Sign inSign up

nnthanh101/runbooks

By nnthanh101

•Updated 9 minutes ago

Enterprise CloudOps Automation Toolkit - Multi-variant DevContainer

Image
Languages & frameworks
Integration & delivery
Data science
0

10K+

nnthanh101/runbooks repository overview

⁠nnthanh101/runbooks

A non-root Python image family for CloudOps automation, notebooks and the runbooks CLI.


⁠Why this image exists

CloudOps reports and automation need the same Python, AWS CLI and runbooks CLI on every laptop and CI runner. One image family, pinned by digest, gives each job exactly one tested set, from a lean read-only CLI to a full notebook devcontainer.


⁠Choose a tag

TagDockerfile stageUse it forContents
clicliRead-only CloudOps reports in CI and in the delivery pluginrunbooks CLI (hash-locked), AWS CLI v2, gh. No vendor coding CLI, no model SDKs
prodprodAWS Lambda or container runtime base; the application brings its own venvPython, dumb-init, non-root user
corecoreMinimal dev shellPython, uv, git, jq, task, starship, and the core Python libraries
full / latestlatestDevcontainer, notebooks and docscore plus AWS CLI v2, Azure CLI, Ansible, Node.js, gh, JupyterLab, MkDocs, Vizro and model SDKs

The runbooks CLI groups finops, inventory, org, cfat, security, cert and vpc run read-only. operate and remediation default to a dry run and change nothing without --apply; automation never passes --apply.


⁠What is included

Image version: 2.11.0 (from .devcontainer/runbooks/VERSION).

ToolcliprodcorefullVersion
runbooks CLI✓1.5.10
Python (runbooks CLI)✓3.13
Python✓✓✓3.14
uv✓✓0.12.18
GitHub CLI (gh)✓✓2.101.0
AWS CLI v2✓✓Wolfi

Base image (every target): cgr.dev/chainguard/wolfi-base:latest@sha256:1d95114038f76513a9ace6fca107d5582b08c65981f81f61cb56bf7fd2ef216d

Wolfi = the signed Wolfi package, updated weekly. The runbooks CLI is installed from a hash-locked lock file.


⁠Get started

# runbooks CLI, read-only, as your own user
docker run --rm --read-only --tmpfs /tmp --user "$(id -u):$(id -g)" -e HOME=/tmp \
  nnthanh101/runbooks:cli runbooks --version

With your AWS sign-in (the config file and the SSO token cache are mounted read-only; no stored keys):

docker run --rm --read-only --tmpfs /tmp --user "$(id -u):$(id -g)" -e HOME=/tmp \
  -v "${AWS_CONFIG_FILE:-$HOME/.aws/config}:/tmp/.aws/config:ro" -v "$HOME/.aws/sso:/tmp/.aws/sso:ro" \
  -e AWS_CONFIG_FILE=/tmp/.aws/config -e AWS_SHARED_CREDENTIALS_FILE=/dev/null -e AWS_PROFILE \
  nnthanh101/runbooks:cli runbooks --help

Full devcontainer (interactive): docker run -it --rm -v "$PWD:/workspace" nnthanh101/runbooks:full. Pin what you tested: docker buildx imagetools inspect nnthanh101/runbooks:cli prints the digest.

GitHub Actions job:

jobs:
  report:
    runs-on: ubuntu-latest
    container:
      image: nnthanh101/runbooks:<version>-cli@sha256:<digest>
      options: --user 0
    steps:
      - uses: actions/checkout@<commit-sha> # pin actions by commit
      - run: runbooks finops --help

⁠Security

  • Base: cgr.dev/chainguard/wolfi-base, pinned by digest in versions.env and the Dockerfile.
  • No third-party registries: uv comes from the Wolfi package inside the pinned base.
  • Hash-locked CLI: the cli venv installs from requirements.cli.txt, wheels only, every file checked against its hash.
  • Verified downloads: gh is checked against its published SHA256 list.
  • Non-root: user os (UID 11111) in every tag. No key material in any image.
  • Signed by CI: .github/workflows/docker-release-runbooks.yml builds linux/amd64 and linux/arm64, attaches provenance (mode=max) and an SBOM, and signs each digest keylessly with cosign. A digest published from a workstation with task docker:publish passes the same gate but is not signed; pin a signed digest for releases.
  • Blocking scan: Trivy stops a release on any fixable HIGH or CRITICAL finding. Accepted exceptions live in trivyignore.yaml with an owner and an expiry date.
  • Weekly rebuild: Wolfi package fixes reach the images every Monday.
  • Known gap: the core and full tags still install the vendor coding CLI with its installer script. The cli tag does not.

⁠Exposed ports (full)

PortService
8888JupyterLab (jupyter.sh)
8000MkDocs serve (docs.sh)
8050Vizro / Dash (python -m vizro)

Tag summary

Content type

Image

Digest

sha256:013024fe5…

Size

894.7 MB

Last updated

about 1 hour ago

docker pull nnthanh101/runbooks