For the complete documentation index, see llms.txt.

Procedural

How to sign and upload metadata to Rekor
Use the Rekor CLI to sign and upload metadata to the Sigstore transparency log
How to sign blobs and standard files with Cosign
Use Cosign to sign non-container software artifacts
Enable PKCE for OAuth token exchange
How to add PKCE to your custom identity provider's OAuth token exchange with Chainguard, either alongside a client secret or as a secret-free public client.
Using the Chainguard API to manage Custom Assembly resources
How to use the Chainguard API to manage Custom Assembly resources.
Bazel rules for apko
Build secure, minimal Wolfi-based container images using Bazel
Create an assumable identity for a Buildkite pipeline
Procedural tutorial outlining how to create a Chainguard identity that can be assumed by a Buildkite workflow.
How to set up an instance of Rekor locally
Create your own instance of the Rekor transparency log