How to Point Docker / OCI at Chainsaw
Pull and push container images through your Chainsaw proxy using the Docker registry v2 API and org-scoped repository paths.
Overview
Point Docker (and other OCI clients) at your Chainsaw instance so image pulls and pushes route through the firewall. This page covers login, pull, and push.
chain305.com with your own Chainsaw deployment host
and swap CLIENT_ID / CLIENT_SECRET for credentials issued from the
Access page in the dashboard. The @default segment is the org
slug — confirm yours under Settings → Organization → Slug.Prerequisites
- A running Chainsaw instance (see Tutorial 01)
- Client credentials (Client ID and Secret)
- Docker installed
Clear Local Caches (First-Time Setup)
Remove locally cached images so they are re-pulled through Chainsaw:
docker image prune -a
Or remove specific images you want re-scanned:
docker rmi <image>:<tag>
Routing Notes
Docker clients connect to Chainsaw via the /v2/ API at the host root. Your reverse proxy must route /v2/* to the Chainsaw backend (see the nginx example in the deployment guide). The pull/push path itself MUST include /repository/@<org-slug>/docker/ — bare chain305.com/<image> will not route to the org-scoped repo.
Docker Login
docker login chain305.com \
--username CLIENT_ID \
--password CLIENT_SECRET
Pull Through Chainsaw
docker pull chain305.com/chainproxy/repository/@default/docker/library/nginx:latest
Push (Publish) an Image
docker tag my-app:latest chain305.com/chainproxy/repository/@default/docker/my-org/my-app:1.0.0
docker push chain305.com/chainproxy/repository/@default/docker/my-org/my-app:1.0.0
Note: Push requires a registered package slug and write permission for the client. Create these via the dashboard or the package management API before pushing.
Verify
After a pull, confirm with chainsaw doctor verify-hook and the
Traffic page in the dashboard.
Next Steps
- How to Configure Your Package Manager to Use Chainsaw — All ecosystems in one place
- How to Manage Repositories and Upstream Mirrors