🏭 Automated Software Factory for Prometheus Exporters. Multi-arch RPM/DEB packages + OCI images. GPG-signed. Trivy-scanned. Always up-to-date. Zero-touch automation.
-
Updated
Oct 9, 2026 - Python
🏭 Automated Software Factory for Prometheus Exporters. Multi-arch RPM/DEB packages + OCI images. GPG-signed. Trivy-scanned. Always up-to-date. Zero-touch automation.
Canonical template for Red Hat UBI 9 application image repositories that build minimal ubi-micro OCI images from pinned inputs (UBI base @sha256 + NVR-pinned dnf packages), with SBOM/provenance, Sigstore signing evidence, OpenSCAP RHEL9 STIG scoring, and runtime hardening checks.
Security-oriented, rootless NGINX container built on Red Hat UBI 9, with hardened configurations, TLS guidance, SBOMs, vulnerability scanning, SCAP evidence, and signed multi-architecture releases.
Red Hat UBI 9 (ubi-micro) OCI image of the AWS IAM Roles Anywhere signing helper; the serve-mode sidecar that vends short-lived STS credentials for HashiCorp Vault KMS auto-unseal on self-hosted clusters. Built from source with the FIPS 140-3 Go Cryptographic Module (GOFIPS140, Go CMVP).
Red Hat UBI 9 (ubi-micro) HashiCorp Vault image built from verified upstream Vault releases with SBOM, provenance, OpenSCAP RHEL9 STIG scoring, and Sigstore signing evidence.
Dissecting Red Hat UBI 9 images and rebuilding them from scratch, with tooling to determine what a container actually needs.
Hardened UBI9 Ansible execution-environment image: runs deploy playbooks on ARC in the Talos cluster and extracts per-repo secrets from HashiCorp Vault via GitHub-OIDC JWT auth. FROM ubi9-base-python, SLSA-L3, cosign keyless signing, per-repo least-privilege secret access.
To associate your repository with the ubi9 topic, visit your repo's landing page and select "manage topics."