This is a Docker image based on Alpine for CloudFlare's CFSSL, it includes all CFSSL utilities.
344
This is a Docker image for CloudFlare's CFSSL including all CFSSL utilities provided by CloudFlare, based on the Alpine base image.
There are two ways to use this image: with a docker run command, or with the bundled wrapper scripts.
docker run -i --rm -v $(pwd):/cfssl lindeboomio/cfssl <command>
Where command is one of:
For each CFSSL command, a wrapper script is included with the proper docker run command.
To dump the wrapper scripts, run the following command:
docker run -i --rm -v $(pwd):/cfssl lindeboomio/cfssl dump-wrappers
The wrapper scripts will be placed in the wrappers directory, and have to be moved to a location in your path, e.g. /usr/local/bin:
sudo mv wrappers/* /usr/local/bin
With the wrapper scripts in your path, the CFSSL commands should be usable as usual, with one minor but important caveat: because only the current directory (pwd) is mounted into the container, only paths relative to the current directory will generally work.
Note: the wrapper scripts runs cfssl and multirootca with host networking enabled, to allow for running the servers on custom ports.
To get going with CFSSL, there is an article over at the CloudFlare blog with examples that have been demonstrated to work, with one addition: to enable a CFSSL server to sign certificates, a sign cert usage needs to be added to the CA policy file (config_ca.json):
[..]
"usages": [
"signing",
"key encipherment",
"server auth",
"sign cert"
]
[..]
Content type
Image
Digest
Size
113.3 MB
Last updated
almost 10 years ago
docker pull lindeboomio/cfssl-alpine