Skip to content
Platform engineering service

Custom OS Image Building & Maintained Image Pipelines

TacitSoft designs, builds, inspects, signs, and maintains reproducible operating-system images for cloud, virtualization, bare metal, appliances, and regulated delivery paths.

No checkout or cloud access is required to scope the work. We start with targets, entitlement, controls, cadence, and ownership boundaries.

Reproducible

One controlled specification, rebuildable on demand

Evidence-backed

SBOM, scan, test, provenance, and checksums

Multi-target

Cloud, hypervisor, ISO, and bootable OCI outputs

Maintained

Scheduled and security-triggered rebuild lanes

What we build

One specification, the artifacts your delivery path needs

The target matrix is agreed before implementation. Format availability depends on the base, platform APIs, boot model, licensing, and the publishing boundary you control.

Operating-system image artifact capabilities
Artifact family Delivery targets Typical use
AMI AWS accounts and regions Golden EC2 bases, autoscaling fleets, private catalogs
Azure / GCP images Azure Compute Gallery and Google Cloud projects Repeatable cloud estates and customer environments
ISO Virtual, USB, and controlled installation paths Appliances, offline installs, bare-metal delivery
QCOW2 / RAW KVM, OpenStack, import workflows, block devices Private cloud, lab, edge, and conversion inputs
VMDK / OVA VMware-compatible delivery paths Virtual appliances and repeatable customer deployments
OCI / bootc Container registries and bootable-container workflows Image-mode operating systems with registry promotion

Supported bases

Selected after the outcome and delivery path are clear.

  • Rocky Linux
  • Red Hat Enterprise Linux (RHEL)
  • Debian
  • Ubuntu
  • AlmaLinux
  • Amazon Linux

Customer and private baselines are considered subject to verifiable source provenance, license entitlement, redistribution rights, and a supportable update path.

Pipeline, not snowflake

Every artifact follows a controlled promotion path

A hand-built VM is undocumented state. We turn image intent into versioned inputs, repeatable automation, policy evidence, release gates, and an owned maintenance decision.

  1. 01

    Source spec

    Pin inputs, packages, configuration, ownership, and target matrix.

  2. 02

    Build

    Create artifacts in isolated, reviewable automation.

  3. 03

    Inspect

    Inventory packages, SBOMs, vulnerabilities, licenses, and drift.

  4. 04

    Test

    Boot, smoke, policy, configuration, and target-specific acceptance checks.

  5. 05

    Sign

    Attach checksums, signatures, and provenance to approved outputs.

  6. 06

    Publish

    Promote through customer-controlled registries, galleries, or catalogs.

  7. 07

    Maintain

    Rebuild on cadence or security trigger, then repeat the same gates.

Evidence delivered

Proof that travels with the release

Evidence is produced by the agreed pipeline and delivered with the artifact release—not reconstructed after an audit request.

Hardening notes and control-oriented evidence support your review process. They are not a formal compliance certification or a substitute for an authorized assessment.

  • SBOM

    Package and component inventory in an agreed machine-readable format.

  • Vulnerability report

    Findings, severity context, exceptions, and remediation disposition.

  • Hardening notes

    Applied baseline, deviations, rationale, and operational impact.

  • Test results

    Boot, smoke, configuration, policy, and artifact acceptance outcomes.

  • Provenance

    Traceability from source specification and build inputs to release.

  • Artifact checksums

    Digest inventory for integrity verification and promotion.

  • Release notes

    What changed, known risks, compatibility notes, and maintenance trigger.

Engagement models

Choose the operating model, not a mystery SKU

Custom OS image building engagement models
Model Best fit Handoff
One-off build A defined artifact and target with a bounded release need. Build inputs, artifact, agreed evidence, and reproducibility notes.
Production golden image A stable base used repeatedly by a platform, fleet, or customer delivery team. Versioned pipeline, acceptance gates, release workflow, and operator runbook.
Maintained image lane Teams that need monthly or security-triggered rebuilds without patch-pressure fire drills. Recurring rebuild, inspection, test, promotion evidence, and release notes under an agreed SLA.
Marketplace / private listing support Products distributed through customer accounts, private catalogs, or provider listing workflows. Packaging and submission-readiness support; account ownership, provider approval, and final activation remain with the customer and marketplace.
Planning ranges

Budget orientation before scoping

These non-binding bands help qualify the shape of the work. They are not quotes, checkout prices, or a promise that every target fits a band.

Image Assessment
$750-$2,500
Inspect the current image and build process and recommend a maintainable path.
One-Off Custom Image Build
$1,500-$5,000
Build one customer-approved target image from a known and lawfully usable base.
Production Golden Image Pipeline
$7,500-$15,000+ setup
Create a reproducible image pipeline with tests, scanning, SBOM generation, signing, and release notes.
Multi-Cloud / Appliance Image Program
$15,000-$40,000+
Use one approved specification to produce multiple target artifacts or cloud releases.
Maintained Image Lane
$1,000-$3,000+/mo minimum
Provide governed ongoing rebuilds, CVE response, scheduled releases, and rollback or revocation support.

What determines the actual scope

Price bands are planning anchors, not offers to sell. Final pricing and every customer-specific statement of work require scoped review and human approval.

Final pricing depends on the target artifact matrix, license entitlement, compliance controls, maintenance cadence, and support SLA. Marketplace support, unusual hardware, disconnected builds, private package sources, and migration work are scoped explicitly.

Free base image versus paid engineering

Many upstream base images are free to download. TacitSoft does not charge for relabeling a free distro image. Paid work covers the controlled specification, automation, inspection, testing, signing, evidence, publishing integration, and optional maintained rebuild pipeline your team can rely on.

Delivery boundaries

When we say no

A trustworthy pipeline has refusal criteria. We pause or decline work when the legal, security, or evidence boundary cannot be made explicit.

  • Unclear licensing or entitlement

    We need a documented right to obtain, modify, build from, and deliver the selected base and packages.

  • Unknown provenance

    We do not bless mystery binaries or inherited images when their source and update path cannot be established.

  • Credential sharing

    Cloud and registry access must use customer-controlled roles, bounded permissions, and auditable handoffs—not shared personal credentials.

  • Unsupported third-party redistribution

    We will not redistribute software, subscriptions, or vendor content beyond the rights you can demonstrate.

  • Certification claims without assessment

    We can implement controls and produce evidence; we do not claim formal certification without a separate, appropriately authorized assessment.

Start with the target matrix

Request an image build assessment

We will determine whether you need a bounded build, a production pipeline, or a maintained lane—and identify entitlement or delivery constraints before proposing implementation.

Bring these scoping inputs

  • Current base image, source owner, and license entitlement
  • Required artifacts, clouds, hypervisors, regions, and architectures
  • Hardening baseline, evidence needs, and assessor expectations
  • Release cadence and security-trigger thresholds
  • Publishing accounts, approval owners, support window, and SLA