
airhacks.fm podcast with adam bien Dynamic Container Images with Quarkus
Oct 5, 2025
Alvaro Hernandez, CEO of Ongres and PostgreSQL expert, dives into the fascinating world of dynamic container images. He shares his experience with building modular laptops and running Ubuntu with a Nix package manager. The discussion highlights the challenges of packaging multiple PostgreSQL extensions and the risks of monolithic images. Alvaro introduces the Dynamic OCI Registry (Dozer), which composes images on-the-fly, ensuring fast generation and security through immutability. His insights lay a foundation for innovative serverless applications and CI/CD integration.
AI Snips
Chapters
Transcript
Episode notes
Immutable Image Expectations Clash With Runtime Mods
- Dynamically injecting extensions into running containers works but triggers security policies that expect immutable images.
- Modifying runtime files breaks static audits and can be flagged by Kubernetes security tools.
Images Are Manifests Over Layers
- Container images are manifests pointing to layer tarballs, not chained Merkle trees at manifest-time.
- That allows composing manifests dynamically by referencing existing immutable layers to build custom images in milliseconds.
Compose Images By Generating Manifests
- Compose images on-demand by generating manifests that reference immutable layer digests instead of running docker build.
- This yields targeted minimal images instantly and keeps layers signed and reused across images.
