiloten/containers/pkgs/container/docker-25-rootful |
| org.opencontainers.image.vendor | Strukturpiloten OHG |
| org.opencontainers.image.version | 25.0.5 |
arm64 OCI config and labels
Manifest: sha256:46f6ad8f636740329d5425384fca73ea60b2c23d1eaa2c968e7299c08b5cc2e2
Config: sha256:3ab08dac162e31c2fa98d04503177eb50e16f72d0827772c1420057e8471e148
Config created: 2026-09-27T19:57:58Z
| Label | Value |
|---|---|
| org.opencontainers.image.base.digest | sha256:294b683cb724975bec92580e1e685676bd4b50bda910ddb8c51d4cabeaec77e6 |
| org.opencontainers.image.base.name | docker.io/library/alpine:3.24 |
| org.opencontainers.image.created | 2026-09-27T19:57:58Z |
| org.opencontainers.image.description | Upstream Docker Engine 25.0.5 static payload on maintained Alpine, rootful daemon |
| org.opencontainers.image.documentation | https://github.com/Strukturpiloten/containers/tree/0b136a13a8bb612d91960ae5d07e72f449c89ec1/images/docker/docker-25-rootful |
| org.opencontainers.image.licenses | AGPL-3.0-only |
| org.opencontainers.image.revision | 0b136a13a8bb612d91960ae5d07e72f449c89ec1 |
| org.opencontainers.image.source | https://github.com/Strukturpiloten/containers |
| org.opencontainers.image.title | Docker Engine 25 rootful |
| org.opencontainers.image.url | https://github.com/Strukturpiloten/containers/pkgs/container/docker-25-rootful |
| org.opencontainers.image.vendor | Strukturpiloten OHG |
| org.opencontainers.image.version | 25.0.5 |
GitHub package activity can include signatures and attestations; it does not identify when the current runnable image was published. A registry observation is a point-in-time check; mutable tags may move afterward. Use the immutable digest and maintenance evidence for an audit.