Sign inSign up

readystack/consul

By readystack

•Updated about 6 hours ago

Image
0

1.6K

readystack/consul repository overview

⁠Consul

Signed: cosign SBOM: SPDX attached Provenance: SLSA v0.2

readystack/consul:v1.16.4-CE-ubuntu24.04-r1

A cosign-signed build of github.com/hashicorp/consul v1.16.4 (MPL-2.0 — LAST open-source release before BUSL), built clean-room from official upstream source by ReadyStack⁠.

⁠What you get

Signature, user and attestations below were measured on the published digest sha256:7520792e60b80f31f55a5d7e828de5f7d87453fed0ba3ea2a14ab643b054d739 on 2026-10-09.

  • Scan scores — we scan every image we publish every day (an SBOM made with syft, vulnerabilities matched with grype, scored with ce.rodeo's published rubric) and record each scan with how its score was derived. This release's first and latest scan: https://readystack.dev/products.html#consul⁠
  • ReadyStack release check — not passed at release on 2026-07-12; this release is sold below that bar, and why is on https://readystack.dev/queue⁠.
  • Signed — cosign signature by the ReadyStack release key (fingerprint 04daa92344a52dbc) on this release's index digest sha256:7520792e60b80f31f55a5d7e828de5f7d87453fed0ba3ea2a14ab643b054d739; verify with cosign verify --key https://readystack.dev/keys/cosign.pub readystack/consul:v1.16.4-CE-ubuntu24.04-r1.
  • Attestations — An SPDX SBOM and SLSA v0.2 build provenance are attached to this digest (Docker Scout now requires SLSA v1).
  • Runs as a non-root user (consul).
  • Built from source by ReadyStack.

⁠Which tag should I pull?

This image follows the ReadyStack release-tag convention:

  • The current release is v1.16.4-CE-ubuntu24.04-r1 — the release on sale at readystack.dev. Release tags use the pattern <upstream-version>-CE-<base-os>-r<N>; the current one is signed, attested (SBOM + provenance), and is provided under the ReadyStack Agreement⁠.

  • Earlier release tags (an older version or revision in the same pattern) are superseded. They stay pullable so existing deployments can pin them, but they are no longer re-graded, and fixes appear only in newer releases: move to the current release. For a superseded release's build kit, ask support.

  • Any tag beginning with internal- is an engineering-pipeline artifact published for build observability. It is unsupported, may change or disappear without notice, and must not be used in production.

# ✓ current release
docker pull readystack/consul:v1.16.4-CE-ubuntu24.04-r1

# ✗ unsupported (do not pull)
docker pull readystack/consul:internal-...

This release is signed; verify it with cosign verify --key https://readystack.dev/keys/cosign.pub readystack/consul:v1.16.4-CE-ubuntu24.04-r1 (the signature is recorded in the public Sigstore transparency log). Support: [email protected]⁠, as set out in the ReadyStack Agreement⁠.

⁠Deployment

Single container, single static Go binary (CGO-free), foreground consul agent. Consul IS its own datastore (embedded raft + boltdb under -data-dir). Service discovery + health checking + KV store + DNS (:8600) + HTTP API (:8500). NO SQL DB, NO sidecar. Web UI is NOT bundled (source-only rebuild) — the API/CLI/DNS are fully functional.

docker run -d readystack/consul:v1.16.4-CE-ubuntu24.04-r1

⁠The full ReadyStack Agent-ready Archive

The complete --network=none build kit for this image — plus admin/DB/API handbooks, the build's validation records, and its build provenance records — is at readystack.dev/buy.html⁠.

— ReadyStack · readystack.dev

Tag summary

Content type

Image

Digest

sha256:2e3653def…

Size

72.5 MB

Last updated

about 6 hours ago

docker pull readystack/consul:internal-v1.16.4-CE-ubuntu24.04-r1-chain517