readystack/netbox:v4.6.5-CE-trixie-r2
A hardened, cosign-signed, offline-rebuildable build of github.com/netbox-community/netbox v4.6.5 (Apache-2.0), built clean-room from official upstream source by ReadyStack.
cosign verify --key https://readystack.dev/keys/cosign.pub --insecure-ignore-tlog=true readystack/netbox:v4.6.5-CE-trixie-r2.This image follows the ReadyStack release-tag convention:
The current release is v4.6.5-CE-trixie-r2 — the release on sale at readystack.dev. Release tags use the pattern <upstream-version>-CE-<base-os>-r<N>; the current one is hermetically built, signed, attested, and supported under your ReadyStack agreement.
Earlier release tags (an older version or revision in the same pattern) are superseded. They stay pullable so existing deployments can pin them, but they are no longer patched or re-graded: move to the current release. A superseded release's build kit is available through support.
Any tag beginning with internal- is an engineering-pipeline artifact published for build observability. It is unsupported, may change or disappear without notice, and must not be used in production.
# ✓ current release
docker pull readystack/netbox:v4.6.5-CE-trixie-r2
# ✗ unsupported (do not pull)
docker pull readystack/netbox:internal-...
Each release tag is signed; verify with cosign verify --key https://readystack.dev/keys/cosign.pub --insecure-ignore-tlog=true readystack/netbox:v4.6.5-CE-trixie-r2 (ReadyStack keeps signatures off the public transparency log, so the check is key-only). Support: [email protected].
ONE product container (supervisord runs the gunicorn web server [:8080] + an RQ worker, which also runs NetBox's scheduled system jobs such as daily housekeeping) PLUS two required datastore sidecars the customer provides: a PostgreSQL server (15 or later — NetBox 4.7 drops PostgreSQL 14 support and needs the trusted ltree extension, installed automatically on first migrate) and a Redis instance (6.0 or later; used for both the task queue and caching). NOT a single self-contained image — NetBox is multi-service.
docker network create netbox-net
docker run -d --name db --network netbox-net -e POSTGRES_DB=netbox -e POSTGRES_USER=netbox -e 'POSTGRES_PASSWORD=YOUR_POSTGRES_PASSWORD' -v netbox-db:/var/lib/postgresql/data postgres:16
docker run -d --name redis --network netbox-net -v netbox-redis:/data redis:7-alpine
docker run -d --name netbox --network netbox-net -p 8080:8080 -e DB_HOST=db -e DB_NAME=netbox -e DB_USER=netbox -e 'DB_PASSWORD=YOUR_POSTGRES_PASSWORD' -e REDIS_HOST=redis -e REDIS_CACHE_HOST=redis -e REDIS_CACHE_DATABASE=1 -e 'SECRET_KEY=YOUR_SECRET_KEY' -e ALLOWED_HOSTS='*' -e SUPERUSER_NAME=admin -e 'SUPERUSER_PASSWORD=YOUR_ADMIN_PASSWORD' -v netbox-media:/opt/netbox/netbox/media -v netbox-reports:/opt/netbox/netbox/reports -v netbox-scripts:/opt/netbox/netbox/scripts readystack/netbox:v4.6.5-CE-trixie-r2
db, redis and netbox share the netbox-net network; db/redis/netbox are this command's own container names, not defaults read from the image. Use the same value for POSTGRES_PASSWORD and DB_PASSWORD, and keep every -e value that holds a password or key in single quotes. SECRET_KEY must be 50+ characters (see Secret key in the handbooks) — the placeholder above is filled with a long generated value by the test harness, not a short password. First start takes several minutes (measured 5m31s on this host) while NetBox applies its full migration set; GET /login/ answers 200 once gunicorn is listening. Sign in as SUPERUSER_NAME (default 'admin') with SUPERUSER_PASSWORD. The archive ships no Compose file.
The complete --network=none build kit to recreate this exact image yourself — plus admin/DB/API handbooks, seed data, a validated test suite, and signed provenance — is at readystack.dev/buy.html.
— ReadyStack · readystack.dev
Content type
Image
Digest
sha256:3cc1180df…
Size
249 Bytes
Last updated
about 16 hours ago
docker pull readystack/netbox:sha256-12093cfb6d19f4c25da523bb50d1bb23a6917acd11ba07d7848a381a2c2357e7.sig