Sign inSign up

readystack/etcd

By readystack

•Updated 1 day ago

Image
0

1.5K

readystack/etcd repository overview

⁠etcd

Signed: cosign SBOM: SPDX attached Provenance: SLSA v0.2

readystack/etcd:v3.7.2-CE-ubuntu24.04-r1

A cosign-signed build of github.com/etcd-io/etcd v3.7.2 (Apache-2.0), built clean-room from official upstream source by ReadyStack⁠.

⁠What you get

Signature, user, attestations and grade below were measured on the published digest sha256:a0679768b769b8761f566c510de545c97c23c0218c14afebc348765d39df7ee8 on 2026-10-07.

  • Docker Scout grade D (44%) on 2026-10-07 — 4 of Docker's 7 default policies fail:
    • 1 fixable critical/high vulnerability (1 high) in 1 package, e.g. openssl 3.0.13-0ubuntu3.15 (fixed in 3.0.13-0ubuntu3.16).
    • Provenance attestation is SLSA v0.2; Docker Scout now requires v1.
    • Base image docker.io/library/ubuntu:24.04 has been updated since this image was built (built on sha256:023f8a753c22…, the tag now points to sha256:534baea6a22c…).
    • 83 packages carry copyleft licences (GPL, LGPL, MPL), all of them operating-system packages.
    • Measured with Docker Scout CLI 1.26.0 (docker scout policy, Docker's default policies); re-checked daily at https://readystack.dev/queue⁠.
  • ReadyStack release check — passed at release on 2026-09-27: no fixable critical or high vulnerability (Docker Scout and OSV), a non-root user, SBOM and provenance attached. This is ReadyStack's own test, not a Docker grade; vulnerabilities published since then are in today's result at https://readystack.dev/queue⁠.
  • Signed — cosign signature by the ReadyStack release key (fingerprint 04daa92344a52dbc) on this release's index digest sha256:a0679768b769b8761f566c510de545c97c23c0218c14afebc348765d39df7ee8; verify with cosign verify --key https://readystack.dev/keys/cosign.pub readystack/etcd:v3.7.2-CE-ubuntu24.04-r1.
  • Attestations — An SPDX SBOM and SLSA v0.2 build provenance are attached to this digest (Docker Scout now requires SLSA v1).
  • Runs as a non-root user (etcd).
  • Built from source by ReadyStack.

⁠Which tag should I pull?

This image follows the ReadyStack release-tag convention:

  • The current release is v3.7.2-CE-ubuntu24.04-r1 — the release on sale at readystack.dev. Release tags use the pattern <upstream-version>-CE-<base-os>-r<N>; the current one is signed, attested (SBOM + provenance), and is provided under the ReadyStack Agreement⁠.

  • Earlier release tags (an older version or revision in the same pattern) are superseded. They stay pullable so existing deployments can pin them, but they are no longer re-graded, and fixes appear only in newer releases: move to the current release. For a superseded release's build kit, ask support.

  • Any tag beginning with internal- is an engineering-pipeline artifact published for build observability. It is unsupported, may change or disappear without notice, and must not be used in production.

# ✓ current release
docker pull readystack/etcd:v3.7.2-CE-ubuntu24.04-r1

# ✗ unsupported (do not pull)
docker pull readystack/etcd:internal-...

This release is signed; verify it with cosign verify --key https://readystack.dev/keys/cosign.pub readystack/etcd:v3.7.2-CE-ubuntu24.04-r1 (the signature is recorded in the public Sigstore transparency log). Support: [email protected]⁠, as set out in the ReadyStack Agreement⁠.

⁠Deployment

A single container running a single-member etcd cluster as the non-root etcd user (uid 999). etcd is its own datastore: an embedded bbolt key-value store under /data (the --data-dir), so there is no separate database, sidecar or web UI. The image contains three static Go binaries: etcd (the server), etcdctl (the client) and etcdutl (offline data tools).

export ETCD_ROOT_PASSWORD='YOUR_STRONG_PASSWORD'; docker run -d --name etcd -p 2379:2379 -e ETCD_ROOT_PASSWORD -v etcd-data:/data readystack/etcd:v3.7.2-CE-ubuntu24.04-r1

-e ETCD_ROOT_PASSWORD with no value passes the variable from your shell, so the password is not typed on the docker command line.

⁠The full ReadyStack Agent-ready Archive

The complete --network=none build kit for this image — plus admin/DB/API handbooks, the build's validation records, and its build provenance records — is at readystack.dev/buy.html⁠. A clean-room rebuild from this release's archive on an egress-blocked host reproduced its linux/amd64 digest sha256:9c183cc03ceb5e57386c3695e5ea65a3a23f738e706e1cdbf9f714aba27a4d1f on 2026-10-07.

— ReadyStack · readystack.dev

Tag summary

Content type

Image

Digest

sha256:f9d87c77c…

Size

336 Bytes

Last updated

1 day ago

docker pull readystack/etcd:sha256-9c183cc03ceb5e57386c3695e5ea65a3a23f738e706e1cdbf9f714aba27a4d1f.sig