Community-maintained Ubuntu base image for the B19 fleet
  • Shell 93.1%
  • Dockerfile 4.3%
  • Makefile 1.6%
  • Jinja 1%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Damián Búho a3d9c2b7cb
All checks were successful
published / source-is-tested (push) Successful in 1s
published / fetched (push) Successful in 1s
published / projectfile-is-valid (push) Successful in 4s
published / source-is-compliant (push) Successful in 7s
published / source-is-secure (push) Successful in 8s
published / projectfile-is-ok (push) Successful in 4s
published / source-passes-lint (push) Successful in 38s
published / source-is-ok (push) Successful in 0s
published / documentation-passes-lint (push) Successful in 50s
published / documentation-is-ok (push) Successful in 0s
published / inputs-are-ok (push) Successful in 0s
published / image-is-built (noble, amd64) (push) Successful in 1m32s
published / image-is-built (resolute, amd64) (push) Successful in 1m32s
published / image-is-built (noble, riscv64) (push) Successful in 4m51s
published / image-is-built (noble, arm64) (push) Successful in 5m59s
published / image-is-built (resolute, arm64) (push) Successful in 7m5s
published / image-is-built (resolute, riscv64) (push) Successful in 8m7s
published / image-is-secure (resolute, riscv64) (push) Successful in 20s
published / image-is-secure (noble, riscv64) (push) Successful in 20s
published / image-is-secure (resolute, arm64) (push) Successful in 20s
published / image-is-secure (resolute, amd64) (push) Successful in 20s
published / secrets-ready (push) Successful in 0s
published / image-is-secure (noble, arm64) (push) Successful in 20s
published / image-is-secure (noble, amd64) (push) Successful in 20s
published / images-are-ok (push) Successful in 0s
published / container-is-ok (push) Successful in 0s
published / container-ready-to-test (push) Successful in 0s
published / container-is-verified (noble, amd64) (push) Successful in 20s
published / container-is-verified (resolute, amd64) (push) Successful in 21s
published / image-is-ready (push) Successful in 0s
published / artifacts-are-ok (push) Successful in 0s
published / ready-to-publish (push) Successful in 0s
published / publish-image (noble, dockerhub) (push) Has been skipped
published / publish-image (noble, kiota) (push) Has been skipped
published / publish-image (resolute, dockerhub) (push) Has been skipped
published / publish-image (resolute, kiota) (push) Has been skipped
published / published (push) Has been skipped
chore: sync versions
2026-09-13 14:47:20 -03:00
.compose chore: init 2026-08-15 13:07:51 -03:00
.container fix: bump mold to 2.42.1 2026-09-11 10:54:06 -03:00
.forgejo/workflows build: sync workflows 2026-09-13 12:58:45 -03:00
.github/workflows ci: regenerate workflows with actions/cache v5.1.0 2026-09-10 23:06:49 -03:00
.makefile fix: bump mold to 2.42.1 2026-09-11 10:54:06 -03:00
.scripts chore: pin ubuntu base image digests and add pinning script 2026-09-10 16:18:19 -03:00
docs chore(style): unify project naming schema 2026-09-13 14:45:05 -03:00
LICENSES chore: init 2026-08-15 13:07:51 -03:00
scaffold chore: init 2026-08-15 13:07:51 -03:00
.claudeignore chore: sorting for claudeignore 2026-09-13 12:48:14 -03:00
.containerignore chore: sorting for containerignore 2026-09-13 12:54:27 -03:00
.dockerignore chore: sorting for dockerignore 2026-09-13 12:51:11 -03:00
.gitattributes chore: sorting for attributes 2026-09-13 12:42:28 -03:00
.gitignore chore: sorting for gitignore 2026-09-13 12:45:13 -03:00
.gitmodules build: hard .gitmodules before big refactoring of m6e 2026-09-02 18:39:54 -03:00
.hadolint.yaml chore: init 2026-08-15 13:07:51 -03:00
AGENTS.md feat(tools): add b19-cache-guard for cache freshness 2026-09-09 17:30:16 -03:00
AI_POLICY.md chore(style): unify project naming schema 2026-09-13 14:45:05 -03:00
CITATION.cff chore(style): unify project naming schema 2026-09-13 14:45:05 -03:00
CLAUDE.md chore: init 2026-08-15 13:07:51 -03:00
CODE_OF_CONDUCT.md chore(style): unify project naming schema 2026-09-13 14:45:05 -03:00
CODEOWNERS chore: init 2026-08-15 13:07:51 -03:00
CONTRIBUTING.md chore(style): unify project naming schema 2026-09-13 14:45:05 -03:00
Dockerfile feat(tools): add b19-cache-guard for cache freshness 2026-09-09 17:30:16 -03:00
FEATURES.md chore: update features docs 2026-09-02 00:08:15 -03:00
lefthook.yaml chore: correct pf-ci name in comments 2026-08-30 22:26:09 -03:00
LICENSE chore: init 2026-08-15 13:07:51 -03:00
Makefile docs: move articles into docs/how-to 2026-08-16 17:47:52 -03:00
projectfile.yaml chore: sync versions 2026-09-13 14:47:20 -03:00
README.md chore(style): unify project naming schema 2026-09-13 14:45:05 -03:00
SECURITY.md chore(style): unify project naming schema 2026-09-13 14:45:05 -03:00
SUPPORT.md chore(style): unify project naming schema 2026-09-13 14:45:05 -03:00

Español · Українська

B19 / Ubuntu

Community-maintained Ubuntu base image for the B19 fleet

Stand with Ukraine Projectfile inside License Commit style Workflow Versioning PRs welcome Citation REUSE compliance

Project status Last commit on kiota.ch

Publish pipeline on kiota.ch Vulnerability audit on kiota.ch Dependency freshness on kiota.ch Analysis sweep on kiota.ch

Features

  • Persistent APT cache across builds
  • Service process management with log routing (b19-exec)
  • Cached artifact downloads with integrity verification
  • Timed command execution with failure reporting (b19-run)
  • Run-once initialization (bootstrap.d)
  • Modular build hooks (build.d)
  • Automatic CPU count detection
  • Declarative dependency management (b19-deps)
  • Pluggable startup system (entrypoint.d)
  • Feature toggles for all subsystems
  • Built-in health monitoring (healthcheck.d)
  • Multilingual shell output (b19-i18n)
  • Image lineage tracking
  • Structured, level-filtered logging (b19-log)
  • Non-root container by default
  • Air-gapped / offline build and runtime support
  • Runtime overlay injection
  • Reproducible base image (pinned by digest)
  • Port validation
  • Unified lifecycle runner family
  • Docker secrets auto-loading
  • Interactive shell hooks
  • Graceful signal handling
  • Jinja2 configuration templates (minijinja-cli)
  • Built-in test framework (test.d)
  • Pre-installed utility tools
  • XDG Base Directory paths

See FEATURES.md for the full list.

What this provides

  • Container image ghcr.io/damian-buho/b19/ubuntu/resolute:latest
  • Container image ghcr.io/damian-buho/b19/ubuntu/noble:latest
  • Container image docker.io/damianbuho/b19-ubuntu-resolute:latest
  • Container image docker.io/damianbuho/b19-ubuntu-noble:latest

Supported platforms

  • linux/amd64
  • linux/arm64
  • linux/riscv64

Installation

Pull the published container image:

Pull from GHCR

docker pull ghcr.io/damian-buho/b19/ubuntu/resolute:latest
docker pull ghcr.io/damian-buho/b19/ubuntu/noble:latest

Pull from DockerHub

docker pull docker.io/damianbuho/b19-ubuntu-resolute:latest
docker pull docker.io/damianbuho/b19-ubuntu-noble:latest

Stable releases also publish X.Y.Z, X.Y and X tags — pull the precision you want to pin.

If the registries above are unreachable, pull from the origin instead:

Pull from Kiota

docker pull kiota.ch/b19/ubuntu/resolute:latest
docker pull kiota.ch/b19/ubuntu/noble:latest

Usage

Build on top of this image:

From GHCR

FROM ghcr.io/damian-buho/b19/ubuntu/resolute:latest
FROM ghcr.io/damian-buho/b19/ubuntu/noble:latest

From DockerHub

FROM docker.io/damianbuho/b19-ubuntu-resolute:latest
FROM docker.io/damianbuho/b19-ubuntu-noble:latest

For the recommended multi-stage pattern and the build-hook system (build.d), scaffold a derivative with b19/scripts/scaffold.sh from m6e/b19.

Building

Run make with no arguments for the default target; run make help to list every target.

For the local dev loop, make dev-container brings up the dev-container.

Pipeline entry points:

  • make analyze — Run the heavy analysis sweep (mutation testing, benchmarks)
  • make audited — Re-scan the pinned dependencies and published artifacts for new vulnerabilities
  • make check-outdated — Report every pinned dependency that lags upstream
  • make ready-to-publish — Run the pseudo-CI pipeline locally — build, test and scan, without publishing

Documentation

Policies

License

This project is licensed under MIT — see the LICENSE file for details.