Maintained OS Image Pipelines
A controlled lifecycle for reproducible operating-system images, from source and entitlement review through build evidence, signing, publication, and maintenance.
Public service definition
Context
Organizations need bootable artifacts that can be rebuilt and explained after the first release, not an opaque image copied between accounts.
Constraint
Base-image entitlement, target formats, hardening controls, signing custody, publishing ownership, and update cadence must be explicit before a build begins.
Work
TacitSoft defined one-off, production golden-image, maintained-lane, and marketplace-support paths with a common evidence contract.
Architecture
- Source specification and entitlement boundary before build
- Artifact targets across AMI, QCOW2, ISO, VMDK, RAW, and OCI or bootc
- Inspection, tests, SBOM, checksums, provenance, signing, and release notes
- Scheduled and security-triggered rebuild policy for maintained lanes
Verified current state
The public service contract now exposes the artifact matrix, evidence package, engagement boundaries, and qualification inputs needed to scope an image lifecycle.
- Evidence strength
- Repository-verified public implementation
- Evidence basis
- Public service route, approved pricing catalog, and focused Laravel contract tests.
Operating responsibility
TacitSoft owns the published service contract and can scope build, evidence, release, and maintenance responsibility per engagement. Customer accounts, credentials, and approval authority remain customer-controlled.
What remains private
No customer image, source entitlement, credential, assessment result, or signing material is shown.