Custom OS Image Building & Maintained Image Pipelines
TacitSoft designs, builds, inspects, signs, and maintains reproducible operating-system images for cloud, virtualization, bare metal, appliances, and regulated delivery paths.
No checkout or cloud access is required to scope the work. We start with targets, entitlement, controls, cadence, and ownership boundaries.
Reproducible
One controlled specification, rebuildable on demand
Evidence-backed
SBOM, scan, test, provenance, and checksums
Multi-target
Cloud, hypervisor, ISO, and bootable OCI outputs
Maintained
Scheduled and security-triggered rebuild lanes
One specification, the artifacts your delivery path needs
The target matrix is agreed before implementation. Format availability depends on the base, platform APIs, boot model, licensing, and the publishing boundary you control.
| Artifact family | Delivery targets | Typical use |
|---|---|---|
| AMI | AWS accounts and regions | Golden EC2 bases, autoscaling fleets, private catalogs |
| Azure / GCP images | Azure Compute Gallery and Google Cloud projects | Repeatable cloud estates and customer environments |
| ISO | Virtual, USB, and controlled installation paths | Appliances, offline installs, bare-metal delivery |
| QCOW2 / RAW | KVM, OpenStack, import workflows, block devices | Private cloud, lab, edge, and conversion inputs |
| VMDK / OVA | VMware-compatible delivery paths | Virtual appliances and repeatable customer deployments |
| OCI / bootc | Container registries and bootable-container workflows | Image-mode operating systems with registry promotion |
Supported bases
Selected after the outcome and delivery path are clear.
- Rocky Linux
- Red Hat Enterprise Linux (RHEL)
- Debian
- Ubuntu
- AlmaLinux
- Amazon Linux
Customer and private baselines are considered subject to verifiable source provenance, license entitlement, redistribution rights, and a supportable update path.
Every artifact follows a controlled promotion path
A hand-built VM is undocumented state. We turn image intent into versioned inputs, repeatable automation, policy evidence, release gates, and an owned maintenance decision.
-
01
Source spec
Pin inputs, packages, configuration, ownership, and target matrix.
-
02
Build
Create artifacts in isolated, reviewable automation.
-
03
Inspect
Inventory packages, SBOMs, vulnerabilities, licenses, and drift.
-
04
Test
Boot, smoke, policy, configuration, and target-specific acceptance checks.
-
05
Sign
Attach checksums, signatures, and provenance to approved outputs.
-
06
Publish
Promote through customer-controlled registries, galleries, or catalogs.
-
07
Maintain
Rebuild on cadence or security trigger, then repeat the same gates.
Proof that travels with the release
Evidence is produced by the agreed pipeline and delivered with the artifact release—not reconstructed after an audit request.
Hardening notes and control-oriented evidence support your review process. They are not a formal compliance certification or a substitute for an authorized assessment.
-
SBOM
Package and component inventory in an agreed machine-readable format.
-
Vulnerability report
Findings, severity context, exceptions, and remediation disposition.
-
Hardening notes
Applied baseline, deviations, rationale, and operational impact.
-
Test results
Boot, smoke, configuration, policy, and artifact acceptance outcomes.
-
Provenance
Traceability from source specification and build inputs to release.
-
Artifact checksums
Digest inventory for integrity verification and promotion.
-
Release notes
What changed, known risks, compatibility notes, and maintenance trigger.
Choose the operating model, not a mystery SKU
| Model | Best fit | Handoff |
|---|---|---|
| One-off build | A defined artifact and target with a bounded release need. | Build inputs, artifact, agreed evidence, and reproducibility notes. |
| Production golden image | A stable base used repeatedly by a platform, fleet, or customer delivery team. | Versioned pipeline, acceptance gates, release workflow, and operator runbook. |
| Maintained image lane | Teams that need monthly or security-triggered rebuilds without patch-pressure fire drills. | Recurring rebuild, inspection, test, promotion evidence, and release notes under an agreed SLA. |
| Marketplace / private listing support | Products distributed through customer accounts, private catalogs, or provider listing workflows. | Packaging and submission-readiness support; account ownership, provider approval, and final activation remain with the customer and marketplace. |
Budget orientation before scoping
These non-binding bands help qualify the shape of the work. They are not quotes, checkout prices, or a promise that every target fits a band.
- Image Assessment
- $750-$2,500
- Inspect the current image and build process and recommend a maintainable path.
- One-Off Custom Image Build
- $1,500-$5,000
- Build one customer-approved target image from a known and lawfully usable base.
- Production Golden Image Pipeline
- $7,500-$15,000+ setup
- Create a reproducible image pipeline with tests, scanning, SBOM generation, signing, and release notes.
- Multi-Cloud / Appliance Image Program
- $15,000-$40,000+
- Use one approved specification to produce multiple target artifacts or cloud releases.
- Maintained Image Lane
- $1,000-$3,000+/mo minimum
- Provide governed ongoing rebuilds, CVE response, scheduled releases, and rollback or revocation support.
What determines the actual scope
Price bands are planning anchors, not offers to sell. Final pricing and every customer-specific statement of work require scoped review and human approval.
Final pricing depends on the target artifact matrix, license entitlement, compliance controls, maintenance cadence, and support SLA. Marketplace support, unusual hardware, disconnected builds, private package sources, and migration work are scoped explicitly.
Free base image versus paid engineering
Many upstream base images are free to download. TacitSoft does not charge for relabeling a free distro image. Paid work covers the controlled specification, automation, inspection, testing, signing, evidence, publishing integration, and optional maintained rebuild pipeline your team can rely on.
When we say no
A trustworthy pipeline has refusal criteria. We pause or decline work when the legal, security, or evidence boundary cannot be made explicit.
-
Unclear licensing or entitlement
We need a documented right to obtain, modify, build from, and deliver the selected base and packages.
-
Unknown provenance
We do not bless mystery binaries or inherited images when their source and update path cannot be established.
-
Credential sharing
Cloud and registry access must use customer-controlled roles, bounded permissions, and auditable handoffs—not shared personal credentials.
-
Unsupported third-party redistribution
We will not redistribute software, subscriptions, or vendor content beyond the rights you can demonstrate.
-
Certification claims without assessment
We can implement controls and produce evidence; we do not claim formal certification without a separate, appropriately authorized assessment.
Request an image build assessment
We will determine whether you need a bounded build, a production pipeline, or a maintained lane—and identify entitlement or delivery constraints before proposing implementation.
Bring these scoping inputs
- Current base image, source owner, and license entitlement
- Required artifacts, clouds, hypervisors, regions, and architectures
- Hardening baseline, evidence needs, and assessor expectations
- Release cadence and security-trigger thresholds
- Publishing accounts, approval owners, support window, and SLA