readystack/ghost:v6.65.0-CE-bookworm-r1
A cosign-signed build of github.com/TryGhost/Ghost v6.65.0 (MIT), packaged from the [email protected] npm release tarball, built clean-room from official upstream source by ReadyStack.
Signature, user, attestations and grade below were measured on the published digest sha256:ff83cb866467156e3bf939b180868b46db7ae67c1ee080844a15a4816a59d606 on 2026-10-07.
docker scout policy, Docker's default policies); re-checked daily at https://readystack.dev/queue.04daa92344a52dbc) on this release's index digest sha256:ff83cb866467156e3bf939b180868b46db7ae67c1ee080844a15a4816a59d606; verify with cosign verify --key https://readystack.dev/keys/cosign.pub readystack/ghost:v6.65.0-CE-bookworm-r1.node).This image follows the ReadyStack release-tag convention:
The current release is v6.65.0-CE-bookworm-r1 — the release on sale at readystack.dev. Release tags use the pattern <upstream-version>-CE-<base-os>-r<N>; the current one is signed, attested (SBOM + provenance), and is provided under the ReadyStack Agreement.
Earlier release tags (an older version or revision in the same pattern) are superseded. They stay pullable so existing deployments can pin them, but they are no longer re-graded, and fixes appear only in newer releases: move to the current release. For a superseded release's build kit, ask support.
Any tag beginning with internal- is an engineering-pipeline artifact published for build observability. It is unsupported, may change or disappear without notice, and must not be used in production.
# ✓ current release
docker pull readystack/ghost:v6.65.0-CE-bookworm-r1
# ✗ unsupported (do not pull)
docker pull readystack/ghost:internal-...
This release is signed; verify it with cosign verify --key https://readystack.dev/keys/cosign.pub readystack/ghost:v6.65.0-CE-bookworm-r1 (the signature is recorded in the public Sigstore transparency log). Support: [email protected], as set out in the ReadyStack Agreement.
Single container (Node.js, node index.js, one foreground process) running Ghost. It REQUIRES an EXTERNAL MySQL 8 database the operator provisions and points the container at via database__connection__host/port/user/password/database env vars — there is NO embedded/SQLite database in production (SQLite is dev-only and Ghost warns loudly). On first start Ghost auto-runs knex-migrator to create its schema. NOT a multi-service cluster, but NOT self-contained: a MySQL 8 server is a hard external dependency; the content/ dir + DB must persist.
docker run -d --name ghost -p 2368:2368 -e url=https://blog.example.com -e database__client=mysql2 -e database__connection__host=YOUR_DB_HOST -e database__connection__port=3306 -e database__connection__user=ghost -e database__connection__password=YOUR_DB_PW -e database__connection__database=ghost -v ghost-content:/var/lib/ghost/content readystack/ghost:v6.65.0-CE-bookworm-r1
The empty 'ghost' database must exist first; first boot creates the schema, then open /ghost to create the owner account. If the database password contains spaces or shell characters, single-quote the whole argument: -e 'database__connection__password=my new pass $x!'. Ghost emails a sign-in code whenever a staff user signs in from a new browser: if the server has no mail settings, add -e security__staffDeviceVerification=false, or those sign-ins fail (see Sign-in codes for new devices).
The complete --network=none build kit for this image — plus admin/DB/API handbooks, the build's validation records, and its build provenance records — is at readystack.dev/buy.html. A clean-room rebuild from this release's archive on an egress-blocked host reproduced its linux/amd64 digest sha256:40d030778917dbe1433210f4372a229748d2007a8ab0360b0ba96a77ccc3411e on 2026-10-07.
— ReadyStack · readystack.dev
Content type
Image
Digest
sha256:3d09effe4…
Size
336 Bytes
Last updated
2 days ago
docker pull readystack/ghost:sha256-40d030778917dbe1433210f4372a229748d2007a8ab0360b0ba96a77ccc3411e.sig