cleanstart/step-issuer

Verified Publisher

By CleanStart

•Updated about 6 hours ago

Secure by Design, Built for Speed, Hardened Container Images on a minimal base CleanStart OS.

Image
Developer tools
0

10K+

cleanstart/step-issuer repository overview

Container Documentation for Step-Issuer

Step-issuer is a specialized container for automated certificate issuance and management using the step-ca certificate authority. It provides automated X.509 certificate provisioning, renewal, and revocation capabilities for enterprise PKI infrastructure. The container integrates with popular certificate authorities and supports automated ACME protocol operations.

šŸ“Œ Base Foundation: Security-hardened, minimal base OS designed for enterprise containerized environments from Cleanstart Registry.

Key Features Core capabilities and strengths of this container

  • Automated X.509 certificate issuance and renewal
  • ACME protocol support for certificate automation
  • Integration with step-ca certificate authority
  • Enterprise PKI infrastructure management

Common Use Cases Typical scenarios where this container excels

  • Automated certificate management for web services
  • PKI infrastructure automation
  • TLS certificate deployment automation
  • Zero-trust security implementations

Pull Latest Image Download the container image from the registry

docker pull cleanstart/step-issuer:latest
docker pull cleanstart/step-issuer:latest-dev

Basic Run Run the container entrypoint with basic configuration

 docker run -it --entrypoint /bin/bash --name step-issuerrrrr-testsss cleanstart/step-issuer:latest-dev

Production Deployment Deploy with production security settings

docker run -d --name step-issuer-prod \
  --read-only \
  --security-opt=no-new-privileges \
  --user 1000:1000 \
  cleanstart/step-issuer:latest

Environment Variables Configuration options available through environment variables

VariableDefaultDescription
STEP_CA_URLhttps://ca.example.com⁠Step CA server URL
STEP_ROOT_FILE/certs/root_ca.crtRoot CA certificate path
STEP_PROVISIONER_NAMEacmeProvisioner name for certificate issuance
STEP_RENEWAL_INTERVAL24hCertificate renewal interval

Security Best Practices Recommended security configurations and practices

  • Secure private keys with appropriate file permissions
  • Use separate volumes for certificate storage
  • Implement proper access controls for certificate management
  • Regular rotation of provisioner credentials
  • Monitor certificate expiration and renewal events
  • Use secure communication channels for CA interactions
  • Implement proper backup procedures for certificates
  • Regular security audits of certificate usage

Kubernetes Security Context Recommended security context for Kubernetes deployments

securityContext:
  runAsNonRoot: true
  runAsUser: 1000
  runAsGroup: 1000
  readOnlyRootFilesystem: true
  allowPrivilegeEscalation: false
  capabilities:
    drop: ["ALL"]

Multi-Platform Images

docker pull --platform linux/amd64 cleanstart/step-issuer:latest
docker pull --platform linux/arm64 cleanstart/step-issuer:latest

⁠Documentation Resources

Essential links and resources for further information

CleanStart Images: https://images.cleanstart.com/⁠

Community Images:
Docker Hub: https://hub.docker.com/u/cleanstart⁠
GitHub: https://github.com/cleanstart-containers⁠
AWS ECR Public Gallery: https://gallery.ecr.aws/cleanstart/⁠

Presence on Social Media:
Community: https://www.linkedin.com/groups/18324021/⁠
YouTube: https://www.youtube.com/@CleanStartOfficial⁠

Contribute to Container Use Cases: https://github.com/cleanstart-dev/cleanstart-use-cases/⁠


Vulnerability Disclaimer

CleanStart offers Docker images that include third-party open-source libraries and packages maintained by independent contributors. While CleanStart maintains these images and applies industry-standard security practices, it cannot guarantee the security or integrity of upstream components beyond its control.

Users acknowledge and agree that open-source software may contain undiscovered vulnerabilities or introduce new risks through updates. CleanStart shall not be liable for security issues originating from third-party libraries, including but not limited to zero-day exploits, supply chain attacks, or contributor-introduced risks.

Security remains a shared responsibility: CleanStart provides updated images and guidance where possible, while users are responsible for evaluating deployments and implementing appropriate controls.

Tag summary

Content type

Image

Digest

sha256:e986a8081…

Size

40.4 MB

Last updated

about 6 hours ago

docker pull cleanstart/step-issuer:0.12.0-amd64