LICENSEWARE

Docker Hardened Images licensing

This article covers how Docker licenses Docker Hardened Images (DHI): the free Community catalog, the per-repository Select and Enterprise subscriptions and the Extended Lifecycle Support add-on. For Docker Desktop plans and the DSSA, see Docker licensing. It is not legal advice.

On This Page

Docker Hardened Images (DHI) is Docker’s catalog of minimal, continuously patched container images. The Docker Product Schedule, which the Docker Subscription Service Agreement (DSSA) incorporates by reference, defines Docker Hardened Images as “a catalog of security-enhanced Docker Images”.[3] Unlike Docker Desktop, DHI is not licensed per user. The free tier is an open source catalog, and the paid tiers are counted in repositories.[1][2]

For a software asset manager, DHI raises three questions. Which images in the estate come from the free catalog and which from a paid, mirrored repository? How many repositories has the organization bought, and when can that number go down? And which teams rely on the Extended Lifecycle Support (ELS) add-on for software whose upstream project is past end of life?

Editions

Docker documents three DHI subscriptions.[1][2]

Feature Community Select Enterprise 
Hardened, minimal images; SBOMs and SLSA Build Level 3 provenance Yes Yes Yes 
Full catalog of open source images under Apache 2.0 Yes Yes Yes 
FIPS and STIG variants No Yes Yes 
Critical CVE fixes in under 7 days with SLA-backed patching No Yes Yes 
Customizations No Up to 5 Unlimited 
Hardened System Packages repository No No Yes 
Full catalog access No No Available 
Extended Lifecycle Support add-on No No Available (+5 years of hardened updates) 

Source: Docker Hardened Images documentation and Docker pricing page, as published on 2026-10-02.[1][4]

The pricing page lists DHI Community as “Free for every developer”, DHI Select as “Starting at $5k/repo” and DHI Enterprise as “Contact us for pricing”.[4] DHI Select can be bought self-serve in the billing portal. DHI Enterprise is sold through Docker sales.[2]

Metrics

The catalog records two DHI metrics, both defined in the Docker Product Schedule (last updated 2026-08-26).[3]

  • Docker Repo Unit. ““Docker Repo Unit” means an individual repository of the Docker Hardened Images catalog.”[3] It is the unit in which DHI Select is billed.[2]
  • ELS Repo Unit. An individual DHI repository “subject to Extended Lifecycle Support”. The repositories for which Docker offers ELS form the ELS Catalog, which Docker identifies in its documentation and updates periodically.[3]

The Product Schedule defines End-of-Life (EOL) as “the date the originating open-source project ceases to provide security or maintenance updates”.[3] The date is set by the upstream project, not by Docker.

Users, cores and hosts are not DHI metrics. When a customer buys DHI Select, it purchases “a set number of repositories that are mirrored into your organization’s namespace”, and “All organization members can then pull from those mirrored repositories.”[2]

Counting / floors

Rule What it says 
DHI Select billed annually per repository with mid-cycle proration Annual plan billed per repository; repositories added mid-cycle prorated; entitlements scoped to the organization chosen at checkout[2] 
DHI repository removals and auto-renewal changes take effect at cycle end Removals and disabling auto-renewal take effect at the end of the billing cycle; no partial refund[2] 
Mirroring DHI repositories requires a Select or Enterprise subscription Mirroring requires Select or Enterprise; a stopped mirror keeps its last images but gets no updates[5] 
Extended Lifecycle Support requires DHI Enterprise Extended Lifecycle Support requires DHI Enterprise[1][4] 
DHI Community images free under Apache 2.0 without remediation SLA Community images free under Apache 2.0, with no guaranteed remediation timelines[1][6] 

“DHI Select is an annual plan billed per repository from the date your plan starts.” Repositories added during the year “are prorated for the remainder of the billing period”.[2] The count can only go down at renewal. Repository removals and disabling auto-renewal “are deferred to the end of the current billing cycle”, and “you cannot stop a plan mid-cycle to receive a partial refund”.[2] DHI Enterprise customers change their plan through their sales representative.[2]

Entitlements “are scoped to the organization account that you assign them to during checkout”.[2] An estate with several Docker Hub organizations should therefore record which organization holds each paid repository.

Mirroring

The paid tiers work through mirroring. “Mirroring requires a DHI Select or Enterprise subscription.” Without a subscription, images are pulled directly from dhi.io.[5] A mirrored repository appears in the organization’s namespace with a dhi- prefix, and it can then be mirrored on to a third-party registry such as Amazon ECR or Google Artifact Registry.[5] If ELS is part of the subscription, it is switched on per mirrored repository.[5]

Stopping a mirror does not delete what was copied. “After you stop mirroring, the repository remains, but it no longer receives updates. You can still use the last images or charts that were mirrored.”[5] After a subscription is reduced, images in a stopped mirror keep running without patches. A licence review should check for them.

Programs

DHI is not sold through a volume program. The subscriptions are Docker Services under the DSSA, which defines Services by reference to the Product Schedule.[7] Docker’s pricing page notes that the Premium Support and TAM service is available “as an add-on to Docker Business and DHI”.[4]

Support differs by tier. Community users get “Community support and public documentation”. DHI Select and Enterprise users get “Access to Docker’s enterprise support team for mission-critical applications”.[6]

Open source licence and redistribution

“DHI’s core features are free to use, share, and build on under Apache 2.0.”[1] The images still contain upstream open source components under their own licences. Docker’s responsibility model names three groups: the upstream maintainers who publish and patch the software, Docker, which builds, hardens and signs the images, and the customer, which runs and optionally customizes them.[6] Open source licence obligations for those components are covered in Open source software licensing.

Images obtained under a paid subscription are also governed by the DSSA. Its licence grant allows the customer to “redistribute Docker Images to third parties but solely when bundled with or incorporated into its own software products, and not on a standalone basis”. The DSSA adds that “All third party images shall be deemed Third-Party Products”.[7] The DSSA’s critical-systems clause bars use of the Services as a basis for systems “that must be hardened or highly secure except to the extent supported by DHI”.[7]

Patching responsibility

Under Docker’s responsibility model, Docker “Rebuilds and re-releases images with upstream patches applied”. The customer must “Apply DHI updates in your environments and patch any software or dependencies you install on top of the base image”.[6] The SLA is the main difference between the tiers. DHI Select and DHI Enterprise include SLA commitments, while “DHI Community offers a secure baseline but no guaranteed remediation timelines.”[6]

Extended Lifecycle Support adds “post-EOL security patches, updated SBOMs, provenance, and signing” as an Enterprise add-on.[1] The pricing page describes it as “Security and compliance for end-of-life software. Requires DHI Enterprise.”[4]

Out of scope

  • DHI Enterprise and Extended Lifecycle Support prices, which Docker does not publish.[4]
  • The service level terms behind the DHI remediation SLA, which the documentation links separately.[6]
  • Licences of individual upstream components inside each image. Each image ships SBOMs that list them.[1]
  • Docker Desktop, Docker Hub and per-user plans, covered in Docker Desktop subscription licensing.

References

  1. Docker Hardened Images (Docker Docs)Feature comparison of Community, Select and Enterprise; Apache 2.0; customization limits; Extended Lifecycle Support.Retrieved 2026-10-02.
  2. DHI plans (Docker Docs)Usage, billing cycle, auto-renewal and repository removal.Retrieved 2026-10-02.
  3. Docker Product ScheduleDefinitions of Docker Hardened Images, Docker Repo Unit, ELS Catalog, ELS Repo Unit and End-of-Life.Effective 2026-08-26. Retrieved 2026-10-02.
  4. Docker PricingDHI Community, Select and Enterprise columns; Extended Lifecycle Support add-on.Retrieved 2026-10-02.
  5. Mirror a Docker Hardened Image repository (Docker Docs)Retrieved 2026-10-02.
  6. Understanding roles and responsibilities for Docker Hardened Images (Docker Docs)Retrieved 2026-10-02.
  7. Docker Subscription Service AgreementLast updated on August 26, 2026. Services definition, licence grant, redistribution of Docker Images, critical systems.Effective 2026-08-26. Retrieved 2026-10-02.

See also

Catalog Rows Cited

2Metrics5Rules

Esc