How to Point Docker / OCI at Chainsaw

Beginner 15 minutes Developers / DevOps Engineers Getting Started

Pull and push container images through your Chainsaw proxy using the Docker registry v2 API and org-scoped repository paths.

Overview

Point Docker (and other OCI clients) at your Chainsaw instance so image pulls and pushes route through the firewall. This page covers login, pull, and push.

Replace chain305.com with your own Chainsaw deployment host and swap CLIENT_ID / CLIENT_SECRET for credentials issued from the Access page in the dashboard. The @default segment is the org slug — confirm yours under Settings → Organization → Slug.

Prerequisites

  • A running Chainsaw instance (see Tutorial 01)
  • Client credentials (Client ID and Secret)
  • Docker installed

Clear Local Caches (First-Time Setup)

Remove locally cached images so they are re-pulled through Chainsaw:

docker image prune -a

Or remove specific images you want re-scanned:

docker rmi <image>:<tag>

Routing Notes

Docker clients connect to Chainsaw via the /v2/ API at the host root. Your reverse proxy must route /v2/* to the Chainsaw backend (see the nginx example in the deployment guide). The pull/push path itself MUST include /repository/@<org-slug>/docker/ — bare chain305.com/<image> will not route to the org-scoped repo.

Docker Login

docker login chain305.com \
  --username CLIENT_ID \
  --password CLIENT_SECRET

Pull Through Chainsaw

docker pull chain305.com/chainproxy/repository/@default/docker/library/nginx:latest

Push (Publish) an Image

docker tag my-app:latest chain305.com/chainproxy/repository/@default/docker/my-org/my-app:1.0.0
docker push chain305.com/chainproxy/repository/@default/docker/my-org/my-app:1.0.0

Note: Push requires a registered package slug and write permission for the client. Create these via the dashboard or the package management API before pushing.

Verify

After a pull, confirm with chainsaw doctor verify-hook and the Traffic page in the dashboard.

Next Steps