OCImendby CloudTrace

Free · online · verified

FIPS-enabled container images

A FIPS-enabled container image runs its cryptography only through a module with a FIPS 140-3 certificate, in FIPS mode, inside the image itself. OCImend enables FIPS on any compatible Docker or OCI image for free and proves it live: non-approved algorithms such as MD5 are refused and FIPS mode reports on. Pull the ready ones below or enable FIPS on your own image online.

Make my image FIPS-enabled → Browse the registry

24ready-to-pull images on this page
0known CVEs removed from them
Freeno sign-up, nothing to install
Verifiedrescanned and run-tested

Why OCImend

FIPS mode in the image

Enforced for every process in the container, not dependent on the host kernel's FIPS flag.

Proven live

Each image is started and tested: approved algorithms work, non-approved ones are refused. The result is on its FIPS report.

Combine with CVE fixes

CVE-fixed + FIPS and hardened + FIPS images in one build.

Honest verdicts

Programs that carry their own crypto (Go, Java, bundled OpenSSL) are checked one by one; when an image cannot be made FIPS the report says why.

Ready to pull

ImagePullKnown CVEs before → afterBuilt
registry.access.redhat.com/ubi9/ubi-minimal
from registry.access.redhat.com/ubi9/ubi-minimal:9.8-1790754119
docker pull ocimend.io/registry.access.redhat.com/ubi9/ubi-minimal:9.8-1790754119-fips0 → 02026-10-01
wordpress
from mirror.gcr.io/library/wordpress:7.1.1-php8.4-fpm
docker pull ocimend.io/wordpress:7.1.1-php8.4-fpm-fips186 → 1862026-10-01
ruby
from mirror.gcr.io/library/ruby:4.0.2
docker pull ocimend.io/ruby:4.0.2-fips379 → 3792026-10-01
php
from mirror.gcr.io/library/php:8.5.10-zts-alpine3.24
docker pull ocimend.io/php:8.5.10-zts-alpine3.24-fips0 → 02026-10-01
haproxy
from mirror.gcr.io/library/haproxy:2.6-alpine3.22
docker pull ocimend.io/haproxy:2.6-alpine3.22-fips101 → 1012026-10-01
traefik
from mirror.gcr.io/library/traefik:v3.1.3
docker pull ocimend.io/traefik:v3.1.3-fips141 → 1412026-10-01
mariadb
from mirror.gcr.io/library/mariadb:11.4.4
docker pull ocimend.io/mariadb:11.4.4-fips309 → 3092026-10-01
ubuntu
from mirror.gcr.io/library/ubuntu:noble-20250404
docker pull ocimend.io/ubuntu:noble-20250404-fips6 → 62026-10-01
alpine
from mirror.gcr.io/library/alpine:20221110
docker pull ocimend.io/alpine:20221110-fips0 → 02026-10-01
python
from mirror.gcr.io/library/python:3.13.0a1-alpine3.17
docker pull ocimend.io/python:3.13.0a1-alpine3.17-fips48 → 482026-10-01
postgres
from mirror.gcr.io/library/postgres:14.24-trixie
docker pull ocimend.io/postgres:14.24-trixie-fips112 → 1122026-10-01
redis
from mirror.gcr.io/library/redis:7.0.14-alpine3.18
docker pull ocimend.io/redis:7.0.14-alpine3.18-fips26 → 262026-10-01
nginx
from mirror.gcr.io/library/nginx:1.28.2
docker pull ocimend.io/nginx:1.28.2-fips65 → 652026-10-01
mongo
from mirror.gcr.io/library/mongo:7.0.43
docker pull ocimend.io/mongo:7.0.43-fips104 → 1042026-09-30
registry.access.redhat.com/ubi9/ubi
from registry.access.redhat.com/ubi9/ubi:9.8-1790665138
docker pull ocimend.io/registry.access.redhat.com/ubi9/ubi:9.8-1790665138-fips18 → 182026-09-30
debian
from mirror.gcr.io/library/debian:trixie-20260623-slim
docker pull ocimend.io/debian:trixie-20260623-slim-fips26 → 262026-09-30
mysql
from mirror.gcr.io/library/mysql:8.0.44-oracle
docker pull ocimend.io/mysql:8.0.44-oracle-fips68 → 682026-09-29
httpd
from mirror.gcr.io/library/httpd:2.4.61
docker pull ocimend.io/httpd:2.4.61-fips107 → 1072026-09-28
caddy
from mirror.gcr.io/library/caddy:latest
docker pull ocimend.io/caddy:latest-fips0 → 362026-09-27
gcr.io/distroless/base-debian12
from gcr.io/distroless/base-debian12:latest
docker pull ocimend.io/gcr.io/distroless/base-debian12:latest-fips3 → 32026-09-27
mcr.microsoft.com/azurelinux/base/core
from mcr.microsoft.com/azurelinux/base/core:3.0.20260909
docker pull ocimend.io/mcr.microsoft.com/azurelinux/base/core:3.0.20260909-fips30 → 302026-09-27
registry
from mirror.gcr.io/library/registry:latest
docker pull ocimend.io/registry:latest-fips0 → 72026-09-27
memcached
from mirror.gcr.io/library/memcached:latest
docker pull ocimend.io/memcached:latest-fips26 → 262026-09-27
ubuntu/nginx
from docker.io/ubuntu/nginx:latest
docker pull ocimend.io/ubuntu/nginx:latest-fips0 → 02026-09-26

Questions

What is the difference between FIPS 140-2 and 140-3?
140-3 is the current standard; new validations are 140-3 and 140-2 certificates are historical. OCImend checks against the 140-3 program.
Do I need a FIPS host?
No. FIPS mode is enforced inside the image, so it behaves the same on any host or Kubernetes cluster.
Is it free?
Yes. FIPS enablement of public images is free, online, with no sign-up.
Does it help with FedRAMP?
FedRAMP and other US federal programs require FIPS-validated cryptography; a FIPS-enabled image with its FIPS report is the evidence for the container layer.

Also on OCImend

CVE-free images · Free online CVE fix · Hardened images · Image CVE reports · Guides · For platform teams

Make my image FIPS-enabled →