Coming soon
Writing Dockerfiles that stay small and quick to rebuild, multi-stage builds that keep build tools out of the image you ship, and provenance attestations that record how an image was made. The worked example is hcw-lab, the image every browser lab on this site runs: one Dockerfile, two build targets, and every download checked against a pinned checksum.
- Dockerfiles
- Multi-stage builds
- Provenance