<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Guarded Entrypoint for Custom Assembly on</title><link>https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/custom-assembly/guarded-entrypoint/</link><description>Recent content in Guarded Entrypoint for Custom Assembly on</description><generator>Hugo -- gohugo.io</generator><language>en-US</language><copyright>Copyright (c) 2023 Chainguard</copyright><lastBuildDate>Tue, 06 Oct 2026 17:41:00 +0000</lastBuildDate><atom:link href="https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/custom-assembly/guarded-entrypoint/index.xml" rel="self" type="application/rss+xml"/><item><title>How Guarded Entrypoint works</title><link>https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/custom-assembly/guarded-entrypoint/how-it-works/</link><pubDate>Tue, 06 Oct 2026 17:41:00 +0000</pubDate><guid>https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/custom-assembly/guarded-entrypoint/how-it-works/</guid><description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Note&lt;/strong&gt;: Guarded Entrypoint is in beta. To use it, contact Chainguard customer support to enable it for your organization.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;This page describes what the Guarded Entrypoint binary does when a container starts. The page calls the binary the wrapper. To turn Guarded Entrypoint on, see &lt;a href="https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/custom-assembly/guarded-entrypoint/"&gt;Guarded Entrypoint for Custom Assembly&lt;/a&gt;.&lt;/p&gt;
&lt;h2 id="what-the-wrapper-does" class="heading-2" data-heading-level="2"&gt;
&lt;span class="heading-text"&gt;What the wrapper does&lt;/span&gt;
&lt;a href="#what-the-wrapper-does" class="anchor" aria-label="Link to What the wrapper does" title="Link to this section"&gt;
&lt;svg width="16" height="9" viewBox="0 0 16 9" fill="none" xmlns="http://www.w3.org/2000/svg" aria-hidden="true"&gt;
&lt;path d="M6.833 8.125H4C3 8.125 2.146 7.77067 1.438 7.062C0.729333 6.354 0.375 5.5 0.375 4.5C0.375 3.5 0.729333 2.646 1.438 1.938C2.146 1.22933 3 0.875 4 0.875H6.833V1.958H4C3.30533 1.958 2.708 2.208 2.208 2.708C1.708 3.208 1.458 3.80533 1.458 4.5C1.458 5.19467 1.708 5.792 2.208 6.292C2.708 6.792 3.30533 7.042 4 7.042H6.833V8.125ZM5.208 5.042V3.958H10.792V5.042H5.208ZM9.167 8.125V7.042H12C12.6947 7.042 13.292 6.792 13.792 6.292C14.292 5.792 14.542 5.19467 14.542 4.5C14.542 3.80533 14.292 3.208 13.792 2.708C13.292 2.208 12.6947 1.958 12 1.958H9.167V0.875H12C13 0.875 13.854 1.22933 14.562 1.938C15.2707 2.646 15.625 3.5 15.625 4.5C15.625 5.5 15.2707 6.354 14.562 7.062C13.854 7.77067 13 8.125 12 8.125H9.167Z" fill="currentColor"/&gt;
&lt;/svg&gt;
&lt;/a&gt;
&lt;/h2&gt;&lt;p&gt;When you turn on Guarded Entrypoint, Chainguard rebuilds the image with &lt;code&gt;/usr/bin/guarded-entrypoint&lt;/code&gt; as the first element of its entrypoint. The image&amp;rsquo;s original entrypoint follows it. Chainguard stores your settings in environment variables in the image configuration. The names of these variables start with &lt;code&gt;GUARDED_&lt;/code&gt;. You can see them with &lt;code&gt;docker inspect&lt;/code&gt;. The &lt;code&gt;GUARDED_&lt;/code&gt; prefix is reserved, and the API rejects it in your own &lt;code&gt;environment&lt;/code&gt; keys.&lt;/p&gt;</description></item><item><title>Guarded Entrypoint examples</title><link>https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/custom-assembly/guarded-entrypoint/examples/</link><pubDate>Tue, 06 Oct 2026 17:41:00 +0000</pubDate><guid>https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/custom-assembly/guarded-entrypoint/examples/</guid><description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Note&lt;/strong&gt;: Guarded Entrypoint is in beta. To use it, contact Chainguard customer support to enable it for your organization.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;This page has four example manifests for &lt;a href="https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/custom-assembly/guarded-entrypoint/"&gt;Guarded Entrypoint&lt;/a&gt;. Each one is a complete manifest for &lt;code&gt;chainctl images repos build edit&lt;/code&gt; or &lt;code&gt;chainctl images repos build apply&lt;/code&gt;. None of them contains a literal secret. Each secret is a reference that the wrapper resolves when the container starts.&lt;/p&gt;
&lt;p&gt;Applying a manifest replaces the repo&amp;rsquo;s stored configuration. If your repo already has other customizations, such as packages, add the Guarded Entrypoint keys to your existing manifest instead of replacing it.&lt;/p&gt;</description></item><item><title>Troubleshoot a wrapped container</title><link>https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/custom-assembly/guarded-entrypoint/troubleshooting/</link><pubDate>Tue, 06 Oct 2026 17:41:00 +0000</pubDate><guid>https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/custom-assembly/guarded-entrypoint/troubleshooting/</guid><description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Note&lt;/strong&gt;: Guarded Entrypoint is in beta. To use it, contact Chainguard customer support to enable it for your organization.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;This page covers two kinds of problems. A container that is built with &lt;a href="https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/custom-assembly/guarded-entrypoint/"&gt;Guarded Entrypoint&lt;/a&gt; can fail to start. A build can also fail because Chainguard refuses to wrap an image.&lt;/p&gt;
&lt;h2 id="first-move-set-guarded_disable" class="heading-2" data-heading-level="2"&gt;
&lt;span class="heading-text"&gt;First move: set GUARDED_DISABLE&lt;/span&gt;
&lt;a href="#first-move-set-guarded_disable" class="anchor" aria-label="Link to First move: set GUARDED_DISABLE" title="Link to this section"&gt;
&lt;svg width="16" height="9" viewBox="0 0 16 9" fill="none" xmlns="http://www.w3.org/2000/svg" aria-hidden="true"&gt;
&lt;path d="M6.833 8.125H4C3 8.125 2.146 7.77067 1.438 7.062C0.729333 6.354 0.375 5.5 0.375 4.5C0.375 3.5 0.729333 2.646 1.438 1.938C2.146 1.22933 3 0.875 4 0.875H6.833V1.958H4C3.30533 1.958 2.708 2.208 2.208 2.708C1.708 3.208 1.458 3.80533 1.458 4.5C1.458 5.19467 1.708 5.792 2.208 6.292C2.708 6.792 3.30533 7.042 4 7.042H6.833V8.125ZM5.208 5.042V3.958H10.792V5.042H5.208ZM9.167 8.125V7.042H12C12.6947 7.042 13.292 6.792 13.792 6.292C14.292 5.792 14.542 5.19467 14.542 4.5C14.542 3.80533 14.292 3.208 13.792 2.708C13.292 2.208 12.6947 1.958 12 1.958H9.167V0.875H12C13 0.875 13.854 1.22933 14.562 1.938C15.2707 2.646 15.625 3.5 15.625 4.5C15.625 5.5 15.2707 6.354 14.562 7.062C13.854 7.77067 13 8.125 12 8.125H9.167Z" fill="currentColor"/&gt;
&lt;/svg&gt;
&lt;/a&gt;
&lt;/h2&gt;&lt;p&gt;When a wrapped container fails to start, set the &lt;code&gt;GUARDED_DISABLE&lt;/code&gt; environment variable on the container and redeploy. The wrapper then starts the image&amp;rsquo;s original entrypoint and arguments without doing anything else. You don&amp;rsquo;t need to rebuild the image.&lt;/p&gt;</description></item><item><title>Guarded Entrypoint trust boundary</title><link>https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/custom-assembly/guarded-entrypoint/trust-boundary/</link><pubDate>Tue, 06 Oct 2026 17:41:00 +0000</pubDate><guid>https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/custom-assembly/guarded-entrypoint/trust-boundary/</guid><description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Note&lt;/strong&gt;: Guarded Entrypoint is in beta. To use it, contact Chainguard customer support to enable it for your organization.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;This page states what the &lt;a href="https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/custom-assembly/guarded-entrypoint/"&gt;Guarded Entrypoint&lt;/a&gt; wrapper connects to, what it never does, and what anyone who can pull your image can read.&lt;/p&gt;
&lt;h2 id="what-the-wrapper-connects-to" class="heading-2" data-heading-level="2"&gt;
&lt;span class="heading-text"&gt;What the wrapper connects to&lt;/span&gt;
&lt;a href="#what-the-wrapper-connects-to" class="anchor" aria-label="Link to What the wrapper connects to" title="Link to this section"&gt;
&lt;svg width="16" height="9" viewBox="0 0 16 9" fill="none" xmlns="http://www.w3.org/2000/svg" aria-hidden="true"&gt;
&lt;path d="M6.833 8.125H4C3 8.125 2.146 7.77067 1.438 7.062C0.729333 6.354 0.375 5.5 0.375 4.5C0.375 3.5 0.729333 2.646 1.438 1.938C2.146 1.22933 3 0.875 4 0.875H6.833V1.958H4C3.30533 1.958 2.708 2.208 2.208 2.708C1.708 3.208 1.458 3.80533 1.458 4.5C1.458 5.19467 1.708 5.792 2.208 6.292C2.708 6.792 3.30533 7.042 4 7.042H6.833V8.125ZM5.208 5.042V3.958H10.792V5.042H5.208ZM9.167 8.125V7.042H12C12.6947 7.042 13.292 6.792 13.792 6.292C14.292 5.792 14.542 5.19467 14.542 4.5C14.542 3.80533 14.292 3.208 13.792 2.708C13.292 2.208 12.6947 1.958 12 1.958H9.167V0.875H12C13 0.875 13.854 1.22933 14.562 1.938C15.2707 2.646 15.625 3.5 15.625 4.5C15.625 5.5 15.2707 6.354 14.562 7.062C13.854 7.77067 13 8.125 12 8.125H9.167Z" fill="currentColor"/&gt;
&lt;/svg&gt;
&lt;/a&gt;
&lt;/h2&gt;&lt;p&gt;The wrapper connects only to the endpoints that your configuration names:&lt;/p&gt;</description></item></channel></rss>