Containers for customer on-premises deployments
Updated

When the code must run on their metal: images, registries, and the handover that survives their data center.
On-premises delivery is a packaging problem first and a code problem second. The image is the contract.
The short answer
One signed image per release, no secrets inside, pinned bases, documented volumes, and a compose or manifest the customer team has run themselves.
The image contract
| Rule | Why | Handover proof |
|---|---|---|
| Pinned base and deps | Rebuilds produce the same bytes | Rebuild log with hashes |
| No secrets in layers | Registries leak, histories persist | Scan report before publish |
| Config by environment | Same image runs in staging and prod | Two-environment run record |
| Documented volumes | Data survives container replacement | Backup and restore tested once |
| Signed and scanned | Customer gate requires both | Signature plus scan attached |
Worked example: the data-center handover
A fictional manufacturer (fictional) accepts one signed image through its gate, runs it with its own secrets and volumes, and rehearses backup plus restore with the FDE watching silently. First restore takes 40 minutes with two missing steps; docs fixed, second takes 11. The image never changes during the drill. The constraints post covers the gate; the handover post covers the silent-watch test.
Checklist: on-prem readiness
- Customer team pulled, ran and stopped the image alone.
- Secrets arrive at runtime, never in layers.
- Backup and restore rehearsed with a timer.
- Rollback is the previous signed image, tested once.
Related reading
Straight answers
Frequently asked questions
When are containers the right call?
When the customer runs its own servers with strict change control: one image, pinned versions, and the same bytes in staging and production.
Who owns the registry?
The customer, on their network, with you publishing signed images through their gate. Your laptop registry never becomes production.
What breaks most often?
Secrets baked into images, unpinned base images drifting, and volumes nobody documented. All three are handover failures, not container failures.