airhacks.fm podcast with adam bien

Dynamic Container Images with Quarkus

Oct 5, 2025
Alvaro Hernandez, CEO of Ongres and PostgreSQL expert, dives into the fascinating world of dynamic container images. He shares his experience with building modular laptops and running Ubuntu with a Nix package manager. The discussion highlights the challenges of packaging multiple PostgreSQL extensions and the risks of monolithic images. Alvaro introduces the Dynamic OCI Registry (Dozer), which composes images on-the-fly, ensuring fast generation and security through immutability. His insights lay a foundation for innovative serverless applications and CI/CD integration.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

Immutable Image Expectations Clash With Runtime Mods

  • Dynamically injecting extensions into running containers works but triggers security policies that expect immutable images.
  • Modifying runtime files breaks static audits and can be flagged by Kubernetes security tools.
INSIGHT

Images Are Manifests Over Layers

  • Container images are manifests pointing to layer tarballs, not chained Merkle trees at manifest-time.
  • That allows composing manifests dynamically by referencing existing immutable layers to build custom images in milliseconds.
ADVICE

Compose Images By Generating Manifests

  • Compose images on-demand by generating manifests that reference immutable layer digests instead of running docker build.
  • This yields targeted minimal images instantly and keeps layers signed and reused across images.
Get the Snipd Podcast app to discover more snips from this episode
Get the app