delonix image

Imagens OCI: pull, list, remove, export — e, com `image vm`, as imagens VM douradas (build/push).

OCI images: pull, list, remove, export — and, with `image vm`, the golden VM images (build/push).

Gestão de imagens de container (registos OCI: Docker Hub, ghcr.io, …) com verificação de digest no pull. image vm <comando> opera sobre as imagens VM douradas (um .qcow2 + metadados por imagem): Ubuntu cloud image + kubeadm/kubelet/kubectl + delonix-cri — a base do delonix cluster.

Container image management (OCI registries: Docker Hub, ghcr.io, …) with digest verification on pull. image vm <command> operates on golden VM images (a .qcow2 plus per-image metadata): Ubuntu cloud image + kubeadm/kubelet/kubectl + delonix-cri — the base delonix cluster builds on.

Usage: delonix image [OPTIONS] <COMMAND>

Commands:
  pull      Pull an image from a registry
  push      Publish a local image to an OCI registry
  remove    Remove a local image
  describe  Human-readable detail of one or more images, `kubectl describe`-style
  history   Layers of an image (digest + size), from base to top
  ls        List local images
  sbom      The image's SBOM as an SPDX 2.3 document, not the table `scan --sbom` prints
  scan      SBOM + CVE scan of an image
  verify    Verify the cosign signature of a local image against a public key
  login     Authenticate to an OCI registry
  logout    Remove the stored credentials of a registry
  sign      Sign an image with cosign-compatible ECDSA-P256, publishing the signature next to it in the registry
  tag       Give another name/tag to a local image (copies nothing — it's just a new name for the same content)
  export    Export an OCI runtime bundle (rootfs + config.json) for `runc`/`crun`
  load      Load an image from an archive (the counterpart of `save`)
  save      Save an image to a portable archive (`docker save`'s counterpart)
  apply     Apply the `kind: Image` documents of a manifest
  prune     Remove unused images and the CAS blobs nobody references any more
  vm        Golden VM images (`<root>/vm-images/`): ls/pull/push/build/rm/describe
  help      Print this message or the help of the given subcommand(s)

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -h, --help
          Print help (see a summary with '-h')

COMMAND MAP:
  Lifecycle    pull · remove · push
  Inspect      ls · describe · history · verify · scan · sbom
  Configure    tag · sign · login · logout
  Storage      export · save · load
  Declarative  apply
  Maintenance  prune
  Advanced     vm

EXAMPLES:
  # fetch an image from a registry
  delonix image pull postgres:16

  # what is on disk, and how much of it
  delonix image ls

  # golden VM images live in a store of their own, next to the container ones
  delonix image vm ls

SEE ALSO:
  delonix build · delonix container run · delonix image vm · delonix image
  scan

  delonix › image

image vm

Golden VM images (<root>/vm-images/): ls/pull/push/build/rm/describe

Usage: delonix image vm [OPTIONS] <COMMAND>

Commands:
  pull       Fetch a VM image from an OCI registry (single-blob artifact) — with no argument, the OFFICIAL Delonix image
  push       Publish a local VM image to an OCI registry
  rm         Remove a local VM image (its disk and its metadata)
  build      Build a VM image: a `vm.yaml`, your own `VMfile`, or the golden recipe
  import     Register an existing disk image under a name, so `vm create --disk <name>` and `image vm push` can use it
  init       Scaffold a `VMfile` (and a cloud-init) for building your own image
  describe   Human-readable detail of one or more VM images, `kubectl describe`-style
  ls         List the local VM images
  ls-remote  List the tags available in a remote OCI repository
  convert    Convert a VM disk to the format another ecosystem imports
  help       Print this message or the help of the given subcommand(s)

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -h, --help
          Print help (see a summary with '-h')

COMMAND MAP:
  Lifecycle    rm · pull · push
  Create       import · init · build
  Inspect      ls · describe · ls-remote
  Maintenance  convert

EXAMPLES:
  # what golden images this node already has
  delonix image vm ls

  # fetch the official Kubernetes golden — the source is known, so no argument
  # is needed
  delonix image vm pull

  # build one of your own from a `VMfile`
  delonix image vm build -f VMfile -t myimage:1

SEE ALSO:
  delonix vm create · delonix image · delonix cluster kubeadm · delonix image
  vm build

  delonix › image › vm

ExemplosExamples

O mesmo grupo de imagens VM, por outro caminho
The same VM image group, via another path
delonix image vm ls
Scaffold de um VMfile (equivalente a vm init --vmfile)
Scaffold a VMfile (equivalent to vm init --vmfile)
delonix image vm init minha-base
Construir a imagem VM dourada (descarrega Ubuntu, valida SHA256SUMS, virt-customize)
Build the golden VM image (downloads Ubuntu, verifies SHA256SUMS, virt-customize)
delonix image vm build -t k8s-golden --k8s-version 1.34
Publicar a imagem VM dourada como artefacto OCI (padrão ORAS)
Publish the golden VM image as an OCI artifact (ORAS-style)
delonix image vm push k8s-golden ghcr.io/angolardevops/delonix-vm-k8s:1.34
Registar um disco que NÃO foi construído aqui — o único ponto de entrada para `import`, que não tem forma `delonix vm …`
Register a disk this engine did NOT build — the only entry point for `import`, which has no `delonix vm …` spelling
delonix image vm import ./OPNsense-26.1.2.qcow2 -t opnsense:26.1.2 \
  --appliance --distro opnsense --release 26.1.2 \
  --default-vcpus 2 --default-memory 2G
`--appliance` diz que o convidado se configura sozinho (OPNsense, Proxmox, TrueNAS) — o `vm create` salta o seed NoCloud em vez de lhe colar um ISO que ninguém lá dentro lê, e RECUSA `--hostname`/`--ssh-key` a nomeá-los, em vez de os aceitar e deitar fora
`--appliance` says the guest configures itself (OPNsense, Proxmox, TrueNAS) — `vm create` then skips the NoCloud seed instead of attaching an ISO nothing inside reads, and REFUSES `--hostname`/`--ssh-key` by name rather than accepting and discarding them
delonix vm create fw --disk opnsense:26.1.2

image logout

Remove the stored credentials of a registry

Usage: delonix image logout [OPTIONS] <REGISTRY>

Arguments:
  <REGISTRY>
          

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # drop the stored credentials of a registry
  delonix image logout ghcr.io

SEE ALSO:
  delonix image login · delonix image push

  delonix › image › logout

ExemplosExamples

Esquecer as credenciais desse registo
Forget that registry's credentials
delonix image logout ghcr.io

image login

Authenticate to an OCI registry.

Stores the credentials in <root>/auth.json, docker/podman format. The password ALWAYS comes from stdin — never from an argument (it would end up in the shell history and in /proc).

Usage: delonix image login [OPTIONS] --username <USERNAME> <REGISTRY>

Arguments:
  <REGISTRY>
          Registry (e.g. `ghcr.io`, `docker.io`)

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -u, --username <USERNAME>
          

      --password-stdin
          Read the password/token from stdin (the only supported way)

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # authenticate to a registry — the token comes from stdin, never from the
  # argv, where it would land in the shell history and in /proc
  printf '%s' "$GITHUB_TOKEN" | delonix image login ghcr.io -u angolardevops --password-stdin

  # the same for Docker Hub
  printf '%s' "$DOCKERHUB_TOKEN" | delonix image login docker.io -u myuser --password-stdin

SEE ALSO:
  delonix image logout · delonix image push · delonix image pull

  delonix › image › login

ExemplosExamples

Autenticar num registo (a password vem do stdin, fora do histórico)
Authenticate to a registry (the password comes from stdin, out of history)
printf '%s' "$GHCR_TOKEN" | delonix image login ghcr.io --username aminhaorg

image load

Load an image from an archive (the counterpart of save).

Reads archives produced by delonix image save, docker save or podman save.

Usage: delonix image load [OPTIONS] --input <FILE>

Options:
  -i, --input <FILE>
          Archive to read (`.tar`; a `.tar.gz` must be gunzipped first)

      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # read back an archive written by `save`, `docker save` or `podman save`
  delonix image load -i postgres-16.tar

  # a gzipped archive has to be gunzipped first
  gunzip -c nginx.tar.gz > nginx.tar && delonix image load -i nginx.tar

SEE ALSO:
  delonix image save · delonix image ls · delonix image pull

  delonix › image › load

ExemplosExamples

Importar esse tar do outro lado
Import that tar on the other end
delonix image load --input app-dev.tar

image save

Save an image to a portable archive (docker save's counterpart).

The way to move an image to another machine with no registry. The archive is an OCI layout WITH the legacy manifest.json, so delonix image load, docker load, podman load and ctr images import all read it.

Usage: delonix image save [OPTIONS] --output <FILE> <IMAGE>

Arguments:
  <IMAGE>
          

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -o, --output <FILE>
          Destination file. Use `-o /dev/stdout` to pipe (e.g. into `gzip`)

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # move an image to another machine with no registry in between
  delonix image save postgres:16 -o postgres-16.tar

  # pipe it straight into gzip instead of writing the plain archive
  delonix image save nginx -o /dev/stdout | gzip > nginx.tar.gz

SEE ALSO:
  delonix image load · delonix image push · delonix image export

  delonix › image › save

ExemplosExamples

Exportar para um tar (para levar para uma máquina sem rede)
Export to a tar (to carry to a machine with no network)
delonix image save app:dev --output app-dev.tar

image scan

SBOM + CVE scan of an image.

Reads the layers from the CAS, without running anything. Pulls the image if missing. See --sbom, --fail-on, --update.

Usage: delonix image scan [OPTIONS] [IMAGE]

Arguments:
  [IMAGE]
          Image to scan (optional with `--update`)

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

      --sbom
          List the SBOM (installed packages) instead of scanning

      --fail-on <SEV>
          Fail (exit 1) if there are vulnerabilities >= this severity (low|medium|high|critical) — gate for CI

      --update
          Sync the CVE feed to the local database (used afterwards by each scan)

      --feed <URL|FICHEIRO>
          Feed source for `--update`: URL or file (or $DELONIX_ADVISORY_FEED)

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # the CVEs of an image, read from the layers on disk — nothing is executed
  delonix image scan postgres:16

  # the installed packages (SBOM) instead of the findings
  delonix image scan --sbom nginx

  # a CI gate: exit 1 if anything high or worse is found
  delonix image scan --fail-on high ghcr.io/angolardevops/app:1.2.0

  # refresh the local feed first — a scan is only as fresh as the database
  # behind it
  delonix image scan --update

SEE ALSO:
  delonix image describe · delonix image pull · delonix image verify

  delonix › image › scan

ExemplosExamples

Procurar vulnerabilidades conhecidas numa imagem
Look for known vulnerabilities in an image
delonix image scan nginx:alpine
Varrer todas as imagens locais
Scan every local image
delonix image scan

image verify

Verify the cosign signature of a local image against a public key

Usage: delonix image verify [OPTIONS] <IMAGE> <PEM>

Arguments:
  <IMAGE>
          

  <PEM>
          Public key in PEM

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # check the cosign signature of an image you already have against the
  # publisher's key
  delonix image verify ghcr.io/angolardevops/app:1.2.0 cosign.pub

  # the gate to run before promoting a local build to production
  delonix image verify kaeso-odoo:18 keys/kaeso.pub

SEE ALSO:
  delonix image pull · delonix image scan · delonix image describe

  delonix › image › verify

ExemplosExamples

Confirmar a assinatura contra uma chave pública
Confirm the signature against a public key
delonix image verify ghcr.io/aminhaorg/app:1.0 chave.pem

image history

Layers of an image (digest + size), from base to top

Usage: delonix image history [OPTIONS] <IMAGE>

Arguments:
  <IMAGE>
          

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # the layers from base to top, with the digest and size of each
  delonix image history postgres:16

  # where the size went, before deciding what to change in the Dockerfile
  delonix image history kaeso-odoo:18

SEE ALSO:
  delonix image describe · delonix build · delonix image ls

  delonix › image › history

ExemplosExamples

Que instrução criou cada camada
Which instruction created each layer
delonix image history app:dev

image tag

Give another name/tag to a local image (copies nothing — it's just a new name for the same content)

Usage: delonix image tag [OPTIONS] <SOURCE> <TARGET>

Arguments:
  <SOURCE>
          

  <TARGET>
          

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # a second name for the same content — nothing is copied
  delonix image tag postgres:16 db:stable

  # the shape a locally-built image needs before it can be pushed to your
  # registry
  delonix image tag kaeso-odoo:18 ghcr.io/angolardevops/kaeso-odoo:18

SEE ALSO:
  delonix image push · delonix image ls · delonix image remove

  delonix › image › tag

ExemplosExamples

Dar um segundo nome à mesma imagem (não copia nada)
Give the same image a second name (copies nothing)
delonix image tag app:dev ghcr.io/aminhaorg/app:1.0

image describe

Human-readable detail of one or more images, kubectl describe-style.

Tags/digest/size/layers + the OCI config: entrypoint/cmd/env/workdir.

Usage: delonix image describe [OPTIONS] <NAMES>...

Arguments:
  <NAMES>...
          

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # tags, digest, size, layers and the OCI config (entrypoint/cmd/env/workdir)
  # in one screen
  delonix image describe postgres:16

  # several at once, to compare what two images actually run
  delonix image describe alpine:3.19 redis:7-alpine

SEE ALSO:
  delonix image ls · delonix image history · delonix image scan

  delonix › image › describe

ExemplosExamples

Camadas, config e digest de uma imagem
An image's layers, config and digest
delonix image describe nginx:alpine

image pull

Pull an image from a registry

Usage: delonix image pull [OPTIONS] <IMAGE>

Arguments:
  <IMAGE>
          

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

      --verify <PEM>
          Verify the cosign signature with this public key (PEM) AFTER the pull, and fail if it does not match. Without this, a pull is not authenticated beyond the registry's own digest

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # the common case — repository and tag
  delonix image pull postgres:16

  # a registry other than Docker Hub — write it out in the reference
  delonix image pull ghcr.io/angolardevops/kaeso-odoo:18

  # refuse the image unless it carries a cosign signature made by this key
  delonix image pull --verify cosign.pub ghcr.io/angolardevops/app:1.2.0

SEE ALSO:
  delonix image ls · delonix image scan · delonix image verify · delonix image
  vm pull

  delonix › image › pull

ExemplosExamples

Referência com tag e digest (formato combinado suportado)
Reference with tag and digest (combined format supported)
delonix image pull kindest/node:v1.34.0@sha256:7416a6…

image ls

List local images

Usage: delonix image ls [OPTIONS]

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -o, --output <OUTPUT>
          Output format: `table` (default) or `json` (ADR-0005)
          
          [default: table]
          [possible values: table, json]

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # what is on disk, newest first
  delonix image ls

  # as JSON, for a script to read instead of a table meant for eyes
  delonix image ls -o json

SEE ALSO:
  delonix image describe · delonix image history · delonix image remove

  delonix › image › ls

ExemplosExamples

delonix image ls

image remove

Remove a local image

Usage: delonix image remove [OPTIONS] <IMAGE>

Arguments:
  <IMAGE>
          

Options:
  -f, --force
          Remove it even if a container still uses it

      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # remove an image nothing is using
  delonix image remove alpine:3.19

  # remove it even though a container still references it
  delonix image remove -f odoo:16

SEE ALSO:
  delonix image ls · delonix container rm · delonix system prune

  delonix › image › remove

ExemplosExamples

delonix image remove alpine:3.19

image export

Export an OCI runtime bundle (rootfs + config.json) for runc/crun

Usage: delonix image export [OPTIONS] <IMAGE> <DIR>

Arguments:
  <IMAGE>
          

  <DIR>
          

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # an OCI runtime bundle (rootfs + config.json) that `runc` or `crun` runs
  # directly
  delonix image export alpine:latest /tmp/alpine-bundle

  # the directory you then hand to another OCI runtime — this is a bundle to
  # run, not an archive to ship
  delonix image export postgres:16 /tmp/pg-bundle

SEE ALSO:
  delonix image save · delonix image load · delonix container run

  delonix › image › export

ExemplosExamples

Bundle OCI runtime para correr com runc/crun
OCI runtime bundle, to run with runc/crun
delonix image export alpine:3.19 /tmp/bundle && sudo runc run -b /tmp/bundle teste

image push

Publish a local image to an OCI registry.

Without target, publishes under the image's own reference.

Usage: delonix image push [OPTIONS] <NAME> [TARGET]

Arguments:
  <NAME>
          

  [TARGET]
          

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # publish under the image's own reference
  delonix image push ghcr.io/angolardevops/app:1.2.0

  # publish a locally-named image under another reference, without tagging it
  # first
  delonix image push kaeso-odoo:18 ghcr.io/angolardevops/kaeso-odoo:18

SEE ALSO:
  delonix image login · delonix image tag · delonix image vm push

  delonix › image › push

ExemplosExamples

Publicar sob a própria referência da imagem
Publish under the image's own reference
delonix image push ghcr.io/angolardevops/app:1.2.0
Publicar uma imagem local com outro nome, sem lhe dar tag primeiro
Publish a locally-named image under another reference, without tagging it first
delonix image push kaeso-odoo:18 ghcr.io/angolardevops/kaeso-odoo:18

image apply

Apply the kind: Image documents of a manifest.

pull is idempotent by reference; build rebuilds and replaces the tag on each apply.

Usage: delonix image apply [OPTIONS]

Options:
  -f, --file <FILE>
          

      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # apply only the `kind: Image` documents of `./delonix-manifest.yaml`,
  # ignoring the other Kinds
  delonix image apply

  # from a file of your own
  delonix image apply -f delonix-manifest.yaml

SEE ALSO:
  delonix stack apply · delonix stack plan · delonix image pull

  delonix › image › apply

ExemplosExamples

delonix image apply -f delonix-manifest.yaml

LaboratórioLab

Traz uma imagem, dá-lhe uma tag própria, e olha para o histórico de camadas antes de a exportar.

delonix image pull alpine:3.20
delonix image tag alpine:3.20 meu-alpine:v1
delonix image history meu-alpine:v1
delonix image export meu-alpine:v1 -o alpine.tar

Pull an image, give it your own tag, and look at the layer history before exporting it.

delonix image pull alpine:3.20
delonix image tag alpine:3.20 my-alpine:v1
delonix image history my-alpine:v1
delonix image export my-alpine:v1 -o alpine.tar

DesafioChallenge

Antes de trazer a imagem VM dourada, vê que versões existem publicadas com ls-remote — sem descarregar nada — e só depois traz a que quiseres.

delonix image vm ls-remote
delonix image vm pull

Before pulling the golden VM image, check which versions are published with ls-remote — without downloading anything — and only then pull the one you want.

delonix image vm ls-remote
delonix image vm pull