Skip to main content


Chainloop is comprised of two main components

  • A Server Side Component (Control Plane + Artifact Storage Proxy) that acts as single source of truth and management console.
  • A Command Line Interface (CLI) used to both a) operate on the control plane and b) run the attestation process on your CI/CD

Command Line Interface (CLI) installation

To install the latest version for macOS, Linux or Windows (using WSL) just choose one of the following installation method.

curl -sfL | bash -s

you can retrieve a specific version with

# You can find all the available versions at
curl -sfL | bash -s -- --version vx.x.x

and customize the install path (default to /usr/local/bin)

curl -sfL | bash -s -- --path /my-path

if cosign is present in your system, in addition to the checksum check, a signature verification will be performed. This behavior can be enforced via the --force-verification flag.

curl -sfL | bash -s -- --force-verification

Deploy Chainloop

To run a Chainloop instance on your Kubernetes cluster follow these instructions.

Configure CLI

If you are running your own instance of Chainloop Control Plane. You can make the CLI point to your instance by using the chainloop config save command.

chainloop config save \
--control-plane \

Another option would be to build a custom version of CLI with default endpoints' values pointing at your Chainloop instance. Please learn more about this method in the following doc.


Authenticate to the Control Plane by running

$ chainloop auth login

That's all!

Welcome to Chainloop!