readystack/temporal:v1.32.0-CE-ubuntu24.04-r1
A hardened, cosign-signed, offline-rebuildable build of github.com/temporalio/temporal v1.32.0 (MIT), built clean-room from official upstream source by ReadyStack.
cosign verify --key https://readystack.dev/keys/cosign.pub --insecure-ignore-tlog=true readystack/temporal:v1.32.0-CE-ubuntu24.04-r1.This image follows the ReadyStack release-tag convention:
The current release is v1.32.0-CE-ubuntu24.04-r1 — the release on sale at readystack.dev. Release tags use the pattern <upstream-version>-CE-<base-os>-r<N>; the current one is hermetically built, signed, attested, and supported under your ReadyStack agreement.
Earlier release tags (an older version or revision in the same pattern) are superseded. They stay pullable so existing deployments can pin them, but they are no longer patched or re-graded: move to the current release. A superseded release's build kit is available through support.
Any tag beginning with internal- is an engineering-pipeline artifact published for build observability. It is unsupported, may change or disappear without notice, and must not be used in production.
# ✓ current release
docker pull readystack/temporal:v1.32.0-CE-ubuntu24.04-r1
# ✗ unsupported (do not pull)
docker pull readystack/temporal:internal-...
Each release tag is signed; verify with cosign verify --key https://readystack.dev/keys/cosign.pub --insecure-ignore-tlog=true readystack/temporal:v1.32.0-CE-ubuntu24.04-r1 (ReadyStack keeps signatures off the public transparency log, so the check is key-only). Support: [email protected].
Single container running the temporal-server binary in the foreground, with all four services (frontend, history, matching, worker) in one process and a self-contained pure-Go SQLite store. This is a durable-execution backend, not an application with a UI — clients connect with a Temporal SDK over gRPC on 7233 and run workflows against it.
docker run -d --name temporal -p 127.0.0.1:7233:7233 -p 127.0.0.1:7243:7243 -v temporal-data:/var/lib/temporal readystack/temporal:v1.32.0-CE-ubuntu24.04-r1
Publishes the frontend ports on 127.0.0.1 only: authorization is off by default, so anything that can reach 7233 or 7243 has full control of every namespace and workflow (see Access control and passwords in the handbooks). To serve workers or clients on other hosts, publish the ports on a private network address instead, or turn on JWT authorization first (see Turning on authorization (JWT) in the handbooks). GET http://127.0.0.1:7243/api/v1/namespaces answers 200 once the server is up. The archive ships no Compose file.
The complete --network=none build kit to recreate this exact image yourself — plus admin/DB/API handbooks, seed data, a validated test suite, and signed provenance — is at readystack.dev/buy.html.
— ReadyStack · readystack.dev
Content type
Image
Digest
sha256:57e67bcff…
Size
251 Bytes
Last updated
7 days ago
docker pull readystack/temporal:sha256-16f9bd9d8deed0d0f6b06ece5db17e97d1b20912f3bb36ccf8a18d9e42dde138.sig