Do people usually roll out their own images from source/based on verified binaries from the parent distribution's repositories or are base images provided by the community?
Do people usually roll out their own images from source/based on verified binaries from the parent distribution's repositories or are base images provided by the community?
The place of trust here is the registry - usually, for convenience, tags are used rather than hashes (and I'm still quite not sure whether the long hex IDs are hashes, or just unique random names). The registry returns hex id for a given tag, and is trusted to deliver correct files for an ID.
I believe that the main index/registry runs over https and provides basic security, but it would be a huge issue if it was compromised. It's quite easy to run your own registry, too. What I'd love to see on top of that is some kind of GPG-based verification of downloaded images (Debian got the problem basically solved in Apt).