Sign inSign up

readystack/mariadb

By readystack

•Updated about 19 hours ago

Image
0

318

readystack/mariadb repository overview

⁠MariaDB Server

Docker Scout: Grade A Fixable Critical/High CVEs: 0 Signed: cosign

readystack/mariadb:12.3.3-CE-ubuntu24.04-r1

A hardened, cosign-signed, offline-rebuildable build of github.com/MariaDB/server tag mariadb-12.3.3 (MariaDB Server 12.3.3, a release of the 12.3 LTS series; server GPL-2.0, client library LGPL-2.1 or later), built clean-room from official upstream source by ReadyStack⁠.

⁠What you get

  • Docker Scout Grade A — 0 fixable Critical/High, non-root, SBOM + provenance attestations; re-checked daily at https://readystack.dev/queue⁠.
  • Signed — cosign signature by the ReadyStack release key; verify with cosign verify --key https://readystack.dev/keys/cosign.pub --insecure-ignore-tlog=true readystack/mariadb:12.3.3-CE-ubuntu24.04-r1.
  • Built from source, non-root.

⁠Which tag should I pull?

This image follows the ReadyStack release-tag convention:

  • Supported customer releases use the pattern <upstream-version>-CE-<base-os>-r<N>. Example: 12.3.3-CE-ubuntu24.04-r1. These tags are hermetically built, signed, attested, and supported under your ReadyStack agreement.

  • Any tag beginning with internal- is an engineering-pipeline artifact published for build observability. It is unsupported, may change or disappear without notice, and must not be used in production.

# ✓ supported
docker pull readystack/mariadb:12.3.3-CE-ubuntu24.04-r1

# ✗ unsupported (do not pull)
docker pull readystack/mariadb:internal-...

Each release tag is signed; verify with cosign verify --key https://readystack.dev/keys/cosign.pub --insecure-ignore-tlog=true readystack/mariadb:12.3.3-CE-ubuntu24.04-r1 (ReadyStack keeps signatures off the public transparency log, so the check is key-only). Support: [email protected]⁠.

⁠Deployment

Single container. MariaDB Server 12.3.3 (12.3 LTS) compiled from the upstream source tag with CMake and installed in /usr/local/mariadb. The image is the whole database server: there is no external database and no sidecar, and Galera clustering is not compiled in. mariadbd runs in the foreground as the non-root mysql user. On the first start with an empty data directory the entrypoint creates the data directory in /var/lib/mysql and sets the root password before the server opens a network port.

docker run -d --name mariadb -e MARIADB_ROOT_PASSWORD=YOUR_ROOT_PASSWORD -p 3306:3306 -v mariadb-data:/var/lib/mysql readystack/mariadb:12.3.3-CE-ubuntu24.04-r1

Replace YOUR_ROOT_PASSWORD with a password of at least 8 characters. On an empty data directory the image refuses to start without one, and refuses the placeholder itself. The MYSQL_* variable names used by the official images (MYSQL_ROOT_PASSWORD, MYSQL_DATABASE, MYSQL_USER, MYSQL_PASSWORD) are accepted as aliases.

⁠The full ReadyStack Agent-ready Archive

The complete --network=none build kit to recreate this exact image yourself — plus admin/DB/API handbooks, seed data, a validated test suite, and signed provenance — is at readystack.dev/buy.html⁠.

— ReadyStack · readystack.dev

Tag summary

Content type

Image

Digest

sha256:87f5ea934…

Size

120.3 MB

Last updated

about 19 hours ago

docker pull readystack/mariadb:12.3.3-CE-ubuntu24.04-r1