Kungfu Build Images
July 26, 2026 ยท View on GitHub
This repository is the source of truth for maintained Kungfu build container images.
The images are runtime environment assets. They are versioned and released as a coherent family through Buildchain-governed repository releases, then consumed by trusted workflows by exact tag or immutable digest.
Initial Image Family
base-linux
-> kungfu-verify
-> node24-pnpm
-> native-linux-x64
base-linuxdefines the common Linux build baseline.kungfu-verifyfixes the lightweight Kungfu CI entry tools used bykungfu-code sync, verify jobs, and publish preparation jobs.node24-pnpmadds Node.js 24 and pnpm for GitHub Action and JavaScript build surfaces.native-linux-x64adds common native build tooling for Linux x64 consumers.
Native Kungfu build images should layer on top of kungfu-verify when their
contract needs the same Buildchain entry tools plus C++/Conan/CMake tooling.
Repository Contract
- Image metadata lives in
images/<name>/image.toml. - Dockerfiles live next to their manifest.
- The manifest graph is shallow and explicit.
- Child images must reference a known parent image from this repository.
- Release summaries must record every published digest.
- Consumers that require reproducibility should pin images by digest.
Local Verification
pnpm run check
The default verification path validates buildchain.toml, image manifests,
the image lock, workflow syntax, and shell syntax. It does not publish images
and does not require a self-hosted runner.
The GitHub Verify workflow exposes a check job so Buildchain v3 promotion
can use it as the protected release-line status check.
Release Model
The repository uses one Buildchain release version for the image family at first. Buildchain v3 owns channel promotion, image publish transactions, durable publish evidence, and exact release tags. Exact image tags mirror exact repository tags, for example:
ghcr.io/kungfu-systems/build-images/base-linux:v1.0.0
ghcr.io/kungfu-systems/build-images/kungfu-verify:v1.0.0
ghcr.io/kungfu-systems/build-images/node24-pnpm:v1.0.0
ghcr.io/kungfu-systems/build-images/native-linux-x64:v1.0.0
See docs/release-and-tags.md for the tag and digest contract.
Runner Boundary
The first release path should prefer GitHub-hosted runners for image build and publish. Do not grant Docker group membership or sudo to an existing self-hosted GitHub Actions runner service account.
See docs/runner-boundary.md.