Immutable artifacts (for example, a container image tagged
v1.1.1 or a specific digest) make deployments reproducible and auditable. Use registries to centralize storage, access control, vulnerability scanning, and promotion workflows.
- Repeatable deployments and rollbacks
- Supply-chain security scans and SBOMs
- Multi-architecture builds and transparent delivery
- Global distribution and caching

- Developers: fast, reliable builds and deployments.
- Security teams: continuous scanning, SBOMs, and signing.
- Operations: predictable, reproducible artifacts and rollbacks.



- Include language-specific artifacts in the image and rely on the runtime within the container at deploy time.
- Build (bake) compiled artifacts into the container image during CI.


- Tagging, manifests, and immutable digests for traceability
- Layer storage and deduplication (for container images)
- Access control, retention policies, and replication
- Integrated vulnerability scanning, SBOM generation, and signing
- Docker Hub — public container registry
- JFrog Artifactory — universal artifact registry (commercial)
- Harbor — CNCF project focused on cloud-native registries
- Cloud provider registries (AWS ECR, GCR, Azure Container Registry)


- Automated vulnerability scanning across formats (images, JARs, npm, wheels)
- SBOM (Software Bill of Materials) generation for transparency
- Policy gates (preventing promotion of vulnerable artifacts)
- Signing and verification to secure the supply chain


- Automatic CI promotion for non-prod environments
- Manual QA approvals or gated pipelines before production
- Traceability for each promotion step (who approved, when, and which artifact digest)


- Harbor — cloud-native artifact registry (CNCF project): https://goharbor.io/
- containerd — container runtime, not a registry: https://containerd.io/
- Notary — image signing and verification (supply-chain security): https://github.com/notaryproject/notary
- OCI — Open Container Initiative, specifying image and runtime formats: https://opencontainers.org/

- Registry infrastructure (high-availability, replication, retention and lifecycle rules).
- Security policies (automated scanning, SBOM generation, signing, RBAC, and enforcement).
- Promotion automation (pipelines, approvals, audit logs, and artifact traceability).

- Prioritize container images for cloud-native deployments but support multiple package and image types.
- Use semantic tags, architecture tags, and manifests for traceability.
- Integrate security into the artifact lifecycle (scanning, SBOMs, signing, and policy gates).
- Maintain golden/standard base images that are immutable and scanned to enforce consistency.
- Support multi-architecture images where required and reuse common layers to optimize storage and cost.


Tip:
Harbor is a cloud-native artifact registry; containerd is a container runtime; Notary enables signing; OCI defines container standards. These distinctions are important for platform design and certification preparation.
- Harbor: https://goharbor.io/
- JFrog Artifactory: https://jfrog.com/artifactory/
- Docker Hub: https://hub.docker.com/
- containerd: https://containerd.io/
- Notary Project: https://github.com/notaryproject/notary
- OCI (Open Container Initiative): https://opencontainers.org/