readystack/nginx:1.31.6-CE-debian-bookworm-r1
A hardened, cosign-signed, offline-rebuildable build of github.com/nginx/nginx tag release-1.31.6, built clean-room from official upstream source by ReadyStack.
cosign verify --key https://readystack.dev/keys/cosign.pub --insecure-ignore-tlog=true readystack/nginx:1.31.6-CE-debian-bookworm-r1.This image follows the ReadyStack release-tag convention:
The current release is 1.31.6-CE-debian-bookworm-r1 — the release on sale at readystack.dev. Release tags use the pattern <upstream-version>-CE-<base-os>-r<N>; the current one is hermetically built, signed, attested, and supported under your ReadyStack agreement.
Earlier release tags (an older version or revision in the same pattern) are superseded. They stay pullable so existing deployments can pin them, but they are no longer patched or re-graded: move to the current release. A superseded release's build kit is available through support.
Any tag beginning with internal- is an engineering-pipeline artifact published for build observability. It is unsupported, may change or disappear without notice, and must not be used in production.
# ✓ current release
docker pull readystack/nginx:1.31.6-CE-debian-bookworm-r1
# ✗ unsupported (do not pull)
docker pull readystack/nginx:internal-...
Each release tag is signed; verify with cosign verify --key https://readystack.dev/keys/cosign.pub --insecure-ignore-tlog=true readystack/nginx:1.31.6-CE-debian-bookworm-r1 (ReadyStack keeps signatures off the public transparency log, so the check is key-only). Support: [email protected].
Single container. The nginx master process is the container's main process (ENTRYPOINT /opt/nginx/sbin/nginx with the default arguments -g 'daemon off;') and starts the worker processes. nginx is compiled from source by this image's build (./auto/configure, make, make install). No database, no sidecar and no state kept on disk: with no mounts at all, the shipped configuration (/etc/nginx/nginx.conf and /etc/nginx/conf.d/default.conf) serves upstream's welcome page and other static files from /usr/share/nginx/html on port 8080. Beyond that, what the server does is decided by the configuration you mount; it works as a web server, a reverse proxy, a TCP/UDP (stream) proxy and a mail proxy.
docker run -d --name nginx -p 8080:8080 readystack/nginx:1.31.6-CE-debian-bookworm-r1
The shipped default site answers http://localhost:8080/ with upstream's 'Welcome to nginx!' page and http://localhost:8080/healthz with the text ok. To serve your own files, mount them over the document root, for example -v "$PWD/site":/usr/share/nginx/html:ro. Mount configuration one file at a time: -v "$PWD/ssl.conf":/etc/nginx/conf.d/ssl.conf:ro adds a site next to the shipped default.conf (nginx.conf includes every /etc/nginx/conf.d/*.conf), a file mounted over /etc/nginx/conf.d/default.conf replaces the default site, and a file mounted over /etc/nginx/nginx.conf replaces the main configuration. Mounting a directory over /etc/nginx/conf.d hides the shipped default.conf, which holds the port 8080 site and /healthz, so nothing answers on 8080 and the container turns unhealthy unless that directory provides its own listen 8080; server. Create each file before docker run: for a missing source path -v creates an empty directory instead. The container runs as the non-root nginx user, so mounted files must be readable by that user; keep nginx's own listen ports on 8080 and 8443 and publish them on the host ports you want (for example -p 80:8080).
The complete --network=none build kit to recreate this exact image yourself — plus admin/DB/API handbooks, seed data, a validated test suite, and signed provenance — is at readystack.dev/buy.html.
— ReadyStack · readystack.dev
Content type
Image
Digest
sha256:5b4c543b5…
Size
43.6 MB
Last updated
1 day ago
docker pull readystack/nginx:1.31.6-CE-debian-bookworm-r1