Project Lightning Talk: ORAS: Create and Distribute a Multi-platform Image with Secu... Andrew Block

Andrew Block

KubeCon + CloudNativeCon Europe 2025 · Project Lightning Talk

Overview

In this lightning talk at KubeCon EU, Andrew Block, a Distinguished Architect at Red Hat and a maintainer of the ORAS project, delved into the capabilities of ORAS for managing and distributing multi-platform images and other OCI artifacts. The presentation highlighted how the open-source ORAS (OCI Registry As Storage) CLI and SDK empower developers and organizations to leverage existing container registries, such as DockerHub, Quay, Zot, and Harbor, not just for container images, but for a diverse range of cloud-native assets. This paradigm shift allows for the standardization of artifact management, distribution, and crucially, the enhancement of software supply chain security.

Watch on YouTube

Visual summary for Project Lightning Talk: ORAS: Create and Distribute a Multi-platform Image with Secu... Andrew Block by Andrew Block
Visual summary for Project Lightning Talk: ORAS: Create and Distribute a Multi-platform Image with Secu... Andrew Block by Andrew Block

Key moments

  1. 0:00 Introduction to ORAS: OCI Artifacts Management CLI
  2. 1:00 Key features of ORAS and registry compatibility
  3. 2:10 Defining and understanding multiplatform images
  4. 2:30 ORAS benefits: Air-gapped, customization, supply chain security
  5. 3:20 Demonstration: Building a multi-platform artifact with ORAS
  6. 3:45 Using ORAS manifest index for multi-architecture images
  7. 4:20 Pushing and verifying multi-platform image in registry
  8. 4:40 Securing images by attaching SBOMs and signatures

Project Lightning Talk: ORAS: Create and Distribute a Multi-platform Image with Secu... Andrew Block

Speakers: Andrew Block, Distinguished Architect, Red Hat

Conference: KubeCon EU

YouTube: https://www.youtube.com/watch?v=2zjxSKAkT9E

Overview

In this lightning talk at KubeCon EU, Andrew Block, a Distinguished Architect at Red Hat and a maintainer of the ORAS project, delved into the capabilities of ORAS for managing and distributing multi-platform images and other OCI artifacts. The presentation highlighted how the open-source ORAS (OCI Registry As Storage) CLI and SDK empower developers and organizations to leverage existing container registries, such as DockerHub, Quay, Zot, and Harbor, not just for container images, but for a diverse range of cloud-native assets. This paradigm shift allows for the standardization of artifact management, distribution, and crucially, the enhancement of software supply chain security.

Block's talk underscored the growing importance of OCI artifacts in modern cloud-native ecosystems, particularly in addressing challenges like supporting multiple hardware architectures (e.g., AMD64 and ARM64) with a single artifact reference. He demonstrated how ORAS simplifies the creation and distribution of these multi-platform artifacts while also enabling the critical attachment of security metadata like Software Bill of Materials (SBOMs) and digital signatures. This capability is vital for establishing artifact provenance and ensuring the integrity of the software supply chain, making ORAS an essential tool for organizations striving for robust, secure, and efficient artifact management.

The significance of ORAS extends beyond mere distribution; it offers a unified approach to managing the entire lifecycle of OCI artifacts. By treating all cloud-native assets as first-class citizens within the OCI registry specification, ORAS allows teams to re-use established tooling and workflows for storage, discovery, and security. This talk served as a compelling introduction to how ORAS is transforming the way organizations handle their digital assets, providing a foundational layer for future cloud-native security and operational efficiencies.

Background

▶ Watch: Introduction to ORAS: OCI Artifacts Management CLI (0:00)

The evolution of cloud-native computing has led to an explosion in the types of digital assets that need to be managed, distributed, and secured. While container images have long been the primary artifact stored in OCI (Open Container Initiative) registries, the capabilities of these registries are far more expansive. The OCI specification defines a standard for container images and runtimes, but its underlying registry specification provides a robust, HTTP-based API for storing and distributing any type of artifact, not just containers. This realization forms the core premise behind the ORAS project.

Historically, different types of artifacts—like Helm charts, WebAssembly (WASM) modules, policy definitions, custom binaries, or even general configuration files—have often been stored in disparate systems, each with its own access controls, distribution mechanisms, and security models. This fragmentation introduces complexity, increases operational overhead, and creates potential security blind spots. The OCI artifact concept addresses this by standardizing the storage and distribution of all these diverse assets within the familiar and widely adopted OCI registry infrastructure. This means organizations can leverage their existing investments in registry infrastructure, security scanning tools, and CI/CD pipelines for a much broader array of digital assets.

ORAS (OCI Registry As Storage) emerged as a CNCF sandbox project to provide a powerful CLI and SDK for interacting with these extended OCI registry capabilities. Its goal is to make it easy for users to push, pull, manage, and manipulate any OCI-compliant artifact. This includes a crucial focus on multi-platform images, which are essential in today's heterogeneous computing environments. With the proliferation of different CPU architectures—such as the traditional AMD64, ARM64 (prevalent in modern data centers and devices like Apple's M1/M2 Macs), and even RISC-V—developers need a seamless way to distribute software that runs natively on all target platforms without requiring users to manually select the correct architecture-specific image. The concept of an OCI image index (often referred to as a manifest list) was introduced to address this, allowing a single reference (e.g., my-image:latest) to point to multiple architecture-specific images, with the client runtime automatically selecting the appropriate one. ORAS provides the tools to effectively create and manage these complex manifest structures.

Furthermore, the increasing focus on software supply chain security has highlighted the need to attach crucial metadata to artifacts. Information like Software Bill of Materials (SBOMs), which list all components and dependencies of a piece of software, and digital signatures, which verify the origin and integrity of an artifact, are becoming mandatory for compliance and risk management. ORAS integrates these capabilities, allowing users to securely attach and manage this vital provenance data directly alongside their artifacts in the registry, thereby enhancing the trustworthiness and transparency of the entire software delivery pipeline. The project also addresses the practical needs of air-gapped environments, where direct internet access is restricted, by providing robust mechanisms for transferring and managing artifacts securely in disconnected settings, a capability highly valued by organizations like Defense Unicorns mentioned in the talk.

Key Findings

▶ Watch: Defining and understanding multiplatform images (2:10)

The core contribution highlighted by Andrew Block is that ORAS dramatically expands the utility of existing OCI registries beyond their traditional role as container image repositories. The key findings and capabilities presented include:

  1. Universal OCI Artifact Management: ORAS provides a unified CLI and SDK for managing any OCI artifact, not just container images. This allows for the distribution, manipulation, and storage of diverse assets like Helm charts, WebAssembly modules, policy definitions, and more, all within standard OCI registries. This standardization simplifies infrastructure and tooling requirements.
  2. Seamless Multi-Platform Image Distribution: ORAS directly addresses the challenge of supporting heterogeneous computing environments by facilitating the creation and distribution of multi-platform images. It leverages the OCI image index (manifest list) concept, enabling a single artifact reference to serve multiple architectures (e.g., AMD64, ARM64), with the correct version automatically selected by the client.
  3. Enhanced Software Supply Chain Security: A critical finding is ORAS's ability to attach vital security metadata, such as Software Bill of Materials (SBOMs) and digital signatures, directly to artifacts—including multi-platform ones. This functionality is pivotal for establishing provenance, verifying integrity, and bolstering the security of the entire software supply chain by making security metadata an intrinsic part of the artifact's registry entry.
  4. Air-Gapped Environment Support: ORAS offers robust capabilities for managing artifact distribution in air-gapped or disconnected environments. This is crucial for high-security or regulatory-compliant sectors, allowing for secure pulling and pushing of artifacts into isolated networks.
  5. Extensive Registry and Language Compatibility: ORAS is designed for broad interoperability, compatible with popular OCI registries like DockerHub, Quay, Zot, and Harbor. Furthermore, its availability as an SDK in multiple programming languages (Java, Golang, Rust) ensures it can be deeply integrated into existing tools, workflows, and CI/CD pipelines, as exemplified by its integration into Argo CD.
  6. Customizable Artifact Metadata: Users can customize OCI artifacts by adding annotations and other metadata. This allows for rich contextual information to be attached to artifacts, which can then be queried and processed for various purposes, including policy enforcement, auditing, and enhanced discoverability.

These findings collectively position ORAS as a foundational tool for modern cloud-native operations, enabling more efficient, secure, and flexible management of all types of digital assets across diverse computing landscapes.

Technical Deep Dive

▶ Watch: Demonstration: Building a multi-platform artifact with ORAS (3:20)

At its heart, ORAS leverages the OCI distribution specification, which defines how content is stored and retrieved from container registries. While commonly associated with Docker images, this specification is generic enough to store any content addressable artifact. An OCI artifact is essentially a piece of data packaged according to OCI standards, allowing it to be pushed to, pulled from, and managed within an OCI-compliant registry. This includes not only container images but also a burgeoning ecosystem of other cloud-native components.

ORAS provides both a command-line interface (CLI) and a set of SDKs across various languages (Go, Java, Rust) to interact with these artifacts. The CLI is the most common entry point for users, offering intuitive commands for push, pull, copy, and attach operations. For deeper integration, the SDKs allow developers to embed ORAS functionality directly into their applications, as exemplified by its use within Argo CD for managing OCI artifacts.

A central technical challenge ORAS addresses is the distribution of multi-platform images. In an increasingly diverse hardware landscape, a single application may need different compiled binaries or container images for AMD64, ARM64, and potentially other architectures. The OCI specification solves this with an OCI image index, often referred to as a manifest list. A manifest list is a special type of manifest that doesn't describe a single image layer, but rather a list of other manifests, each pointing to an architecture-specific image. When a client (like Docker or Containerd) requests an image referenced by a manifest list, it automatically inspects the manifest list and pulls the appropriate architecture-specific image for the host system.

ORAS simplifies the creation and management of these manifest lists. As demonstrated in the talk, an oras manifest index command is used to combine existing, architecture-specific artifacts into a single, unified reference. For instance, if you have my-app:amd64 and my-app:arm64 in your registry, ORAS can create my-app:latest as a manifest list that points to both. This means users only need to reference my-app:latest, and the underlying OCI runtime handles the architecture selection transparently.

Beyond multi-platform support, ORAS is crucial for software supply chain security through its oras attach command. This command allows users to associate arbitrary, related artifacts with a primary artifact. Critically, this includes security metadata such as:

  • Software Bill of Materials (SBOMs): An SBOM is a formal, machine-readable list of ingredients that make up a piece of software. By attaching an SBOM to a container image or any other artifact, consumers can gain transparency into its components, identify potential vulnerabilities, and understand its provenance. ORAS enables the SBOM to be stored directly alongside the artifact in the OCI registry, making it easily discoverable and verifiable.
  • Signatures: Digital signatures provide cryptographic assurance of an artifact's integrity and origin. When an artifact is signed, ORAS can attach this signature as a separate artifact reference. This allows consumers to verify that the artifact has not been tampered with since it was signed by a trusted entity. This is a fundamental building block for trust in the software supply chain.

These attached artifacts are managed as references, meaning they are linked to the primary artifact but can be independently queried and validated. This architectural choice ensures that the security metadata is always associated with the artifact it describes, regardless of where the artifact is pulled from, reinforcing the concept of immutability and verifiable provenance. Furthermore, ORAS allows for the addition of annotations and other custom metadata to artifacts, which can be leveraged for advanced policy enforcement, auditing, or custom organizational workflows. This fine-grained control over metadata allows for a highly adaptable and secure artifact management strategy within any OCI-compliant registry.

Demo / Proof of Concept

▶ Watch: Using ORAS manifest index for multi-architecture images (3:45)

Andrew Block provided a concise, live demonstration of how ORAS facilitates the creation and distribution of a multi-platform OCI artifact. Despite the brevity of a lightning talk, the steps clearly illustrated ORAS's power and simplicity.

The demonstration began by showcasing existing artifacts in a local OCI layer, implying the prior creation of architecture-specific images (e.g., one for AMD64 and another for ARM64). The core of the demo revolved around the use of the oras manifest index command. This command is ORAS's mechanism for combining multiple distinct artifacts, each tailored for a specific platform or architecture, into a single, unified OCI image index (or manifest list). In this scenario, two pre-existing artifacts—one built for AMD64 and another for ARM64—were referenced to construct a new manifest index. This index effectively acts as a "smart pointer," allowing a single tag (e.g., my-image:latest) to represent both architectural variants.

Once the multi-platform manifest index was created locally, the next step involved pushing this consolidated artifact to a remote OCI registry. Block demonstrated pushing the artifact to GitHub Packages, a popular registry service. This action made the multi-platform image accessible to users across different architectures. The power of this approach was then visually confirmed by showing that both the AMD64 and ARM64 versions were available under the single, unified tag within the GitHub Packages interface, ready for consumption by users regardless of their underlying hardware.

The final, crucial aspect of the demonstration, though briefly touched upon due to time constraints, highlighted ORAS's capability to attach security-critical references. Block mentioned how the oras attach command could be used to link SBOMs (Software Bill of Materials) and signatures to the newly created multi-platform image. This demonstrated how ORAS not only streamlines multi-architecture distribution but also integrates essential software supply chain security practices, ensuring that provenance and integrity data travel alongside the artifact itself. The entire process, from creating the multi-platform index to pushing and securing it, was presented as "nice and simple," underscoring ORAS's user-friendliness for complex artifact management tasks.

Defensive Implications

▶ Watch: Securing images by attaching SBOMs and signatures (4:40)

The capabilities of ORAS present significant opportunities for strengthening an organization's defensive posture, particularly in the realm of software supply chain security and artifact integrity. Defenders can leverage ORAS in several key ways:

  1. Enforce SBOM and Signature Requirements: ORAS's ability to attach Software Bill of Materials (SBOMs) and digital signatures to any OCI artifact is a game-changer. Defenders should mandate the use of ORAS in CI/CD pipelines to automatically attach SBOMs to all published artifacts—not just container images, but also Helm charts, WebAssembly modules, policy files, and application binaries. Simultaneously, all artifacts should be digitally signed, and ORAS can be used to attach these signatures. Downstream systems can then use ORAS to verify these signatures and query SBOMs before deploying any artifact, ensuring its provenance and integrity.
  2. Standardize Artifact Provenance: By storing security metadata (SBOMs, signatures, attestations) as linked OCI artifacts, defenders gain a standardized, auditable trail for every component in their software supply chain. This allows for centralized scanning and policy enforcement. If a new vulnerability is discovered in a common library, an organization can quickly query the SBOMs attached via ORAS to identify all affected artifacts across all registries.
  3. Secure Multi-Architecture Deployments: The seamless management of multi-platform images with ORAS reduces the risk of misconfiguration or accidental deployment of an incorrect or unsupported architecture. Defenders can be confident that the correct, verified artifact is being deployed, even in diverse environments, simplifying security audits for heterogeneous clusters.
  4. Enhance Air-Gapped Environment Security: For organizations operating in highly regulated or disconnected air-gapped environments, ORAS provides a robust mechanism for securely transferring and managing artifacts. This minimizes reliance on ad-hoc or less secure transfer methods, ensuring that artifacts entering the air gap maintain their integrity and can be validated with attached signatures and SBOMs, even without external connectivity.
  5. Integrate with Policy Enforcement Tools: The ability to add custom annotations and metadata to OCI artifacts via ORAS opens doors for advanced policy enforcement. Defenders can define policies that require specific annotations (e.g., "security-scan-passed: true") or metadata before an artifact can be pulled or deployed. Tools can then use ORAS to query these annotations as part of a continuous compliance framework.
  6. Centralized Vulnerability Management: With all artifacts and their associated SBOMs residing in OCI registries, security teams can integrate registry scanning tools that understand OCI artifacts. This allows for a more comprehensive and centralized approach to vulnerability management across all types of software assets, moving beyond just scanning container images.

By embracing ORAS, organizations can move towards a more transparent, verifiable, and resilient software supply chain, proactively defending against integrity attacks and ensuring compliance with evolving security standards.

Key Takeaways

  • ORAS extends OCI registry utility: ORAS transforms OCI registries into universal storage for any OCI artifact, not just container images, enabling standardized management of diverse cloud-native assets.
  • Multi-platform support simplified: ORAS streamlines the creation and distribution of multi-platform images using OCI image indexes (manifest lists), allowing a single reference to serve multiple architectures transparently.
  • Supply chain security is paramount: ORAS facilitates robust software supply chain security by enabling the attachment of critical metadata like SBOMs and digital signatures directly to artifacts, ensuring provenance and integrity.
  • Air-gapped environments are supported: The tool offers essential capabilities for managing artifact distribution in air-gapped or disconnected networks, maintaining security and integrity in isolated settings.
  • Broad compatibility and integration: ORAS is compatible with popular OCI registries and provides SDKs in multiple languages, making it highly integrable into existing CI/CD pipelines and development workflows.
  • Customizable metadata for control: Users can add custom annotations and metadata to artifacts, enabling advanced querying, policy enforcement, and auditing across their artifact ecosystem.

About the Speaker(s)

Andrew Block is a Distinguished Architect at Red Hat and a dedicated maintainer of the ORAS project. His work focuses on advancing cloud-native patterns and leveraging OCI artifacts for modern software distribution and security. His deep involvement with ORAS highlights his expertise in OCI registries and their expanding role beyond container images. Block is an active participant in the cloud-native community, frequently speaking at conferences like KubeCon EU and ArgoCon, where he has shared insights into integrating ORAS with tools like Argo CD to enhance artifact management within continuous delivery workflows. His contributions are instrumental in shaping the future of secure and efficient artifact handling in cloud-native environments.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

This lightning talk by Andrew Block on ORAS effectively demonstrates how to leverage existing OCI registries beyond simple container images, focusing on multi-platform artifact distribution and crucial software supply chain security. Block, an ORAS maintainer, provides a clear, no-nonsense overview of how the tool enables attachment of SBOMs and signatures, making it a highly practical and actionable solution for modern cloud-native defense. It's a solid technical presentation that cuts through the noise and delivers real value.

Heather Calloway (CISO) — STRONG ACCEPT

Andrew Block's lightning talk on ORAS presents a fundamentally important tool for modern cloud-native security and operations. By standardizing the storage and distribution of all OCI artifacts—including critical security metadata like SBOMs and signatures—ORAS directly addresses core supply chain risks. This isn't just technical elegance; it's a practical mechanism for establishing verifiable provenance and integrity, enabling clear risk ownership and accountability across the software delivery pipeline.

→ Top-rated talks at KubeCon + CloudNativeCon Europe 2025

All talks from KubeCon + CloudNativeCon Europe 2025