Sign inSign up

smallstep/step-kms-plugin

By smallstep

Updated 5 months ago

A tool that helps manage keys and certificates on cloud KMSs and HSMs

Image
0

10K+

smallstep/step-kms-plugin repository overview

step-kms-plugin is a tool that helps manage keys and certificates on a cloud KMSs and hardware HSMs.

It can be used independently, or as a plugin for our step CLI tool, which is a command-line swiss army knife for working with X.509, TLS, OAuth OIDC, JWT, OATH OTP, etc.

This image contains both the step and step-kms-plugin binaries, so you can run step kms commands right out of the box.

The following "Key Management Systems" or KMSs are supported, but not all of them provide the full functionality:

  • PKCS #11 modules
  • Amazon AWS KMS
  • Google Cloud Key Management
  • Microsoft Azure Key Vault
  • YubiKey PIV
  • ssh-agent

Documentation is in the GitHub README for the plugin.

To use this plugin with our step-ca Certificate Authority server, see our Cryptographic Protection documentation.

Tags

  • The default, latest, and versioned tags (eg. 0.8.2) are Alpine-based images.
  • The bullseye, bullseye-0.8.2, etc. tags are Bullseye-based images. These may be most helpful when employing a proprietary, glibc-compatible PKCS #11 library from your HSM vendor.
  • The cloud, cloud-0.8.2, etc. tags are Alpine-based alternative images for use with cloud KMSs only. These images do not support hardware modules such as PKCS#11 HSMs or Yubikey PIV.

Tag summary

Content type

Image

Digest

sha256:ea19a6e4f

Size

33.6 MB

Last updated

5 months ago

docker pull smallstep/step-kms-plugin