DevOpsArk + Docker
Image build, scan and registry publishing
Vendor: Docker, Inc.
What does the DevOpsArk Docker integration do?
The DevOpsArk Docker integration covers the full image lifecycle: generating container definitions, building with BuildKit, hardening to policy, scanning for vulnerabilities, producing an SBOM and publishing by immutable digest.
What the Docker integration provides
- Generate multi-stage Dockerfiles from repository analysis, committed for review.
- Build images with BuildKit, including layer caching and per-layer size reporting.
- Enforce hardening policy: non-root user, dropped capabilities, no shell in the final layer.
- Scan OS packages and application dependencies against published advisories.
- Produce and index an SBOM per image so dependency questions are answered from a query.
- Publish to any OCI registry by immutable digest rather than a floating tag.
- Track base image lineage and raise rebuild plans when a base image is patched.
Exactly what is read, and what can be written
Read and write are separate grants. Nothing in the write column happens unless you explicitly allow it.
- Repository manifests, lock files and existing Dockerfiles
- Registry image metadata, tags and digests
- Image layer composition and sizes
- Generated Dockerfiles committed to the repository
- Built images pushed to the configured registry
- SBOM and scan records stored against each build
Connecting Docker
- 1Connect the repository
Authorise the Git provider so ArkBuilder can analyse the application.
- 2Connect the registry
Provide push credentials for ECR, ACR, Artifact Registry, GHCR, GitLab Registry or Harbor.
- 3Set container policy
Choose the approved base images and hardening rules for your organisation.
- 4Build
Run the first build and review the generated definition and the layer size report.
Which modules use Docker
ArkBuilder
AI-powered build and containerization
Containerization
Automated containerization for any application
Scanners
Image, code, IaC and secret scanning
Pipelines
CI/CD pipelines with policy and provenance
Kubernetes
Multi-cluster Kubernetes management
Vulnerability Management
From finding to fix, with ownership
Docker integration: frequently asked questions
No. Images are built with BuildKit and produced in OCI format, so they run on Docker, containerd, Podman or Kubernetes. Docker is supported as a runtime and a registry, not as a requirement.
Only if you ask it to. An existing Dockerfile is built as-is by default, while still getting caching, size reporting, scanning and SBOM generation.
Amazon ECR, Azure Container Registry, Google Artifact Registry, GitHub Container Registry, GitLab Container Registry and self-hosted Harbor, plus any other OCI-compliant registry.
A tag can be moved to point at a different image; a digest cannot. Publishing and deploying by digest means the artifact that was scanned and approved is provably the artifact that runs.
Integrations that commonly go with this one
Connect Docker and see your own data
Read-only connection takes minutes. Most demos start with the customer estate rather than a sample one.