delonix image
Imagens OCI: pull, list, remove, export — e, com `image vm`, as imagens VM douradas (build/push).
OCI images: pull, list, remove, export — and, with `image vm`, the golden VM images (build/push).
Gestão de imagens de container (registos OCI: Docker Hub, ghcr.io, …) com
verificação de digest no pull. image vm <comando> opera sobre as
imagens VM douradas (um .qcow2 + metadados por imagem): Ubuntu cloud
image + kubeadm/kubelet/kubectl + delonix-cri — a base do delonix cluster.
Container image management (OCI registries: Docker Hub, ghcr.io, …) with
digest verification on pull. image vm <command> operates on golden VM
images (a .qcow2 plus per-image metadata): Ubuntu cloud image +
kubeadm/kubelet/kubectl + delonix-cri — the base delonix cluster builds
on.
📄 Implementação real em Rust: cmd/image.rs
Usage: delonix image [OPTIONS] <COMMAND>
Commands:
pull Pull an image from a registry
push Publish a local image to an OCI registry
remove Remove a local image
describe Human-readable detail of one or more images, `kubectl describe`-style
history Layers of an image (digest + size), from base to top
ls List local images
sbom The image's SBOM as an SPDX 2.3 document, not the table `scan --sbom` prints
scan SBOM + CVE scan of an image
verify Verify the cosign signature of a local image against a public key
login Authenticate to an OCI registry
logout Remove the stored credentials of a registry
sign Sign an image with cosign-compatible ECDSA-P256, publishing the signature next to it in the registry
tag Give another name/tag to a local image (copies nothing — it's just a new name for the same content)
export Export an OCI runtime bundle (rootfs + config.json) for `runc`/`crun`
load Load an image from an archive (the counterpart of `save`)
save Save an image to a portable archive (`docker save`'s counterpart)
apply Apply the `kind: Image` documents of a manifest
prune Remove unused images and the CAS blobs nobody references any more
vm Golden VM images (`<root>/vm-images/`): ls/pull/push/build/rm/describe
help Print this message or the help of the given subcommand(s)
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
COMMAND MAP:
Lifecycle pull · remove · push
Inspect ls · describe · history · verify · scan · sbom
Configure tag · sign · login · logout
Storage export · save · load
Declarative apply
Maintenance prune
Advanced vm
EXAMPLES:
# fetch an image from a registry
delonix image pull postgres:16
# what is on disk, and how much of it
delonix image ls
# golden VM images live in a store of their own, next to the container ones
delonix image vm ls
SEE ALSO:
delonix build · delonix container run · delonix image vm · delonix image
scan
delonix › imageimage vm
Golden VM images (<root>/vm-images/): ls/pull/push/build/rm/describe
Usage: delonix image vm [OPTIONS] <COMMAND>
Commands:
pull Fetch a VM image from an OCI registry (single-blob artifact) — with no argument, the OFFICIAL Delonix image
push Publish a local VM image to an OCI registry
rm Remove a local VM image (its disk and its metadata)
build Build a VM image: a `vm.yaml`, your own `VMfile`, or the golden recipe
import Register an existing disk image under a name, so `vm create --disk <name>` and `image vm push` can use it
init Scaffold a `VMfile` (and a cloud-init) for building your own image
describe Human-readable detail of one or more VM images, `kubectl describe`-style
ls List the local VM images
ls-remote List the tags available in a remote OCI repository
convert Convert a VM disk to the format another ecosystem imports
help Print this message or the help of the given subcommand(s)
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
COMMAND MAP:
Lifecycle rm · pull · push
Create import · init · build
Inspect ls · describe · ls-remote
Maintenance convert
EXAMPLES:
# what golden images this node already has
delonix image vm ls
# fetch the official Kubernetes golden — the source is known, so no argument
# is needed
delonix image vm pull
# build one of your own from a `VMfile`
delonix image vm build -f VMfile -t myimage:1
SEE ALSO:
delonix vm create · delonix image · delonix cluster kubeadm · delonix image
vm build
delonix › image › vmExemplosExamples
delonix image vm lsdelonix image vm init minha-basedelonix image vm build -t k8s-golden --k8s-version 1.34delonix image vm push k8s-golden ghcr.io/angolardevops/delonix-vm-k8s:1.34delonix image vm import ./OPNsense-26.1.2.qcow2 -t opnsense:26.1.2 \
--appliance --distro opnsense --release 26.1.2 \
--default-vcpus 2 --default-memory 2Gdelonix vm create fw --disk opnsense:26.1.2image logout
Remove the stored credentials of a registry
Usage: delonix image logout [OPTIONS] <REGISTRY>
Arguments:
<REGISTRY>
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# drop the stored credentials of a registry
delonix image logout ghcr.io
SEE ALSO:
delonix image login · delonix image push
delonix › image › logoutExemplosExamples
delonix image logout ghcr.ioimage login
Authenticate to an OCI registry.
Stores the credentials in <root>/auth.json, docker/podman format. The password ALWAYS comes from stdin — never from an argument (it would end up in the shell history and in /proc).
Usage: delonix image login [OPTIONS] --username <USERNAME> <REGISTRY>
Arguments:
<REGISTRY>
Registry (e.g. `ghcr.io`, `docker.io`)
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-u, --username <USERNAME>
--password-stdin
Read the password/token from stdin (the only supported way)
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# authenticate to a registry — the token comes from stdin, never from the
# argv, where it would land in the shell history and in /proc
printf '%s' "$GITHUB_TOKEN" | delonix image login ghcr.io -u angolardevops --password-stdin
# the same for Docker Hub
printf '%s' "$DOCKERHUB_TOKEN" | delonix image login docker.io -u myuser --password-stdin
SEE ALSO:
delonix image logout · delonix image push · delonix image pull
delonix › image › loginExemplosExamples
printf '%s' "$GHCR_TOKEN" | delonix image login ghcr.io --username aminhaorgimage load
Load an image from an archive (the counterpart of save).
Reads archives produced by delonix image save, docker save or podman save.
Usage: delonix image load [OPTIONS] --input <FILE>
Options:
-i, --input <FILE>
Archive to read (`.tar`; a `.tar.gz` must be gunzipped first)
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# read back an archive written by `save`, `docker save` or `podman save`
delonix image load -i postgres-16.tar
# a gzipped archive has to be gunzipped first
gunzip -c nginx.tar.gz > nginx.tar && delonix image load -i nginx.tar
SEE ALSO:
delonix image save · delonix image ls · delonix image pull
delonix › image › loadExemplosExamples
delonix image load --input app-dev.tarimage save
Save an image to a portable archive (docker save's counterpart).
The way to move an image to another machine with no registry. The archive is an OCI layout WITH the legacy manifest.json, so delonix image load, docker load, podman load and ctr images import all read it.
Usage: delonix image save [OPTIONS] --output <FILE> <IMAGE>
Arguments:
<IMAGE>
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-o, --output <FILE>
Destination file. Use `-o /dev/stdout` to pipe (e.g. into `gzip`)
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# move an image to another machine with no registry in between
delonix image save postgres:16 -o postgres-16.tar
# pipe it straight into gzip instead of writing the plain archive
delonix image save nginx -o /dev/stdout | gzip > nginx.tar.gz
SEE ALSO:
delonix image load · delonix image push · delonix image export
delonix › image › saveExemplosExamples
delonix image save app:dev --output app-dev.tarimage scan
SBOM + CVE scan of an image.
Reads the layers from the CAS, without running anything. Pulls the image if missing. See --sbom, --fail-on, --update.
Usage: delonix image scan [OPTIONS] [IMAGE]
Arguments:
[IMAGE]
Image to scan (optional with `--update`)
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
--sbom
List the SBOM (installed packages) instead of scanning
--fail-on <SEV>
Fail (exit 1) if there are vulnerabilities >= this severity (low|medium|high|critical) — gate for CI
--update
Sync the CVE feed to the local database (used afterwards by each scan)
--feed <URL|FICHEIRO>
Feed source for `--update`: URL or file (or $DELONIX_ADVISORY_FEED)
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# the CVEs of an image, read from the layers on disk — nothing is executed
delonix image scan postgres:16
# the installed packages (SBOM) instead of the findings
delonix image scan --sbom nginx
# a CI gate: exit 1 if anything high or worse is found
delonix image scan --fail-on high ghcr.io/angolardevops/app:1.2.0
# refresh the local feed first — a scan is only as fresh as the database
# behind it
delonix image scan --update
SEE ALSO:
delonix image describe · delonix image pull · delonix image verify
delonix › image › scanExemplosExamples
delonix image scan nginx:alpinedelonix image scanimage verify
Verify the cosign signature of a local image against a public key
Usage: delonix image verify [OPTIONS] <IMAGE> <PEM>
Arguments:
<IMAGE>
<PEM>
Public key in PEM
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# check the cosign signature of an image you already have against the
# publisher's key
delonix image verify ghcr.io/angolardevops/app:1.2.0 cosign.pub
# the gate to run before promoting a local build to production
delonix image verify kaeso-odoo:18 keys/kaeso.pub
SEE ALSO:
delonix image pull · delonix image scan · delonix image describe
delonix › image › verifyExemplosExamples
delonix image verify ghcr.io/aminhaorg/app:1.0 chave.pemimage history
Layers of an image (digest + size), from base to top
Usage: delonix image history [OPTIONS] <IMAGE>
Arguments:
<IMAGE>
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# the layers from base to top, with the digest and size of each
delonix image history postgres:16
# where the size went, before deciding what to change in the Dockerfile
delonix image history kaeso-odoo:18
SEE ALSO:
delonix image describe · delonix build · delonix image ls
delonix › image › historyExemplosExamples
delonix image history app:devimage tag
Give another name/tag to a local image (copies nothing — it's just a new name for the same content)
Usage: delonix image tag [OPTIONS] <SOURCE> <TARGET>
Arguments:
<SOURCE>
<TARGET>
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# a second name for the same content — nothing is copied
delonix image tag postgres:16 db:stable
# the shape a locally-built image needs before it can be pushed to your
# registry
delonix image tag kaeso-odoo:18 ghcr.io/angolardevops/kaeso-odoo:18
SEE ALSO:
delonix image push · delonix image ls · delonix image remove
delonix › image › tagExemplosExamples
delonix image tag app:dev ghcr.io/aminhaorg/app:1.0image describe
Human-readable detail of one or more images, kubectl describe-style.
Tags/digest/size/layers + the OCI config: entrypoint/cmd/env/workdir.
Usage: delonix image describe [OPTIONS] <NAMES>...
Arguments:
<NAMES>...
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# tags, digest, size, layers and the OCI config (entrypoint/cmd/env/workdir)
# in one screen
delonix image describe postgres:16
# several at once, to compare what two images actually run
delonix image describe alpine:3.19 redis:7-alpine
SEE ALSO:
delonix image ls · delonix image history · delonix image scan
delonix › image › describeExemplosExamples
delonix image describe nginx:alpineimage pull
Pull an image from a registry
Usage: delonix image pull [OPTIONS] <IMAGE>
Arguments:
<IMAGE>
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
--verify <PEM>
Verify the cosign signature with this public key (PEM) AFTER the pull, and fail if it does not match. Without this, a pull is not authenticated beyond the registry's own digest
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# the common case — repository and tag
delonix image pull postgres:16
# a registry other than Docker Hub — write it out in the reference
delonix image pull ghcr.io/angolardevops/kaeso-odoo:18
# refuse the image unless it carries a cosign signature made by this key
delonix image pull --verify cosign.pub ghcr.io/angolardevops/app:1.2.0
SEE ALSO:
delonix image ls · delonix image scan · delonix image verify · delonix image
vm pull
delonix › image › pullExemplosExamples
delonix image pull kindest/node:v1.34.0@sha256:7416a6…image ls
List local images
Usage: delonix image ls [OPTIONS]
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-o, --output <OUTPUT>
Output format: `table` (default) or `json` (ADR-0005)
[default: table]
[possible values: table, json]
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# what is on disk, newest first
delonix image ls
# as JSON, for a script to read instead of a table meant for eyes
delonix image ls -o json
SEE ALSO:
delonix image describe · delonix image history · delonix image remove
delonix › image › lsExemplosExamples
delonix image lsimage remove
Remove a local image
Usage: delonix image remove [OPTIONS] <IMAGE>
Arguments:
<IMAGE>
Options:
-f, --force
Remove it even if a container still uses it
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# remove an image nothing is using
delonix image remove alpine:3.19
# remove it even though a container still references it
delonix image remove -f odoo:16
SEE ALSO:
delonix image ls · delonix container rm · delonix system prune
delonix › image › removeExemplosExamples
delonix image remove alpine:3.19image export
Export an OCI runtime bundle (rootfs + config.json) for runc/crun
Usage: delonix image export [OPTIONS] <IMAGE> <DIR>
Arguments:
<IMAGE>
<DIR>
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# an OCI runtime bundle (rootfs + config.json) that `runc` or `crun` runs
# directly
delonix image export alpine:latest /tmp/alpine-bundle
# the directory you then hand to another OCI runtime — this is a bundle to
# run, not an archive to ship
delonix image export postgres:16 /tmp/pg-bundle
SEE ALSO:
delonix image save · delonix image load · delonix container run
delonix › image › exportExemplosExamples
delonix image export alpine:3.19 /tmp/bundle && sudo runc run -b /tmp/bundle testeimage push
Publish a local image to an OCI registry.
Without target, publishes under the image's own reference.
Usage: delonix image push [OPTIONS] <NAME> [TARGET]
Arguments:
<NAME>
[TARGET]
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# publish under the image's own reference
delonix image push ghcr.io/angolardevops/app:1.2.0
# publish a locally-named image under another reference, without tagging it
# first
delonix image push kaeso-odoo:18 ghcr.io/angolardevops/kaeso-odoo:18
SEE ALSO:
delonix image login · delonix image tag · delonix image vm push
delonix › image › pushExemplosExamples
delonix image push ghcr.io/angolardevops/app:1.2.0delonix image push kaeso-odoo:18 ghcr.io/angolardevops/kaeso-odoo:18image apply
Apply the kind: Image documents of a manifest.
pull is idempotent by reference; build rebuilds and replaces the tag on each apply.
Usage: delonix image apply [OPTIONS]
Options:
-f, --file <FILE>
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# apply only the `kind: Image` documents of `./delonix-manifest.yaml`,
# ignoring the other Kinds
delonix image apply
# from a file of your own
delonix image apply -f delonix-manifest.yaml
SEE ALSO:
delonix stack apply · delonix stack plan · delonix image pull
delonix › image › applyExemplosExamples
delonix image apply -f delonix-manifest.yamlLaboratórioLab
Traz uma imagem, dá-lhe uma tag própria, e olha para o histórico de camadas antes de a exportar.
delonix image pull alpine:3.20
delonix image tag alpine:3.20 meu-alpine:v1
delonix image history meu-alpine:v1
delonix image export meu-alpine:v1 -o alpine.tarPull an image, give it your own tag, and look at the layer history before exporting it.
delonix image pull alpine:3.20
delonix image tag alpine:3.20 my-alpine:v1
delonix image history my-alpine:v1
delonix image export my-alpine:v1 -o alpine.tarDesafioChallenge
Antes de trazer a imagem VM dourada, vê que versões existem
publicadas com ls-remote — sem descarregar nada — e só depois traz a que quiseres.
delonix image vm ls-remote
delonix image vm pullBefore pulling the golden VM image, check which versions are
published with ls-remote — without downloading anything — and only then pull the one
you want.
delonix image vm ls-remote
delonix image vm pull