Re: [Openembedded-architecture] RFQ: Yocto Project Reference Containers

"Weber (US), Matthew L" <[email protected]> Mon, 23 Feb 2026 15:06:04 +0000
Newsgroups org.yoctoproject.lists.yocto
Message-ID <BN0P110MB20672B646387310764FA5DBBF377A@BN0P110MB2067.NAMP110.PROD.OUTLOOK.COM>
> -----Original Message-----
> From: [email protected] <[email protected]> On Behalf Of Paul Barker
> Sent: Monday, February 23, 2026 7:46 AM
> To: Alexander Kanavin <[email protected]>
> Cc: [email protected]; [email protected]
> Subject: Re: [Openembedded-architecture] RFQ: Yocto Project Reference Containers
> 
> On Mon, 2026-02-23 at 13:39 +0100, Alexander Kanavin wrote:
> > On Mon, 23 Feb 2026 at 13:10, Paul Barker via lists.openembedded.org 
> > <[email protected]> wrote:
> > > New recipes must be defined for an initial set of reference container images, using the `image-oci` bbclass in meta-virtualization. > The initial set should focus on software which is commonly deployed via containers, such as:
> > > 
> > > A minimal image (based on core-image-minimal) A Python 3 base image 
> > > A sample web application written in Python A PostgreSQL database 
> > > server A multi-service container using systemd to manage services
> > > 
> > > The above list is not intended to be prescriptive - we appreciate input on appropriate reference container images. The final list of > approximately 3-5 reference container images will be agreed with the Yocto Project TSC.
> > 
> > An image containing bitbake-setup and everything else (e.g.
> > buildtools-extended) needed to set up and run yocto builds?
> 
> I think that would be a logical next step in the future. With the reference containers in this RFQ though, we want to focus on "cloud" > use cases to show that we can do more than just embedded. The goal is to reach a wider audience and generate new interest.

If considering "cloud" cases, would the reference containers have:

1) Signing (sigstore) and a prototype of the workflow to build on + attest?
2) Any prototype of recuring registry scans + reporting?
3) Any of the meta-security building blocks for security hardening?  (e.g., Security Technical Implementation Guide(STIG), build/runtime flags)

100% good with these questions getting added to a (future) list.

Best regards,
—
Matthew L. Weber
The Boeing Company / Associate Technical Fellow
ELISA Aerospace WG Chair