readystack/seaweedfs:4.48-CE-ubuntu24.04-r1
A hardened, cosign-signed, offline-rebuildable build of github.com/seaweedfs/seaweedfs 4.48 (Apache-2.0 — distributed S3-compatible object storage), built clean-room from official upstream source by ReadyStack.
cosign verify --key https://readystack.dev/keys/cosign.pub --insecure-ignore-tlog=true readystack/seaweedfs:4.48-CE-ubuntu24.04-r1.This image follows the ReadyStack release-tag convention:
The current release is 4.48-CE-ubuntu24.04-r1 — the release on sale at readystack.dev. Release tags use the pattern <upstream-version>-CE-<base-os>-r<N>; the current one is hermetically built, signed, attested, and supported under your ReadyStack agreement.
Earlier release tags (an older version or revision in the same pattern) are superseded. They stay pullable so existing deployments can pin them, but they are no longer patched or re-graded: move to the current release. A superseded release's build kit is available through support.
Any tag beginning with internal- is an engineering-pipeline artifact published for build observability. It is unsupported, may change or disappear without notice, and must not be used in production.
# ✓ current release
docker pull readystack/seaweedfs:4.48-CE-ubuntu24.04-r1
# ✗ unsupported (do not pull)
docker pull readystack/seaweedfs:internal-...
Each release tag is signed; verify with cosign verify --key https://readystack.dev/keys/cosign.pub --insecure-ignore-tlog=true readystack/seaweedfs:4.48-CE-ubuntu24.04-r1 (ReadyStack keeps signatures off the public transparency log, so the check is key-only). Support: [email protected].
Single container, single static Go binary (weed, CGO-free), foreground weed server -s3. Master+volume+filer+S3 in one process: the S3 API on :8333 is the one port meant for clients; the filer, master and volume server listen on the container's loopback interface only (see Ports in the handbooks). Object storage — data + metadata under /data. NO SQL DB, NO sidecar (production scales master/volume/filer as separate roles; this image is the single-node S3 endpoint).
docker run -d --name seaweedfs -p 8333:8333 -e 'SEAWEEDFS_S3_ACCESS_KEY=YOUR_ACCESS_KEY' -e 'SEAWEEDFS_S3_SECRET_KEY=YOUR_SECRET_KEY' -v seaweedfs-data:/data readystack/seaweedfs:4.48-CE-ubuntu24.04-r1
Starts a single SeaweedFS server (master+volume+filer+S3 in one process) with its data in the seaweedfs-data volume. SEAWEEDFS_S3_ACCESS_KEY and SEAWEEDFS_S3_SECRET_KEY are required (or a mounted SEAWEEDFS_S3_CONFIG identities file): without them the container exits at once (see Required and optional environment in the handbooks). /healthz answered 200 within about 3-11 seconds on a fresh boot (tested; on existing data see Health check in the handbooks) and does not need credentials, even once they are configured. Only port 8333 (S3) is published by the run command above, on all interfaces: credentials are required by default (see Access control and passwords in the handbooks), and an unsigned request gets 403 AccessDenied (tested). Do not publish any other port: 18333 (the S3 gateway's gRPC port) refuses every call without the container's admin token and no client outside the container needs it; 8888 (filer), 9333 (master) and 8080 (volume) listen on the container's loopback interface only, so a published mapping to them only resets connections (tested) — see Ports in the handbooks. The Iceberg REST Catalog (:8181) and Lance Namespace server (:9101) are disabled (tested: no listener). Extra arguments after readystack/seaweedfs:4.48-CE-ubuntu24.04-r1 replace the default CMD (server -s3 -ip=127.0.0.1 -ip.bind=127.0.0.1 -s3.ip.bind=0.0.0.0 -s3.port.iceberg=0 -s3.port.lance=0 -filer.disableHttp) entirely, so repeat those flags when you add your own; the entrypoint still puts -volume.max=0 before them (a later -volume.max wins) and appends -dir=/data and -master.volumeSizeLimitMB=1024 after them, which cannot be overridden this way (tested). The archive ships no Compose file.
The complete --network=none build kit to recreate this exact image yourself — plus admin/DB/API handbooks, seed data, a validated test suite, and signed provenance — is at readystack.dev/buy.html.
— ReadyStack · readystack.dev
Content type
Image
Digest
sha256:02ed4952d…
Size
115.3 MB
Last updated
about 23 hours ago
docker pull readystack/seaweedfs:4.48-CE-ubuntu24.04-r1