🧰 A zero trust swiss army knife for working with X509, OAuth, JWT, OATH OTP, etc.
1M+
The step command is an easy-to-use CLI tool for building, operating, and automating Public Key Infrastructure (PKI) systems and workflows. step acts as front-end interface to step-ca, an online X.509 and SSH Certificate Authority (CA). step is also a general-purpose PKI toolkit: You can use it to run a minimalist, offline X.509 CA and to perform many basic crypto operations.
latest and naked versions eg. 0.23.0, 0.23.1, ...bullseye and bullseye- versions eg. bullseye-0.23.0, bullseye-0.23.1, ...step-cli uses sigstore/cosign for signing and verifying containers.
Here is an example of how to use cosign to verify a container:
cosign verify smallstep/step-cli:0.23.0 \
--certificate-identity-regexp "https://github\.com/smallstep/workflows/.*" \
--certificate-oidc-issuer https://token.actions.githubusercontent.com
Questions? Ask us on GitHub Discussions or Discord.
Content type
Image
Digest
sha256:70c80d930…
Size
250 Bytes
Last updated
3 months ago
docker pull smallstep/step-cli:sha256-14ed72c81e843b9b01a3e2345ac54250a44c59ea6008803001402aef8b9949f8.sig