Glossary
The vocabulary of hardened images.
Plain definitions of the compliance, hardening, and software-supply-chain terms that show up whenever golden images are discussed. No marketing — just what the term means.
AMIAmazon Machine Image
The image format an EC2 instance boots from on AWS.
Build provenance
Signed metadata describing how an artifact was produced: from what sources, by which builder, with which inputs.
CIS BenchmarkCenter for Internet Security Benchmark
A consensus-developed configuration baseline that prescribes how to securely configure a specific operating system or application.
Cosign
A Sigstore tool for signing and verifying software artifacts, including container images and files.
CVECommon Vulnerabilities and Exposures
A public identifier assigned to a specific, disclosed software vulnerability.
CycloneDX
An SBOM standard maintained by OWASP, designed for security use cases and standardized by Ecma International.
DISA STIGDefense Information Systems Agency Security Technical Implementation Guide
The hardening standard required for information systems operated by or for the US Department of Defense.
FIPS 140-3Federal Information Processing Standard 140-3
The US standard for validating cryptographic modules, required for federal systems handling sensitive information.
Golden image
A pre-built, pre-hardened VM image that serves as the standard base for every server an organization deploys.
Immutable infrastructure
An operational model in which servers are never modified after deployment; changes ship as a new image and a replacement.
OpenSCAP
An open-source scanner that evaluates a system against a SCAP security policy and can automatically remediate what fails.
QCOW2QEMU Copy-On-Write version 2
QEMU's native disk image format, and the usual working format for Linux VM image builds.
SBOMSoftware Bill of Materials
A machine-readable inventory of every software component in an artifact, and the metadata describing each one.
SLSASupply-chain Levels for Software Artifacts
A framework of increasingly strict requirements on how software is built, designed to make build provenance verifiable.
SPDXSoftware Package Data Exchange
A Linux Foundation SBOM standard, and an ISO standard, with deep roots in license compliance.
Get started now.
Request access, describe the image you want, and have your first hardened image in about 15 minutes — a typical estimate, before publishing to your clouds. Primcoat builds, hardens, scans, signs, and publishes it, on the operating systems you already run.