Red Hat UBI 9 Podman rootless¶
Red Hat UBI 9 distro-packaged Podman rootless compatibility image for CI
Image: ghcr.io/strukturpiloten/podman-ubi-9-rootless
Declared image version: v1.0.0
Family: Podman
Architecture: amd64, arm64
Inner mode: rootless
Declared runtime base: registry.access.redhat.com/ubi9/ubi:latest@sha256:7a38d75d376f7989033e75fcaaf9fcbb090fafc58e05c2c99de76ae0ba083fdb
Image source and metadata · GHCR package · Detailed guide
Choose and inspect¶
The distribution selects the installed engine package at build time. Inspect the published image's component manifest or SBOM for its exact revision.
Declared tags: v1.0.0, v1.0, v1, main, latest. These are publication policy aliases, not proof that any tag exists in GHCR. Even the exact SemVer tag can move after a reviewed rebuild.
Registry status: observed; checked at 2026-09-28T10:17:35.030381+00:00.
Observed latest index digest: sha256:74e0a03f823105c744b2f4ba793cc70da30b16cafbb683bc5430018d7b56857e.
Pull the observed immutable artifact:
podman pull ghcr.io/strukturpiloten/podman-ubi-9-rootless@sha256:74e0a03f823105c744b2f4ba793cc70da30b16cafbb683bc5430018d7b56857e
A CLI check can run without a nested workload:
podman run --rm ghcr.io/strukturpiloten/podman-ubi-9-rootless:v1.0.0 podman --version
Nested workloads require the profile-specific outer privilege and device setup in the detailed guide. Some rootless distro profiles intentionally omit nested workload checks.
Support and runtime contract¶
Lifecycle: maintained; admission: isolated-test; review after: 2026-12-31.
Repository rebuilds refresh distribution packages; vendor support determines installed Podman security maintenance.
Declared runtime profiles: podman. Declared test settings are in the metadata source. Admission is policy, not evidence of a passed test.
Declared runtime test contract:
{
"podman": {
"mode": "rootless",
"nestedRuntime": false,
"outerPrivilege": "privileged"
}
}
Registry aliases and history¶
Aliases resolved to the observed current digest: latest, main, v1, v1.0, v1.0.0.
Listed without digest resolution: run-32739402388-1-sha-f0259a080e8a49be43358fc00c4cac89528d4954, run-32808812826-1-sha-34e7193852a44ffade6d186f9c664368856ccb6c, run-32918078087-1-sha-36f12397c825a765d498654657c2cfa99ae413c9, run-32930106309-1-sha-36f12397c825a765d498654657c2cfa99ae413c9, run-33084138768-1-sha-501915f06c2f36c0254a08ad5c70ae9ec14c9a64, run-33304142817-1-sha-30faee7ada474e455a43b7abf2d90bbf24977056, run-33369549209-1-sha-8ba6168227ce22ebd58ab732a665d717cbcd54ab, run-33380856986-1-sha-699c4fd9be1a508c33387aa87e6211de92d6e480, run-33429018056-1-sha-2c8f273f70857b8fd2ecfdb600c9a87f48a584fd, run-33499424710-1-sha-34372bb39b2bc633ce194e28304eef808e1959ca, run-34389535369-1-sha-852114c75ac8d7d655e5f4873e74b730f5b6391b, run-34798102526-1-sha-57d3540f7f8edd558e31808e369b52df68a99d71, run-35042287292-1-sha-9ced62eea6e4976f8d6fc2aa1f60845cd228b22a, run-35153643596-1-sha-f6e29816396a7a02e339d83486983d473a04175b, run-35269754784-1-sha-ec6d3de9caf2eb601535e4f004d24e66c9e40294, run-35725276402-1-sha-d9facb12bab3b3e05c0365835d6525f1617d67e4, run-36320630115-1-sha-73e79fd9ca8cffa73bd60d360c8db2929271d48a, run-36346260768-1-sha-0b136a13a8bb612d91960ae5d07e72f449c89ec1, run-36389409256-1-sha-dfccaa9bf2505707372932363f14e40b15ed8b70, sha-0b136a13a8bb612d91960ae5d07e72f449c89ec1, sha-2c8f273f70857b8fd2ecfdb600c9a87f48a584fd, sha-34372bb39b2bc633ce194e28304eef808e1959ca, sha-36f12397c825a765d498654657c2cfa99ae413c9, sha-57d3540f7f8edd558e31808e369b52df68a99d71, sha-73e79fd9ca8cffa73bd60d360c8db2929271d48a, sha-852114c75ac8d7d655e5f4873e74b730f5b6391b, sha-8ba6168227ce22ebd58ab732a665d717cbcd54ab, sha-9ced62eea6e4976f8d6fc2aa1f60845cd228b22a, sha-d9facb12bab3b3e05c0365835d6525f1617d67e4, sha-dfccaa9bf2505707372932363f14e40b15ed8b70, sha-ec6d3de9caf2eb601535e4f004d24e66c9e40294, sha-f0259a080e8a49be43358fc00c4cac89528d4954, sha-f6e29816396a7a02e339d83486983d473a04175b, sha256-04681bfcac3ea8a751f4ace6035b603e9b9f262d32d61d440829cdf5e249c360, sha256-0670c65993323ad32cddcb4098472e0fcc18da7c4d95bb338ef8cccfe66f925a, sha256-08aad592d7135f52de730d44870bd7174eb5ece75b724c8f63d92cb419dc1b8b, sha256-0c683742c2be96e3996c8699e0cb2730eed4bc5f92414f40231dbe2940ff007c, sha256-109f2f9b016349d76ea202e73e3508a00ed81e577d58d1a63816fa5a8646cc96, sha256-10ac36f31a2c433885f40a757685897c1e16bc7f4da8705aced115068fc43c52, sha256-112f21c152728b77ce61d9b06931cffe69168a608b3ac509fdc3050e3fc5a9df, sha256-15c2acbb270daae8473da31d6db38e3c82a729fdf5144682950cdaa09a48b7e0, sha256-16b362a9fc69a8a59d2bfaf786d8cf0579291a34f5e5e6020500d99769243ba5, sha256-1b8cc859ce8ad7e38e0cd66f7726094ee32da67427ccb3b6e1e0832a8eaaa535, sha256-1eea190859f4fb1274f93c5d041db17f62ace04c30ae4336ed59400d06ab8622, sha256-1eee51aba5079c4666d47569d4fb510e860e1b6ab13504b31bccc8ad7d81305c, sha256-20239f34a886192942f81c33164cd2ea7c79a4fe6f6affc9ff6bdc2adb99a536, sha256-20aa3f2028e46ff79539f2409f30f45c8af385344b07bdef6ded5d032cd99513, sha256-2a46dcfebeaad08b24713b881a53e90e18d46db3c4faa7e0d029db957f74b5f8, sha256-2cf591b10b32707eab4f5b8df5efd024f2a471c25d352399ce842aa531a2330c, sha256-3e12de9eac650651139462e2b67e42e0f67e1f02fc347f2986ba047161649dd8, sha256-40f72e3db66c2264d327548d92ee4bc397190e361bb6f0b28313ffe4eca6e48c, sha256-4303741a9ff04486af11948b817302dba7b94fb49db78765a69913d606054762, sha256-44c30f7a033d93dd5b4efee27d2106a38375015bc16ab376dcaffe1c648efb50, sha256-50d58843f9ff6f9915d19c40bd61b76a25c38346abc81e348daa094090c1963d, sha256-545df0712e2aa884a42d201b86b0adf97bb2c381edea39b10266f3e5999b84d3, sha256-54953ea88a9831a49bce717b7e74586ea8a40d39e3164d437efa72c55565ef43, sha256-5ad9156a53392f3d0a28bb7db64304cecdf56d2cefa5784d44b7ed26363efb38, sha256-5b5107e57f73005818ca547b137d9e5bd5769a97c2a61b6dbfd2e464c8d2273b, sha256-5fa790aa177b0e846a4b273d75be33525b3ee28cccd8b8fdbdc4405ff60445f7, sha256-6ab79be7094ac3c90c828e0b99b01fd247565b0e0c6e6a019614b9d3daa62a8d, sha256-74e0a03f823105c744b2f4ba793cc70da30b16cafbb683bc5430018d7b56857e, sha256-7585028d4f70c956e1b6f7ecbbd4b901e5cb5712924f075709b60b0822ee1ea4, sha256-76e03cd9617ecc5c0ab1ccb1a09592e280623fa52280a1dd3b4ac48141b37184, sha256-7929f3f448ce95f585e225be6953d0738a8694a71324e5943180861e9be9213f, sha256-7d8666f03eee7ca5a49c796794764c1c0c1628d02b5462ac4ad194a6742049e9, sha256-8510045d1bdaa6f2d50e6db8f89edb9252953d4f7eaa03f6344a6c90b2d5ed5c, sha256-880e6e1e0d2923d9e4092b1d5ea81b8a184ba24a50bce98a21bd0513194b4bef, sha256-89b8ff0c0ee65f7d053bb25c5be904acda3a31a06efeead997a8fbf5ae6d1652, sha256-8a83fb5791a730c26fb4dc4c3ffb27bb42053cbfee051f65e7facacb850f44c3, sha256-8f28efa3d6418365677432ec8718e2cd8f34fa9b5173cf412b236815a252bda9, sha256-902528055341282928adbd647438bb4ab9dd97fd8e04a64d4b5aadc235cab438, sha256-92b16c29226859f58680ff2dda71fcc5d09526f220b72e1630549ea321b2b87d, sha256-93d0d5d2d388424b4b6676b5389094706d9d4cccb5a90e341641d1f53ce74312, sha256-96c6aa2c9545947c239944ba3e7463b1c8dab552a694c677f1e2f4838b425c2e, sha256-9993cd7bf4d5a54dc5c999b176ed4afd5ac62d8b8b305f8900c5356c819fec3f, sha256-9b13f53323aa4ebd0bce4019d5f3122ac0b75122ac4cbc1fee3c5103fe9ae71b, sha256-a5c9a451228d694c6976c5f4e35edaeb623c7fe84c91b3b8bcec95590c9ebcf6, sha256-a6e12fa88e84aafd06e1826cbe445377ed4758cc2b49c8e323d9a46f61cd8ae5, sha256-aabb53ced7d73cf7fc3b3aa10ecd05586f40953b280c713378f766526df9013f, sha256-ba1f1c14635773ff3f9c1fd2108258368fc5176b5d7087cf5cbad9224f9bdf09, sha256-c6c06ce87937cdf42845e44a1274526f332a4e7576a1c96ad19626cf5ac733c7, sha256-c9d36ffd26fe4f9d500a4e84fccd45592cc9b0f11dd4d3e0d7511be2f36ea52a, sha256-dad33b42a054f78382916ca2b789e88886fc4801165a8a9f3b84afdaf7e7e2e1, sha256-de26996f4ef00f51fbc56c366624cac11070b8793927bc46d8bbf76a0ed7dd2a, sha256-ee6f69b313a6b6b019ee0f38c8fd4325f538bc7ef0d74f7484b2b5e370f9dac1, sha256-f0127d24b34121d4be88172afa9770225af7128bd9164ef913b6bc0a0d8dba0f, sha256-f2735cac4e3c3f08db4df0bd6a5f622949d113d2c21a140cd517db56f9c4abdb, sha256-f38a9e58ef88f995ee33c83da311c8004f72dcac4e56727f033fc4273281f4f6, sha256-f7d3c761d308874062e1b064ea50af11744b9415584fc1105ecdea2fc8026ebc, sha256-fc9ec6ee76f5b433cdeaac55a857e8183649b248b8c16acba1869a759053004e.
Evidence and timestamps¶
| Field | Observed value |
|---|---|
| Source revision | dfccaa9bf2505707372932363f14e40b15ed8b70 |
| Build succeeded | 2026-09-28T07:05:53.124793+00:00 |
| Published | unknown |
| Registry checked | 2026-09-28T10:17:35.030381+00:00 |
| Evidence | verified |
| Compared with current declarations | matched |
Matching release asset verified the build record and per-architecture runtime and scan evidence. Signature and provenance remain unverified in this snapshot.
Maintenance release · Evidence asset
amd64 OCI config and labels
Manifest: sha256:7929f3f448ce95f585e225be6953d0738a8694a71324e5943180861e9be9213f
Config: sha256:0345362510feb62ff43647b73ac254ceede6f27e86eade5a83d1fbf44c187255
Config created: 2026-09-28T07:01:21Z
| Label | Value |
|---|---|
| architecture | x86_64 |
| build-date | 2026-09-28T00:44:34Z |
| com.redhat.component | ubi9-container |
| com.redhat.license_terms | https://www.redhat.com/en/about/red-hat-end-user-license-agreements#UBI |
| cpe | cpe:/a:redhat:enterprise_linux:9::appstream |
| description | The Universal Base Image is designed and engineered to be the base layer for all of your containerized applications, middleware and utilities. This base image is freely redistributable, but Red Hat only supports Red Hat technologies through subscriptions for Red Hat products. This image is maintained by Red Hat and updated regularly. |
| distribution-scope | public |
| io.buildah.version | 1.44.0 |
| io.k8s.description | The Universal Base Image is designed and engineered to be the base layer for all of your containerized applications, middleware and utilities. This base image is freely redistributable, but Red Hat only supports Red Hat technologies through subscriptions for Red Hat products. This image is maintained by Red Hat and updated regularly. |
| io.k8s.display-name | Red Hat Universal Base Image 9 |
| io.openshift.expose-services | |
| io.openshift.tags | base rhel9 |
| maintainer | Red Hat, Inc. |
| name | ubi9/ubi |
| org.opencontainers.image.base.digest | sha256:7a38d75d376f7989033e75fcaaf9fcbb090fafc58e05c2c99de76ae0ba083fdb |
| org.opencontainers.image.base.name | registry.access.redhat.com/ubi9/ubi:latest |
| org.opencontainers.image.created | 2026-09-28T07:01:21Z |
| org.opencontainers.image.description | Red Hat UBI 9 distro-packaged Podman rootless compatibility image for CI |
| org.opencontainers.image.documentation | https://github.com/Strukturpiloten/containers/tree/dfccaa9bf2505707372932363f14e40b15ed8b70/images/podman/podman-ubi-9-rootless |
| org.opencontainers.image.licenses | AGPL-3.0-only |
| org.opencontainers.image.revision | dfccaa9bf2505707372932363f14e40b15ed8b70 |
| org.opencontainers.image.source | https://github.com/Strukturpiloten/containers |
| org.opencontainers.image.title | Red Hat UBI 9 Podman rootless |
| org.opencontainers.image.url | https://github.com/Strukturpiloten/containers/pkgs/container/podman-ubi-9-rootless |
| org.opencontainers.image.vendor | Strukturpiloten OHG |
| org.opencontainers.image.version | 1.0.0 |
| release | 1790556197 |
| summary | Provides the latest release of Red Hat Universal Base Image 9. |
| url | https://catalog.redhat.com/en/search?searchType=containers |
| vcs-ref | de6cfebe750e57846d6201a17d331080b9df4a01 |
| vcs-type | git |
| vendor | Red Hat, Inc. |
| version | 9.8 |
arm64 OCI config and labels
Manifest: sha256:16b362a9fc69a8a59d2bfaf786d8cf0579291a34f5e5e6020500d99769243ba5
Config: sha256:219aa6d73bf403a0630318bca7b687a396e7f92d2b7fd6cb96657dc138f53145
Config created: 2026-09-28T07:01:21Z
| Label | Value |
|---|---|
| architecture | aarch64 |
| build-date | 2026-09-28T00:46:24Z |
| com.redhat.component | ubi9-container |
| com.redhat.license_terms | https://www.redhat.com/en/about/red-hat-end-user-license-agreements#UBI |
| cpe | cpe:/a:redhat:enterprise_linux:9::appstream |
| description | The Universal Base Image is designed and engineered to be the base layer for all of your containerized applications, middleware and utilities. This base image is freely redistributable, but Red Hat only supports Red Hat technologies through subscriptions for Red Hat products. This image is maintained by Red Hat and updated regularly. |
| distribution-scope | public |
| io.buildah.version | 1.44.0 |
| io.k8s.description | The Universal Base Image is designed and engineered to be the base layer for all of your containerized applications, middleware and utilities. This base image is freely redistributable, but Red Hat only supports Red Hat technologies through subscriptions for Red Hat products. This image is maintained by Red Hat and updated regularly. |
| io.k8s.display-name | Red Hat Universal Base Image 9 |
| io.openshift.expose-services | |
| io.openshift.tags | base rhel9 |
| maintainer | Red Hat, Inc. |
| name | ubi9/ubi |
| org.opencontainers.image.base.digest | sha256:7a38d75d376f7989033e75fcaaf9fcbb090fafc58e05c2c99de76ae0ba083fdb |
| org.opencontainers.image.base.name | registry.access.redhat.com/ubi9/ubi:latest |
| org.opencontainers.image.created | 2026-09-28T07:01:21Z |
| org.opencontainers.image.description | Red Hat UBI 9 distro-packaged Podman rootless compatibility image for CI |
| org.opencontainers.image.documentation | https://github.com/Strukturpiloten/containers/tree/dfccaa9bf2505707372932363f14e40b15ed8b70/images/podman/podman-ubi-9-rootless |
| org.opencontainers.image.licenses | AGPL-3.0-only |
| org.opencontainers.image.revision | dfccaa9bf2505707372932363f14e40b15ed8b70 |
| org.opencontainers.image.source | https://github.com/Strukturpiloten/containers |
| org.opencontainers.image.title | Red Hat UBI 9 Podman rootless |
| org.opencontainers.image.url | https://github.com/Strukturpiloten/containers/pkgs/container/podman-ubi-9-rootless |
| org.opencontainers.image.vendor | Strukturpiloten OHG |
| org.opencontainers.image.version | 1.0.0 |
| release | 1790556197 |
| summary | Provides the latest release of Red Hat Universal Base Image 9. |
| url | https://catalog.redhat.com/en/search?searchType=containers |
| vcs-ref | de6cfebe750e57846d6201a17d331080b9df4a01 |
| vcs-type | git |
| vendor | Red Hat, Inc. |
| version | 9.8 |
GitHub package activity can include signatures and attestations; it does not identify when the current runnable image was published. A registry observation is a point-in-time check; mutable tags may move afterward. Use the immutable digest and maintenance evidence for an audit.