Your Container Image Customizations Belong to You, Not Your Vendor

Your Container Image Customizations Belong to You, Not Your Vendor
Container image customizations shown as a complex Rube Goldberg build pipeline with multiple vendor portals versus a simple Containerfile

I’ve been having a lot of conversations lately with people who are evaluating hardened container image vendors, and one particular feature keeps coming up that, frankly, surprises me. Customers are asking vendors like Docker and Chainguard to pre-inject customizations into container images on their behalf, things like CA certificates, security configurations, and other environment-specific tweaks.