ClearCutt
Hardened Image Blueprint
The forkable platform kit for hardened base images

Hardened Base Images,
Evidence Built In.

Fork the kit · Own the trust chain

ClearCutt is a free, forkable platform kit for publishing your own hardened base-image fleet — with signatures, SBOM attestations, SLSA provenance, catalog evidence, app-team templates, and governance gates under your own GitHub OIDC identities. You run the pipeline; there is no hosted ClearCutt control plane to trust.

Cryptographic Seal
Sigstore OIDC & Attestations
Runtime Fleet
Nix Immutable store closures
App Teams FLEXIBLE OVERLAY
dev, certify, rebase, deploy

One kit, from fleet ownership to app updates

Managers see the operating outcome; platform engineers can follow each step into commands, workflow evidence, and policy hooks.

  1. 1 Own the fleet

    Platform teams fork the kit and turn base images into governed source, not a vendor dependency.

    clearcutt.fleet.yaml · Nix matrix · platform status

  2. 2 Publish evidence

    Release workflows produce signed images, SBOMs, provenance, scans, and a catalog that shows each channel independently.

    catalog build · release evidence · SLSA + Sigstore

  3. 3 Onboard apps

    App teams get matching dev images, starter templates, and rebasable build paths without learning Nix.

    list · inspect · dev · app template/build

  4. 4 Gate delivery

    CI and admission policies block images that miss your runtime, evidence, or vulnerability contract.

    certify · verify · conformance · policy

  5. 5 Operate updates

    Security teams triage findings, document exceptions, and move compatible app layers onto patched bases under review.

    scan · remediation · VEX · app diff-base/rebase

Application developers don't need Nix — pull, run, and verify the published images with plain Docker, Podman, or Kubernetes. Nix is only for the platform team authoring the fleet.

Command Line Interface

See the CLI in action

The statically compiled clearcutt Go CLI handles base-image discovery, local policy-gate verification, and byte-for-byte base rebases — all offline, no Docker daemon or Nix required.

The panel is an illustrative walk-through of real command shapes — scripted sample output, not a live run. Verify any image yourself from the audit guide.

Illustrative
~$

Interactive Platform Perspective

Switch perspectives to see how ClearCutt serves both platform engineering teams and security auditors.

Hermetic Store Closures

Nix-based hermetic compilation prevents untracked package injection. Read how downstream forks run bit-for-bit reproducibility checks on their Nix store closures. Run verification checks →

Structural Hardening

ClearCutt distroless images reduce runtime utility surface by omitting shells, package managers, and core system tools. The security model names what that proves, and what it does not.

High Reusability

Forkable platform kit. Publish your own signed fleet, catalog site, app templates, CI/CD checks, admission policies, and approved remediation PR flow.

Blueprint Reference Notice: This catalog represents a live-worked reference feed generated from the canonical northcutted/clearcutt blueprint. These images are verified worked-examples of our hardening methods. Organizations should fork this blueprint repository to compile, sign, and host their own internal production-grade base image feeds under their own OIDC identities.

Supply Chain Health & Telemetry

Catalog Compiled: 6/4/2026, 7:57:02 AM • Target: ghcr.io/northcutted/clearcutt
Image Verification
39 / 39

All images keyless OIDC signed

SLSA Provenance
39 / 39

All images have SLSA Build L3 provenance

Structural Standards
Shell-Free / Overlays

Distroless Shell-Free

Reference Runtimes
39 / 39

declarative target closures