Getting Started with the GitLab Chainguard Containers
Learn how to deploy GitLab using Chainguard's security-hardened container images with reduced vulnerabilities, …
For the complete documentation index, see llms.txt.
Chainguard Catalog Starter is a way to try production-grade Chainguard Containers for free, without committing to a full subscription. It lets you choose a set of five container images from the broader Chainguard catalog so you can validate security, performance, and operational fit in your own environment before you buy.
Note: Chainguard Catalog Starter is in beta.
To sign up for Catalog Starter, follow the steps on this page. Once set up, you can start piloting up to five secure container images from the Chainguard catalog.
With Chainguard Catalog Starter, users can choose any five non-FIPS images from our catalog of secure-by-default containers. Any Helm charts that depend on those images are included and count toward the five-image limit.
Catalog Starter is designed as a standalone free plan, separate from paid Catalog or per-image subscriptions. It’s meant for teams who want to try Chainguard Containers in real workloads before committing to a larger rollout, giving them a better understanding of how Chainguard’s hardened images and CVE posture behave in practice.
Note: Catalog Starter is best suited for small teams to get them started right away. When you are ready to standardize on Chainguard and deploy organization-wide, we have several paid plans that provide unlimited user access to the Chainguard Containers and additional features like Custom Assembly, FIPS images, EOL/EmeritOSS image versions, a contractual CVE-remediation SLA, and dedicated support.
Once you’ve added all five images, a prompt directs you to contact Chainguard if you need access to additional images.
After you complete signup, you’re free to use the five images you selected however you like. For example, you can pull them into your CI/CD pipelines and runtime environments, or pull them through a third-party registry like JFrog Artifactory. These container images are the same as those provided to Chainguard’s paying customers, and are covered by Chainguard’s standard hardening, rebuild, and CVE-remediation processes, although they are not covered by Chainguard’s CVE SLA.
After trying out Chainguard Containers with Catalog Starter, you can reach out to our sales team to upgrade to one of Chainguard’s paid plans:
Moving to a paid plan means moving off Catalog Starter; the free five-image entitlement is not stacked on top of a paid subscription.
Catalog Starter allows users to try out Chainguard Containers, but it comes with certain limitations, including the following:
limited_owner role, which allows them to browse the Console, pull images, and create pull tokens, but does not include permission to invite other users to the organization or access features like Custom Assembly.No. Once you’ve selected your five images under Catalog Starter, that selection is fixed for the life of the free plan and cannot be swapped or replaced.
If you anticipate needing different images over time, we recommend talking to our team about Catalog Pricing or per-image licensing.
No. FIPS images and Chainguard Commercial Builds are not included in the Catalog Starter plan.
If you require FIPS-validated images or dedicated commercial build work, you’ll need a paid plan that includes those capabilities.
Yes. If a Catalog Starter organization already exists for your email domain, the administrator of that organization receives an email with instructions for adding you to it. Once added, you’ll have access to the five images the first user selected, and neither of you will be able to change them.
Catalog Starter does not include user management or RBAC, so users can’t add others to their Chainguard organization themselves.
No. Catalog Starter is a distinct, standalone free plan meant for new organizations. It can’t be combined with existing licenses or used to “carve out” a subset of images from a current subscription.
If you try to sign up using an email domain already associated with a paid Chainguard account, you’ll receive an error message. Contact your Chainguard account administrator for access to your organization’s existing account.
No. Catalog Starter is not a discount instrument for larger deployments. You can’t, for example, license 10 images but expect to pay for only five by applying this plan to the rest.
If you know you’ll need more than five images, it’s usually better to start with Catalog Pricing or per-image licensing so you can scale cleanly.
No. Catalog Starter requires a business email address. If you sign in using a social login (such as GitHub or Google), you’ll be prompted to create a new account with a business email instead.
When you upgrade:
Our team will work with you to map your existing Catalog Starter images into the right long-term structure.
Last updated: 2026-07-13 00:00