Install
Install the maqpna CLI on macOS, Linux or Windows, then MAQPNA itself on Kubernetes with Helm, online or air-gapped.
There are two things to install:
- The CLI,
maqpna, on your own machine. It runs a local MAQPNA with no cluster, and it operates an installation. Its lifecycle plugin,maqpna-install, installs and upgrades MAQPNA in a cluster. - MAQPNA itself, in a Kubernetes cluster, for production. Skip this until you need it: the quickstart runs on a laptop.
Release v0.1.1 is current. Every binary is signed (Sigstore cosign) and listed in the release's
checksums.txt; maqpna verify checks them.
Install the CLI#
Install script (macOS and Linux)#
curl -fsSL https://maqpna.com/install.sh | sh
The script downloads maqpna, maqpna-install and maqpna-sovereign for your platform from the release,
checks each against the release's checksums.txt and, when cosign is installed, its signature, and installs them
to /usr/local/bin (or ~/.local/bin when that is not writable).
# A specific version, one binary, and require a valid cosign signature
curl -fsSL https://maqpna.com/install.sh | sh -s -- --version v0.1.1 --bin maqpna --cosign
# From the dl.maqpna.com mirror instead of GitHub
curl -fsSL https://maqpna.com/install.sh | sh -s -- --mirror
PowerShell (Windows)#
irm https://maqpna.com/install.ps1 | iex
It installs to %LOCALAPPDATA%\Programs\maqpna\bin and adds that directory to your PATH.
More install options: maqpna.com/download lists every binary, package manager and signature for each release.
Linux packages: .deb, .rpm and .apk#
Each release has packages for amd64, arm64, ppc64le and s390x. Download maqpna and its plugin
maqpna-install for your architecture from maqpna.com/download, then install
them together:
# Debian, Ubuntu
sudo apt install ./maqpna_0.1.1_linux_amd64.deb ./maqpna-install_0.1.1_linux_amd64.deb
# RHEL, Fedora, SUSE
sudo dnf install ./maqpna_0.1.1_linux_amd64.rpm ./maqpna-install_0.1.1_linux_amd64.rpm
# Alpine
sudo apk add --allow-untrusted ./maqpna_0.1.1_linux_amd64.apk ./maqpna-install_0.1.1_linux_amd64.apk
Check the install#
maqpna version
Then turn on tab completion for your shell with maqpna completion.
Install MAQPNA on Kubernetes#
With the CLI#
maqpna preflight checks the cluster first and changes nothing.
maqpna install then installs the Helm chart with a values profile: dev, prod or
sovereign-eu.
maqpna preflight --profile dev
maqpna install --profile dev --wait
# Production, with your own values
maqpna preflight --profile prod -f values.yaml --strict
maqpna install --profile prod -f values.yaml --wait --timeout 15m
Check the result with maqpna status and
maqpna doctor.
With Helm#
The chart is an OCI artifact. The values-sovereign-eu.yaml profile ships inside it. Set REGISTRY to the
release registry listed on maqpna.com/download:
helm pull "oci://$REGISTRY/charts/maqpna" --version 0.1.1 --untar
helm install maqpna ./maqpna \
--namespace maqpna-system --create-namespace \
--set image.registry="$REGISTRY" \
-f maqpna/values-sovereign-eu.yaml
Validate your values offline before installing with
maqpna values validate.
Air-gapped clusters#
Build a bundle on a connected host, carry it across, verify it and push its images to your registry:
# Connected side: every image, the chart, the agent-sandbox manifest, SBOMs and signed checksums
maqpna airgap bundle --tag v0.1.1 --out bundle/
# Disconnected side
maqpna airgap verify bundle/ --require-signature --key cosign.pub
maqpna airgap push bundle/ --registry registry.internal:5000
Then install with the bundle's hack/airgap-install.sh or maqpna install. The bundle commands are described in
maqpna airgap.