MAQPNADocs

Install

Install the maqpna CLI on macOS, Linux or Windows, then MAQPNA itself on Kubernetes with Helm, online or air-gapped.

There are two things to install:

  • The CLI, maqpna, on your own machine. It runs a local MAQPNA with no cluster, and it operates an installation. Its lifecycle plugin, maqpna-install, installs and upgrades MAQPNA in a cluster.
  • MAQPNA itself, in a Kubernetes cluster, for production. Skip this until you need it: the quickstart runs on a laptop.

Release v0.1.1 is current. Every binary is signed (Sigstore cosign) and listed in the release's checksums.txt; maqpna verify checks them.

Install the CLI#

Install script (macOS and Linux)#

curl -fsSL https://maqpna.com/install.sh | sh

The script downloads maqpna, maqpna-install and maqpna-sovereign for your platform from the release, checks each against the release's checksums.txt and, when cosign is installed, its signature, and installs them to /usr/local/bin (or ~/.local/bin when that is not writable).

# A specific version, one binary, and require a valid cosign signature
curl -fsSL https://maqpna.com/install.sh | sh -s -- --version v0.1.1 --bin maqpna --cosign

# From the dl.maqpna.com mirror instead of GitHub
curl -fsSL https://maqpna.com/install.sh | sh -s -- --mirror

PowerShell (Windows)#

irm https://maqpna.com/install.ps1 | iex

It installs to %LOCALAPPDATA%\Programs\maqpna\bin and adds that directory to your PATH.

More install options: maqpna.com/download lists every binary, package manager and signature for each release.

Linux packages: .deb, .rpm and .apk#

Each release has packages for amd64, arm64, ppc64le and s390x. Download maqpna and its plugin maqpna-install for your architecture from maqpna.com/download, then install them together:

# Debian, Ubuntu
sudo apt install ./maqpna_0.1.1_linux_amd64.deb ./maqpna-install_0.1.1_linux_amd64.deb

# RHEL, Fedora, SUSE
sudo dnf install ./maqpna_0.1.1_linux_amd64.rpm ./maqpna-install_0.1.1_linux_amd64.rpm

# Alpine
sudo apk add --allow-untrusted ./maqpna_0.1.1_linux_amd64.apk ./maqpna-install_0.1.1_linux_amd64.apk

Check the install#

maqpna version
maqpna version.cast

Then turn on tab completion for your shell with maqpna completion.

Install MAQPNA on Kubernetes#

With the CLI#

maqpna preflight checks the cluster first and changes nothing. maqpna install then installs the Helm chart with a values profile: dev, prod or sovereign-eu.

maqpna preflight --profile dev
maqpna install --profile dev --wait

# Production, with your own values
maqpna preflight --profile prod -f values.yaml --strict
maqpna install --profile prod -f values.yaml --wait --timeout 15m

Check the result with maqpna status and maqpna doctor.

With Helm#

The chart is an OCI artifact. The values-sovereign-eu.yaml profile ships inside it. Set REGISTRY to the release registry listed on maqpna.com/download:

helm pull "oci://$REGISTRY/charts/maqpna" --version 0.1.1 --untar
helm install maqpna ./maqpna \
  --namespace maqpna-system --create-namespace \
  --set image.registry="$REGISTRY" \
  -f maqpna/values-sovereign-eu.yaml

Validate your values offline before installing with maqpna values validate.

Air-gapped clusters#

Build a bundle on a connected host, carry it across, verify it and push its images to your registry:

# Connected side: every image, the chart, the agent-sandbox manifest, SBOMs and signed checksums
maqpna airgap bundle --tag v0.1.1 --out bundle/

# Disconnected side
maqpna airgap verify bundle/ --require-signature --key cosign.pub
maqpna airgap push bundle/ --registry registry.internal:5000

Then install with the bundle's hack/airgap-install.sh or maqpna install. The bundle commands are described in maqpna airgap.