cosigner-cli v0.1.1 · runtime v0.1.14→

Run the Fystack Cosigner on your own servers

One command installs cosigner-cli. Every download is checked against signed checksums and Sigstore signatures before it runs.

$curl -sSL https://cosigner.fystack.io/install.sh | sh
ops@cosigner-host

Current release

Two artifacts, each with its own signature

cosigner-cli runs on your host. The Cosigner runtime runs in Docker. Each is built and signed by its own release workflow, and each is verified before it runs.

Host CLI

cosigner-cli v0.1.1

GitHub release
Released
Oct 11, 2026
Commit
175aa02bf75e
Signed by
fystack/cosigner-cli/.github/workflows/release.yml@refs/tags/v0.1.1
install.sh SHA-256
7eac5b3745c39ccd84406e002d83a474912935d545982de29d0bd89dc16c5f33
PlatformSHA-256
Linux · x86_64a0ed93e5538a8c3995f80a97…Download
Linux · ARM646d62651522d2e8ee3a68fd9b…Download
macOS · Intel14e503e3611ba918097878a2…Download
macOS · Apple silicon15916849aa47057ebae04499…Download
Runtime image

cosigner v0.1.14

JSON
Built
Oct 7, 2026
Platforms
linux/amd64, linux/arm64
Signed by
fystack/cosigner/.github/workflows/release.yml@refs/tags/v0.1.14
Image digest
sha256:c0f2c54a97444286158164b99354b306fb496fed7223189f5b6b5c3e8d3f056b

cosigner-cli up picks the newest signed release from ghcr.io/fystack/cosigner, verifies it with cosign and pins its digest. To install this exact image:

pin this release
$cosigner-cli up \
    --image ghcr.io/fystack/cosigner@sha256:c0f2c54a97444286158164b99354b306fb496fed7223189f5b6b5c3e8d3f056b

Verify it yourself

Don't trust the pipe. Check it.

Everything the installer and cosigner-cli check, you can check by hand with the same commands.

Read install.sh before you run it

Each release has its own installer with that release's checksums written into it. Download the one for v0.1.1, compare its SHA-256 with the one published here, read it, then run it.

Pinned per releasePOSIX shNo telemetry
verify
$curl -sSLO https://cosigner.fystack.io/v0.1.1/install.sh
$echo "7eac5b3745c39ccd84406e002d83a474912935d545982de29d0bd89dc16c5f33  install.sh" | shasum -a 256 -c
$less install.sh
$sh install.sh

Get started

From install to a running cosigner

Three commands. Your key shares, approval callback and encrypted database stay on your host.

  1. 1

    Install

    Installs cosign if needed, verifies cosigner-cli and checks Docker.

    shell
    $curl -sSL https://cosigner.fystack.io/install.sh | sh
  2. 2

    Check the host

    Confirms Docker, cosign, your config and the install state.

    shell
    $cosigner-cli doctor
  3. 3

    Pair and start

    Pulls the newest signed runtime, verifies it, pins its digest, then asks for your pairing token.

    shell
    $export COSIGNER_HOME=/srv/cosigner
    $cosigner-cli up \
        --apex-endpoint https://YOUR-APEX-HOST \
        --config /secure/config.yaml

Before you start

  • Linux for production. macOS or WSL 2 for development.
  • Docker with Compose v2.
  • cosign v3+ (the installer adds it if missing).
  • A pairing token and your Apex endpoint.

// Running in a Nitro enclave? That setup is different, see the Fystack docs.

All releases

Every release, every checksum

Each cosigner-cli release keeps its own installer, so --version installs exactly what was published. Runtime images are listed with the digest that up pins.

VersionReleasedCommitInstall
v0.1.1LatestOct 11, 2026175aa02bf75einstall.sh