Sign inSign up

niceos/base-os

By niceos

Updated 12 months ago

Premium rolling-release NiceOS Linux base image. Built for containers: minimal, secure.

Image
Operating systems
2

291

niceos/base-os repository overview

🌐 NiceOS Base Image

Docker Pulls License: GPL-2.0


🧩 What is NiceOS Base?

NiceOS Base is not just another minimal Linux image.
It is a premium, purpose-built, rolling-release operating system, engineered from the ground up for containers.

No systemd.
No background daemons.
No accidental cruft.

Every package, every flag, every layer is deliberate.
This is not a stripped-down general-purpose distro.
This is the first and only RPM-based operating system designed exclusively for containers.


🔄 Rolling Release Model

NiceOS follows a rolling release strategy, tuned for production:

  • Predictable cadence: updates ship once per month, after full QA and integration testing.
  • Critical CVEs: patches are delivered immediately, without waiting for the next cycle.
  • 🧩 This balance ensures you run fresh code, but without the churn of unstable nightly images.
  • 📌 Stable tags (5.2-latest-x86_64) for convenience, pinned builds (5.2-<build>-x86_64) for determinism.

Rolling does not mean chaos. It means a living base system, carefully curated to stay modern, secure, and trustworthy.


🛡 Premium Security Workflow

Every push is more than a build — it’s a security ritual:

  1. 🔍 Dependency scanning with multiple engines (grype, trivy).
  2. 📜 SBOM generation (SPDX and CycloneDX) — software composition is always visible.
  3. Automatic gating: if a critical vulnerability is detected, the image never ships.
  4. 📦 Reports embedded directly in the image under /nicesoft/niceos/reports/.

When you pull NiceOS, you don’t just get a base system.
You get proof of integrity — transparent, verifiable, undeniable.

Example auto-generated metadata:

{
  "releasever": "5.2",
  "arch": "x86_64",
  "build_number": "latest",
  "profile": "runtime",
  "products": ["gdu", "niceos-repos", "tdnf"],
  "product_versions": {
    "gdu": "5.31.0",
    "niceos-repos": "5.2",
    "tdnf": "3.5.12"
  },
  "reports": {
    "in_chroot": "/nicesoft/niceos/reports/5.2-latest-x86_64",
    "grype_dir_json": "/nicesoft/niceos/reports/5.2-latest-x86_64/grype.dir.vulns.json",
    "index_json": "/niceos/nicesoft/reports/5.2-latest-x86_64/index.json"
  }
}

Pull the image, open the reports — the truth is right there. No hidden issues. No blind trust. Security you can inspect.


✨ Why This is Truly “Premium”

NiceOS Base is not an accident of repackaging. It’s a contract of trust:

  • 🔒 CVE discipline → no critical CVEs pass. Medium and low issues are tracked, triaged, and reported.
  • 🧪 Reproducible builds → pinned rootfs tarballs, verified SHA256.
  • 🧹 Clean layers → caches, logs, and noise removed. Every byte has purpose.
  • 📊 Observability baked in → SBOMs and vulnerability scan reports ship inside the image.
  • 📦 Curated essentials onlybash, coreutils, tdnf, SSL, CA certs — nothing more, nothing less.
  • 🚀 Optimized for runtime → no build toolchains, no init, no detours.
  • 🧱 Container-first contract → one promise: a clean, stable foundation for your workloads.

This is not “just a minimal distro.” This is the premium RPM-based container OS.


🚀 Quick Start

# Pull the latest stable build
docker pull niceos/base-os:5.2-latest-x86_64

# Run an interactive shell
docker run -it --rm niceos/base-os:5.2-latest-x86_64 bash

Use it as your base:

FROM niceos/base-os:5.2-latest-x86_64
RUN tdnf install -y less && \
    tdnf clean all && \
    rm -rf /var/cache/tdnf/*

🏷 Tags

  • 5.2-latest-x86_64 → stable rolling release (monthly refreshed).
  • 5.2-<build>-x86_64 → pinned, deterministic builds.

📦 What’s Inside

Core runtime packages include:

  • bash-5.3, coreutils-9.7, tdnf-3.5.12
  • glibc-2.42, openssl-3.5.3, ca-certificates-1.16.1
  • curl-libs-8.16.0, gdu-5.31.0, ncurses-6.5
  • Supporting libs: zlib, xz, zstd, and others.

Not one package more. Not one package less.


🧭 Philosophy

NiceOS Base is not a derivative of something bloated. It is a system with purpose, not an accident of history.

  • Not “just busybox minimalism.” Instead: a careful balance of usability and slimness.
  • Not “security theater.” Instead: verifiable hardening, CVE discipline, transparent scanning.
  • Not “forks and hacks.” Instead: a clean RPM-based ecosystem, intentionally built for containers.

👉 This is not a distro. This is a contract of trust.

With NiceOS Base you inherit no baggage, no noise. You inherit clarity, predictability, and confidence.


📖 Support


📜 License

GPL-2.0-only WITH Classpath-exception-2.0 See LICENSE for details.


🌐 NiceOS Base Image

Docker Pulls License: GPL-2.0


🧩 Что такое NiceOS Base?

NiceOS Base — это не просто ещё один минимальный Linux-образ.
Это премиальная, специализированная, rolling-release операционная система, созданная с нуля для контейнеров.

Никакого systemd.
Никаких фоновых демонов.
Никакого случайного хлама.

Каждый пакет, каждый флаг, каждый слой выверен.
Это не урезанная версия универсального дистрибутива.
Это первая и единственная RPM-базированная операционная система, созданная исключительно для контейнеров.


🔄 Rolling Release модель

NiceOS использует rolling-release стратегию, ориентированную на продакшн:

  • Предсказуемый ритм: обновления выпускаются раз в месяц после полного QA и интеграции.
  • Критические CVE: закрываются немедленно, не дожидаясь планового релиза.
  • 🧩 Такой баланс даёт актуальность без хаоса ночных билдов.
  • 📌 Удобные стабильные теги (5.2-latest-x86_64) и зафиксированные сборки (5.2-<build>-x86_64) для CI/CD.

Rolling здесь — не хаос. Rolling — это дыхание системы.
Это не буря каждую ночь, а аккуратное, предсказуемое течение.
Стабильность не приносится в жертву новизне, а новизна не тормозится страхом стабильности.
Каждый выпуск — это маленький шаг вперёд, сделанный без суеты.


🛡 Премиальный security-пайплайн

Каждый push — это больше, чем билд. Это ритуал безопасности:

  1. 🔍 Сканирование зависимостей несколькими движками (grype, trivy).
  2. 📜 Генерация SBOM (SPDX и CycloneDX) — состав ПО всегда прозрачен.
  3. Автоматический стоп: если найдена критическая уязвимость, образ не публикуется.
  4. 📦 Отчёты вшиваются прямо в образ под /nicesoft/niceos/reports/.

Скачивая NiceOS, вы получаете не просто систему.
Вы получаете доказательство целостности — прозрачное, проверяемое, безусловное.

Пример автоматически генерируемых метаданных:

{
  "releasever": "5.2",
  "arch": "x86_64",
  "build_number": "latest",
  "profile": "runtime",
  "products": ["gdu", "niceos-repos", "tdnf"],
  "product_versions": {
    "gdu": "5.31.0",
    "niceos-repos": "5.2",
    "tdnf": "3.5.12"
  },
  "reports": {
    "in_chroot": "/nicesoft/niceos/reports/5.2-latest-x86_64",
    "grype_dir_json": "/nicesoft/niceos/reports/5.2-latest-x86_64/grype.dir.vulns.json",
    "index_json": "/nicesoft/niceos/reports/5.2-latest-x86_64/index.json"
  }
}

Тяните образ, открывайте отчёты — правда лежит прямо внутри. Никаких скрытых дыр. Никакой слепой веры. Безопасность, которую можно проверить.


✨ Почему это действительно «Премиум»

NiceOS Base — это не случайный ремикс. Это контракт доверия:

  • 🔒 Дисциплина CVE → критические уязвимости не проходят. Средние и низкие фиксируются, документируются и отслеживаются.
  • 🧪 Воспроизводимость → rootfs с SHA256, пинованные версии, предсказуемый билд.
  • 🧹 Чистые слои → никакого мусора, очищенные кэши, только нужное.
  • 📊 Наблюдаемость встроена → SBOM и отчёты сканеров поставляются внутри образа.
  • 📦 Только необходимоеbash, coreutils, tdnf, SSL, CA certs.
  • 🚀 Оптимизация под runtime → никаких toolchain, init-систем и обходных путей.
  • 🧱 Container-first контракт → одно обещание: быть чистой и стабильной основой для ваших приложений.

Это не «просто минималистичный дистрибутив». Это премиальная RPM-based контейнерная ОС.


🚀 Быстрый старт

# Скачайте последний стабильный билд
docker pull niceos/base-os:5.2-latest-x86_64

# Запустите интерактивную оболочку
docker run -it --rm niceos/base-os:5.2-latest-x86_64 bash

Используйте как базовый слой:

FROM niceos/base-os:5.2-latest-x86_64
RUN tdnf install -y less && \
    tdnf clean all && \
    rm -rf /var/cache/tdnf/*

🏷 Теги

  • 5.2-latest-x86_64 → стабильный rolling-release (обновляется ежемесячно).
  • 5.2-<build>-x86_64 → зафиксированные, детерминированные сборки.

📦 Что внутри

Основные runtime-пакеты:

  • bash-5.3, coreutils-9.7, tdnf-3.5.12
  • glibc-2.42, openssl-3.5.3, ca-certificates-1.16.1
  • curl-libs-8.16.0, gdu-5.31.0, ncurses-6.5
  • Поддерживающие библиотеки: zlib, xz, zstd и др.

Ни одного лишнего пакета. Ни одного недостающего.


🧭 Философия

NiceOS Base — это не урезанная копия чего-то большого. Это система с целью, а не побочный продукт истории.

  • Не «аскетичный busybox». Вместо этого: продуманный баланс минимализма и удобства.
  • Не «театр безопасности». Вместо этого: проверяемый hardening, дисциплина CVE, прозрачные сканы.
  • Не «форки и хаки». Вместо этого: чистая RPM-экосистема, изначально созданная под контейнеры.

👉 Это не дистрибутив. Это контракт доверия.

С NiceOS Base вы не наследуете хлам и шум. Вы наследуете ясность, предсказуемость и уверенность.


📖 Поддержка


📜 Лицензия

GPL-2.0-only WITH Classpath-exception-2.0 Подробнее: LICENSE

Tag summary

Content type

Image

Digest

sha256:f7113930f

Size

246 Bytes

Last updated

12 months ago

docker pull niceos/base-os:sha256-83a6bcf36ac434cc87d08d522c8eb2983d4af2350704cf5a7e7b430de05e3a0d.sig