Orchestration

DevOpsArk + Docker

Image build, scan and registry publishing

Vendor: Docker, Inc.

Short answer

What does the DevOpsArk Docker integration do?

The DevOpsArk Docker integration covers the full image lifecycle: generating container definitions, building with BuildKit, hardening to policy, scanning for vulnerabilities, producing an SBOM and publishing by immutable digest.

Capabilities

What the Docker integration provides

  • Generate multi-stage Dockerfiles from repository analysis, committed for review.
  • Build images with BuildKit, including layer caching and per-layer size reporting.
  • Enforce hardening policy: non-root user, dropped capabilities, no shell in the final layer.
  • Scan OS packages and application dependencies against published advisories.
  • Produce and index an SBOM per image so dependency questions are answered from a query.
  • Publish to any OCI registry by immutable digest rather than a floating tag.
  • Track base image lineage and raise rebuild plans when a base image is patched.
Access

Exactly what is read, and what can be written

Read and write are separate grants. Nothing in the write column happens unless you explicitly allow it.

Read
  • Repository manifests, lock files and existing Dockerfiles
  • Registry image metadata, tags and digests
  • Image layer composition and sizes
Write, only if granted
  • Generated Dockerfiles committed to the repository
  • Built images pushed to the configured registry
  • SBOM and scan records stored against each build
Setup

Connecting Docker

  1. 1
    Connect the repository

    Authorise the Git provider so ArkBuilder can analyse the application.

  2. 2
    Connect the registry

    Provide push credentials for ECR, ACR, Artifact Registry, GHCR, GitLab Registry or Harbor.

  3. 3
    Set container policy

    Choose the approved base images and hardening rules for your organisation.

  4. 4
    Build

    Run the first build and review the generated definition and the layer size report.

FAQ

Docker integration: frequently asked questions

Connect Docker and see your own data

Read-only connection takes minutes. Most demos start with the customer estate rather than a sample one.