chainctl
chainctl Chainguard Control
For the complete documentation index, see llms.txt.
Attach a Custom Assembly overlay to a repo.
Attach a Custom Assembly overlay to a repo by creating a binding.
The binding selects which of the repo’s tags the overlay applies to. Pass exactly one of:
A repo can hold several bindings of the same kind only when their overlays do not conflict; a conflicting binding is rejected, and the error names the conflicting binding and fields. An overlay can be attached to a repo only once.
The command prints the binding UID. Use it with “update-binding” and “detach”, or look it up later with “chainctl images overlays list”.
chainctl images overlays attach [flags] # Apply an overlay to every tag of a repo
chainctl images overlays attach --overlay my-overlay --repo python --parent my-org --all
# Apply an overlay to -dev tags only
chainctl images overlays attach --overlay my-overlay --repo python --parent my-org --variant dev
# Apply an overlay to specific tags
chainctl images overlays attach --overlay my-overlay --repo python --parent my-org --tag 3.12 --tag 3.13 --all Bind to every tag on the repo; multiple --all bindings may coexist when their overlays do not conflict. Mutually exclusive with --tag and --variant.
--overlay string Overlay to attach: UIDP or name (resolved within the repo's org).
--parent string Org name or UIDP for resolving --repo by name; unused when --repo is a UIDP. If unset, auto-selects when the caller belongs to a single org, otherwise prompts.
--repo string Target repo: UIDP, or name resolved within --parent.
--tag strings Exact tag names to bind to (repeatable). Mutually exclusive with --all and --variant.
--variant string Bind to a tag variant: currently only "dev" (matches tags ending in -dev). Mutually exclusive with --tag and --all. --api string The url of the Chainguard platform API. (default "https://console-api.enforce.dev")
--audience string The Chainguard token audience to request. (default "https://console-api.enforce.dev")
--config string A specific chainctl config file. Uses CHAINCTL_CONFIG environment variable if a file is not passed explicitly.
--console string The url of the Chainguard platform Console. (default "https://console.chainguard.dev")
--force-color Force color output even when stdout is not a TTY.
-h, --help Help for chainctl
--issuer string The url of the Chainguard STS endpoint. (default "https://issuer.enforce.dev")
--log-level string Set the log level (debug, info) (default "ERROR")
-o, --output string Output format. One of: [csv, env, go-template, id, json, markdown, none, table, terse, tree, wide]
-v, --v int Set the log verbosity level.Last updated: 2026-09-29 17:51