TL;DR: Tell trivy which platform to scan with the platform flag, matching an architecture the image actually publishes. The registry has no manifest for the platform trivy requested - usually the scanner's default arch, which the image never built. List the image's available platforms first, then scan the one you actually deploy.

```text
failed to get image manifest: manifest unknown
```

1. List the platforms the image publishes using a manifest-inspection tool against the image reference. Expected: you see which architectures exist, for example linux/amd64 only.
2. Compare with the platform trivy requests by default (the scanner host's architecture). Expected: you confirm the mismatch - trivy asked for an arch the image does not publish.
3. Re-run the scan with the platform flag set to a published architecture. Expected: the manifest resolves and layer analysis begins.
4. Scan each platform you actually deploy, separately. Expected: findings are per-architecture, which is correct - vulnerabilities can differ between builds.
5. If a needed platform does not exist, fix the image build to publish it rather than working around the scan. Expected: the registry lists the missing architecture on the next push.

## Use this when
- trivy fails on multi-arch images with manifest errors
- the image publishes only a subset of architectures
- CI runners differ in architecture from the image
- the error appears before any layer downloads

## Not for this skill when
- the image reference itself is wrong or mistyped
- registry credentials are missing or expired
- the manifest exists but a layer fails mid-pull (a network problem)
- the image is single-arch

## Variant phrasings
- trivy manifest unknown multi-arch
- trivy failed to get image manifest
- trivy platform manifest not found
- trivy multi-arch image scan fails

## Why it happens
A multi-arch image is an index of per-platform manifests. Trivy requests the manifest for its default platform; if the publisher never built that architecture, the registry answers "manifest unknown" and the scan cannot start.

## Edge cases
- some registries return this error for private repos when credentials are missing - verify auth before assuming a platform gap
- emulated runners (ARM CI scanning AMD64 images) still need the platform flag set explicitly
- scanning the index without a platform is not supported - pick one explicitly every time
- vulnerability results legitimately differ per architecture - do not copy findings across platforms

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_vVZ_R9fe8946jHIaUQnpnw
