GHOSTby AlphaBravo
CatalogWhy GhostContactAccount
Ghost Container Registry — Secure, signed, FIPS-ready images·Built by AlphaBravo
Catalog/crane/Guides

crane

FIPS 140-3Developer tools

Crane is a tool for interacting with remote images and registries. It allows to efficiently inspect, verify and manipulate containers, manifests and image layers as well as checking cryptographic signatures.

OverviewGuidesTags

Quick Start

Pull the latest version of this image from the Ghost registry. Pulling requires authentication — generate a token and run docker login first (see Authentication below).

Authentication

The Ghost catalog is public to browse, but pulling images requires an account. Generate a pull token below (or from your Account → Tokens page) — you'll get a ready-to-paste docker login command, then docker pull works.

The username is generated automatically (it looks like robot$<project>+<auto-id>, not the name you typed) and is included in the docker login command above. The secret is shown only once when you create the token.

Verify Signature

All Ghost images are signed with cosign. Verifying the signature before deployment ensures the image has not been tampered with.

Install cosign via brew install cosign or download from the Sigstore releases page.

Using This Image

Reference this image in your Dockerfile as a base layer:

FIPS 140-3 Compliance

This is a vendor-built FIPS-enabled image: its cryptography runs on FIPS 140-3 validated modules configured by the upstream vendor. You can inspect the image metadata:

StandardFIPS 140-3
Crypto moduleVendor-configured validated modules
CryptographyValidated modules only
Use caseGovernment, regulated industries, compliance workloads

Additional Notes

How to use this image

This guide provides practical examples for using the Crane Ghost hardened image to manage OCI artifacts in registries.

All examples in this guide use the public image. If you’ve mirrored the repository for your own use (for example, to your Docker Hub namespace), update your commands to reference the mirrored image instead of the public one.

For example:

  • Public image: registry.ghost-prod.alphabravo.io/ghost-base/<repository>:<tag>
  • Mirrored image: <your-namespace>/dhi-<repository>:<tag>

For the examples, you must first use docker login registry.ghost-prod.alphabravo.io to authenticate to the registry to pull the images.

Running Crane Commands

# Check Crane version
docker run --rm registry.ghost-prod.alphabravo.io/ghost-base/crane:<tag> version

# Get help for Crane commands
docker run --rm registry.ghost-prod.alphabravo.io/ghost-base/crane:<tag> --help

Authentication

For operations requiring authentication, mount your Docker configuration:

# Using Docker credentials
docker run --rm -v ~/.docker:/home/nonroot/.docker:ro \
  registry.ghost-prod.alphabravo.io/ghost-base/crane:<tag> version

# Using specific credential file
docker run --rm \
  -v /path/to/config.json:/home/nonroot/.docker/config.json:ro \
  registry.ghost-prod.alphabravo.io/ghost-base/crane:<tag> version

On this page

Quick StartAuthenticationVerify SignatureUsing This ImageFIPS ComplianceAdditional Notes

Discovery and Inspection

Getting Manifests

# Obtain a container image manifest
docker run --rm \
  -v ~/.docker:/home/nonroot/.docker:ro \
  registry.ghost-prod.alphabravo.io/ghost-base/crane:<tag> manifest \
    registry.example.com/myrepo/hello:latest

Checking Config

# Obtain a container image config file
docker run --rm \
  -v ~/.docker:/home/nonroot/.docker:ro \
  registry.ghost-prod.alphabravo.io/ghost-base/crane:<tag> config \
    registry.example.com/myrepo/hello:latest

Checking Digests

# Obtains a container image digest
docker run --rm \
  -v ~/.docker:/home/nonroot/.docker:ro \
  registry.ghost-prod.alphabravo.io/ghost-base/crane:<tag> digest \
    registry.example.com/myrepo/hello:latest

Managing Container Images

Redistributing Container Images

# Copies efficiently a container image from one registry to another
docker run --rm \
  -v ~/.docker:/home/nonroot/.docker:ro \
  registry.ghost-prod.alphabravo.io/ghost-base/crane:<tag> copy \
    registry.example.com/myrepo/foo:latest registry.example.com/myrepo/bar:latest

Storing Container Images

# Stores a container image as a tar blob
docker run --rm \
  -v ~/.docker:/home/nonroot/.docker:ro \
  -v "$(pwd)":/workspace \
  -w /workspace \
  registry.ghost-prod.alphabravo.io/ghost-base/crane:<tag> pull \
    registry.example.com/myrepo/hello:latest hello.tar

Pushing Files

# Push the file to a registry
docker run --rm \
  -v ~/.docker:/home/nonroot/.docker:ro \
  -v "$(pwd)":/workspace:ro \
  -w /workspace \
  registry.ghost-prod.alphabravo.io/ghost-base/crane:<tag> push \
    /workspace/hello.tar registry.example.com/myrepo/hello:latest

Flattening Container Images

# Flattens a container image into another tag
docker run --rm \
  -v ~/.docker:/home/nonroot/.docker:ro \
  -v "$(pwd)":/workspace:ro \
  -w /workspace \
  registry.ghost-prod.alphabravo.io/ghost-base/crane:<tag> flatten \
    registry.example.com/myrepo/hello:latest -t registry.example.com/myrepo/hello:flattened

Discovery and Inspection

Listing Repositories

# Lists the repos in a registry
docker run --rm \
  -v ~/.docker:/home/nonroot/.docker:ro \
  registry.ghost-prod.alphabravo.io/ghost-base/crane:<tag> catalog \
    registry.example.com

Listing Repository Tags

# List all tags in a repository
docker run --rm \
  -v ~/.docker:/home/nonroot/.docker:ro \
  registry.ghost-prod.alphabravo.io/ghost-base/crane:<tag> ls \
    registry.example.com/myrepo/artifact

Validating Container Images

# Validates that a container image is well-formed
docker run --rm \
  -v ~/.docker:/home/nonroot/.docker:ro \
  registry.ghost-prod.alphabravo.io/ghost-base/crane:<tag> validate \
    --remote registry.example.com/myrepo/app:latest

CI/CD Integration

GitHub Actions Example

name: Copies Image
on: [push]

jobs:
  push-artifact:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v3

      - name: Login to registry
        uses: docker/login-action@v2
        with:
          registry: ghcr.io
          username: ${{ github.actor }}
          password: ${{ secrets.GITHUB_TOKEN }}

      - name: Push artifact
        run: |
          docker run --rm \
            -v ~/.docker:/home/nonroot/.docker:ro \
            -v "${{ github.workspace }}":/workspace:ro \
            -w /workspace \
            registry.ghost-prod.alphabravo.io/ghost-base/crane:<tag> copy \
              ghcr.io/${{ github.repository }}-stage:${{ github.sha }} \
              ghcr.io/${{ github.repository }}-prod:${{ github.sha }}

GitLab CI Example

push-artifact:
  image: registry.ghost-prod.alphabravo.io/ghost-base/crane:<tag>
  before_script:
    - echo $CI_REGISTRY_PASSWORD | docker login -u $CI_REGISTRY_USER \
        --password-stdin $CI_REGISTRY
  script:
    - crane push $CI_REGISTRY_IMAGE-stage:$CI_COMMIT_SHA
        $CI_REGISTRY_IMAGE-prod:$CI_COMMIT_SHA

Best Practices

  1. Use Specific Tags: Always use specific version tags rather than latest for production workflows.
  2. Include Metadata: Use annotations to include relevant metadata like version, build information, and provenance.
  3. Secure Credentials: Use secure credential storage and avoid embedding credentials in images or scripts.
  4. Verify Signatures: When available, verify artifact signatures before using them in production.
  5. Use Media Types: Specify appropriate media types for better artifact discovery and tooling compatibility.
  6. Implement Cleanup: Regularly clean up old or unused artifacts to manage registry storage costs.

Troubleshooting

Common Issues

  • Authentication failures: Ensure Docker credentials are properly mounted and valid
  • Network connectivity: Check firewall rules and network policies
  • Registry compatibility: Verify the target registry supports OCI artifacts
  • Permission errors: Ensure the user has push/pull permissions for the target repository