# chainctl images overlays create

URL: https://deploy-preview-4106--ornate-narwhal-088216.netlify.app/platform/chainctl/chainctl-docs/chainctl_images_overlays_create.md
Last Modified: October 1, 2026
Tags: chainctl, Reference, Product

 chainctl images overlays create Create a Custom Assembly overlay.
Synopsis Create a Custom Assembly overlay under an organization or folder.
Pass the overlay configuration either as repeated &ndash;package flags, or as a YAML file with &ndash;file in the same shape that &ldquo;chainctl images repos build apply&rdquo; accepts. Certificates, runtime APK repositories, and runtime APK signing keys can also be read from files with &ndash;with-certificates, &ndash;with-runtime-repositories, and &ndash;with-runtime-keys; they merge into the &ndash;package or &ndash;file configuration. Creating an overlay does not change any image; attach it to a repo with &ldquo;chainctl images overlays attach&rdquo;.
chainctl images overlays create &lt;NAME&gt; [flags] Examples # Create an overlay from packages chainctl images overlays create my-overlay --parent my-org --package curl --package jq # Create an overlay from a configuration file chainctl images overlays create my-overlay --parent my-org -f overlay.yaml # Create an overlay carrying custom CA certificates from a PEM bundle chainctl images overlays create my-overlay --parent my-org --with-certificates ca-bundle.pem Options -f, --file chainctl images repos build The name of the YAML file containing the overlay configuration, the same shape chainctl images repos build accepts. Takes precedence over --package. --package strings Package to include (repeatable). --parent string Parent group name or UIDP under which to create the overlay. Defaults to the default.group config value (env: CHAINGUARD_DEFAULT_GROUP). --with-certificates strings Comma separated list of files to read the custom certificates from. --with-runtime-keys strings Comma separated list of files to read customer APK signing public keys from. Each file becomes a key in /etc/apk/keys named after the file&#39;s basename, which must match the filename referenced by the repository&#39;s APKINDEX signature (.SIGN.RSA256.&lt;name&gt;). --with-runtime-repositories strings Comma separated list of runtime APK repository URLs to write to /etc/apk/repositories in the image. Options inherited from parent commands --api string The url of the Chainguard platform API. (default &#34;https://console-api.enforce.dev&#34;) --audience string The Chainguard token audience to request. (default &#34;https://console-api.enforce.dev&#34;) --config string A specific chainctl config file. Uses CHAINCTL_CONFIG environment variable if a file is not passed explicitly. --console string The url of the Chainguard platform Console. (default &#34;https://console.chainguard.dev&#34;) --force-color Force color output even when stdout is not a TTY. -h, --help Help for chainctl --issuer string The url of the Chainguard STS endpoint. (default &#34;https://issuer.enforce.dev&#34;) --log-level string Set the log level (debug, info) (default &#34;ERROR&#34;) -o, --output string Output format. One of: [csv, env, go-template, id, json, markdown, none, table, terse, tree, wide] -v, --v int Set the log verbosity level. SEE ALSO chainctl images overlays	- Manage Custom Assembly overlays and the repos they are attached to. 
