a day ago
Hello Railway team,
We host Closive’s staging and production backend on Railway using Railway-built container images. We’re completing a Google CASA AL1 assessment and want to scan the exact deployed artifacts.
Is there a supported API, CLI command or authenticated registry method to pull/export these images using their deployment IDs and image digests?
We already have those identifiers and have scanned installed application and OS packages. We’re looking for the original deployed image, including its manifest and layers.
If direct image access is unavailable, can Railway provide an SBOM or vulnerability report tied to the deployment image digest?
Happy to provide the deployment details through the appropriate channel.
Thanks,
Manpreet
1 Replies
a day ago
Pulling or exporting a Railway-built image, its manifest, or its layers by deployment ID or digest isn't something we offer through the API, the CLI, or a registry endpoint, and we don't produce an SBOM or vulnerability report tied to a deployment image.
The running container itself is reachable. railway ssh opens a shell in it, and the same SSH access supports scp and sftp against ssh.railway.com once an SSH key is registered on your account, so you can inspect or copy the live filesystem of a specific deployment instance with railway ssh --deployment-instance <instance-id>.
Status changed to Awaiting User Response Railway • 1 day ago