Sign inSign up

readystack/uptimekuma

By readystack

•Updated about 14 hours ago

Image
0

2.2K

readystack/uptimekuma repository overview

⁠Uptime Kuma

Docker Scout: Grade A Fixable Critical/High CVEs: 0 Signed: cosign

readystack/uptimekuma:2.5.5-CE-debian-bookworm-r1

A hardened, cosign-signed, offline-rebuildable build of github.com/louislam/uptime-kuma 2.5.5 (MIT), built clean-room from official upstream source by ReadyStack⁠.

⁠What you get

  • Docker Scout Grade A — 0 fixable Critical/High, non-root, SBOM + provenance attestations; re-checked daily at https://readystack.dev/queue⁠.
  • Signed — cosign signature by the ReadyStack release key; verify with cosign verify --key https://readystack.dev/keys/cosign.pub --insecure-ignore-tlog=true readystack/uptimekuma:2.5.5-CE-debian-bookworm-r1.
  • Built from source, non-root.

⁠Which tag should I pull?

This image follows the ReadyStack release-tag convention:

  • The current release is 2.5.5-CE-debian-bookworm-r1 — the release on sale at readystack.dev. Release tags use the pattern <upstream-version>-CE-<base-os>-r<N>; the current one is hermetically built, signed, attested, and supported under your ReadyStack agreement.

  • Earlier release tags (an older version or revision in the same pattern) are superseded. They stay pullable so existing deployments can pin them, but they are no longer patched or re-graded: move to the current release. A superseded release's build kit is available through support.

  • Any tag beginning with internal- is an engineering-pipeline artifact published for build observability. It is unsupported, may change or disappear without notice, and must not be used in production.

# ✓ current release
docker pull readystack/uptimekuma:2.5.5-CE-debian-bookworm-r1

# ✗ unsupported (do not pull)
docker pull readystack/uptimekuma:internal-...

Each release tag is signed; verify with cosign verify --key https://readystack.dev/keys/cosign.pub --insecure-ignore-tlog=true readystack/uptimekuma:2.5.5-CE-debian-bookworm-r1 (ReadyStack keeps signatures off the public transparency log, so the check is key-only). Support: [email protected]⁠.

⁠Deployment

Single container. A Node.js (Express + socket.io) self-hosted uptime/status monitor with an embedded SQLite database under /app/data by default. The image IS the complete running instance for that default (no external DB, no sidecar needed). An external MariaDB is technically reachable through environment variables (tested — see Database in the handbooks), but it is not the tested/supported deployment for this release.

docker run -d --name uptime-kuma -p 127.0.0.1:3001:3001 -e UPTIME_KUMA_DB_TYPE=sqlite -v uptime-kuma-data:/app/data readystack/uptimekuma:2.5.5-CE-debian-bookworm-r1

Starts the Node.js server in the foreground under dumb-init. The -p 127.0.0.1:3001:3001 publishes the port on the host's loopback only, on purpose: the image itself listens on every interface inside the container (UPTIME_KUMA_HOST=0.0.0.0), and on a brand-new data volume the FIRST visitor to reach the port becomes the permanent administrator, with no password or token of the operator's choosing checked first — see First boot in the handbooks before changing it. UPTIME_KUMA_DB_TYPE=sqlite skips an extra unauthenticated database-selection screen that otherwise appears on a brand-new volume (tested — see Database in the handbooks). Visit http://127.0.0.1:3001⁠ from the host, create the administrator account, and only then republish the port to whatever interface it actually needs: stop and remove the container and re-create it with the same -e UPTIME_KUMA_DB_TYPE=sqlite and -v uptime-kuma-data:/app/data, changing only the -p (see First boot in the handbooks for the check to run). Never re-create it without that -v: the image declares no volume, so a container started without one keeps its data in its own writable layer, docker rm deletes it, and the next container opens a new, unclaimed setup window (tested). A fresh volume answered GET /api/entry-page with HTTP 200 about 3 seconds after docker run in testing. The archive ships no ReadyStack Compose file; the compose.yaml files inside docs/source-acquisition/source/ and vendored/uptimekuma-src/ are upstream's (they run louislam/uptime-kuma:2 and publish 3001 on every interface), so do not use them.

⁠The full ReadyStack Agent-ready Archive

The complete --network=none build kit to recreate this exact image yourself — plus admin/DB/API handbooks, seed data, a validated test suite, and signed provenance — is at readystack.dev/buy.html⁠.

— ReadyStack · readystack.dev

Tag summary

Content type

Image

Digest

sha256:122bc286b…

Size

143.2 MB

Last updated

about 14 hours ago

docker pull readystack/uptimekuma:2.5.5-CE-debian-bookworm-r1