Continuity controls
Make the container path reproducible without one laptop, registry tag, or daemon administrator.
Container estates accumulate local-only build steps, mutable tags, undocumented base choices, secrets in history, hidden host mounts, daemon socket shortcuts, unbounded resources, health folklore, orphaned volumes, and recovery procedures that restore a filesystem but not usable application state. The client record should let another qualified person rebuild, verify, run, recover, and retire the path.
- Client-held image and runtime register
- Workloads and owners, source and build definitions, bases and dependencies, image digests and platforms, provenance and registries, hosts and engines, runtime configuration, users and policies, mounts and state, networks and ports, resources and health, deployments, vulnerabilities, incidents, backup and restore, costs, versions, exceptions, migrations and retirement remain current in approved client systems.
- Reproducible build and recovery chain
- Versioned Dockerfiles and contexts, locked inputs, controlled builders, temporary secret mounts, representative fixtures, final-image tests, manifests, SBOM and provenance where required, registry and promotion receipts, runtime definitions, policy and resource tests, network and volume inventory, exact release markers, shutdown and failure exercises, protected backups, restore and reconciliation evidence, runbooks and owner acceptance let the client repeat important paths safely.
- Least-privilege host and supply-chain authority
- Source, builder, cache, registry, signing, host, daemon, runtime, network, storage, secret, data, deployment, telemetry, recovery and cleanup identities are scoped and auditable; privileged containers, host mounts, devices, Docker API access, policy exceptions and destructive cleanup require explicit review; and emergency credentials can be revoked without losing the operating record.
- Demonstrated rebuild, operation, and exit
- A receiving specialist can obtain approved access, trace an image digest to source and inputs, rebuild and test a representative target, verify artifact evidence, start it with the intended user and boundaries, explain its networks, state and resource controls, diagnose one failure, stop it safely, restore and reconcile representative data, apply an approved image update, and retire an obsolete image and volume without the original specialist present.