Sign inSign up

readystack/rabbitmq

By readystack

•Updated 2 days ago

Image
0

1.9K

readystack/rabbitmq repository overview

⁠RabbitMQ

Signed: cosign SBOM: SPDX attached Provenance: SLSA v0.2

readystack/rabbitmq:4.3.2-CE-debian-bookworm-r1

A cosign-signed build of github.com/rabbitmq/rabbitmq-server 4.3.2 (MPL-2.0), built clean-room from official upstream source by ReadyStack⁠.

⁠What you get

Signature, user, attestations and grade below were measured on the published digest sha256:40a2dd3ad714b9e1578fdd27930778449c4692844a99e3e31653f99e8607c48c on 2026-10-07.

  • Docker Scout grade D (44%) on 2026-10-07 — 4 of Docker's 7 default policies fail:
    • 24 fixable critical/high vulnerabilities (6 critical, 18 high) in 8 packages, e.g. perl-base 5.40.1-6 (fixed in 5.40.1-6+deb13u1); openssl 3.5.6-1deb13u2 (fixed in 3.5.7-1deb13u2).
    • Provenance attestation is SLSA v0.2; Docker Scout now requires v1.
    • Base image docker.io/library/erlang:28-slim has been updated since this image was built (built on sha256:8a797f91eed7…, the tag now points to sha256:01a44e0b900e…).
    • 94 packages carry copyleft licences (GPL, LGPL, MPL), all of them operating-system packages.
    • Measured with Docker Scout CLI 1.26.0 (docker scout policy, Docker's default policies); re-checked daily at https://readystack.dev/queue⁠.
  • ReadyStack release check — passed at release on 2026-07-01: no fixable critical or high vulnerability (Docker Scout and OSV), a non-root user, SBOM and provenance attached. This is ReadyStack's own test, not a Docker grade; vulnerabilities published since then are in today's result at https://readystack.dev/queue⁠.
  • Signed — cosign signature by the ReadyStack release key (fingerprint 04daa92344a52dbc) on this release's index digest sha256:40a2dd3ad714b9e1578fdd27930778449c4692844a99e3e31653f99e8607c48c; verify with cosign verify --key https://readystack.dev/keys/cosign.pub readystack/rabbitmq:4.3.2-CE-debian-bookworm-r1.
  • Attestations — An SPDX SBOM and SLSA v0.2 build provenance are attached to this digest (Docker Scout now requires SLSA v1).
  • Runs as a non-root user (rabbitmq).
  • Built from source by ReadyStack.

⁠Which tag should I pull?

This image follows the ReadyStack release-tag convention:

  • The current release is 4.3.2-CE-debian-bookworm-r1 — the release on sale at readystack.dev. Release tags use the pattern <upstream-version>-CE-<base-os>-r<N>; the current one is signed, attested (SBOM + provenance), and is provided under the ReadyStack Agreement⁠.

  • Earlier release tags (an older version or revision in the same pattern) are superseded. They stay pullable so existing deployments can pin them, but they are no longer re-graded, and fixes appear only in newer releases: move to the current release. For a superseded release's build kit, ask support.

  • Any tag beginning with internal- is an engineering-pipeline artifact published for build observability. It is unsupported, may change or disappear without notice, and must not be used in production.

# ✓ current release
docker pull readystack/rabbitmq:4.3.2-CE-debian-bookworm-r1

# ✗ unsupported (do not pull)
docker pull readystack/rabbitmq:internal-...

This release is signed; verify it with cosign verify --key https://readystack.dev/keys/cosign.pub readystack/rabbitmq:4.3.2-CE-debian-bookworm-r1 (the signature is recorded in the public Sigstore transparency log). Support: [email protected]⁠, as set out in the ReadyStack Agreement⁠.

⁠Deployment

Single container, single self-contained Erlang/OTP broker process (the BEAM VM) bootstrapping a single-node RabbitMQ broker. RabbitMQ IS its own datastore: an embedded metadata store (Mnesia by default, Khepri when enabled) plus the message/queue store, all on the local filesystem under /var/lib/rabbitmq. NO relational/SQL database, NO external store, NO sidecar. The rabbitmq_management (UI + REST API) and rabbitmq_prometheus (metrics) plugins are enabled at build time. The image IS the complete running instance.

docker run -d --name rabbitmq -p 5672:5672 -p 15672:15672 -p 15692:15692 -v rabbitmq-data:/var/lib/rabbitmq readystack/rabbitmq:4.3.2-CE-debian-bookworm-r1

⁠The full ReadyStack Agent-ready Archive

The complete --network=none build kit for this image — plus admin/DB/API handbooks, the build's validation records, and its build provenance records — is at readystack.dev/buy.html⁠. The latest clean-room rebuild from this release's archive (2026-09-25) did not reproduce the published digest (first failing step: kit_complete).

— ReadyStack · readystack.dev

Tag summary

Content type

Image

Digest

sha256:369cbed22…

Size

347 Bytes

Last updated

2 days ago

docker pull readystack/rabbitmq:sha256-b894b1be9569c6ca2b170902ce4d2cfca203e582b181154a6b5da1ffc36eb859.sig