Images
Pull, inspect, tag, prune, and update Docker images, and save private registry credentials.
The Images page lists every Docker image on the selected host and lets you search registries, pull, tag, inspect, prune, and remove images. Arcane also flags images that have a newer release available.
Browse images
Open Images in the sidebar. The table shows tag, ID, size, and creation date for each image.
When scan results are available, sort the Vulnerabilities column to order images by vulnerability count.
Pull an image
- Click Pull Image.
- Enter the image reference, e.g.
redis:latest. - Click Pull. The image appears in the list once the download finishes.
Search a registry
Use Search Registry from the pull dialog when you do not know the exact image name. Enter a search term, pick a result, choose a tag, and Arcane pulls the selected image.
Inspect an image
Click the image’s name, ID, or Inspect button to see its full details: tags, configuration, layer history, vulnerability results, and labels.
Image history
The History tab shows the Docker layer history for the image, including layer IDs, creation time, size, command, tags, and comments. Use it to inspect how a local image was built or to compare images after a rebuild.
Attestations
The Attestations tab shows in-toto attestations, which are signed statements published with an image, such as build provenance or an SBOM. They appear when Arcane can resolve the image to a usable registry tag or digest. Images that only exist as local IDs may not have a registry reference Arcane can query.
You can filter attestations by platform and predicate type. Open an attestation to inspect its digest, media type, statement type, subject, platform, and size.
Tag an image
- Open the image detail page.
- Click Tag Image.
- Enter the target repository and tag. If the tag is omitted, Docker uses
latest. - Save.
Tagging requires the images:tag permission.
Remove an image
- Click the trash icon on the image row.
- Confirm.
Images used by any container can’t be removed.
Prune unused images
- Click Prune Unused.
- Pick what to remove: Dangling Only removes images without tags, All Unused removes every image no container uses.
- Confirm.
Check for image updates
Click Check Updates in the toolbar to ask the registries whether newer images exist. The Refresh icon only reloads the list. Arcane also checks on the schedule described in Auto Updates.
An image with an update shows one of two indicators:
- Version Update: a newer version tag is available.
- Digest Update: the tag is unchanged, but it now points to a different build, because its digest (the content hash the registry assigns to one exact image) has changed. This is common with tags like
latest.
Open the indicator to see the latest version or digest, update the containers that use the image, or select Re-check Updates. If updates don’t appear, check that Arcane can reach the registry and that its credentials are saved.
Private registries
Save registry credentials in Arcane so it can pull private images and check them for updates.
- In the sidebar, open Customization → Container Registries.
- Add the registry host, username, and password or token.
- Optionally fill in Repository Names (see below).
- Save.
You can save several registries. Arcane picks the matching credentials from the hostname in each image reference.
If you change a registry’s URL, enter its credentials again in the same save. Arcane rejects the change otherwise, so saved secrets are never sent to a new host. The same rule applies wherever a secret is tied to a URL, such as an environment’s API URL, the OIDC issuer, the Trivy server, and notification provider hosts.
Repository names
Repository Names lists the repositories you push to on this registry, one complete name per line:
team/api
team/platform/apiArcane checks each entry against Docker’s reference format and removes duplicates. These names fill the Repository name dropdown for builds that push images (see Image Builds). A registry without repository names still works for pulls and update checks, but can’t be a push target.
Amazon ECR
ECR is a first-class registry type. When adding an ECR registry, provide:
- AWS access key ID
- AWS secret access key
- AWS region
Arcane exchanges those credentials for a temporary ECR authorization token, caches it, and refreshes it when needed, so you don’t manage a Docker token yourself. When you change an ECR registry’s URL, re-enter both the access key ID and the secret access key.