Command-line interface used to interact with CyberArk Identity Security platform services
3.1K
The Idsec CLI is a Go command-line tool to interact with CyberArk Identity Security services (profile management, PCloud account operations, service execution, and more).
Full documentation is published at cyberark.github.io/idsec-cli-golang.
There are two sets of supported tags:
latest — the most recently released version of the Idsec CLI. There are no backwards-compatibility guarantees when relying on latest. See notes on backwards compatibility for more information.<major.minor.patch> — each released version of the Idsec CLI (e.g. 1.2.3). These tags are immutable; they are only ever pushed once, on release.Architecture note: images are currently published for
linux/amd64only. Apple Silicon and other arm64 hosts will need Docker's emulation layer (Rosetta on macOS, qemu on Linux).
The Idsec CLI can be executed from the Docker CLI with the docker run command:
$ docker run --rm -it cyberark/idsec-cli-golang:1.2.3 version
This prints the version of the Idsec CLI being used in the container. Note that the idsec executable is not specified on the docker run line because it is defined as the image's entrypoint.
For any Idsec CLI command, you can request help with --help:
$ docker run --rm -it cyberark/idsec-cli-golang:1.2.3 --help
$ docker run --rm -it cyberark/idsec-cli-golang:1.2.3 configure --help
For the full command reference, see the Idsec CLI documentation site.
The Idsec CLI stores profiles at /idsec/profiles and the credential keyring at /idsec/keyring inside the container (controlled by the IDSEC_PROFILES_FOLDER and IDSEC_KEYRING_FOLDER environment variables). Without a volume mount, both are lost when the container exits. Mount ~/.idsec from the host to persist them between runs:
$ docker run --rm -it \
-v "$HOME/.idsec:/idsec" \
cyberark/idsec-cli-golang:1.2.3 \
configure
The image's working directory is /data — the user-facing scratch area for input/output. Mount your current host directory there so the CLI can read inputs and write outputs to it:
$ docker run --rm -it \
-v "$HOME/.idsec:/idsec" \
-v "$(pwd):/data" \
cyberark/idsec-cli-golang:1.2.3 \
<subcommand> --input ./input.json
Anything you write under /data inside the container shows up in your current working directory on the host.
To shorten docker commands, add a shell alias:
$ alias idsec='docker run --rm -it -v "$HOME/.idsec:/idsec" -v "$(pwd):/data" cyberark/idsec-cli-golang:latest'
You can then invoke the CLI as if it were installed natively on the host:
$ idsec version
$ idsec configure
idsec executable should ever be invoked directly./data directory is user-controlled. The image will not write to it unless an Idsec CLI command does so on your behalf.idsec-cli). Files written into bind-mounted host volumes will be owned by that user's in-container UID. If you need files in ~/.idsec or your working directory to be owned by your host user, run the container with --user "$(id -u):$(id -g)" and pre-create the host directories with appropriate permissions.IDSEC_PROFILES_FOLDER defaults to /idsec/profiles, IDSEC_KEYRING_FOLDER defaults to /idsec/keyring. Mounting /idsec (or each subdirectory individually) is what persists CLI state across runs.latest tag. Between updates to latest, any of the following may change:
alpine:3.19) may be upgraded.<major.minor.patch> tag — those are immutable; they will only ever be pushed to once upon release of a particular version of the Idsec CLI.For information on general usage of the Idsec CLI, please refer to:
The source for the Idsec CLI lives at github.com/cyberark/idsec-cli-golang. The Docker image is built from docker/Dockerfile in that repository.
To file feature requests or report issues related to this Docker image, please open an issue at the GitHub repository.
Content type
Image
Digest
sha256:d199d72d5…
Size
13.2 MB
Last updated
about 22 hours ago
docker pull cyberark/idsec-cli-golang