# Guarded Entrypoint for Custom Assembly

URL: https://chainguard-docs-preview-git-bot-docs-bundle-refresh.chainguard.app/chainguard/containers/custom-assembly/guarded-entrypoint.md

How Guarded Entrypoint lets a Custom Assembly image resolve secrets, run preflight checks, and override its command at container start, and how to turn it on.

## Pages

- [How Guarded Entrypoint works](https://chainguard-docs-preview-git-bot-docs-bundle-refresh.chainguard.app/chainguard/containers/custom-assembly/guarded-entrypoint/how-it-works.md): What the Guarded Entrypoint wrapper does at container start: secret references, fail mode, preflight checks, command override, and variable expansion.
- [Guarded Entrypoint examples](https://chainguard-docs-preview-git-bot-docs-bundle-refresh.chainguard.app/chainguard/containers/custom-assembly/guarded-entrypoint/examples.md): Example Custom Assembly manifests that use Guarded Entrypoint to inject secrets, wait for a dependency, override a command, and fail open.
- [Troubleshoot a wrapped container](https://chainguard-docs-preview-git-bot-docs-bundle-refresh.chainguard.app/chainguard/containers/custom-assembly/guarded-entrypoint/troubleshooting.md): How to recover a container that fails to start under Guarded Entrypoint, what the wrapper's exit codes mean, and how a refused build appears in chainctl.
- [Guarded Entrypoint trust boundary](https://chainguard-docs-preview-git-bot-docs-bundle-refresh.chainguard.app/chainguard/containers/custom-assembly/guarded-entrypoint/trust-boundary.md): What the Guarded Entrypoint wrapper connects to, what it never does, and what is visible in the image configuration.

