<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Custom Assembly on</title><link>https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/tags/custom-assembly/</link><description>Recent content in Custom Assembly on</description><generator>Hugo -- gohugo.io</generator><language>en-US</language><copyright>Copyright (c) 2023 Chainguard</copyright><lastBuildDate>Tue, 06 Oct 2026 17:41:00 +0000</lastBuildDate><atom:link href="https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/tags/custom-assembly/index.xml" rel="self" type="application/rss+xml"/><item><title>How Guarded Entrypoint works</title><link>https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/custom-assembly/guarded-entrypoint/how-it-works/</link><pubDate>Tue, 06 Oct 2026 17:41:00 +0000</pubDate><guid>https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/custom-assembly/guarded-entrypoint/how-it-works/</guid><description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Note&lt;/strong&gt;: Guarded Entrypoint is in beta. To use it, contact Chainguard customer support to enable it for your organization.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;This page describes what the Guarded Entrypoint binary does when a container starts. The page calls the binary the wrapper. To turn Guarded Entrypoint on, see &lt;a href="https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/custom-assembly/guarded-entrypoint/"&gt;Guarded Entrypoint for Custom Assembly&lt;/a&gt;.&lt;/p&gt;
&lt;h2 id="what-the-wrapper-does" class="heading-2" data-heading-level="2"&gt;
&lt;span class="heading-text"&gt;What the wrapper does&lt;/span&gt;
&lt;a href="#what-the-wrapper-does" class="anchor" aria-label="Link to What the wrapper does" title="Link to this section"&gt;
&lt;svg width="16" height="9" viewBox="0 0 16 9" fill="none" xmlns="http://www.w3.org/2000/svg" aria-hidden="true"&gt;
&lt;path d="M6.833 8.125H4C3 8.125 2.146 7.77067 1.438 7.062C0.729333 6.354 0.375 5.5 0.375 4.5C0.375 3.5 0.729333 2.646 1.438 1.938C2.146 1.22933 3 0.875 4 0.875H6.833V1.958H4C3.30533 1.958 2.708 2.208 2.208 2.708C1.708 3.208 1.458 3.80533 1.458 4.5C1.458 5.19467 1.708 5.792 2.208 6.292C2.708 6.792 3.30533 7.042 4 7.042H6.833V8.125ZM5.208 5.042V3.958H10.792V5.042H5.208ZM9.167 8.125V7.042H12C12.6947 7.042 13.292 6.792 13.792 6.292C14.292 5.792 14.542 5.19467 14.542 4.5C14.542 3.80533 14.292 3.208 13.792 2.708C13.292 2.208 12.6947 1.958 12 1.958H9.167V0.875H12C13 0.875 13.854 1.22933 14.562 1.938C15.2707 2.646 15.625 3.5 15.625 4.5C15.625 5.5 15.2707 6.354 14.562 7.062C13.854 7.77067 13 8.125 12 8.125H9.167Z" fill="currentColor"/&gt;
&lt;/svg&gt;
&lt;/a&gt;
&lt;/h2&gt;&lt;p&gt;When you turn on Guarded Entrypoint, Chainguard rebuilds the image with &lt;code&gt;/usr/bin/guarded-entrypoint&lt;/code&gt; as the first element of its entrypoint. The image&amp;rsquo;s original entrypoint follows it. Chainguard stores your settings in environment variables in the image configuration. The names of these variables start with &lt;code&gt;GUARDED_&lt;/code&gt;. You can see them with &lt;code&gt;docker inspect&lt;/code&gt;. The &lt;code&gt;GUARDED_&lt;/code&gt; prefix is reserved, and the API rejects it in your own &lt;code&gt;environment&lt;/code&gt; keys.&lt;/p&gt;</description></item><item><title>Managing tag-based Custom Assembly with chainctl</title><link>https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/custom-assembly/tag-based-custom-assembly/chainctl/</link><pubDate>Mon, 28 Sep 2026 16:33:22 +0000</pubDate><guid>https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/custom-assembly/tag-based-custom-assembly/chainctl/</guid><description>&lt;p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Note&lt;/strong&gt;: Tag-based Custom Assembly is in beta. Contact your Chainguard account team to enable it for your organization.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;/p&gt;
&lt;p&gt;This guide shows how to use &lt;code&gt;chainctl&lt;/code&gt; to apply Custom Assembly customizations to some of a repository&amp;rsquo;s tags. You create an overlay that holds the customizations, then bind it to a repository with a tag selector.&lt;/p&gt;
&lt;p&gt;For an explanation of overlays, bindings, and tag selectors, see &lt;a href="https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/custom-assembly/tag-based-custom-assembly/"&gt;Overview of tag-based Custom Assembly&lt;/a&gt;.&lt;/p&gt;
&lt;h2 id="prerequisites" class="heading-2" data-heading-level="2"&gt;
&lt;span class="heading-text"&gt;Prerequisites&lt;/span&gt;
&lt;a href="#prerequisites" class="anchor" aria-label="Link to Prerequisites" title="Link to this section"&gt;
&lt;svg width="16" height="9" viewBox="0 0 16 9" fill="none" xmlns="http://www.w3.org/2000/svg" aria-hidden="true"&gt;
&lt;path d="M6.833 8.125H4C3 8.125 2.146 7.77067 1.438 7.062C0.729333 6.354 0.375 5.5 0.375 4.5C0.375 3.5 0.729333 2.646 1.438 1.938C2.146 1.22933 3 0.875 4 0.875H6.833V1.958H4C3.30533 1.958 2.708 2.208 2.208 2.708C1.708 3.208 1.458 3.80533 1.458 4.5C1.458 5.19467 1.708 5.792 2.208 6.292C2.708 6.792 3.30533 7.042 4 7.042H6.833V8.125ZM5.208 5.042V3.958H10.792V5.042H5.208ZM9.167 8.125V7.042H12C12.6947 7.042 13.292 6.792 13.792 6.292C14.292 5.792 14.542 5.19467 14.542 4.5C14.542 3.80533 14.292 3.208 13.792 2.708C13.292 2.208 12.6947 1.958 12 1.958H9.167V0.875H12C13 0.875 13.854 1.22933 14.562 1.938C15.2707 2.646 15.625 3.5 15.625 4.5C15.625 5.5 15.2707 6.354 14.562 7.062C13.854 7.77067 13 8.125 12 8.125H9.167Z" fill="currentColor"/&gt;
&lt;/svg&gt;
&lt;/a&gt;
&lt;/h2&gt;&lt;p&gt;Before you start, you need the following:&lt;/p&gt;</description></item><item><title>Adding a package to a Chainguard Container</title><link>https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/building-and-modifying/adding-packages/</link><pubDate>Wed, 09 Sep 2026 00:00:00 +0000</pubDate><guid>https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/building-and-modifying/adding-packages/</guid><description>&lt;p&gt;Chainguard Containers ship with only the packages their application needs, so sooner or later you&amp;rsquo;ll want one that isn&amp;rsquo;t there. &lt;a href="https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/custom-assembly/overview/"&gt;Custom Assembly&lt;/a&gt; is the supported way to add it. You declare the package you want, Chainguard builds the image on its own infrastructure, and Chainguard rebuilds that image whenever the package is updated. You can drive Custom Assembly from the Chainguard Console, interactively with &lt;code&gt;chainctl&lt;/code&gt;, or non-interactively with &lt;code&gt;chainctl&lt;/code&gt; from a pipeline.&lt;/p&gt;</description></item><item><title>Overview of Chainguard Custom Assembly</title><link>https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/custom-assembly/overview/</link><pubDate>Wed, 19 Feb 2025 11:07:52 +0200</pubDate><guid>https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/custom-assembly/overview/</guid><description>&lt;p&gt;Chainguard Custom Assembly enables organizations to build container images
tailored to their internal requirements and application dependencies, without
sacrificing security. By extending Chainguard&amp;rsquo;s hardened base images with
additional packages, environment variables, user accounts, and certificates,
teams can reduce CVE exposure while maintaining the flexibility their workflows
demand.&lt;/p&gt;
&lt;p&gt;This overview of Custom Assembly outlines how it works, its limitations, and how you can use container images customized with Custom Assembly.&lt;/p&gt;
&lt;p&gt;You can drive Custom Assembly through any of the following interfaces. They produce the same result, so pick the one that matches how you work:&lt;/p&gt;</description></item><item><title>Guarded Entrypoint examples</title><link>https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/custom-assembly/guarded-entrypoint/examples/</link><pubDate>Tue, 06 Oct 2026 17:41:00 +0000</pubDate><guid>https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/custom-assembly/guarded-entrypoint/examples/</guid><description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Note&lt;/strong&gt;: Guarded Entrypoint is in beta. To use it, contact Chainguard customer support to enable it for your organization.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;This page has four example manifests for &lt;a href="https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/custom-assembly/guarded-entrypoint/"&gt;Guarded Entrypoint&lt;/a&gt;. Each one is a complete manifest for &lt;code&gt;chainctl images repos build edit&lt;/code&gt; or &lt;code&gt;chainctl images repos build apply&lt;/code&gt;. None of them contains a literal secret. Each secret is a reference that the wrapper resolves when the container starts.&lt;/p&gt;
&lt;p&gt;Applying a manifest replaces the repo&amp;rsquo;s stored configuration. If your repo already has other customizations, such as packages, add the Guarded Entrypoint keys to your existing manifest instead of replacing it.&lt;/p&gt;</description></item><item><title>Managing tag-based Custom Assembly with Terraform</title><link>https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/custom-assembly/tag-based-custom-assembly/terraform/</link><pubDate>Mon, 28 Sep 2026 16:33:22 +0000</pubDate><guid>https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/custom-assembly/tag-based-custom-assembly/terraform/</guid><description>&lt;p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Note&lt;/strong&gt;: Tag-based Custom Assembly is in beta. Contact your Chainguard account team to enable it for your organization.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;/p&gt;
&lt;p&gt;This guide shows how to manage tag-based Custom Assembly with the &lt;a href="https://registry.terraform.io/providers/chainguard-dev/chainguard/latest"&gt;Chainguard Terraform provider&lt;/a&gt;. You define overlays with the &lt;code&gt;chainguard_image_overlay&lt;/code&gt; resource and bind them to repositories with the &lt;code&gt;chainguard_image_overlay_binding&lt;/code&gt; resource.&lt;/p&gt;
&lt;p&gt;For an explanation of overlays, bindings, and tag selectors, see &lt;a href="https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/custom-assembly/tag-based-custom-assembly/"&gt;Overview of tag-based Custom Assembly&lt;/a&gt;.&lt;/p&gt;
&lt;h2 id="prerequisites" class="heading-2" data-heading-level="2"&gt;
&lt;span class="heading-text"&gt;Prerequisites&lt;/span&gt;
&lt;a href="#prerequisites" class="anchor" aria-label="Link to Prerequisites" title="Link to this section"&gt;
&lt;svg width="16" height="9" viewBox="0 0 16 9" fill="none" xmlns="http://www.w3.org/2000/svg" aria-hidden="true"&gt;
&lt;path d="M6.833 8.125H4C3 8.125 2.146 7.77067 1.438 7.062C0.729333 6.354 0.375 5.5 0.375 4.5C0.375 3.5 0.729333 2.646 1.438 1.938C2.146 1.22933 3 0.875 4 0.875H6.833V1.958H4C3.30533 1.958 2.708 2.208 2.208 2.708C1.708 3.208 1.458 3.80533 1.458 4.5C1.458 5.19467 1.708 5.792 2.208 6.292C2.708 6.792 3.30533 7.042 4 7.042H6.833V8.125ZM5.208 5.042V3.958H10.792V5.042H5.208ZM9.167 8.125V7.042H12C12.6947 7.042 13.292 6.792 13.792 6.292C14.292 5.792 14.542 5.19467 14.542 4.5C14.542 3.80533 14.292 3.208 13.792 2.708C13.292 2.208 12.6947 1.958 12 1.958H9.167V0.875H12C13 0.875 13.854 1.22933 14.562 1.938C15.2707 2.646 15.625 3.5 15.625 4.5C15.625 5.5 15.2707 6.354 14.562 7.062C13.854 7.77067 13 8.125 12 8.125H9.167Z" fill="currentColor"/&gt;
&lt;/svg&gt;
&lt;/a&gt;
&lt;/h2&gt;&lt;p&gt;Before you start, you need the following:&lt;/p&gt;</description></item><item><title>Using the Chainguard Console to manage Custom Assembly resources</title><link>https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/custom-assembly/custom-assembly-console/</link><pubDate>Wed, 09 Jul 2025 11:07:52 +0200</pubDate><guid>https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/custom-assembly/custom-assembly-console/</guid><description>&lt;p&gt;Chainguard&amp;rsquo;s &lt;a href="https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/custom-assembly/overview/"&gt;Custom Assembly feature&lt;/a&gt; allows you to build customized container images that include only the packages your application needs. This tutorial walks you through using the &lt;a href="https://console.chainguard.dev"&gt;Chainguard console&amp;rsquo;s web interface&lt;/a&gt; to manage Custom Assembly resources, including selecting packages, building customized containers, and monitoring build status.&lt;/p&gt;
&lt;p&gt;By the end of this guide, you&amp;rsquo;ll be able to create, customize, and manage your own container images through the Chainguard console, giving you full control over your container dependencies while maintaining Chainguard&amp;rsquo;s security and compliance standards.&lt;/p&gt;</description></item><item><title>Troubleshoot a wrapped container</title><link>https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/custom-assembly/guarded-entrypoint/troubleshooting/</link><pubDate>Tue, 06 Oct 2026 17:41:00 +0000</pubDate><guid>https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/custom-assembly/guarded-entrypoint/troubleshooting/</guid><description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Note&lt;/strong&gt;: Guarded Entrypoint is in beta. To use it, contact Chainguard customer support to enable it for your organization.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;This page covers two kinds of problems. A container that is built with &lt;a href="https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/custom-assembly/guarded-entrypoint/"&gt;Guarded Entrypoint&lt;/a&gt; can fail to start. A build can also fail because Chainguard refuses to wrap an image.&lt;/p&gt;
&lt;h2 id="first-move-set-guarded_disable" class="heading-2" data-heading-level="2"&gt;
&lt;span class="heading-text"&gt;First move: set GUARDED_DISABLE&lt;/span&gt;
&lt;a href="#first-move-set-guarded_disable" class="anchor" aria-label="Link to First move: set GUARDED_DISABLE" title="Link to this section"&gt;
&lt;svg width="16" height="9" viewBox="0 0 16 9" fill="none" xmlns="http://www.w3.org/2000/svg" aria-hidden="true"&gt;
&lt;path d="M6.833 8.125H4C3 8.125 2.146 7.77067 1.438 7.062C0.729333 6.354 0.375 5.5 0.375 4.5C0.375 3.5 0.729333 2.646 1.438 1.938C2.146 1.22933 3 0.875 4 0.875H6.833V1.958H4C3.30533 1.958 2.708 2.208 2.208 2.708C1.708 3.208 1.458 3.80533 1.458 4.5C1.458 5.19467 1.708 5.792 2.208 6.292C2.708 6.792 3.30533 7.042 4 7.042H6.833V8.125ZM5.208 5.042V3.958H10.792V5.042H5.208ZM9.167 8.125V7.042H12C12.6947 7.042 13.292 6.792 13.792 6.292C14.292 5.792 14.542 5.19467 14.542 4.5C14.542 3.80533 14.292 3.208 13.792 2.708C13.292 2.208 12.6947 1.958 12 1.958H9.167V0.875H12C13 0.875 13.854 1.22933 14.562 1.938C15.2707 2.646 15.625 3.5 15.625 4.5C15.625 5.5 15.2707 6.354 14.562 7.062C13.854 7.77067 13 8.125 12 8.125H9.167Z" fill="currentColor"/&gt;
&lt;/svg&gt;
&lt;/a&gt;
&lt;/h2&gt;&lt;p&gt;When a wrapped container fails to start, set the &lt;code&gt;GUARDED_DISABLE&lt;/code&gt; environment variable on the container and redeploy. The wrapper then starts the image&amp;rsquo;s original entrypoint and arguments without doing anything else. You don&amp;rsquo;t need to rebuild the image.&lt;/p&gt;</description></item><item><title>Using chainctl to manage Custom Assembly resources</title><link>https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/custom-assembly/custom-assembly-chainctl/</link><pubDate>Thu, 01 May 2025 11:07:52 +0200</pubDate><guid>https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/custom-assembly/custom-assembly-chainctl/</guid><description>&lt;p&gt;Chainguard&amp;rsquo;s &lt;a href="https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/custom-assembly/overview/"&gt;Custom Assembly&lt;/a&gt; is a tool that allows customers to create customized containers with extra packages and annotations added. This enables customers to reduce their risk exposure by creating container images that are tailored to their internal organization and application requirements while still having few-to-zero CVEs.&lt;/p&gt;
&lt;p&gt;You can use &lt;a href="https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/platform/chainctl/"&gt;&lt;code&gt;chainctl&lt;/code&gt;, Chainguard&amp;rsquo;s command-line interface tool&lt;/a&gt;, to further customize your Custom Assembly builds and retrieve information about them. This guide provides an overview of the relevant &lt;code&gt;chainctl&lt;/code&gt; commands and outlines how you can edit the configuration of Custom Assembly containers, as well as retrieve a list of a customized image&amp;rsquo;s builds and its build logs.&lt;/p&gt;</description></item><item><title>Overview of tag-based Custom Assembly</title><link>https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/custom-assembly/tag-based-custom-assembly/</link><pubDate>Mon, 28 Sep 2026 16:33:22 +0000</pubDate><guid>https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/custom-assembly/tag-based-custom-assembly/</guid><description>&lt;p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Note&lt;/strong&gt;: Tag-based Custom Assembly is in beta. Contact your Chainguard account team to enable it for your organization.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;/p&gt;
&lt;p&gt;Standard &lt;a href="https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/custom-assembly/overview/"&gt;Custom Assembly&lt;/a&gt; applies one customization to every tag in a repository. This fails for images that ship several language or runtime versions side by side, because a package built for one version can&amp;rsquo;t install on the others.&lt;/p&gt;
&lt;p&gt;For example, the &lt;code&gt;python&lt;/code&gt; image publishes tags for Python 3.11, 3.12, 3.13, and 3.14. The &lt;code&gt;py3.13-typer&lt;/code&gt; package depends on Python 3.13. If you add it with standard Custom Assembly, every tag tries to install it, and the 3.11, 3.12, and 3.14 builds fail.&lt;/p&gt;</description></item><item><title>Guarded Entrypoint trust boundary</title><link>https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/custom-assembly/guarded-entrypoint/trust-boundary/</link><pubDate>Tue, 06 Oct 2026 17:41:00 +0000</pubDate><guid>https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/custom-assembly/guarded-entrypoint/trust-boundary/</guid><description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Note&lt;/strong&gt;: Guarded Entrypoint is in beta. To use it, contact Chainguard customer support to enable it for your organization.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;This page states what the &lt;a href="https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/custom-assembly/guarded-entrypoint/"&gt;Guarded Entrypoint&lt;/a&gt; wrapper connects to, what it never does, and what anyone who can pull your image can read.&lt;/p&gt;
&lt;h2 id="what-the-wrapper-connects-to" class="heading-2" data-heading-level="2"&gt;
&lt;span class="heading-text"&gt;What the wrapper connects to&lt;/span&gt;
&lt;a href="#what-the-wrapper-connects-to" class="anchor" aria-label="Link to What the wrapper connects to" title="Link to this section"&gt;
&lt;svg width="16" height="9" viewBox="0 0 16 9" fill="none" xmlns="http://www.w3.org/2000/svg" aria-hidden="true"&gt;
&lt;path d="M6.833 8.125H4C3 8.125 2.146 7.77067 1.438 7.062C0.729333 6.354 0.375 5.5 0.375 4.5C0.375 3.5 0.729333 2.646 1.438 1.938C2.146 1.22933 3 0.875 4 0.875H6.833V1.958H4C3.30533 1.958 2.708 2.208 2.208 2.708C1.708 3.208 1.458 3.80533 1.458 4.5C1.458 5.19467 1.708 5.792 2.208 6.292C2.708 6.792 3.30533 7.042 4 7.042H6.833V8.125ZM5.208 5.042V3.958H10.792V5.042H5.208ZM9.167 8.125V7.042H12C12.6947 7.042 13.292 6.792 13.792 6.292C14.292 5.792 14.542 5.19467 14.542 4.5C14.542 3.80533 14.292 3.208 13.792 2.708C13.292 2.208 12.6947 1.958 12 1.958H9.167V0.875H12C13 0.875 13.854 1.22933 14.562 1.938C15.2707 2.646 15.625 3.5 15.625 4.5C15.625 5.5 15.2707 6.354 14.562 7.062C13.854 7.77067 13 8.125 12 8.125H9.167Z" fill="currentColor"/&gt;
&lt;/svg&gt;
&lt;/a&gt;
&lt;/h2&gt;&lt;p&gt;The wrapper connects only to the endpoints that your configuration names:&lt;/p&gt;</description></item><item><title>Using GitOps to manage Custom Assembly resources</title><link>https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/custom-assembly/custom-assembly-gitops/</link><pubDate>Thu, 29 Jan 2026 11:07:52 +0200</pubDate><guid>https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/custom-assembly/custom-assembly-gitops/</guid><description>&lt;p&gt;Chainguard&amp;rsquo;s &lt;a href="https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/custom-assembly/overview/"&gt;Custom Assembly&lt;/a&gt; is a tool that lets customers create customized container images with extra packages and annotations added. This enables customers to reduce their risk exposure by creating container images that are tailored to their internal organization and application requirements while still having few-to-zero CVEs. It can be managed in the &lt;a href="https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/custom-assembly/custom-assembly-console/"&gt;Chainguard Console&lt;/a&gt;, &lt;a href="https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/custom-assembly/custom-assembly-chainctl/"&gt;with &lt;code&gt;chainctl&lt;/code&gt;&lt;/a&gt;, &lt;a href="https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/custom-assembly/custom-assembly-api-demo/"&gt;with the API&lt;/a&gt;, or from a CI/CD pipeline.&lt;/p&gt;
&lt;p&gt;This guide shows how to use Chainguard Custom Assembly as code from a CI/CD pipeline, storing your configuration in Git and using automation to apply changes and trigger builds. The examples in this guide focus on GitHub Actions, and are adapted from &lt;a href="https://github.com/chainguard-demo/custom-assembly-as-code"&gt;Chainguard&amp;rsquo;s custom-assembly-as-code demo repository&lt;/a&gt;.&lt;/p&gt;</description></item><item><title>Using the Chainguard API to manage Custom Assembly resources</title><link>https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/custom-assembly/custom-assembly-api-demo/</link><pubDate>Thu, 01 May 2025 11:07:52 +0200</pubDate><guid>https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/custom-assembly/custom-assembly-api-demo/</guid><description>&lt;p&gt;Chainguard&amp;rsquo;s &lt;a href="https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/custom-assembly/"&gt;Custom Assembly&lt;/a&gt; is a tool that allows customers to create customized containers with extra packages added. This enables customers to reduce their risk exposure by creating container images that are tailored to their internal organization and application requirements while still having few-to-zero CVEs.&lt;/p&gt;
&lt;p&gt;You can use the Chainguard API to further customize your Custom Assembly builds and retrieve information about them. This tutorial highlights a demo application (which can be found in &lt;a href="https://github.com/chainguard-dev/edu-images-demos/tree/main"&gt;Chainguard Academy&amp;rsquo;s Demo Applications repository&lt;/a&gt;) which, when run, updates a Custom Assembly container&amp;rsquo;s configuration based on a provided YAML file.&lt;/p&gt;</description></item><item><title>Adding custom certificates with Custom Assembly</title><link>https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/custom-assembly/custom-assembly-certs/</link><pubDate>Thu, 12 Mar 2026 11:07:52 +0200</pubDate><guid>https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/custom-assembly/custom-assembly-certs/</guid><description>&lt;p&gt;Many enterprise environments use internal certificate authorities (CAs) to issue certificates for internal services. These custom certificates need to be trusted by containers that communicate with the internal services. Custom Assembly allows you to build custom certificates directly into your container images, ensuring they trust your organization&amp;rsquo;s internal services without requiring manual certificate mounting at runtime.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Note&lt;/strong&gt;: If you are looking for a way to embed certificates at build time, refer to our guide on &lt;a href="https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/custom-assembly/incert-custom-certs/"&gt;How to use incert to create container images with built-in custom certificates&lt;/a&gt;.&lt;/p&gt;</description></item><item><title>Guarded Entrypoint for Custom Assembly</title><link>https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/custom-assembly/guarded-entrypoint/</link><pubDate>Tue, 06 Oct 2026 17:41:00 +0000</pubDate><guid>https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/custom-assembly/guarded-entrypoint/</guid><description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Note&lt;/strong&gt;: Guarded Entrypoint is in beta. To use it, contact Chainguard customer support to enable it for your organization.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Guarded Entrypoint lets a Custom Assembly image run startup logic without a derived image build. You declare the logic as part of your Custom Assembly configuration. Chainguard builds it into the image and signs the result.&lt;/p&gt;
&lt;p&gt;This page explains what Guarded Entrypoint is and how to turn it on. The other pages in this section cover the details:&lt;/p&gt;</description></item><item><title>Custom Assembly FAQs</title><link>https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/custom-assembly/faq/</link><pubDate>Wed, 19 Feb 2025 11:07:52 +0200</pubDate><guid>https://chainguard-docs-preview-git-create-pull-request-patch.chainguard.app/chainguard/containers/custom-assembly/faq/</guid><description>&lt;h2 id="what-is-chainguards-custom-assembly" class="heading-2" data-heading-level="2"&gt;
&lt;span class="heading-text"&gt;What is Chainguard’s Custom Assembly?&lt;/span&gt;
&lt;a href="#what-is-chainguards-custom-assembly" class="anchor" aria-label="Link to What is Chainguard’s Custom Assembly?" title="Link to this section"&gt;
&lt;svg width="16" height="9" viewBox="0 0 16 9" fill="none" xmlns="http://www.w3.org/2000/svg" aria-hidden="true"&gt;
&lt;path d="M6.833 8.125H4C3 8.125 2.146 7.77067 1.438 7.062C0.729333 6.354 0.375 5.5 0.375 4.5C0.375 3.5 0.729333 2.646 1.438 1.938C2.146 1.22933 3 0.875 4 0.875H6.833V1.958H4C3.30533 1.958 2.708 2.208 2.208 2.708C1.708 3.208 1.458 3.80533 1.458 4.5C1.458 5.19467 1.708 5.792 2.208 6.292C2.708 6.792 3.30533 7.042 4 7.042H6.833V8.125ZM5.208 5.042V3.958H10.792V5.042H5.208ZM9.167 8.125V7.042H12C12.6947 7.042 13.292 6.792 13.792 6.292C14.292 5.792 14.542 5.19467 14.542 4.5C14.542 3.80533 14.292 3.208 13.792 2.708C13.292 2.208 12.6947 1.958 12 1.958H9.167V0.875H12C13 0.875 13.854 1.22933 14.562 1.938C15.2707 2.646 15.625 3.5 15.625 4.5C15.625 5.5 15.2707 6.354 14.562 7.062C13.854 7.77067 13 8.125 12 8.125H9.167Z" fill="currentColor"/&gt;
&lt;/svg&gt;
&lt;/a&gt;
&lt;/h2&gt;&lt;p&gt;Custom Assembly is a tool from Chainguard that allows users to build customized container images by assembling packages from a curated, secure set of base images provided by Chainguard.&lt;/p&gt;</description></item></channel></rss>