Kubernetes Operator for OpenVox - rootless container images and operator for running OpenVox (Puppet) environments on Kubernetes/OpenShift
-
Updated
Oct 9, 2026 - Go
Kubernetes Operator for OpenVox - rootless container images and operator for running OpenVox (Puppet) environments on Kubernetes/OpenShift
Security-hardened ClickHouse Server container image built on Red Hat Universal Base Image 9.
🏭 Automated Software Factory for Prometheus Exporters. Multi-arch RPM/DEB packages + OCI images. GPG-signed. Trivy-scanned. Always up-to-date. Zero-touch automation.
Security-oriented, rootless Lakekeeper Apache Iceberg REST catalog container built on Red Hat UBI 9, with a digest-verified upstream artifact lock, SBOMs, vulnerability scanning, and signed multi-architecture releases.
Canonical template for Red Hat UBI 9 application image repositories that build minimal ubi-micro OCI images from pinned inputs (UBI base @sha256 + NVR-pinned dnf packages), with SBOM/provenance, Sigstore signing evidence, OpenSCAP RHEL9 STIG scoring, and runtime hardening checks.
Red Hat UBI 9 (ubi-micro) OCI image of the Apache Guacamole guacd proxy daemon, RDP-only. Built from pinned guacamole-server source against FreeRDP, with SBOM, provenance, OpenSCAP RHEL9 STIG scoring, Trivy scan evidence, and Sigstore signing.
Red Hat UBI 9 (ubi-micro) HashiCorp Vault image built from verified upstream Vault releases with SBOM, provenance, OpenSCAP RHEL9 STIG scoring, and Sigstore signing evidence.
Security-oriented, rootless NGINX container built on Red Hat UBI 9, with hardened configurations, TLS guidance, SBOMs, vulnerability scanning, SCAP evidence, and signed multi-architecture releases.
Red Hat UBI 9 (ubi-micro) OCI image of the AWS IAM Roles Anywhere signing helper; the serve-mode sidecar that vends short-lived STS credentials for HashiCorp Vault KMS auto-unseal on self-hosted clusters. Built from source with the FIPS 140-3 Go Cryptographic Module (GOFIPS140, Go CMVP).
Dissecting Red Hat UBI 9 images and rebuilding them from scratch, with tooling to determine what a container actually needs.
Security-oriented, rootless PostgreSQL 18 container built on Red Hat UBI 9.
Hardened UBI9 Ansible execution-environment image: runs deploy playbooks on ARC in the Talos cluster and extracts per-repo secrets from HashiCorp Vault via GitHub-OIDC JWT auth. FROM ubi9-base-python, SLSA-L3, cosign keyless signing, per-repo least-privilege secret access.
Security-oriented, rootless SeaweedFS S3-compatible object storage container built on Red Hat UBI 9, with a digest-verified upstream artifact lock, fail-closed authentication guards, SBOMs, vulnerability scanning, and signed multi-architecture releases.
Red Hat UBI 9 container images: a base, plus runtimes and toolsets for Java, Python, Node.js, .NET and Go. Built reproducibly from locked RPMs, tested on amd64 and arm64, FIPS crypto policy, published to GHCR with SLSA provenance.
To associate your repository with the ubi9 topic, visit your repo's landing page and select "manage topics."