Docker Engine Fedora 44 rootful

Native Fedora 44 moby-engine package with rootful Docker daemon for isolated compatibility tests

Image: ghcr.io/strukturpiloten/docker-fedora-44-rootful
Declared image version: v1.0.0
Family: Docker Engine
Architecture: amd64, arm64
Inner mode: rootful

Declared runtime base: registry.fedoraproject.org/fedora:44@sha256:1ccd18224d9b302fe62d3cefd0a9e0724c365ea8ac3bfb017c569540fe76433a

Image source and metadata · GHCR package · Detailed guide

Choose and inspect

The distribution selects the installed engine package at build time. Inspect the published image's component manifest or SBOM for its exact revision.

Declared tags: v1.0.0, v1.0, v1, main, latest. These are publication policy aliases, not proof that any tag exists in GHCR. Even the exact SemVer tag can move after a reviewed rebuild.

Registry status: observed; checked at 2026-09-28T10:16:13.688048+00:00.

Observed latest index digest: sha256:1fa67a39ec27bf60ba464aaca9b45d9214bf7b88367903a9d80ebd82fa8ce9e3.

Pull the observed immutable artifact:

podman pull ghcr.io/strukturpiloten/docker-fedora-44-rootful@sha256:1fa67a39ec27bf60ba464aaca9b45d9214bf7b88367903a9d80ebd82fa8ce9e3

For an isolated Linux nested-Docker test, the outer Podman boundary runs rootfully and privileged. Use a trusted runner and keep its image store separate from other tests:

sudo podman run --rm --detach --name nested-docker --privileged --device /dev/fuse --security-opt label=disable ghcr.io/strukturpiloten/docker-fedora-44-rootful@sha256:1fa67a39ec27bf60ba464aaca9b45d9214bf7b88367903a9d80ebd82fa8ce9e3
ready=0
for attempt in $(seq 1 30); do
  if sudo podman exec nested-docker docker info >/dev/null 2>&1; then ready=1; break; fi
  sleep 2
done
if [ "$ready" -eq 1 ]; then sudo podman exec nested-docker docker info; else sudo podman logs nested-docker; fi
sudo podman stop nested-docker
test "$ready" -eq 1

This fixture does not use the host Docker socket. Read the detailed guide for nested workloads.

Support and runtime contract

Lifecycle: maintained; admission: isolated-test; review after: 2026-10-27.

Vendor package revisions can advance with repository updates; image shares runner kernel and host security policy.

Declared runtime profiles: docker. Declared test settings are in the metadata source. Admission is policy, not evidence of a passed test.

Declared runtime test contract:

{
  "docker": {
    "mode": "rootful",
    "nestedRuntime": true,
    "outerPrivilege": "privileged"
  }
}

Registry aliases and history

Aliases resolved to the observed current digest: latest, main, v1, v1.0, v1.0.0.

Listed without digest resolution: run-36346260768-1-sha-0b136a13a8bb612d91960ae5d07e72f449c89ec1, run-36406523319-1-sha-c7db148388c855b6e42bb5ec046a6ee1f998ab43, sha-0b136a13a8bb612d91960ae5d07e72f449c89ec1, sha-c7db148388c855b6e42bb5ec046a6ee1f998ab43, sha256-1da174f83a0a0bc6432ad6e7ce5a57cf176df0626df03db813bd4a396c5e7dbf, sha256-1fa67a39ec27bf60ba464aaca9b45d9214bf7b88367903a9d80ebd82fa8ce9e3, sha256-284dec9c21a69d5bda308359ab83cc712e0370420aa21f084df98943c8ea4d60, sha256-949768b26ee57b4e14ab515c4b6f546c59512a86abf93cc66dfc38d3ccfd04d9, sha256-992a89f354e64d079e69757682a426f8dbe70c982b3436117056817044027868, sha256-ec072dcc01a9abe584ecea8db730951bf8b1726bab74071e02120e83b7e7b7a6.

Evidence and timestamps

Field Observed value
Source revision c7db148388c855b6e42bb5ec046a6ee1f998ab43
Build succeeded 2026-09-28T10:13:28.233133+00:00
Published unknown
Registry checked 2026-09-28T10:16:13.688048+00:00
Evidence verified
Compared with current declarations matched

Matching release asset verified the build record and per-architecture runtime and scan evidence. Signature and provenance remain unverified in this snapshot.

Maintenance release · Evidence asset

amd64 OCI config and labels

Manifest: sha256:ec072dcc01a9abe584ecea8db730951bf8b1726bab74071e02120e83b7e7b7a6
Config: sha256:0eb5809671b65647b0c1f856812313bf44736932b0ec82406f57e69a15821e68
Config created: 2026-09-28T09:55:13Z

LabelValue
io.buildah.version1.43.4
org.opencontainers.image.base.digestsha256:1ccd18224d9b302fe62d3cefd0a9e0724c365ea8ac3bfb017c569540fe76433a
org.opencontainers.image.base.nameregistry.fedoraproject.org/fedora:44
org.opencontainers.image.created2026-09-28T09:55:13Z
org.opencontainers.image.descriptionNative Fedora 44 moby-engine package with rootful Docker daemon for isolated compatibility tests
org.opencontainers.image.documentationhttps://github.com/Strukturpiloten/containers/tree/c7db148388c855b6e42bb5ec046a6ee1f998ab43/images/docker/docker-fedora-44-rootful
org.opencontainers.image.licensesAGPL-3.0-only
org.opencontainers.image.revisionc7db148388c855b6e42bb5ec046a6ee1f998ab43
org.opencontainers.image.sourcehttps://github.com/Strukturpiloten/containers
org.opencontainers.image.titleDocker Engine Fedora 44 rootful
org.opencontainers.image.urlhttps://github.com/Strukturpiloten/containers/pkgs/container/docker-fedora-44-rootful
org.opencontainers.image.vendorStrukturpiloten OHG
org.opencontainers.image.version1.0.0
arm64 OCI config and labels

Manifest: sha256:284dec9c21a69d5bda308359ab83cc712e0370420aa21f084df98943c8ea4d60
Config: sha256:c7f57fe0f6950e62ddc172b7aa5849a9b2f3c9c9d61dd1abcf9c59a875991b52
Config created: 2026-09-28T09:55:13Z

LabelValue
io.buildah.version1.43.4
org.opencontainers.image.base.digestsha256:1ccd18224d9b302fe62d3cefd0a9e0724c365ea8ac3bfb017c569540fe76433a
org.opencontainers.image.base.nameregistry.fedoraproject.org/fedora:44
org.opencontainers.image.created2026-09-28T09:55:13Z
org.opencontainers.image.descriptionNative Fedora 44 moby-engine package with rootful Docker daemon for isolated compatibility tests
org.opencontainers.image.documentationhttps://github.com/Strukturpiloten/containers/tree/c7db148388c855b6e42bb5ec046a6ee1f998ab43/images/docker/docker-fedora-44-rootful
org.opencontainers.image.licensesAGPL-3.0-only
org.opencontainers.image.revisionc7db148388c855b6e42bb5ec046a6ee1f998ab43
org.opencontainers.image.sourcehttps://github.com/Strukturpiloten/containers
org.opencontainers.image.titleDocker Engine Fedora 44 rootful
org.opencontainers.image.urlhttps://github.com/Strukturpiloten/containers/pkgs/container/docker-fedora-44-rootful
org.opencontainers.image.vendorStrukturpiloten OHG
org.opencontainers.image.version1.0.0

GitHub package activity can include signatures and attestations; it does not identify when the current runnable image was published. A registry observation is a point-in-time check; mutable tags may move afterward. Use the immutable digest and maintenance evidence for an audit.

View source ↗ Read as Markdown Source updated