readystack/rabbitmq:4.3.2-CE-debian-bookworm-r1
A cosign-signed build of github.com/rabbitmq/rabbitmq-server 4.3.2 (MPL-2.0), built clean-room from official upstream source by ReadyStack.
Signature, user, attestations and grade below were measured on the published digest sha256:40a2dd3ad714b9e1578fdd27930778449c4692844a99e3e31653f99e8607c48c on 2026-10-07.
docker scout policy, Docker's default policies); re-checked daily at https://readystack.dev/queue.04daa92344a52dbc) on this release's index digest sha256:40a2dd3ad714b9e1578fdd27930778449c4692844a99e3e31653f99e8607c48c; verify with cosign verify --key https://readystack.dev/keys/cosign.pub readystack/rabbitmq:4.3.2-CE-debian-bookworm-r1.rabbitmq).This image follows the ReadyStack release-tag convention:
The current release is 4.3.2-CE-debian-bookworm-r1 — the release on sale at readystack.dev. Release tags use the pattern <upstream-version>-CE-<base-os>-r<N>; the current one is signed, attested (SBOM + provenance), and is provided under the ReadyStack Agreement.
Earlier release tags (an older version or revision in the same pattern) are superseded. They stay pullable so existing deployments can pin them, but they are no longer re-graded, and fixes appear only in newer releases: move to the current release. For a superseded release's build kit, ask support.
Any tag beginning with internal- is an engineering-pipeline artifact published for build observability. It is unsupported, may change or disappear without notice, and must not be used in production.
# ✓ current release
docker pull readystack/rabbitmq:4.3.2-CE-debian-bookworm-r1
# ✗ unsupported (do not pull)
docker pull readystack/rabbitmq:internal-...
This release is signed; verify it with cosign verify --key https://readystack.dev/keys/cosign.pub readystack/rabbitmq:4.3.2-CE-debian-bookworm-r1 (the signature is recorded in the public Sigstore transparency log). Support: [email protected], as set out in the ReadyStack Agreement.
Single container, single self-contained Erlang/OTP broker process (the BEAM VM) bootstrapping a single-node RabbitMQ broker. RabbitMQ IS its own datastore: an embedded metadata store (Mnesia by default, Khepri when enabled) plus the message/queue store, all on the local filesystem under /var/lib/rabbitmq. NO relational/SQL database, NO external store, NO sidecar. The rabbitmq_management (UI + REST API) and rabbitmq_prometheus (metrics) plugins are enabled at build time. The image IS the complete running instance.
docker run -d --name rabbitmq -p 5672:5672 -p 15672:15672 -p 15692:15692 -v rabbitmq-data:/var/lib/rabbitmq readystack/rabbitmq:4.3.2-CE-debian-bookworm-r1
The complete --network=none build kit for this image — plus admin/DB/API handbooks, the build's validation records, and its build provenance records — is at readystack.dev/buy.html. The latest clean-room rebuild from this release's archive (2026-09-25) did not reproduce the published digest (first failing step: kit_complete).
— ReadyStack · readystack.dev
Content type
Image
Digest
sha256:369cbed22…
Size
347 Bytes
Last updated
2 days ago
docker pull readystack/rabbitmq:sha256-b894b1be9569c6ca2b170902ce4d2cfca203e582b181154a6b5da1ffc36eb859.sig