Command-line interface for administrating a CyberArk Conjur server
500K+
It's the most complete interface for administrating a Conjur server. You can load security policies, check permissions, store and fetch secrets, rotate API keys, and more.
Note: It is generally simpler to use the CLI binary directly as opposed to using this Docker image. See the official documentation for details. Continue on if you're sure you want to use the Docker image instead.
The CLI binary is included in the standalone cyberark/conjur-cli:8 Docker image. Docker containers are designed to be ephemeral, which means they don't store state after the container exits.
You can run commands with the Conjur CLI using Docker like so:
$ docker run --rm -it cyberark/conjur-cli:8
Any initialization you do or files you create in that session will be discarded (permanently lost) when you exit the shell. Changes that you make to the Conjur server will remain.
You can also use a folder on your filesystem to persist the data that the Conjur CLI uses to connect. For example:
$ mkdir mydata
$ chmod 700 mydata
$ docker run --rm -it -v $(PWD)/mydata:/root cyberark/conjur-cli:8 init -u https://my-conjur-server -a myAccount
$ ls -A mydata
.conjurrc conjur-server.pem
$ docker run --rm -it -v $(PWD)/mydata:/root cyberark/conjur-cli:8 login -i admin
Please enter admin's password (it will not be echoed):
Logged in
$ ls -A mydata
.conjurrc .netrc conjur-server.pem
You can use a shell alias to make this easier:
$ alias conjur='docker run --rm -it -v $(PWD)/mydata:/root cyberark/conjur-cli:8'
# Now you can use the Conjur CLI like so:
$ conjur whoami
Security notice: the file .netrc, created or updated by conjur login, contains a user identity credential that can be used to access the Conjur API. You should remove it after use or otherwise secure it like you would another netrc file.
When using the Conjur CLI with Docker, credentials can only be stored in a file, not in the native operating system keychain. Additionally, OIDC authentication is not supported in Docker.
The Conjur CLI is the property of CyberArk and made available as Free Software under the APLv2. (See LICENSE) This Docker image, like many others, contains a variety of other packages (such as Bash, Ruby, etc) with their own licenses. As for any pre-built image usage, it is the image user's responsibility to ensure that any use of this image complies with any relevant licenses for all software contained within.
Content type
Image
Digest
sha256:44919b9d9…
Size
78.7 MB
Last updated
14 days ago
docker pull cyberark/conjur-cli