opensourceprojects.dev

A broadsheet for software that doesn't ask for your email

Buildah builds OCI images without a daemon or Dockerfiles
GitHub RepoImpressions4

Project Description

View on GitHub

Building OCI Images Without a Daemon or a Dockerfile

If you've ever wanted to build container images but didn't want to run a background daemon or wrestle with a Dockerfile for every little thing, you're not alone. Buildah is a command-line tool that lets you build OCI container images directly, without needing root privileges and without a daemon running in the background.

What It Does

Buildah is a command line tool for building Open Container Initiative (OCI) container images. It's written in Go and provides an API that can be vendored into other tools, but you can also use it directly from your terminal. The tool follows a simple fork-exec model, which means it doesn't run as a daemon—it just executes commands when you call them.

The core workflow revolves around working containers. You can create a working container from scratch or from an existing image, mount its root filesystem, manipulate it however you like, and then use those changes as a filesystem layer to create a new image. Buildah can build images either from a working container or from the instructions in a Dockerfile, and it supports both the OCI image format and the traditional upstream Docker image format.

Beyond just building, Buildah handles the full lifecycle of your working containers and images. You can mount and unmount root filesystems, delete containers or images, and rename local containers. Its commands replicate everything you'd find in a Dockerfile, which means you can build images with or without Dockerfiles—giving you the flexibility to integrate other scripting languages into your build process.

Why It's Cool

Here's what makes Buildah worth your attention:

  • No daemon required. Buildah doesn't run as a background service. It's a straightforward command-line tool that does its job and exits. That's one less thing to manage, one less attack surface, and one less process eating up resources.

  • Rootless builds. Buildah can build images without requiring root privileges. If you've ever been frustrated by needing elevated permissions just to create a container image, this is a welcome change.

  • Dockerfile optional. While Buildah can absolutely use Dockerfiles, it doesn't force you to. You can build images using shell scripts, Python, or any other scripting language that suits your workflow. This opens up possibilities for more dynamic and programmatic image builds.

  • Go API for embedding. Buildah is built on a comprehensive Go API that can be vendored into other tools. In fact, Podman uses Buildah's Go API for building container images via Dockerfiles—so if you're already using Podman, you're indirectly using Buildah.

  • Clear separation of concerns. Buildah and Podman are complementary projects. Buildah specializes in building OCI images, while Podman focuses on managing and maintaining those images and containers. The distinction is intentional: buildah run emulates the RUN command in a Dockerfile, while podman run emulates docker run. Because of their different storage models, you can't see Podman containers from within Buildah or vice versa—which keeps things clean and predictable.

  • OCI-native. Buildah works with OCI images and containers from the ground up. It's not bolted onto a legacy system; it's designed for the modern container ecosystem.

How to Try It

Getting started with Buildah is straightforward if you're on a Linux platform. The project provides installation notes in its repository, and you can find detailed tutorials in the docs folder.

  1. Head over to the Buildah repository on GitHub.

  2. Check the installation notes for your platform. Buildah is available on most Linux distributions.

  3. Once installed, you can start building images. The tutorials in the repo walk you through common workflows.

  4. If you want to see Buildah in action, the project maintains a demos directory with practical examples.

  5. For blogs, release announcements, and more, check out the buildah.io website.

The repository also includes a troubleshooting guide and a changelog if you run into issues or want to see what's new.

Final Thoughts

Buildah is a solid choice if you're building OCI images on Linux and want to avoid the overhead of a daemon or the constraints of Dockerfiles. It's particularly well-suited for developers who want more control over their build process, whether that means scripting builds in a language other than Dockerfile syntax or embedding image-building capabilities into their own Go tools. If you're already using Podman, Buildah is likely already part of your workflow—but even if you're not, it's worth exploring as a standalone tool. The project is actively maintained, has a clear development plan, and sits at the center of a healthy ecosystem of container tools.


Follow @githubprojects for more developer tools and open source projects.

Back to Projects
Project ID: 1a0a15f2-316e-4d40-af5b-ea05ab48a356Last updated: October 9, 2026 at 07:15 AM