Secure containers,
hardened by design

Free and open source hardened container images with supply chain security at the core. Every layer verified. Every dependency tracked. GPL-3.0. Always free.

Built for Security

Every image is crafted with security as the primary concern, not an afterthought.

[+]

Minimal Attack Surface

Stripped-down images containing only what is necessary. No shells, no package managers, no unnecessary utilities.

[#]

SBOM Included

Every image ships with a complete Software Bill of Materials. Know exactly what runs in your infrastructure.

[~]

Signed & Verified

All images are cryptographically signed using Sigstore. Verify provenance before deployment.

[@]

CVE Monitoring

Continuous vulnerability scanning with automated rebuilds when critical CVEs are discovered.

[&]

Reproducible Builds

Deterministic build process ensures anyone can verify that the source matches the binary.

[!]

Non-root by Default

All containers run as non-privileged users. No root access, no privilege escalation vectors.

Quick Start

Get started with armorred images in seconds.

terminal
$ podman pull ghcr.io/armorred/nginx:latest
[+] Pulling image...
[+] Verifying signature...
[+] Image verified and ready

$ cosign verify ghcr.io/armorred/nginx:latest
[+] Signature valid. Signed by: armorred@github

Secure your supply chain

Join the growing community using armorred images to protect their infrastructure from supply chain attacks.