Chainguard

Chainguard Academy

  • Product Docs
    • Chainguard Enforce
    • Chainguard Images
    • chainctl
  • Open Source
    • Sigstore
    • Wolfi
    • apko
    • melange
    • Open Containers
    • SBOMs
    • SLSA
  • Software Security
    • What is Software Supply Chain Security
    • How to Select a Secure Base Image
    • Secure Software Recommendations
    • Glossary
    • Videos


  • GitHub
  • Twitter

    • Overview of Chainguard Images
    • How to Use Chainguard Images
    • Comparison of Vulnerabilities in Container Images
    • Network Requirements for Chainguard Images
    • Using the Tag History API
    • Debugging Distroless Images
    • Chainguard Images FAQs
      • Registry Overview
      • Authenticating to Chainguard Registry
        • Image Overview: apko
        • apko Image Variants
        • Provenance Information for apko Images
        • Image Overview: argocd
        • argocd Image Variants
        • Provenance Information for argocd Images
        • Image Overview: argocd-repo-server
        • argocd-repo-server Image Variants
        • Provenance Information for argocd-repo-server Images
        • Image Overview: aspnet-runtime
        • aspnet-runtime Image Variants
        • Provenance Information for aspnet-runtime Images
        • Image Overview: aws-cli
        • aws-cli Image Variants
        • Provenance Information for aws-cli Images
        • Image Overview: aws-efs-csi-driver
        • aws-efs-csi-driver Image Variants
        • Provenance Information for aws-efs-csi-driver Images
        • Image Overview: aws-load-balancer-controller
        • aws-load-balancer-controller Image Variants
        • Provenance Information for aws-load-balancer-controller Images
        • Image Overview: bash
        • bash Image Variants
        • Provenance Information for bash Images
        • Image Overview: bazel
        • bazel Image Variants
        • Provenance Information for bazel Images
        • Image Overview: buck2
        • buck2 Image Variants
        • Provenance Information for buck2 Images
        • Image Overview: busybox
        • busybox Image Variants
        • Provenance Information for busybox Images
        • Image Overview: cc-dynamic
        • cc-dynamic Image Variants
        • Provenance Information for cc-dynamic Images
        • Image Overview: cert-manager-acmesolver
        • cert-manager-acmesolver Image Variants
        • Provenance Information for cert-manager-acmesolver Images
        • Image Overview: cert-manager-cainjector
        • cert-manager-cainjector Image Variants
        • Provenance Information for cert-manager-cainjector Images
        • Image Overview: cert-manager-controller
        • cert-manager-controller Image Variants
        • Provenance Information for cert-manager-controller Images
        • Image Overview: cert-manager-webhook
        • cert-manager-webhook Image Variants
        • Provenance Information for cert-manager-webhook Images
        • Image Overview: clang
        • clang Image Variants
        • Provenance Information for clang Images
        • Image Overview: cluster-autoscaler
        • cluster-autoscaler Image Variants
        • Provenance Information for cluster-autoscaler Images
        • Image Overview: cluster-proportional-autoscaler
        • cluster-proportional-autoscaler Image Variants
        • Provenance Information for cluster-proportional-autoscaler Images
        • Image Overview: consul
        • consul Image Variants
        • Provenance Information for consul Images
        • Image Overview: coredns
        • coredns Image Variants
        • Provenance Information for coredns Images
        • Image Overview: cosign
        • cosign Image Variants
        • Provenance Information for cosign Images
        • Image Overview: crane
        • crane Image Variants
        • Provenance Information for crane Images
        • Image Overview: curl
        • curl Image Variants
        • Provenance Information for curl Images
        • Image Overview: deno
        • deno Image Variants
        • Provenance Information for deno Images
        • Image Overview: dex
        • dex Image Variants
        • Provenance Information for dex Images
        • Image Overview: dotnet-runtime
        • dotnet-runtime Image Variants
        • Provenance Information for dotnet-runtime Images
        • Image Overview: dotnet-sdk
        • dotnet-sdk Image Variants
        • Provenance Information for dotnet-sdk Images
        • Image Overview: envoy
        • envoy Image Variants
        • Provenance Information for envoy Images
        • Image Overview: envoy-ratelimit
        • envoy-ratelimit Image Variants
        • Provenance Information for envoy-ratelimit Images
        • Image Overview: etcd
        • etcd Image Variants
        • Provenance Information for etcd Images
        • Image Overview: external-attacher
        • external-attacher Image Variants
        • Provenance Information for external-attacher Images
        • Image Overview: external-dns
        • external-dns Image Variants
        • Provenance Information for external-dns Images
        • Image Overview: external-resizer
        • external-resizer Image Variants
        • Provenance Information for external-resizer Images
        • Image Overview: external-secrets
        • external-secrets Image Variants
        • Provenance Information for external-secrets Images
        • Image Overview: fluent-bit
        • fluent-bit Image Variants
        • Provenance Information for fluent-bit Images
        • Image Overview: fluentd
        • fluentd Image Variants
        • Provenance Information for fluentd Images
        • Image Overview: flux
        • flux Image Variants
        • Provenance Information for flux Images
        • Image Overview: gatekeeper
        • gatekeeper Image Variants
        • Provenance Information for gatekeeper Images
        • Image Overview: gcc-glibc
        • gcc-glibc Image Variants
        • Provenance Information for gcc-glibc Images
        • Image Overview: gcc-musl
        • gcc-musl Image Variants
        • Provenance Information for gcc-musl Images
        • Image Overview: git
        • git Image Variants
        • Provenance Information for git Images
        • Image Overview: glibc-dynamic
        • glibc-dynamic Image Variants
        • Provenance Information for glibc-dynamic Images
        • Image Overview: go
        • go Image Variants
        • Provenance Information for go Images
        • Getting Started with the Go Chainguard Image
        • Image Overview: google-cloud-sdk
        • google-cloud-sdk Image Variants
        • Provenance Information for google-cloud-sdk Images
        • Image Overview: graalvm-native
        • graalvm-native Image Variants
        • Provenance Information for graalvm-native Images
        • Image Overview: gradle
        • gradle Image Variants
        • Provenance Information for gradle Images
        • Image Overview: haproxy
        • haproxy Image Variants
        • Provenance Information for haproxy Images
        • Image Overview: haproxy-ingress
        • haproxy-ingress Image Variants
        • Provenance Information for haproxy-ingress Images
        • Image Overview: helm
        • helm Image Variants
        • Provenance Information for helm Images
        • Image Overview: helm-chartmuseum
        • helm-chartmuseum Image Variants
        • Provenance Information for helm-chartmuseum Images
        • Image Overview: helm-controller
        • helm-controller Image Variants
        • Provenance Information for helm-controller Images
        • Image Overview: http-echo
        • http-echo Image Variants
        • Provenance Information for http-echo Images
        • Image Overview: hugo
        • hugo Image Variants
        • Provenance Information for hugo Images
        • Image Overview: influxdb
        • influxdb Image Variants
        • Provenance Information for influxdb Images
        • Image Overview: jdk
        • jdk Image Variants
        • Provenance Information for jdk Images
        • Image Overview: jenkins
        • jenkins Image Variants
        • Provenance Information for jenkins Images
        • Image Overview: jre
        • jre Image Variants
        • Provenance Information for jre Images
        • Image Overview: k8s-sidecar
        • k8s-sidecar Image Variants
        • Provenance Information for k8s-sidecar Images
        • Image Overview: k8sgpt
        • k8sgpt Image Variants
        • Provenance Information for k8sgpt Images
        • Image Overview: k8sgpt-operator
        • k8sgpt-operator Image Variants
        • Provenance Information for k8sgpt-operator Images
        • Image Overview: kafka
        • kafka Image Variants
        • Provenance Information for kafka Images
        • Image Overview: karpenter
        • karpenter Image Variants
        • Provenance Information for karpenter Images
        • Image Overview: keda
        • keda Image Variants
        • Provenance Information for keda Images
        • Image Overview: keda-adapter
        • keda-adapter Image Variants
        • Provenance Information for keda-adapter Images
        • Image Overview: keda-admission-webhooks
        • keda-admission-webhooks Image Variants
        • Provenance Information for keda-admission-webhooks Images
        • Image Overview: ko
        • ko Image Variants
        • Provenance Information for ko Images
        • Image Overview: kube-bench
        • kube-bench Image Variants
        • Provenance Information for kube-bench Images
        • Image Overview: kube-downscaler
        • kube-downscaler Image Variants
        • Provenance Information for kube-downscaler Images
        • Image Overview: kube-state-metrics
        • kube-state-metrics Image Variants
        • Provenance Information for kube-state-metrics Images
        • Image Overview: kubectl
        • kubectl Image Variants
        • Provenance Information for kubectl Images
        • Image Overview: kubernetes-csi-external-provisioner
        • kubernetes-csi-external-provisioner Image Variants
        • Provenance Information for kubernetes-csi-external-provisioner Images
        • Image Overview: kubernetes-csi-livenessprobe
        • kubernetes-csi-livenessprobe Image Variants
        • Provenance Information for kubernetes-csi-livenessprobe Images
        • Image Overview: kubernetes-csi-node-driver-registrar
        • kubernetes-csi-node-driver-registrar Image Variants
        • Provenance Information for kubernetes-csi-node-driver-registrar Images
        • Image Overview: kubernetes-dashboard
        • kubernetes-dashboard Image Variants
        • Provenance Information for kubernetes-dashboard Images
        • Image Overview: kubernetes-dashboard-metrics-scraper
        • kubernetes-dashboard-metrics-scraper Image Variants
        • Provenance Information for kubernetes-dashboard-metrics-scraper Images
        • Image Overview: kubernetes-ingress-defaultbackend
        • kubernetes-ingress-defaultbackend Image Variants
        • Provenance Information for kubernetes-ingress-defaultbackend Images
        • Image Overview: kustomize-controller
        • kustomize-controller Image Variants
        • Provenance Information for kustomize-controller Images
        • Image Overview: mariadb
        • mariadb Image Variants
        • Provenance Information for mariadb Images
        • Image Overview: maven
        • maven Image Variants
        • Provenance Information for maven Images
        • Image Overview: melange
        • melange Image Variants
        • Provenance Information for melange Images
        • Image Overview: memcached
        • memcached Image Variants
        • Provenance Information for memcached Images
        • Image Overview: memcached-exporter
        • memcached-exporter Image Variants
        • Provenance Information for memcached-exporter Images
        • Image Overview: metacontroller
        • metacontroller Image Variants
        • Provenance Information for metacontroller Images
        • Image Overview: metrics-server
        • metrics-server Image Variants
        • Provenance Information for metrics-server Images
        • Image Overview: minio
        • minio Image Variants
        • Provenance Information for minio Images
        • Image Overview: minio-client
        • minio-client Image Variants
        • Provenance Information for minio-client Images
        • Image Overview: musl-dynamic
        • musl-dynamic Image Variants
        • Provenance Information for musl-dynamic Images
        • Image Overview: nats
        • nats Image Variants
        • Provenance Information for nats Images
        • Image Overview: netcat
        • netcat Image Variants
        • Provenance Information for netcat Images
        • Image Overview: newrelic-fluent-bit-output
        • newrelic-fluent-bit-output Image Variants
        • Provenance Information for newrelic-fluent-bit-output Images
        • Image Overview: newrelic-k8s-events-forwarder
        • newrelic-k8s-events-forwarder Image Variants
        • Provenance Information for newrelic-k8s-events-forwarder Images
        • Image Overview: newrelic-prometheus-configurator
        • newrelic-prometheus-configurator Image Variants
        • Provenance Information for newrelic-prometheus-configurator Images
        • Image Overview: nginx
        • nginx Image Variants
        • Provenance Information for nginx Images
        • Image Overview: node
        • node Image Variants
        • Provenance Information for node Images
        • Getting Started with the Node Chainguard Image
        • Image Overview: notification-controller
        • notification-controller Image Variants
        • Provenance Information for notification-controller Images
        • Image Overview: nri-kube-events
        • nri-kube-events Image Variants
        • Provenance Information for nri-kube-events Images
        • Image Overview: nri-kubernetes
        • nri-kubernetes Image Variants
        • Provenance Information for nri-kubernetes Images
        • Image Overview: nri-prometheus
        • nri-prometheus Image Variants
        • Provenance Information for nri-prometheus Images
        • Image Overview: ntpd-rs
        • ntpd-rs Image Variants
        • Provenance Information for ntpd-rs Images
        • Image Overview: nvidia-device-plugin
        • nvidia-device-plugin Image Variants
        • Provenance Information for nvidia-device-plugin Images
        • Image Overview: oauth2-proxy
        • oauth2-proxy Image Variants
        • Provenance Information for oauth2-proxy Images
        • Image Overview: oidc-discovery-provider
        • oidc-discovery-provider Image Variants
        • Provenance Information for oidc-discovery-provider Images
        • Image Overview: openai
        • openai Image Variants
        • Provenance Information for openai Images
        • Image Overview: opensearch
        • opensearch Image Variants
        • Provenance Information for opensearch Images
        • Image Overview: paranoia
        • paranoia Image Variants
        • Provenance Information for paranoia Images
        • Image Overview: php
        • php Image Variants
        • Provenance Information for php Images
        • Getting Started with the PHP Chainguard Image
        • Image Overview: postgres
        • postgres Image Variants
        • Provenance Information for postgres Images
        • Image Overview: powershell
        • powershell Image Variants
        • Provenance Information for powershell Images
        • Image Overview: prometheus
        • prometheus Image Variants
        • Provenance Information for prometheus Images
        • Image Overview: prometheus-alertmanager
        • prometheus-alertmanager Image Variants
        • Provenance Information for prometheus-alertmanager Images
        • Image Overview: prometheus-cloudwatch-exporter
        • prometheus-cloudwatch-exporter Image Variants
        • Provenance Information for prometheus-cloudwatch-exporter Images
        • Image Overview: prometheus-config-reloader
        • prometheus-config-reloader Image Variants
        • Provenance Information for prometheus-config-reloader Images
        • Image Overview: prometheus-elasticsearch-exporter
        • prometheus-elasticsearch-exporter Image Variants
        • Provenance Information for prometheus-elasticsearch-exporter Images
        • Image Overview: prometheus-mysqld-exporter
        • prometheus-mysqld-exporter Image Variants
        • Provenance Information for prometheus-mysqld-exporter Images
        • Image Overview: prometheus-node-exporter
        • prometheus-node-exporter Image Variants
        • Provenance Information for prometheus-node-exporter Images
        • Image Overview: prometheus-operator
        • prometheus-operator Image Variants
        • Provenance Information for prometheus-operator Images
        • Image Overview: prometheus-postgres-exporter
        • prometheus-postgres-exporter Image Variants
        • Provenance Information for prometheus-postgres-exporter Images
        • Image Overview: prometheus-redis-exporter
        • prometheus-redis-exporter Image Variants
        • Provenance Information for prometheus-redis-exporter Images
        • Image Overview: pulumi
        • pulumi Image Variants
        • Provenance Information for pulumi Images
        • Image Overview: python
        • python Image Variants
        • Provenance Information for python Images
        • Getting Started with the Python Chainguard Image
        • Image Overview: rabbitmq
        • rabbitmq Image Variants
        • Provenance Information for rabbitmq Images
        • Image Overview: redis
        • redis Image Variants
        • Provenance Information for redis Images
        • Image Overview: rqlite
        • rqlite Image Variants
        • Provenance Information for rqlite Images
        • Image Overview: ruby
        • ruby Image Variants
        • Provenance Information for ruby Images
        • Getting Started with the Ruby Chainguard Image
        • Image Overview: rust
        • rust Image Variants
        • Provenance Information for rust Images
        • Image Overview: sdk
        • Provenance Information for sdk Images
        • Image Overview: secrets-store-csi-driver
        • secrets-store-csi-driver Image Variants
        • Provenance Information for secrets-store-csi-driver Images
        • Image Overview: secrets-store-csi-driver-provider-gcp
        • secrets-store-csi-driver-provider-gcp Image Variants
        • Provenance Information for secrets-store-csi-driver-provider-gcp Images
        • Image Overview: skaffold
        • skaffold Image Variants
        • Provenance Information for skaffold Images
        • Image Overview: source-controller
        • source-controller Image Variants
        • Provenance Information for source-controller Images
        • Image Overview: spire-agent
        • spire-agent Image Variants
        • Provenance Information for spire-agent Images
        • Image Overview: spire-server
        • spire-server Image Variants
        • Provenance Information for spire-server Images
        • Image Overview: stakater-reloader
        • stakater-reloader Image Variants
        • Provenance Information for stakater-reloader Images
        • Image Overview: static
        • static Image Variants
        • Provenance Information for static Images
        • Image Overview: telegraf
        • telegraf Image Variants
        • Provenance Information for telegraf Images
        • Image Overview: terraform
        • terraform Image Variants
        • Provenance Information for terraform Images
        • Image Overview: thanos
        • thanos Image Variants
        • Provenance Information for thanos Images
        • Image Overview: traefik
        • traefik Image Variants
        • Provenance Information for traefik Images
        • Image Overview: trust-manager
        • trust-manager Image Variants
        • Provenance Information for trust-manager Images
        • Image Overview: vault
        • vault Image Variants
        • Provenance Information for vault Images
        • Image Overview: vault-k8s
        • vault-k8s Image Variants
        • Provenance Information for vault-k8s Images
        • Image Overview: vela-cli
        • vela-cli Image Variants
        • Provenance Information for vela-cli Images
        • Image Overview: vertical-pod-autoscaler-admission-controller
        • vertical-pod-autoscaler-admission-controller Image Variants
        • Provenance Information for vertical-pod-autoscaler-admission-controller Images
        • Image Overview: vertical-pod-autoscaler-recommender
        • vertical-pod-autoscaler-recommender Image Variants
        • Provenance Information for vertical-pod-autoscaler-recommender Images
        • Image Overview: vertical-pod-autoscaler-updater
        • vertical-pod-autoscaler-updater Image Variants
        • Provenance Information for vertical-pod-autoscaler-updater Images
        • Image Overview: vt
        • vt Image Variants
        • Provenance Information for vt Images
        • Image Overview: wait-for-it
        • wait-for-it Image Variants
        • Provenance Information for wait-for-it Images
        • Image Overview: wavefront-proxy
        • wavefront-proxy Image Variants
        • Provenance Information for wavefront-proxy Images
        • Image Overview: weaviate
        • weaviate Image Variants
        • Provenance Information for weaviate Images
        • Image Overview: wolfi-base
        • wolfi-base Image Variants
        • Provenance Information for wolfi-base Images
        • Image Overview: zookeeper
        • zookeeper Image Variants
        • Provenance Information for zookeeper Images
        • Image Overview: zot
        • zot Image Variants
        • Provenance Information for zot Images
    • Overview
    • Getting Started
    • Connect
    • Cloud Account Associations
    • Discover Your Workloads
      • Sign In
      • Custom IDPs
        • Okta
        • Ping Identity
        • Azure Active Directory
      • Installation
      • Profiles
      • Enforcer Options
      • Console Policy Management
      • chainctl Policy Management
      • Rego Policies
      • Disable Policy Enforcement
      • Example Policies
        • Critical CVEs
        • Kubernetes Registry Deprecation
        • Limit “Build Horizon”
      • IAM Overview
      • Manage IAM Groups
      • Assumable Identities
        • GitHub Actions Assumable Identity
        • Buildkite Assumable Identity
        • Bitbucket Assumable Identity
        • Jenkins Assumable Identity
      • Create Jira Issues from Enforce CloudEvents
      • Create GitHub Issues from Enforce CloudEvents
      • Create Slack Alerts from Enforce CloudEvents
      • Annotation-based Caching
      • Connect to Private Registries
      • Gulfstream
      • Continuous Verification
      • SBOMs and Attestations
      • Detect Log4Shell
      • Overview and FAQs
      • Get Started with Enforce Signing
      • How to Set Up a CA
      • Example Policy for Enforce Signed Images
      • Getting Started with Chainguard Enforce for Git
      • How to Install Chainguard Enforce for Git
      • Agent Requirements
      • Network Requirements
      • Data Collection
      • OpenAPI Specification
      • Chainguard Enforce Events
    • Chainguard Enforce Changelog
    • Troubleshooting Tips
    • Install chainctl
    • chainctl
    • chainctl auth
    • chainctl auth login
    • chainctl auth logout
    • chainctl auth status
    • chainctl clusters
    • chainctl clusters cidrs
    • chainctl clusters cidrs list
    • chainctl clusters describe
    • chainctl clusters discover
    • chainctl clusters install
    • chainctl clusters list
    • chainctl clusters open
    • chainctl clusters print-config
    • chainctl clusters profiles
    • chainctl clusters profiles list
    • chainctl clusters records
    • chainctl clusters records list
    • chainctl clusters records vulns
    • chainctl clusters records vulns list
    • chainctl clusters search
    • chainctl clusters uninstall
    • chainctl clusters update
    • chainctl clusters workloads
    • chainctl clusters workloads list
    • chainctl config
    • chainctl config edit
    • chainctl config reset
    • chainctl config save
    • chainctl config set
    • chainctl config unset
    • chainctl config view
    • chainctl events
    • chainctl events subscriptions
    • chainctl events subscriptions create
    • chainctl events subscriptions delete
    • chainctl events subscriptions list
    • chainctl iam
    • chainctl iam account-associations
    • chainctl iam account-associations check
    • chainctl iam account-associations check aws
    • chainctl iam account-associations check gcp
    • chainctl iam account-associations describe
    • chainctl iam account-associations set
    • chainctl iam account-associations set aws
    • chainctl iam account-associations set gcp
    • chainctl iam account-associations unset
    • chainctl iam account-associations unset aws
    • chainctl iam account-associations unset gcp
    • chainctl iam groups
    • chainctl iam groups create
    • chainctl iam groups delete
    • chainctl iam groups describe
    • chainctl iam groups list
    • chainctl iam groups update
    • chainctl iam identities
    • chainctl iam identities create
    • chainctl iam identities create github
    • chainctl iam identities create gitlab
    • chainctl iam identities delete
    • chainctl iam identities list
    • chainctl iam identities update
    • chainctl iam identities view
    • chainctl iam identity-providers
    • chainctl iam identity-providers create
    • chainctl iam identity-providers delete
    • chainctl iam identity-providers list
    • chainctl iam identity-providers update
    • chainctl iam invites
    • chainctl iam invites create
    • chainctl iam invites delete
    • chainctl iam invites list
    • chainctl iam role-bindings
    • chainctl iam role-bindings create
    • chainctl iam role-bindings delete
    • chainctl iam role-bindings list
    • chainctl iam role-bindings update
    • chainctl iam roles
    • chainctl iam roles capabilities
    • chainctl iam roles capabilities list
    • chainctl iam roles list
    • chainctl images
    • chainctl images list
    • chainctl images repos
    • chainctl images repos list
    • chainctl policies
    • chainctl policies apply
    • chainctl policies delete
    • chainctl policies edit
    • chainctl policies list
    • chainctl policies update
    • chainctl policies versions
    • chainctl policies versions activate
    • chainctl policies versions diff
    • chainctl policies versions list
    • chainctl policies versions view
    • chainctl policies view
    • chainctl sigstore
    • chainctl sigstore ca
    • chainctl sigstore ca create
    • chainctl sigstore ca delete
    • chainctl sigstore ca describe
    • chainctl sigstore ca list
    • chainctl sigstore env
    • chainctl update
    • chainctl version

Chainguard Enforce

The Chainguard Enforce security platform offers a suite of tools for increased security across your software supply chain.

Overview of Chainguard Enforce →
Getting Started With Chainguard Enforce →
Connect Kubernetes Clusters to Enforce →
How to Set Up Chainguard Enforce Cloud Account Associations →
Getting Started With Enforce Discovery →
Authentication →
Installation →
Policies →
IAM Groups & Users →
CloudEvents →
Administration →
Concepts →
Enforce Signing →
Enforce for Git →
Reference →
Chainguard Enforce Changelog →
Troubleshooting Tips →
How to Install Chainctl →
  • ©2023 Chainguard, CC BY-NC-SA 4.0