0 Try the Demo

Images

Pull, inspect, tag, prune, and update Docker images, and save private registry credentials.

The Images page lists every Docker image on the selected host and lets you search registries, pull, tag, inspect, prune, and remove images. Arcane also flags images that have a newer release available.

Compare image tags and see which images your containers use.

Browse images

Open Images in the sidebar. The table shows tag, ID, size, and creation date for each image.

When scan results are available, sort the Vulnerabilities column to order images by vulnerability count.

Pull an image

  1. Click Pull Image.
  2. Enter the image reference, e.g. redis:latest.
  3. Click Pull. The image appears in the list once the download finishes.

Search a registry

Use Search Registry from the pull dialog when you do not know the exact image name. Enter a search term, pick a result, choose a tag, and Arcane pulls the selected image.

Inspect an image

Click the image’s name, ID, or Inspect button to see its full details: tags, configuration, layer history, vulnerability results, and labels.

Image history

The History tab shows the Docker layer history for the image, including layer IDs, creation time, size, command, tags, and comments. Use it to inspect how a local image was built or to compare images after a rebuild.

Attestations

The Attestations tab shows in-toto attestations, which are signed statements published with an image, such as build provenance or an SBOM. They appear when Arcane can resolve the image to a usable registry tag or digest. Images that only exist as local IDs may not have a registry reference Arcane can query.

You can filter attestations by platform and predicate type. Open an attestation to inspect its digest, media type, statement type, subject, platform, and size.

Tag an image

  1. Open the image detail page.
  2. Click Tag Image.
  3. Enter the target repository and tag. If the tag is omitted, Docker uses latest.
  4. Save.

Tagging requires the images:tag permission.

Remove an image

  1. Click the trash icon on the image row.
  2. Confirm.
Note

Images used by any container can’t be removed.

Prune unused images

  1. Click Prune Unused.
  2. Pick what to remove: Dangling Only removes images without tags, All Unused removes every image no container uses.
  3. Confirm.

Check for image updates

Click Check Updates in the toolbar to ask the registries whether newer images exist. The Refresh icon only reloads the list. Arcane also checks on the schedule described in Auto Updates.

An image with an update shows one of two indicators:

  • Version Update: a newer version tag is available.
  • Digest Update: the tag is unchanged, but it now points to a different build, because its digest (the content hash the registry assigns to one exact image) has changed. This is common with tags like latest.

Open the indicator to see the latest version or digest, update the containers that use the image, or select Re-check Updates. If updates don’t appear, check that Arcane can reach the registry and that its credentials are saved.

Private registries

Save registry credentials in Arcane so it can pull private images and check them for updates.

  1. In the sidebar, open Customization → Container Registries.
  2. Add the registry host, username, and password or token.
  3. Optionally fill in Repository Names (see below).
  4. Save.

You can save several registries. Arcane picks the matching credentials from the hostname in each image reference.

Note

If you change a registry’s URL, enter its credentials again in the same save. Arcane rejects the change otherwise, so saved secrets are never sent to a new host. The same rule applies wherever a secret is tied to a URL, such as an environment’s API URL, the OIDC issuer, the Trivy server, and notification provider hosts.

Repository names

Repository Names lists the repositories you push to on this registry, one complete name per line:

team/api
team/platform/api

Arcane checks each entry against Docker’s reference format and removes duplicates. These names fill the Repository name dropdown for builds that push images (see Image Builds). A registry without repository names still works for pulls and update checks, but can’t be a push target.

Amazon ECR

ECR is a first-class registry type. When adding an ECR registry, provide:

  • AWS access key ID
  • AWS secret access key
  • AWS region

Arcane exchanges those credentials for a temporary ECR authorization token, caches it, and refreshes it when needed, so you don’t manage a Docker token yourself. When you change an ECR registry’s URL, re-enter both the access key ID and the secret access key.