Docker Engine Fedora 43 rootful¶
Native Fedora 43 moby-engine package with rootful Docker daemon for isolated compatibility tests
Image: ghcr.io/strukturpiloten/docker-fedora-43-rootful
Declared image version: v1.0.0
Family: Docker Engine
Architecture: amd64, arm64
Inner mode: rootful
Declared runtime base: registry.fedoraproject.org/fedora:43@sha256:a0615357ebdfac87a5249c3b4280c08c48bd46bc992683a559a6905ebfce91a2
Image source and metadata · GHCR package · Detailed guide
Choose and inspect¶
The distribution selects the installed engine package at build time. Inspect the published image's component manifest or SBOM for its exact revision.
Declared tags: v1.0.0, v1.0, v1, main, latest. These are publication policy aliases, not proof that any tag exists in GHCR. Even the exact SemVer tag can move after a reviewed rebuild.
Registry status: observed; checked at 2026-09-28T10:16:13.602597+00:00.
Observed latest index digest: sha256:eac6f5bfe04658df672cc650431cb619a9e5b422934d4d8de25a20e405b80bf3.
Pull the observed immutable artifact:
podman pull ghcr.io/strukturpiloten/docker-fedora-43-rootful@sha256:eac6f5bfe04658df672cc650431cb619a9e5b422934d4d8de25a20e405b80bf3
For an isolated Linux nested-Docker test, the outer Podman boundary runs rootfully and privileged. Use a trusted runner and keep its image store separate from other tests:
sudo podman run --rm --detach --name nested-docker --privileged --device /dev/fuse --security-opt label=disable ghcr.io/strukturpiloten/docker-fedora-43-rootful@sha256:eac6f5bfe04658df672cc650431cb619a9e5b422934d4d8de25a20e405b80bf3
ready=0
for attempt in $(seq 1 30); do
if sudo podman exec nested-docker docker info >/dev/null 2>&1; then ready=1; break; fi
sleep 2
done
if [ "$ready" -eq 1 ]; then sudo podman exec nested-docker docker info; else sudo podman logs nested-docker; fi
sudo podman stop nested-docker
test "$ready" -eq 1
This fixture does not use the host Docker socket. Read the detailed guide for nested workloads.
Support and runtime contract¶
Lifecycle: maintained; admission: isolated-test; review after: 2026-10-27.
Vendor package revisions can advance with repository updates; image shares runner kernel and host security policy.
Declared runtime profiles: docker. Declared test settings are in the metadata source. Admission is policy, not evidence of a passed test.
Declared runtime test contract:
{
"docker": {
"mode": "rootful",
"nestedRuntime": true,
"outerPrivilege": "privileged"
}
}
Registry aliases and history¶
Aliases resolved to the observed current digest: latest, main, v1, v1.0, v1.0.0.
Listed without digest resolution: run-36346260768-1-sha-0b136a13a8bb612d91960ae5d07e72f449c89ec1, run-36401422287-1-sha-1983e53aa68e4f0f445bdb9c2cce47a875c05a30, sha-0b136a13a8bb612d91960ae5d07e72f449c89ec1, sha-1983e53aa68e4f0f445bdb9c2cce47a875c05a30, sha256-05e31d44eefd2ced9019b5c34b0b564c02b8a3884d542f63fd06302324cdba48, sha256-1e60f4084ecd33a1325d451afc8399c76ee10d856be45568289a7e7640423f52, sha256-508a808760732fb93e35e89d15494ac81804c78127924f8f1a774c67889b6131, sha256-98623cdc43c755a1ac7ec40bd6ad6016ca0ea87b9a9d6b3abd84ebe8184542f9, sha256-da1eaa63e15c37f68a43cffa10a1d19bb34a1afd616d2dc7ce7aeaac33f2d621, sha256-eac6f5bfe04658df672cc650431cb619a9e5b422934d4d8de25a20e405b80bf3.
Evidence and timestamps¶
| Field | Observed value |
|---|---|
| Source revision | 1983e53aa68e4f0f445bdb9c2cce47a875c05a30 |
| Build succeeded | 2026-09-28T09:15:18.393807+00:00 |
| Published | unknown |
| Registry checked | 2026-09-28T10:16:13.602597+00:00 |
| Evidence | verified |
| Compared with current declarations | matched |
Matching release asset verified the build record and per-architecture runtime and scan evidence. Signature and provenance remain unverified in this snapshot.
Maintenance release · Evidence asset
amd64 OCI config and labels
Manifest: sha256:98623cdc43c755a1ac7ec40bd6ad6016ca0ea87b9a9d6b3abd84ebe8184542f9
Config: sha256:e0963c7a329a0ecf4ed2fbb50fe6e76beb4c18d2058b847424bb0deefc667256
Config created: 2026-09-28T09:06:40Z
| Label | Value |
|---|---|
| io.buildah.version | 1.43.2 |
| license | MIT |
| name | fedora |
| org.opencontainers.image.base.digest | sha256:a0615357ebdfac87a5249c3b4280c08c48bd46bc992683a559a6905ebfce91a2 |
| org.opencontainers.image.base.name | registry.fedoraproject.org/fedora:43 |
| org.opencontainers.image.created | 2026-09-28T09:06:40Z |
| org.opencontainers.image.description | Native Fedora 43 moby-engine package with rootful Docker daemon for isolated compatibility tests |
| org.opencontainers.image.documentation | https://github.com/Strukturpiloten/containers/tree/1983e53aa68e4f0f445bdb9c2cce47a875c05a30/images/docker/docker-fedora-43-rootful |
| org.opencontainers.image.license | MIT |
| org.opencontainers.image.licenses | AGPL-3.0-only |
| org.opencontainers.image.name | fedora |
| org.opencontainers.image.revision | 1983e53aa68e4f0f445bdb9c2cce47a875c05a30 |
| org.opencontainers.image.source | https://github.com/Strukturpiloten/containers |
| org.opencontainers.image.title | Docker Engine Fedora 43 rootful |
| org.opencontainers.image.url | https://github.com/Strukturpiloten/containers/pkgs/container/docker-fedora-43-rootful |
| org.opencontainers.image.vendor | Strukturpiloten OHG |
| org.opencontainers.image.version | 1.0.0 |
| vendor | Fedora Project |
| version | 43 |
arm64 OCI config and labels
Manifest: sha256:508a808760732fb93e35e89d15494ac81804c78127924f8f1a774c67889b6131
Config: sha256:bffe2fba7b4b0ba502e5763f6bbb71290dad582e08f69b02cb666dc15c68e35d
Config created: 2026-09-28T09:06:40Z
| Label | Value |
|---|---|
| io.buildah.version | 1.43.2 |
| license | MIT |
| name | fedora |
| org.opencontainers.image.base.digest | sha256:a0615357ebdfac87a5249c3b4280c08c48bd46bc992683a559a6905ebfce91a2 |
| org.opencontainers.image.base.name | registry.fedoraproject.org/fedora:43 |
| org.opencontainers.image.created | 2026-09-28T09:06:40Z |
| org.opencontainers.image.description | Native Fedora 43 moby-engine package with rootful Docker daemon for isolated compatibility tests |
| org.opencontainers.image.documentation | https://github.com/Strukturpiloten/containers/tree/1983e53aa68e4f0f445bdb9c2cce47a875c05a30/images/docker/docker-fedora-43-rootful |
| org.opencontainers.image.license | MIT |
| org.opencontainers.image.licenses | AGPL-3.0-only |
| org.opencontainers.image.name | fedora |
| org.opencontainers.image.revision | 1983e53aa68e4f0f445bdb9c2cce47a875c05a30 |
| org.opencontainers.image.source | https://github.com/Strukturpiloten/containers |
| org.opencontainers.image.title | Docker Engine Fedora 43 rootful |
| org.opencontainers.image.url | https://github.com/Strukturpiloten/containers/pkgs/container/docker-fedora-43-rootful |
| org.opencontainers.image.vendor | Strukturpiloten OHG |
| org.opencontainers.image.version | 1.0.0 |
| vendor | Fedora Project |
| version | 43 |
GitHub package activity can include signatures and attestations; it does not identify when the current runnable image was published. A registry observation is a point-in-time check; mutable tags may move afterward. Use the immutable digest and maintenance evidence for an audit.