chainctl
chainctl Chainguard Control
For the complete documentation index, see llms.txt.
Manage Custom Assembly overlays and the repos they are attached to.
Manage tag-based Custom Assembly overlays.
An overlay is a reusable image customization (packages, environment variables, annotations, accounts, and certificates) owned by an organization or folder. Attaching an overlay to a repo creates a binding that selects which of the repo’s tags the overlay applies to:
When bindings of different kinds match the same tag, they layer in the order ALL, then VARIANT, then EXACT, with later layers taking precedence. Bindings of the same kind may coexist on a repo only when their overlays do not conflict.
Chainguard rebuilds the matching images after an overlay or binding changes. These rebuilds run only for organizations enrolled in tag-based Custom Assembly. Contact your Chainguard account team to enroll.
# Create an overlay that adds packages
chainctl images overlays create my-overlay --parent my-org --package curl --package jq
# Attach it to every tag of a repo
chainctl images overlays attach --overlay my-overlay --repo python --parent my-org --all
# List overlays and their bindings
chainctl images overlays list --parent my-org --api string The url of the Chainguard platform API. (default "https://console-api.enforce.dev")
--audience string The Chainguard token audience to request. (default "https://console-api.enforce.dev")
--config string A specific chainctl config file. Uses CHAINCTL_CONFIG environment variable if a file is not passed explicitly.
--console string The url of the Chainguard platform Console. (default "https://console.chainguard.dev")
--force-color Force color output even when stdout is not a TTY.
-h, --help Help for chainctl
--issuer string The url of the Chainguard STS endpoint. (default "https://issuer.enforce.dev")
--log-level string Set the log level (debug, info) (default "ERROR")
-o, --output string Output format. One of: [csv, env, go-template, id, json, markdown, none, table, terse, tree, wide]
-v, --v int Set the log verbosity level.Last updated: 2026-09-29 17:51