Skip to main content
Microsoft
separator
https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.dragonfly-oss-04134213-83d4-4c62-8abe-024975e7e56d/image6_logolarge.png

Dragonfly on Ubuntu 24.04 LTS

by cloudimg

Peer-to-peer file and image distribution: a complete Dragonfly cluster on one VM

Dragonfly is an open-source, cloud-native peer-to-peer (P2P) file and container image distribution system, and a graduated project of the Cloud Native Computing Foundation. It turns the machines that pull artifacts into a swarm that shares pieces with each other, so a large image, model file or dataset is fetched from the origin once and then spread P2P between peers. This cuts origin bandwidth, speeds up mass rollouts, and stops registries and object stores from being overwhelmed when many hosts pull the same content at once.

What the cloudimg image gives you

  • Dragonfly server 2.5.1 (the manager and scheduler) and Dragonfly client 1.4.9 (the Rust dfdaemon and dfget), installed from pinned upstream releases
  • A complete single-node cluster on one VM under systemd: the manager and its web console, the scheduler, and a dfdaemon running in seed-peer mode
  • MariaDB and Redis preconfigured as the manager backing store, bound to loopback and tuned to run on a small VM
  • An HTTP/HTTPS proxy and the dfget command line for pulling content through the P2P network
  • Ubuntu 24.04 LTS with the latest security patches applied at build time

Secure by default

Dragonfly's manager ships a default console login of root / dragonfly. An appliance that shipped that unchanged would be wide open. This image inverts that: on the first boot of each VM the manager console is brought up on the loopback interface only, its root password is rotated to a value unique to your VM, and only then is the console rebound to the network — so the published default is never reachable off the box. The captured image contains no console password, no database password, no Redis password and no API signing key; all of them are generated uniquely on your VM at first boot and written to a root-only file. Every image is verified before it ships by pulling a real file end to end through the seed peer and scheduler and checksum-matching the delivered bytes.

Licensing and pricing

Dragonfly is licensed under the Apache License 2.0 and is free — there is no per-node or per-user fee. The cloudimg charge of 0.04 USD per vCPU hour covers packaging, security patching, image maintenance and 24/7 expert support. Recommended size: Standard_B2s to start; scale up or add more peers for busy swarms.

Before you deploy

Prerequisites: an Azure subscription, a VNet and subnet, and an SSH key. NSG inbound: port 22 for SSH, port 8080 for the manager web console (restrict this to trusted addresses), and port 4001 if you want other machines to pull through this node's proxy. The manager job API has a known upstream advisory (CVE-2026-24124) in which preheat endpoints are callable without authentication, so the console port should never be open to the whole internet.

At a glance

https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.dragonfly-oss-04134213-83d4-4c62-8abe-024975e7e56d/image7_screenshot01.png
https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.dragonfly-oss-04134213-83d4-4c62-8abe-024975e7e56d/image5_screenshot02.png
https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.dragonfly-oss-04134213-83d4-4c62-8abe-024975e7e56d/image3_screenshot03.png
https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.dragonfly-oss-04134213-83d4-4c62-8abe-024975e7e56d/image1_screenshot04.png
English (United States)
Your Privacy Choices Opt-Out Icon Your Privacy Choices
Consumer Health Privacy Sitemap Contact Us Privacy & Cookies Terms of Use About our ads Manage cookies