# Use Clair to scan container images and generate vulnerability reports

## In this learning path

- [Introduction](https://learn.arm.com/learning-paths/servers-and-cloud-computing/clair/)
- [Introduction to Clair deployment models](https://learn.arm.com/learning-paths/servers-and-cloud-computing/clair/clair/)
- [Create a combined deployment](https://learn.arm.com/learning-paths/servers-and-cloud-computing/clair/combo_clair/)
- [Create a distributed deployment](https://learn.arm.com/learning-paths/servers-and-cloud-computing/clair/distributed_clair/)
- [Generate vulnerability reports](https://learn.arm.com/learning-paths/servers-and-cloud-computing/clair/vulnerability_report/)
- [Next Steps](https://learn.arm.com/learning-paths/servers-and-cloud-computing/clair/_next-steps/)

## About this Learning Path

| Skill level: | Advanced |
|--------------|----------|
| Reading time: | 1 hr |
| Last updated: | 31 Jul 2026 |

| Author: | Jason Andrews, Arm [GitHub](https://github.com/jasonrandrews) [LinkedIn](https://linkedin.com/in/jason-andrews-7b05a8) |
|----------|--------------------------------------------------------------------------------------------------------|
| Arm IP: | [Neoverse](https://support.arm.com/?tab=compute-ip&Product%20Type=Infrastructure%20Processors) |
| Tags: | [Containers and Virtualization](https://learn.arm.com/tag/containers-and-virtualization), [AWS](https://learn.arm.com/tag/aws), [Microsoft Azure](https://learn.arm.com/tag/microsoft-azure), [Google Cloud](https://learn.arm.com/tag/google-cloud), [Oracle](https://learn.arm.com/tag/oracle), [Linux](https://learn.arm.com/tag/linux), [Docker](https://learn.arm.com/tag/docker), [Go](https://learn.arm.com/tag/go), [Clair](https://learn.arm.com/tag/clair) |

### Who is this for?
This is an advanced topic for software developers interested in scanning container images for vulnerabilities on Arm servers.

### What will you learn?
Upon completion of this Learning Path, you will be able to:
- Install Clair on an Arm server
- Run Clair using combined and distributed deployment models
- Submit container images using the Clair CLI (command-line interface) and generate vulnerability reports

### Prerequisites
Before starting, you will need the following:
- An [Arm based instance](https://learn.arm.com/learning-paths/servers-and-cloud-computing/csp/) from a cloud service provider or an Arm server with recent versions of Docker and Go installed.

### Summary
You’ll install and run Clair on Arm-based Linux servers using both combined and distributed deployment models. First, you’ll set up the combined deployment to run all services in a single process, then explore the distributed option where the indexer, matcher, and notifier operate as separate services. With Clair running, you’ll submit a container image manifest using `clairctl` to perform static analysis and generate a vulnerability report. You’ll learn about timing considerations — allowing initial vulnerability data to populate the PostgreSQL database — so reports reflect current findings. By the end, you’ll launch Clair, select a deployment model, and produce a report for a chosen image.

### Frequently asked questions
#### Which deployment model should I start with?
The combined deployment runs all Clair services in a single OS process and is the easiest to configure. The distributed deployment runs the indexer, matcher, and notifier as separate services.

#### How do I know Clair is ready before submitting a manifest?
Wait 5–10 minutes after starting Clair for vulnerabilities to populate in the PostgreSQL database. Submitting too soon can return a clean report even when issues exist. If that happens, wait and resubmit.

#### What do I submit to Clair to scan an image?
Submit the image’s manifest to your running Clair deployment using clairctl. The CLI sends the request and returns a vulnerability report when analysis completes.

#### In a distributed deployment, which services run separately?
The indexer, matcher, and notifier run as separate services in a distributed setup. The indexer retrieves image layers, scans them, and generates an intermediate IndexReport.

#### Does Clair run the container image during analysis?
No. Clair performs static analysis of container images without running them.
