kodebeat / papers / families

One pinned image per job, instead of ad-hoc installs

Pinned, multi-arch, single-purpose container images.

Nine small container images, each bundling one job's worth of tooling, pinned to an exact version, built multi-arch, scanned in CI and published to GHCR. They exist because the alternative every team reaches for first, installing the tools ad hoc at runtime, reproduces the same twenty lines of apt-get in every repository and produces a different result each month.

What is in it

  • The problem — what goes unanswered without it, and who notices first.
  • Why the obvious alternative falls short — stated plainly, including where it is the better choice.
  • How it works — the method, not a feature list.
  • Concrete use cases — with console output quoted from the repository, never reconstructed.
  • The methodology behind any number it emits — every term shown, so the figure survives a question.
  • What it deliberately does not do — the section most papers leave out.

Part of the catalogue.

Get the PDF

One email with the download link, and this paper already selected. No follow-up sequence.

Send it to me