Docker Engine 25 rootless

Upstream Docker Engine 25.0.5 static payload on maintained Alpine, rootless daemon

Image: ghcr.io/strukturpiloten/docker-25-rootless
Declared image version: v25.0.5
Family: Docker Engine
Architecture: amd64, arm64
Inner mode: rootless

Declared runtime base: docker.io/library/alpine:3.24@sha256:294b683cb724975bec92580e1e685676bd4b50bda910ddb8c51d4cabeaec77e6

Image source and metadata · GHCR package · Detailed guide

Choose and inspect

Declared upstream software: 25.0.5

Declared tags: v25.0.5, v25.0, v25, main, latest. These are publication policy aliases, not proof that any tag exists in GHCR. Even the exact SemVer tag can move after a reviewed rebuild.

Registry status: observed; checked at 2026-09-28T10:15:41.147841+00:00.

Observed latest index digest: sha256:957512b0478258e69fc80e824a2f27ba5194e6d3fbf91798655be7e81eb1b636.

Pull the observed immutable artifact:

podman pull ghcr.io/strukturpiloten/docker-25-rootless@sha256:957512b0478258e69fc80e824a2f27ba5194e6d3fbf91798655be7e81eb1b636

For an isolated Linux nested-Docker test, the outer Podman boundary runs rootfully and privileged. Use a trusted runner and keep its image store separate from other tests:

sudo podman run --rm --detach --name nested-docker --privileged --device /dev/fuse --security-opt label=disable ghcr.io/strukturpiloten/docker-25-rootless@sha256:957512b0478258e69fc80e824a2f27ba5194e6d3fbf91798655be7e81eb1b636
ready=0
for attempt in $(seq 1 30); do
  if sudo podman exec nested-docker docker info >/dev/null 2>&1; then ready=1; break; fi
  sleep 2
done
if [ "$ready" -eq 1 ]; then sudo podman exec nested-docker docker info; else sudo podman logs nested-docker; fi
sudo podman stop nested-docker
test "$ready" -eq 1

This fixture does not use the host Docker socket. Read the detailed guide for nested workloads.

Support and runtime contract

Lifecycle: legacy; admission: isolated-test; review after: 2026-10-27.

Pinned static Engine and bundled dependencies are not patched by Alpine OS rebuilds; isolated compatibility fixture only.

Declared runtime profiles: docker. Declared test settings are in the metadata source. Admission is policy, not evidence of a passed test.

Declared runtime test contract:

{
  "docker": {
    "mode": "rootless",
    "nestedRuntime": true,
    "outerPrivilege": "privileged"
  }
}

Registry aliases and history

Aliases resolved to the observed current digest: latest, main, v25, v25.0, v25.0.5.

Listed without digest resolution: run-36338188065-1-sha-237848af5481e58c6b0fec3ee0944d644eb59867, run-36346260768-1-sha-0b136a13a8bb612d91960ae5d07e72f449c89ec1, sha-0b136a13a8bb612d91960ae5d07e72f449c89ec1, sha-237848af5481e58c6b0fec3ee0944d644eb59867, sha256-094fef9cb9ef2043a276f6f9726af9d7bfcc66352b6e1abd6ed06629f57cfdd4, sha256-7107a00729a4c88ba8dbc5e018a31df04b51290132416201136635f903a731c3, sha256-957512b0478258e69fc80e824a2f27ba5194e6d3fbf91798655be7e81eb1b636, sha256-b7b06f2d9bab312eb9447d1b1a0868b344eb5ee8026200153893cea085d242d4, sha256-d15d2b771361862284c1c1313ba0047301223ae9b116ca3db62e29ccfc2256d0, sha256-fa1d4d4f91e7e263de95e74d520795f94d168b0315a3a54ec959bf1b84718f7b.

Evidence and timestamps

Field Observed value
Source revision 0b136a13a8bb612d91960ae5d07e72f449c89ec1
Build succeeded 2026-09-27T20:22:29.549755+00:00
Published unknown
Registry checked 2026-09-28T10:15:41.147841+00:00
Evidence verified
Compared with current declarations matched

Matching release asset verified the build record and per-architecture runtime and scan evidence. Signature and provenance remain unverified in this snapshot.

Maintenance release · Evidence asset

amd64 OCI config and labels

Manifest: sha256:b7b06f2d9bab312eb9447d1b1a0868b344eb5ee8026200153893cea085d242d4
Config: sha256:e90c73badbcd7684127f1d97a16e575e0abfda5eba5159450fb8e836b74b98f6
Config created: 2026-09-27T19:57:58Z

LabelValue
org.opencontainers.image.base.digestsha256:294b683cb724975bec92580e1e685676bd4b50bda910ddb8c51d4cabeaec77e6
org.opencontainers.image.base.namedocker.io/library/alpine:3.24
org.opencontainers.image.created2026-09-27T19:57:58Z
org.opencontainers.image.descriptionUpstream Docker Engine 25.0.5 static payload on maintained Alpine, rootless daemon
org.opencontainers.image.documentationhttps://github.com/Strukturpiloten/containers/tree/0b136a13a8bb612d91960ae5d07e72f449c89ec1/images/docker/docker-25-rootless
org.opencontainers.image.licensesAGPL-3.0-only
org.opencontainers.image.revision0b136a13a8bb612d91960ae5d07e72f449c89ec1
org.opencontainers.image.sourcehttps://github.com/Strukturpiloten/containers
org.opencontainers.image.titleDocker Engine 25 rootless
org.opencontainers.image.urlhttps://github.com/Strukturpiloten/containers/pkgs/container/docker-25-rootless
org.opencontainers.image.vendorStrukturpiloten OHG
org.opencontainers.image.version25.0.5
arm64 OCI config and labels

Manifest: sha256:fa1d4d4f91e7e263de95e74d520795f94d168b0315a3a54ec959bf1b84718f7b
Config: sha256:ff80cdd8977de9ce5e4c434bfbd66acfe6676ea8e20f2d0d7cdad2aaa8274c28
Config created: 2026-09-27T19:57:58Z

LabelValue
org.opencontainers.image.base.digestsha256:294b683cb724975bec92580e1e685676bd4b50bda910ddb8c51d4cabeaec77e6
org.opencontainers.image.base.namedocker.io/library/alpine:3.24
org.opencontainers.image.created2026-09-27T19:57:58Z
org.opencontainers.image.descriptionUpstream Docker Engine 25.0.5 static payload on maintained Alpine, rootless daemon
org.opencontainers.image.documentationhttps://github.com/Strukturpiloten/containers/tree/0b136a13a8bb612d91960ae5d07e72f449c89ec1/images/docker/docker-25-rootless
org.opencontainers.image.licensesAGPL-3.0-only
org.opencontainers.image.revision0b136a13a8bb612d91960ae5d07e72f449c89ec1
org.opencontainers.image.sourcehttps://github.com/Strukturpiloten/containers
org.opencontainers.image.titleDocker Engine 25 rootless
org.opencontainers.image.urlhttps://github.com/Strukturpiloten/containers/pkgs/container/docker-25-rootless
org.opencontainers.image.vendorStrukturpiloten OHG
org.opencontainers.image.version25.0.5

GitHub package activity can include signatures and attestations; it does not identify when the current runnable image was published. A registry observation is a point-in-time check; mutable tags may move afterward. Use the immutable digest and maintenance evidence for an audit.

View source ↗ Read as Markdown Source updated