Your Container Image Customizations Belong to You, Not Your Vendor

Your Container Image Customizations Belong to You, Not Your Vendor
Container image customizations shown as a complex Rube Goldberg build pipeline with multiple vendor portals versus a simple Containerfile

I’ve been having a lot of conversations lately with people who are evaluating hardened container image vendors, and one particular feature keeps coming up that, frankly, surprises me. Customers are asking vendors like Docker and Chainguard to pre-inject customizations into container images on their behalf, things like CA certificates, security configurations, and other environment-specific tweaks.

Red Hat Summit 2026: Introducing Fedora Hummingbird Linux

May 12-13, 2026 | Atlanta, GA Speakers: Stef Walter & Scott McCarty At Red Hat Summit 2026, Stef Walter and I introduced Fedora Hummingbird Linux — a new Linux for Builders. Abstract With more software being written faster than ever — driven by AI-assisted development — the security landscape is changing. More software means more

Red Hat Summit 2026: The Roadmap Beyond Red Hat Enterprise Linux 10: Building Platforms the Open Source Way

May 12-13, 2026 | Atlanta, GA Speakers: Brian Stinson & Scott McCarty At Red Hat Summit 2026, Brian Stinson and I presented “The Roadmap Beyond Red Hat Enterprise Linux 10: Building Platforms the Open Source Way.” Abstract How do you build the world’s most trusted enterprise Linux platform — transparently, collaboratively, and in the open?

Red Hat Summit 2026: From Fedora to RHEL: Building the Future of Enterprise Linux Together

May 12-13, 2026 | Atlanta, GA Speakers: Jef Spaleta & Scott McCarty At Red Hat Summit 2026, Jef Spaleta (Fedora Project Lead) and I presented “From Fedora to RHEL: Building the Future of Enterprise Linux Together.” Abstract This session explores the pipeline from Fedora to Red Hat Enterprise Linux, covering the RHEL 10 launch and

MCP-Airlock Is Now Trentina: The 1377 Quarantine That Inspired Our Rename

MCP-Airlock Is Now Trentina: The 1377 Quarantine That Inspired Our Rename
Trentina MCP security - medieval ship anchored near quarantine island off Ragusa, with torn tape labels reading Trentina, 1377, Quarantine, and MCP Security on aged parchment

MCP-Airlock is becoming Trentina — named after the 1377 quarantine system from Ragusa that inspired its architecture. Same three-layer defense, same gateway, better name.

Project Bluefin is Helping Prove That Dark Factories Work for Operating Systems

Project Bluefin is Helping Prove That Dark Factories Work for Operating Systems
90s zine collage showing a fire truck crossed out with a red X next to a building inspector clipboard with green checkmarks and the GNOME foot logo, representing the shift from reactive bug reporting to automated desktop testing

Six years ago, I wrote about the good, better, best approach to Linux quality when evaluating container images. The same framework applies to desktop Linux distributions – maybe even more so, because desktops have a GUI that’s notoriously hard to test automatically. Here’s what I wrote: Good: Use a bug tracker and collect problems as

Put The Tron Ares Album On and Build Something at Midnight

Put The Tron Ares Album On and Build Something at Midnight
You Have to Build with AI to Get Tron Ares

I’ve loved Tron since I was a kid. When I was about seven or eight years old (early 1980s!!!), my Mom took me to see Walt Disney’s Magic Kingdom on Ice at the Richfield Coliseum, which was this massive arena between Cleveland and Akron (sadly, torn down in 1999). The show had a Tron segment,

image mode Gave Me the Confidence to Go Fully Agentic

image mode Gave Me the Confidence to Go Fully Agentic
image mode Gave Me the Confidence to Go Fully Agentic - thumbnail showing broken packages vs container registry

I’ve been running Claude Code on my RHEL 10 workstation for a few months now, and I have to admit, with some embarrassment, I often run it with the ominous –dangerously-skip-permissions option. It reads and writes files, executes shell commands, installs packages, modifies system configs, all without asking permission first. I’ve been letting an AI