Red Hat UBI 9 Podman rootful¶
Red Hat UBI 9 distro-packaged Podman rootful compatibility image for CI
Image: ghcr.io/strukturpiloten/podman-ubi-9-rootful
Declared image version: v1.0.0
Family: Podman
Architecture: amd64, arm64
Inner mode: rootful
Declared runtime base: registry.access.redhat.com/ubi9/ubi:latest@sha256:7a38d75d376f7989033e75fcaaf9fcbb090fafc58e05c2c99de76ae0ba083fdb
Image source and metadata · GHCR package · Detailed guide
Choose and inspect¶
The distribution selects the installed engine package at build time. Inspect the published image's component manifest or SBOM for its exact revision.
Declared tags: v1.0.0, v1.0, v1, main, latest. These are publication policy aliases, not proof that any tag exists in GHCR. Even the exact SemVer tag can move after a reviewed rebuild.
Registry status: observed; checked at 2026-09-28T10:17:34.895295+00:00.
Observed latest index digest: sha256:87a50be16a3c9f636d901d34528370fb304ae571d89cf68894a00f33ba4d440a.
Pull the observed immutable artifact:
podman pull ghcr.io/strukturpiloten/podman-ubi-9-rootful@sha256:87a50be16a3c9f636d901d34528370fb304ae571d89cf68894a00f33ba4d440a
A CLI check can run without a nested workload:
podman run --rm ghcr.io/strukturpiloten/podman-ubi-9-rootful:v1.0.0 podman --version
Nested workloads require the profile-specific outer privilege and device setup in the detailed guide. Some rootless distro profiles intentionally omit nested workload checks.
Support and runtime contract¶
Lifecycle: maintained; admission: isolated-test; review after: 2026-12-31.
Repository rebuilds refresh distribution packages; vendor support determines installed Podman security maintenance.
Declared runtime profiles: podman. Declared test settings are in the metadata source. Admission is policy, not evidence of a passed test.
Declared runtime test contract:
{
"podman": {
"mode": "rootful",
"outerPrivilege": "privileged"
}
}
Registry aliases and history¶
Aliases resolved to the observed current digest: latest, main, v1, v1.0, v1.0.0.
Listed without digest resolution: run-32739402388-1-sha-f0259a080e8a49be43358fc00c4cac89528d4954, run-32808812826-1-sha-34e7193852a44ffade6d186f9c664368856ccb6c, run-32918078087-1-sha-36f12397c825a765d498654657c2cfa99ae413c9, run-32930106309-1-sha-36f12397c825a765d498654657c2cfa99ae413c9, run-33084138768-1-sha-501915f06c2f36c0254a08ad5c70ae9ec14c9a64, run-33304142817-1-sha-30faee7ada474e455a43b7abf2d90bbf24977056, run-33369549209-1-sha-8ba6168227ce22ebd58ab732a665d717cbcd54ab, run-33380856986-1-sha-699c4fd9be1a508c33387aa87e6211de92d6e480, run-33429018056-1-sha-2c8f273f70857b8fd2ecfdb600c9a87f48a584fd, run-33499424710-1-sha-34372bb39b2bc633ce194e28304eef808e1959ca, run-34389535369-1-sha-852114c75ac8d7d655e5f4873e74b730f5b6391b, run-34798102526-1-sha-57d3540f7f8edd558e31808e369b52df68a99d71, run-35042287292-1-sha-9ced62eea6e4976f8d6fc2aa1f60845cd228b22a, run-35153643596-1-sha-f6e29816396a7a02e339d83486983d473a04175b, run-35269754784-1-sha-ec6d3de9caf2eb601535e4f004d24e66c9e40294, run-35725276402-1-sha-d9facb12bab3b3e05c0365835d6525f1617d67e4, run-36320630115-1-sha-73e79fd9ca8cffa73bd60d360c8db2929271d48a, run-36346260768-1-sha-0b136a13a8bb612d91960ae5d07e72f449c89ec1, run-36389409256-1-sha-dfccaa9bf2505707372932363f14e40b15ed8b70, sha-0b136a13a8bb612d91960ae5d07e72f449c89ec1, sha-2c8f273f70857b8fd2ecfdb600c9a87f48a584fd, sha-34372bb39b2bc633ce194e28304eef808e1959ca, sha-36f12397c825a765d498654657c2cfa99ae413c9, sha-57d3540f7f8edd558e31808e369b52df68a99d71, sha-73e79fd9ca8cffa73bd60d360c8db2929271d48a, sha-852114c75ac8d7d655e5f4873e74b730f5b6391b, sha-8ba6168227ce22ebd58ab732a665d717cbcd54ab, sha-9ced62eea6e4976f8d6fc2aa1f60845cd228b22a, sha-d9facb12bab3b3e05c0365835d6525f1617d67e4, sha-dfccaa9bf2505707372932363f14e40b15ed8b70, sha-ec6d3de9caf2eb601535e4f004d24e66c9e40294, sha-f0259a080e8a49be43358fc00c4cac89528d4954, sha-f6e29816396a7a02e339d83486983d473a04175b, sha256-007bfa08aa8ff65f90ac366a958080a7d5888aa1704d2855e65e89789c9a2c91, sha256-03d8ba71276102878b13492c4ae27d5020b35b52697037b76dccd81d53ccc41c, sha256-04ded6bcf79403f62ec3f2c33740ef4169ba7f77b90839c52043eeb3a0571c51, sha256-06431785f6f3c8b66b943af49d0483a1af2f52f4b30af40f69d97074a8294e0b, sha256-1199acd158c6886131c6a8133979a071d083b48ea1ced4404595a1ea66797a6f, sha256-12a269cbda09e55f59e9a812961735f35fee0dbe156ca16112dca849f92e2dc6, sha256-17724bf2dd3a5dd983def93327a1ac3955361c5e77046914f75cf40dd8d036ba, sha256-1a5f1a72001bf3340811d65e91800931d09972252f9fe2f0c0ddc571c15c0d1b, sha256-1f253e26d79ff9bc802a6a9667740ea3c33a9276531d524861fe25c52e8b79be, sha256-20aaf0a310d0680607dbbfbea04bca7ea2edae36c331b3f28b61cc0d638c0f90, sha256-2795c58d7072dd40aca075f36b430058d3d247a1814955c038053bfab06ff1c4, sha256-2ceb0aae00ad5b628bf65930a544b1d672d7e07b49cd1a1bbd7480390baf2d5e, sha256-2e8ff326a022047bf91b37a615262a8d5a5fabbb001d749c30e5e32ea2d50a51, sha256-30220cb1a457153c2726709c49508a72dc78aaa76680a872b70ad727c40adfba, sha256-35e3382d226b9ce7b74b2a973ef15a77ac17a7062c9199794cf89c4ba08ea149, sha256-3fa45649c8c620221965d130cfb26f722f126489cfff1e3b963398454e2434ec, sha256-4cf851a784abc354129176c275550fb8982f8e1d2dd316dd8da1353c24eff255, sha256-5266d8c3b9fc4fc8eb57b938de985b3c3b00d09f6f100e46b689a22031c1de61, sha256-52acd5aaea761b3434d16cd6f4315ffb966b9e52a02d1ce11a762ccec2d490a4, sha256-5b4a4221b43a235460cbead9f2ee4833d24fa6636b34fcbacd7a04f5db8fe053, sha256-5d3f7b55ae8722402bc7789742aa56dc51a3394899f75045e48c9a83150ee0a6, sha256-5d8fca2918c46aa9e363eef99b2624c5766d2faf9edda9ce8379709b8b2abb1c, sha256-66dbb25bac5a36666ec1d2dd99d0adb06430c7b796fcd80791ecd412d5e1892a, sha256-74f697b752f29fc205ea9a92da31f07d397ce08ad5246fd326e0024db98dc0d5, sha256-76e02ff469ddc38eb79144ab0dce6bc391e792a9858c9943159a21d6a4d1669b, sha256-7777d5917f1df1d4950c961fe900da1a2e5576bef1a82d941579e2a9cb92420a, sha256-7816b03716e8e17857e9e795ef0d34da2cdd8b2ebabfb48933937a2642500f86, sha256-7c4ad825d71f577e07719cba5af9c513fa34d98abe6d03f8e3d16700a1152cc6, sha256-8125c47af2ee9d68f594d5862e0a941cbdacd2d89ec7a1cb8d72d06f077af184, sha256-8189fd48863f5b6d6cba536916d38a310e6d2c3198ff198e9992f6075fbcba1e, sha256-82a563607e0a58b2e4447efb82d015255312f790dd1473f88e1b75c39fb18d17, sha256-87a50be16a3c9f636d901d34528370fb304ae571d89cf68894a00f33ba4d440a, sha256-8b1eaa4a15ef2cd0b924974a068e2c645872a3178ce13fc45fc78caa33a943a9, sha256-8ce437af2729010c2e7ef026641d0a891626322411880d6bd32f74a85772c794, sha256-9212bbaaf1bc968efe318c63990e55531b8e3ad2cd6bfc498d60a900f66dbb77, sha256-9345ea38aa323792827bc0cf31f9cec330fe73456649934a02249eba1b88b940, sha256-9680229dda2886a0edac6126791c1ae3efceaf5be89caa1015a05a449c4e374e, sha256-9807e58321380237792c26fbdccbd044780215c03c78f57a6db4295aec5dfd19, sha256-9c09f859da5ab5aebd0ca046213b041c5819f50c2a57a5f894f5048a44977122, sha256-9d6730648167ec65f5cc98db1f0b634e7a66fb6096c363edbb7775736dbee504, sha256-9d89903404f4729f81f8a6bbe646c3c5c0edfb7d130ac3158406b1ba266dafba, sha256-a51b33aa116b3821440a146f039e2aa85668a43c666eda864ccc6530ddeb7a18, sha256-ae000757b6da29857db5780179fcec656a21920b2f52e2c3aa4ea3a89e165e62, sha256-aeee63d9ad4c95de97e85a40ceb21128969963d132499acaa3497d452dfc793a, sha256-bb925d1a4b0116f0e0a2e83e981f190c0348bec2e269a67b502df2ba8a540330, sha256-bd64e47178fbd40541b09f01118055501ebb26508936b127ffdf7b433fdb0bb3, sha256-ce601551d4214053225e79bd29841bb19d58ad5a2ed6ee02a5297b20c9f058e6, sha256-cfaadb4b8ee5aff63c6234b9abead3b58c893d9f2218a21ff975ba31aabb7b20, sha256-d1c6520d0003595b9772047317eeb076aa7c52d981b53caad6c3ccd5e8a3faae, sha256-d1fa5edb871ed90a45fce34266544a3910102dc38bb8e9969e207257b8c102d6, sha256-d2bb8145098a0073664db5a83fe65fd78231e30a54a891e4777563c56061f4f4, sha256-dfb15fbe6e0f51ae8111cf0aae44e2d51dee4c44f12738ab0e407a079cd04cd7, sha256-e22ae8635646e725ee997f8b9ddab98d412261af730be3d65f73f3f3c353f350, sha256-e8ef9648af1a9047ee3642f6f4116654e563cab4772df4b51f5d09c178956ecf, sha256-fa928399f2d4739ec4c87a9c1fa017a755e9f67a5a1ba0d4e91dfee85dc64dd7, sha256-fbde989e4d6128ba6f0c8d2ba924be58af239282b6951c9ce16eef9ea27e6449, sha256-ff6c363c9a851f083b6baebc699931cb9971234705be90aba6329b8451988266.
Evidence and timestamps¶
| Field | Observed value |
|---|---|
| Source revision | dfccaa9bf2505707372932363f14e40b15ed8b70 |
| Build succeeded | 2026-09-28T07:06:07.956590+00:00 |
| Published | unknown |
| Registry checked | 2026-09-28T10:17:34.895295+00:00 |
| Evidence | verified |
| Compared with current declarations | matched |
Matching release asset verified the build record and per-architecture runtime and scan evidence. Signature and provenance remain unverified in this snapshot.
Maintenance release · Evidence asset
amd64 OCI config and labels
Manifest: sha256:5266d8c3b9fc4fc8eb57b938de985b3c3b00d09f6f100e46b689a22031c1de61
Config: sha256:91d24fdcb4bb3678ef2a298c96eba29b98ff2b4f958bd20327a068e3d6edf2d4
Config created: 2026-09-28T07:01:21Z
| Label | Value |
|---|---|
| architecture | x86_64 |
| build-date | 2026-09-28T00:44:34Z |
| com.redhat.component | ubi9-container |
| com.redhat.license_terms | https://www.redhat.com/en/about/red-hat-end-user-license-agreements#UBI |
| cpe | cpe:/a:redhat:enterprise_linux:9::appstream |
| description | The Universal Base Image is designed and engineered to be the base layer for all of your containerized applications, middleware and utilities. This base image is freely redistributable, but Red Hat only supports Red Hat technologies through subscriptions for Red Hat products. This image is maintained by Red Hat and updated regularly. |
| distribution-scope | public |
| io.buildah.version | 1.44.0 |
| io.k8s.description | The Universal Base Image is designed and engineered to be the base layer for all of your containerized applications, middleware and utilities. This base image is freely redistributable, but Red Hat only supports Red Hat technologies through subscriptions for Red Hat products. This image is maintained by Red Hat and updated regularly. |
| io.k8s.display-name | Red Hat Universal Base Image 9 |
| io.openshift.expose-services | |
| io.openshift.tags | base rhel9 |
| maintainer | Red Hat, Inc. |
| name | ubi9/ubi |
| org.opencontainers.image.base.digest | sha256:7a38d75d376f7989033e75fcaaf9fcbb090fafc58e05c2c99de76ae0ba083fdb |
| org.opencontainers.image.base.name | registry.access.redhat.com/ubi9/ubi:latest |
| org.opencontainers.image.created | 2026-09-28T07:01:21Z |
| org.opencontainers.image.description | Red Hat UBI 9 distro-packaged Podman rootful compatibility image for CI |
| org.opencontainers.image.documentation | https://github.com/Strukturpiloten/containers/tree/dfccaa9bf2505707372932363f14e40b15ed8b70/images/podman/podman-ubi-9-rootful |
| org.opencontainers.image.licenses | AGPL-3.0-only |
| org.opencontainers.image.revision | dfccaa9bf2505707372932363f14e40b15ed8b70 |
| org.opencontainers.image.source | https://github.com/Strukturpiloten/containers |
| org.opencontainers.image.title | Red Hat UBI 9 Podman rootful |
| org.opencontainers.image.url | https://github.com/Strukturpiloten/containers/pkgs/container/podman-ubi-9-rootful |
| org.opencontainers.image.vendor | Strukturpiloten OHG |
| org.opencontainers.image.version | 1.0.0 |
| release | 1790556197 |
| summary | Provides the latest release of Red Hat Universal Base Image 9. |
| url | https://catalog.redhat.com/en/search?searchType=containers |
| vcs-ref | de6cfebe750e57846d6201a17d331080b9df4a01 |
| vcs-type | git |
| vendor | Red Hat, Inc. |
| version | 9.8 |
arm64 OCI config and labels
Manifest: sha256:e22ae8635646e725ee997f8b9ddab98d412261af730be3d65f73f3f3c353f350
Config: sha256:85c9991dca9e07552dd79926e601c359f3e39ee71b6ff4ec97bf5991e6d97f05
Config created: 2026-09-28T07:01:21Z
| Label | Value |
|---|---|
| architecture | aarch64 |
| build-date | 2026-09-28T00:46:24Z |
| com.redhat.component | ubi9-container |
| com.redhat.license_terms | https://www.redhat.com/en/about/red-hat-end-user-license-agreements#UBI |
| cpe | cpe:/a:redhat:enterprise_linux:9::appstream |
| description | The Universal Base Image is designed and engineered to be the base layer for all of your containerized applications, middleware and utilities. This base image is freely redistributable, but Red Hat only supports Red Hat technologies through subscriptions for Red Hat products. This image is maintained by Red Hat and updated regularly. |
| distribution-scope | public |
| io.buildah.version | 1.44.0 |
| io.k8s.description | The Universal Base Image is designed and engineered to be the base layer for all of your containerized applications, middleware and utilities. This base image is freely redistributable, but Red Hat only supports Red Hat technologies through subscriptions for Red Hat products. This image is maintained by Red Hat and updated regularly. |
| io.k8s.display-name | Red Hat Universal Base Image 9 |
| io.openshift.expose-services | |
| io.openshift.tags | base rhel9 |
| maintainer | Red Hat, Inc. |
| name | ubi9/ubi |
| org.opencontainers.image.base.digest | sha256:7a38d75d376f7989033e75fcaaf9fcbb090fafc58e05c2c99de76ae0ba083fdb |
| org.opencontainers.image.base.name | registry.access.redhat.com/ubi9/ubi:latest |
| org.opencontainers.image.created | 2026-09-28T07:01:21Z |
| org.opencontainers.image.description | Red Hat UBI 9 distro-packaged Podman rootful compatibility image for CI |
| org.opencontainers.image.documentation | https://github.com/Strukturpiloten/containers/tree/dfccaa9bf2505707372932363f14e40b15ed8b70/images/podman/podman-ubi-9-rootful |
| org.opencontainers.image.licenses | AGPL-3.0-only |
| org.opencontainers.image.revision | dfccaa9bf2505707372932363f14e40b15ed8b70 |
| org.opencontainers.image.source | https://github.com/Strukturpiloten/containers |
| org.opencontainers.image.title | Red Hat UBI 9 Podman rootful |
| org.opencontainers.image.url | https://github.com/Strukturpiloten/containers/pkgs/container/podman-ubi-9-rootful |
| org.opencontainers.image.vendor | Strukturpiloten OHG |
| org.opencontainers.image.version | 1.0.0 |
| release | 1790556197 |
| summary | Provides the latest release of Red Hat Universal Base Image 9. |
| url | https://catalog.redhat.com/en/search?searchType=containers |
| vcs-ref | de6cfebe750e57846d6201a17d331080b9df4a01 |
| vcs-type | git |
| vendor | Red Hat, Inc. |
| version | 9.8 |
GitHub package activity can include signatures and attestations; it does not identify when the current runnable image was published. A registry observation is a point-in-time check; mutable tags may move afterward. Use the immutable digest and maintenance evidence for an audit.