clearcutt-java21 : dev
Builder tier — full toolchain, shells, debug utilities, credential helper.
Published Sat, 11 Jul 2026 00:47:46 GMT
Last Rebuilt Tue, 04 Aug 2026 07:05:52 GMT
About this Image & Usage
Explore container capabilities, common use cases, and integration blueprints.
Capabilities & Guarantees
This Java Development Kit (JDK) image provides a comprehensive Zulu OpenJDK 21 compilation and troubleshooting environment. It contains complete profiling, diagnostic, and build toolchains.
Common Use Cases
- Compiling complex Java/Kotlin applications using Maven or Gradle wrappers
- Running JVM diagnostic pipelines (jmap, jstack, jcmd) inside dev containers
- Executing unit and integration testing pipelines with full shell access
Runtime Security & Execution Contract
Developer blueprints
Copy pre-configured code structures to accelerate deployment pipelines.
# Stage 1: Build the Maven application inside Java JDK dev builder
FROM ghcr.io/northcutted/clearcutt/clearcutt-java21:v0.14.0-dev AS builder
WORKDIR /app
COPY pom.xml .
COPY src ./src
RUN mvn clean package -DskipTests
# Stage 2: Hardened runner stage (distroless or slim Java JRE runtime)
FROM ghcr.io/northcutted/clearcutt/clearcutt-java21:v0.14.0-dev
WORKDIR /app
# Copy JRE-optimized JAR file
COPY --from=builder /app/target/*.jar ./app.jar
# Run JRE application as secure non-root operator
USER 10001:10001
CMD ["java", "-jar", "app.jar"]
If your organization mandates a certified base OS (like Red Hat UBI, Amazon Linux, or Ubuntu Pro) for compliance, you can stack ClearCutt's RPATH-bound /nix/store closure directly on top without modifying base layers or bundled agents.
{
description = "ClearCutt java21 grafted onto a mandated base";
inputs = {
nixpkgs.url = "github:NixOS/nixpkgs/nixpkgs-unstable";
clearcutt.url = "github:northcutted/clearcutt/v0.14.0?dir=core";
};
outputs = { self, nixpkgs, clearcutt }:
let
system = "x86_64-linux";
pkgs = import nixpkgs { inherit system; };
mandatedBase = pkgs.dockerTools.pullImage {
imageName = "registry.access.redhat.com/ubi9/ubi-minimal";
imageDigest = "sha256:REPLACE_WITH_PINNED_BASE_DIGEST";
sha256 = "sha256-REPLACE_WITH_NIX_PREFETCH_DOCKER_HASH";
};
in {
packages.${system}.overlayImage = clearcutt.lib.graftOntoBase {
inherit system;
fromImage = mandatedBase;
runtime = "java21";
tier = "dev";
name = "acme-java21-ubi";
tag = "v0.14.0";
};
};
}
# Build: nix build .#packages.x86_64-linux.overlayImage
# Then prove the grafted runtime is byte-identical to the native runtime:
# clearcutt overlay verify \
# --runtime-archive clearcutt-java21.tar \
# --grafted-archive result \
# --runtime-ref ghcr.io/northcutted/clearcutt/clearcutt-java21:v0.14.0-dev@sha256:... \
# --grafted-ref ghcr.io/acme/java21-ubi:v0.14.0@sha256:... \
# --target java21-dev \
# --output-predicate # Run an interactive local dev shell with the exact same remediated Zulu JDK:
$ nix shell github:northcutted/clearcutt/v0.14.0?dir=core#clearcuttJava21-native
# Or declare inside your local flake.nix:
{
inputs.clearcutt.url = "github:northcutted/clearcutt/v0.14.0?dir=core";
outputs = { self, nixpkgs, clearcutt }: {
devShells.x86_64-linux.default = let
pkgs = import nixpkgs {
system = "x86_64-linux";
overlays = [ clearcutt.overlays.default ];
};
in pkgs.mkShell {
buildInputs = [ pkgs.clearcuttJava21 ];
};
};
} # Layer a custom JAR application declaratively in your Nix configuration
pkgs.dockerTools.buildImage {
name = "custom-java-microservice";
tag = "latest";
# Layer on top of ClearCutt's JRE base
fromImage = clearcutt-base-image;
copyToRoot = pkgs.buildEnv {
name = "image-root";
paths = [
pkgs.zlib # Layer in native dynamic libraries
java-app-package # Include your packaged JAR launcher
];
pathsToLink = [ "/bin" "/lib" ];
};
config = {
Cmd = [ "/bin/java-app" ];
User = "10001:10001";
};
} Pull & Run Workspace
Select your preferred container engine or deployment platform target.
Pull by multi-arch digest (Recommended, Secure)
docker pull ghcr.io/northcutted/clearcutt/clearcutt-java21@sha256:9e7ac490808de645b84b73b3415f0a5f9a2e0ec4a716d298446d8c14e7d6ee9d Pinned to release
docker pull ghcr.io/northcutted/clearcutt/clearcutt-java21:v0.14.0-dev Quick pull (rolling)
docker pull ghcr.io/northcutted/clearcutt/clearcutt-java21:dev Hardened docker run
docker run --rm \
--read-only \
--cap-drop=ALL \
--security-opt no-new-privileges \
--user 10001:10001 \
--tmpfs /tmp:mode=1777 \
ghcr.io/northcutted/clearcutt/clearcutt-java21:v0.14.0-dev Pull by multi-arch digest (Recommended, Secure)
podman pull ghcr.io/northcutted/clearcutt/clearcutt-java21@sha256:9e7ac490808de645b84b73b3415f0a5f9a2e0ec4a716d298446d8c14e7d6ee9d Pinned to release
podman pull ghcr.io/northcutted/clearcutt/clearcutt-java21:v0.14.0-dev Quick pull (rolling)
podman pull ghcr.io/northcutted/clearcutt/clearcutt-java21:dev Hardened podman run
podman run --rm \
--read-only \
--cap-drop=ALL \
--security-opt no-new-privileges \
--user 10001:10001 \
--tmpfs /tmp:mode=1777 \
ghcr.io/northcutted/clearcutt/clearcutt-java21:v0.14.0-dev services:
app:
image: ghcr.io/northcutted/clearcutt/clearcutt-java21:v0.14.0-dev
read_only: true
user: "10001:10001"
security_opt:
- no-new-privileges:true
cap_drop:
- ALL
tmpfs:
- /tmp:mode=1777 apiVersion: v1
kind: Pod
metadata:
name: clearcutt-java21
spec:
automountServiceAccountToken: false
securityContext:
runAsNonRoot: true
runAsUser: 10001
runAsGroup: 10001
seccompProfile: { type: RuntimeDefault }
containers:
- name: app
image: ghcr.io/northcutted/clearcutt/clearcutt-java21:v0.14.0-dev
imagePullPolicy: IfNotPresent
securityContext:
readOnlyRootFilesystem: true
allowPrivilegeEscalation: false
capabilities: { drop: ["ALL"] }
volumeMounts:
- { name: tmp, mountPath: /tmp }
volumes:
- { name: tmp, emptyDir: { medium: Memory } } {
inputs.clearcutt.url = "github:northcutted/clearcutt/v0.14.0?dir=core";
outputs = { self, nixpkgs, clearcutt }: {
devShells.x86_64-linux.default = let
pkgs = import nixpkgs {
system = "x86_64-linux";
overlays = [ clearcutt.overlays.default ];
};
in pkgs.mkShell {
buildInputs = [ pkgs.clearcuttJava21 ];
};
};
} Verify & Audit Compliance
Inspect catalog evidence, run registry-side verification where evidence exists, and review vulnerability gates.
Provenance & signatures
Cryptographically audit OCI identity claims and supply chain gating artifacts.
Cryptographic Proof
CATALOG REPORTS SIGNATUREOIDC Certificate Subject
Supply Chain Provenance
PROVENANCE RECORDED 3Compilation & Tests
TESTS PASSEDAttestations
4 kinds of evidence for this image. The counts are how many times each was independently signed into the public transparency log — not how many distinct artifacts exist.
cosign verify-attestation. gh attestation verify. The subject above is the multi-arch index (amd64 + arm64). Each architecture's SBOM is attested separately, in both ecosystems — so one SBOM naturally appears as several signed records below. Records also accumulate as the image is rebuilt, with each release re-signing into the transparency log afresh. Every entry is independent and publicly verifiable: click any #index below to inspect it in Sigstore Rekor, or use the copy-paste commands below to verify them locally.
How and where the image was built — binds this digest to the exact workflow run, commit, and builder.
Software Bill of Materials — the full inventory of packages baked into the image.
Signed evidence that the release-gate test suite passed for this exact digest.
The keyless cosign signature statement covering the image index.
Active Verification Toolkit
Run registry-side verification commands for the recorded release evidence.
Direct Cryptographic Evidence & Verification
https://github.com/northcutted/clearcutt/.github/workflows/release.yml@refs/heads/main https://token.actions.githubusercontent.com sha256:9e7ac490808de645b84b73b3415f0a5f9a2e0ec4a716d298446d8c14e7d6ee9d Run the native compiled Go CLI command locally to verify the registry digest, Sigstore signature, SBOM and test attestations, and SLSA provenance:
clearcutt verify release-evidence \
--ref ghcr.io/northcutted/clearcutt/clearcutt-java21@sha256:9e7ac490808de645b84b73b3415f0a5f9a2e0ec4a716d298446d8c14e7d6ee9d \
--repo northcutted/clearcutt \
--workflow-identity 'https://github.com/northcutted/clearcutt/.github/workflows/release.yml@refs/heads/main' 1. Inspect Security Metadata
Query deep, high-fidelity security metadata, dynamic entrypoints, non-root user settings, architectures, and release asset URLs.
CATALOG_DIR=./path/to/catalog
clearcutt --catalog "$CATALOG_DIR" inspect java21-dev --tag v0.14.0 2. Local Policy Gate Verification
Check catalog-record evidence flags, smoke tests, vulnerability limits, and lifecycle constraints locally or in CI pipelines. Use the release-evidence command or the Cosign/SLSA tabs for registry-side cryptographic verification.
CATALOG_DIR=./path/to/catalog
clearcutt --catalog "$CATALOG_DIR" verify image java21-dev \
--tag v0.14.0 \
--require-production \
--require-signature \
--require-sbom \
--require-provenance \
--max-critical 0 \
--max-high 5 3. Runtime Conformance Audit
Verify runtime specifications offline, asserting timezone configurations, dynamic links, CA certificate paths, and rootless isolation boundaries.
clearcutt conformance run \
--expect-runtime java 4. Scaffold Nix Overlay Graft
Under strict corporate base OS mandates, generate a workspace scaffolding to graft this runtime overlay onto existing host layers.
clearcutt overlay generate \
--runtime java21 \
--tier dev \
--base registry.access.redhat.com/ubi9/ubi-minimal \
--output my-java21-overlay/ 1. Verify Keyless OIDC Signature
Confirm this OCI image was built in your official release workflow and signed via keyless OIDC certificates.
cosign verify ghcr.io/northcutted/clearcutt/clearcutt-java21@sha256:9e7ac490808de645b84b73b3415f0a5f9a2e0ec4a716d298446d8c14e7d6ee9d \
--certificate-identity 'https://github.com/northcutted/clearcutt/.github/workflows/release.yml@refs/heads/main' \
--certificate-oidc-issuer 'https://token.actions.githubusercontent.com' \
--output json 2. Verify Cryptographic SBOM Attestation
Extract and cryptographically verify the compiled package software bill of materials statement.
cosign verify-attestation ghcr.io/northcutted/clearcutt/clearcutt-java21@sha256:9e7ac490808de645b84b73b3415f0a5f9a2e0ec4a716d298446d8c14e7d6ee9d \
--type spdxjson \
--certificate-identity 'https://github.com/northcutted/clearcutt/.github/workflows/release.yml@refs/heads/main' \
--certificate-oidc-issuer 'https://token.actions.githubusercontent.com' \
| jq '.payload | @base64d | fromjson | .predicate' slsa-verifier (SLSA Build L3)
Verify SLSA Build L3 provenance from the configured builder and source ref.
slsa-verifier verify-image ghcr.io/northcutted/clearcutt/clearcutt-java21@sha256:9e7ac490808de645b84b73b3415f0a5f9a2e0ec4a716d298446d8c14e7d6ee9d \
--source-uri 'github.com/northcutted/clearcutt' \
--source-branch 'main' GitHub Native Attestation
Audit the GitHub-native provenance attestation using the GitHub CLI client.
gh attestation verify oci://ghcr.io/northcutted/clearcutt/clearcutt-java21@sha256:9e7ac490808de645b84b73b3415f0a5f9a2e0ec4a716d298446d8c14e7d6ee9d \
--repo northcutted/clearcutt \
--cert-identity 'https://github.com/northcutted/clearcutt/.github/workflows/release.yml@refs/heads/main' \
--source-ref refs/heads/main Deep-Dive & OCI Specifications
Analyze the full Nix store dependency closure, image layer architecture, and OCI configuration labels.
Software Bill of Materials
Every package included in the image's /nix/store
closure. Generated from the actual OCI archive at build time and attached as an SPDX SBOM,
using the same package inventory as the CVE findings above.
SBOM generated Sat, 11 Jul 2026 00:04:05 GMT. Toggle between architectures; the package set typically matches but layer hashes differ.
Image Specifications & Release Ledger
Inspect the static OCI container metadata labels and browse the immutable published release history for this image.
| Key | Value |
|---|---|
| dev.clearcutt.recipe.license | Apache-2.0 |
| org.opencontainers.image.authors | ClearCutt maintainers |
| org.opencontainers.image.description | Hardened ClearCutt Base Image for java (21) - Tier: dev |
| org.opencontainers.image.licenses | NOASSERTION |
| org.opencontainers.image.ref.name | dev |
| org.opencontainers.image.source | https://github.com/northcutted/clearcutt |
| org.opencontainers.image.title | clearcutt-java-21 |
| org.opencontainers.image.url | https://github.com/northcutted/clearcutt |
| org.opencontainers.image.vendor | ClearCutt |
| org.opencontainers.image.version | 21 |
| Tag | Published | Archs | Packages | |
|---|---|---|---|---|
| v0.14.0 latest | Sat, 11 Jul 2026 00:47:46 GMT | amd64arm64 | 781 | .intoto.jsonl ↗ |
| v0.13.0 | Fri, 10 Jul 2026 00:21:20 GMT | amd64arm64 | 781 | .intoto.jsonl ↗ |
| v0.12.2 | Sat, 04 Jul 2026 17:29:57 GMT | amd64arm64 | 781 | .intoto.jsonl ↗ |
| v0.12.1 | Sat, 04 Jul 2026 13:08:58 GMT | amd64arm64 | 781 | .intoto.jsonl ↗ |
| v0.11.1 | Wed, 10 Jun 2026 02:52:21 GMT | amd64arm64 | 781 | .intoto.jsonl ↗ |
| v0.11.0 | Wed, 10 Jun 2026 01:24:14 GMT | amd64arm64 | 781 | .intoto.jsonl ↗ |
| v0.10.4 | Tue, 09 Jun 2026 12:54:17 GMT | amd64arm64 | 781 | .intoto.jsonl ↗ |
| v0.10.2 | Sun, 07 Jun 2026 21:31:16 GMT | amd64arm64 | 781 | .intoto.jsonl ↗ |
| v0.10.1 | Sun, 07 Jun 2026 16:42:20 GMT | amd64arm64 | 781 | .intoto.jsonl ↗ |
| v0.10.0 | Sun, 07 Jun 2026 14:37:59 GMT | amd64arm64 | 781 | .intoto.jsonl ↗ |