Guardener container image suggestions
Configure Guardener to recommend Chainguard Containers for the container images a pull request adds or changes.
For the complete documentation index, see llms.txt.
chainctl images discover reads the image references in a directory, such as a repository checkout, and reports the Chainguard Container that replaces each upstream image. For each replacement, it also tells you whether your organization can pull it today. Use it to size a migration before you start, or to find what’s left after one.
The command only reports. It doesn’t edit any files. To get replacements suggested on pull requests as images are introduced, enable Guardener container image suggestions. To convert a Dockerfile, use the Dockerfile Converter.
chainctl installed and authenticated with chainctl auth login. If chainctl images discover --help reports an unknown command, update chainctl.--parent with the organization name.From the root of a repository, run:
chainctl images discoverTo scan another directory, pass its path:
chainctl images discover ./servicesThe command reads the following files, skipping .git, node_modules, vendor, .terraform, and testdata directories:
FROM instruction, in every build stage, with ARG defaults substituted. FROM scratch and references to earlier build stages are skipped.image value. Helm values are read as written, not rendered, so a reference computed inside a chart template isn’t seen.image argument or a docker run command.Images used only in COPY --from or RUN --mount instructions aren’t reported.
For each reference, the output shows the file, the current image, and up to three Chainguard replacements, best first. Each replacement has a status:
| Status | Meaning | What to do |
|---|---|---|
entitled | Your organization has this image and the tag, ready to pull. | Switch the reference to the suggested image. |
entitled, not ready | Your organization has this image, but the suggested tag isn’t in your repository yet. | Wait for the tag to sync, or choose another tag. |
available to add | Chainguard publishes this image, but your organization doesn’t have it. | Add the image to your organization, then switch. |
no maintained tag for <tag> | Chainguard publishes this image, but no maintained tag matches the one you asked for. | Choose a maintained tag. Use --all-candidates to list them. |
on chainguard | The reference already uses a Chainguard image. | Nothing. |
not available | Chainguard doesn’t publish a replacement. | Nothing to move to. Keep the image or find an alternative. |
References with no replacement are listed too, so the output shows everything a migration would leave behind.
To check one image without scanning files, pass --image. You can repeat it:
chainctl images discover --image nginx:1.29 --image redis:7.4To see every matching variant and all of its maintained tags, pass one image to --all-candidates:
chainctl images discover --all-candidates nginx:1.29chainctl images discover matches an image to a Chainguard Container by catalog alias first. Otherwise, it matches the end of the repository path, so registry.example.com/cache/dotnet/sdk keeps dotnet/sdk. A match identifies the Chainguard offering for that software, not an image with identical contents, so test the replacement before you ship it.
The suggested tag follows the reference you wrote:
python:3.12-slim, resolves to the same version without the variant suffix.latest. Check these before you switch, because latest can be a different major version.FIPS variants rank first by default. To rank standard images first, pass --fips=false:
chainctl images discover --fips=falsePass -o json for machine-readable output. Each result includes the file, line, build stage, requested tag, how the match was made, and every ranked candidate.
chainctl images discover -o jsonFor every flag, refer to the chainctl images discover reference.
Last updated: 2026-10-02 00:00