Files
buildx/docs/reference/buildx.md
T
Tonis Tiigi acaf251f0b policy: verify BuildKit builder images
Extend the built-in policy to validate signed moby/buildkit release and
floating tags before docker-container builders are created.

Pull the image first, inspect it through Docker, and bind verification to the
descriptor digest. Resolve signature attestations through the BuildKit API
embedded in the Docker daemon.

If pulling fails, use a local image while applying the same verification when
the containerd image store exposes an immutable descriptor. Keep the classic
image-store behavior unchanged because no descriptor is available.

Allow unmanaged repositories and digest-only references unchanged. Add the
allow-untrusted-image driver option as an explicit verification bypass.

Document the behavior and add policy, digest-pinning, and local fallback
coverage.

Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com>
2026-07-20 18:22:41 -07:00

2.8 KiB

buildx

docker buildx [OPTIONS] COMMAND

Extended build capabilities with BuildKit

Subcommands

Name Description
bake Build from a file
build Start a build
create Create a new builder instance
dap Start debug adapter protocol compatible debugger
debug Start debugger (EXPERIMENTAL)
dial-stdio Proxy current stdio streams to builder instance
du Disk usage
history Commands to work on build records
imagetools Commands to work on images in registry
inspect Inspect current builder instance
ls List builder instances
policy Commands for working with build policies
prune Remove build cache
rm Remove one or more builder instances
stop Stop builder instance
use Set the current builder instance
version Show buildx version information

Options

Name Type Default Description
--builder string Override the configured builder instance
-D, --debug bool Enable debug logging

Examples

Override the configured builder instance (--builder)

You can also use the BUILDX_BUILDER environment variable.

Enable the default policy

Set BUILDX_DEFAULT_POLICY=1 to enable Buildx's built-in source policy. The policy verifies signed tags for images managed by Docker, including BuildKit builder images and Dockerfile frontends. Untagged digest references and images outside the managed repositories are allowed unchanged. Tagged references that also contain a digest still have their release identity verified.