Enterprise CloudOps Automation Toolkit - Multi-variant DevContainer
10K+
A non-root Python image family for CloudOps automation, notebooks and the runbooks CLI.
CloudOps reports and automation need the same Python, AWS CLI and runbooks CLI on every laptop and CI runner. One image family, pinned by digest, gives each job exactly one tested set, from a lean read-only CLI to a full notebook devcontainer.
| Tag | Dockerfile stage | Use it for | Contents |
|---|---|---|---|
cli | cli | Read-only CloudOps reports in CI and in the delivery plugin | runbooks CLI (hash-locked), AWS CLI v2, gh. No vendor coding CLI, no model SDKs |
prod | prod | AWS Lambda or container runtime base; the application brings its own venv | Python, dumb-init, non-root user |
core | core | Minimal dev shell | Python, uv, git, jq, task, starship, and the core Python libraries |
full / latest | latest | Devcontainer, notebooks and docs | core plus AWS CLI v2, Azure CLI, Ansible, Node.js, gh, JupyterLab, MkDocs, Vizro and model SDKs |
The runbooks CLI groups finops, inventory, org, cfat, security, cert and vpc run read-only.
operate and remediation default to a dry run and change nothing without --apply; automation never passes --apply.
Image version: 2.11.0 (from .devcontainer/runbooks/VERSION).
| Tool | cli | prod | core | full | Version |
|---|---|---|---|---|---|
| runbooks CLI | ✓ | 1.5.10 | |||
| Python (runbooks CLI) | ✓ | 3.13 | |||
| Python | ✓ | ✓ | ✓ | 3.14 | |
| uv | ✓ | ✓ | 0.12.18 | ||
| GitHub CLI (gh) | ✓ | ✓ | 2.101.0 | ||
| AWS CLI v2 | ✓ | ✓ | Wolfi |
Base image (every target): cgr.dev/chainguard/wolfi-base:latest@sha256:1d95114038f76513a9ace6fca107d5582b08c65981f81f61cb56bf7fd2ef216d
Wolfi = the signed Wolfi package, updated weekly. The runbooks CLI is installed from a hash-locked lock file.
# runbooks CLI, read-only, as your own user
docker run --rm --read-only --tmpfs /tmp --user "$(id -u):$(id -g)" -e HOME=/tmp \
nnthanh101/runbooks:cli runbooks --version
With your AWS sign-in (the config file and the SSO token cache are mounted read-only; no stored keys):
docker run --rm --read-only --tmpfs /tmp --user "$(id -u):$(id -g)" -e HOME=/tmp \
-v "${AWS_CONFIG_FILE:-$HOME/.aws/config}:/tmp/.aws/config:ro" -v "$HOME/.aws/sso:/tmp/.aws/sso:ro" \
-e AWS_CONFIG_FILE=/tmp/.aws/config -e AWS_SHARED_CREDENTIALS_FILE=/dev/null -e AWS_PROFILE \
nnthanh101/runbooks:cli runbooks --help
Full devcontainer (interactive): docker run -it --rm -v "$PWD:/workspace" nnthanh101/runbooks:full.
Pin what you tested: docker buildx imagetools inspect nnthanh101/runbooks:cli prints the digest.
GitHub Actions job:
jobs:
report:
runs-on: ubuntu-latest
container:
image: nnthanh101/runbooks:<version>-cli@sha256:<digest>
options: --user 0
steps:
- uses: actions/checkout@<commit-sha> # pin actions by commit
- run: runbooks finops --help
cgr.dev/chainguard/wolfi-base, pinned by digest in versions.env and the Dockerfile.cli venv installs from requirements.cli.txt, wheels only, every file checked against its hash.os (UID 11111) in every tag. No key material in any image..github/workflows/docker-release-runbooks.yml builds linux/amd64 and linux/arm64, attaches provenance (mode=max) and an SBOM, and signs each digest keylessly with cosign. A digest published from a workstation with task docker:publish passes the same gate but is not signed; pin a signed digest for releases.trivyignore.yaml with an owner and an expiry date.core and full tags still install the vendor coding CLI with its installer script. The cli tag does not.| Port | Service |
|---|---|
| 8888 | JupyterLab (jupyter.sh) |
| 8000 | MkDocs serve (docs.sh) |
| 8050 | Vizro / Dash (python -m vizro) |
Content type
Image
Digest
sha256:013024fe5…
Size
894.7 MB
Last updated
about 1 hour ago
docker pull nnthanh101/runbooks