pkg.soopen package index

brew / rank 6269

Install roxctl with Homebrew, Nix

CLI for Stackrox. Version 4.11.4 via Homebrew; verified 2026-09-14. Also installable with nix: nix profile install nixpkgs#roxctl.

install

Additional install commands

macOS

Homebrewverified · 100%
brew install roxctl

local Homebrew formula metadata

Linux

Nixverified · 92%
nix profile install nixpkgs#roxctl

nixpkgs package indexes · pkgs/by-name/ro/roxctl/package.nix · source: api.github.com

overview

Package summary

CLI for Stackrox

Commands and aliases

  • roxctl

history

Project history and usage

roxctl is the command-line client for StackRox and Red Hat Advanced Cluster Security for Kubernetes, covering security checks, scanning, deployment management, diagnostics, and interaction with Central.

Project history

roxctl originated as the command-line interface for StackRox, the open-source Kubernetes security platform.

Following Red Hat's acquisition and productization of StackRox as Red Hat Advanced Cluster Security for Kubernetes, roxctl continued as the supported administrative and automation CLI. Its commands have evolved alongside RHACS releases, including image scanning, policy checks, SBOM generation, network-policy analysis, and operator-oriented installation workflows.

Adoption history

roxctl is distributed as part of the StackRox/RHACS ecosystem and is packaged independently by Homebrew and Nix, making the security platform's automation client available through general-purpose package managers.

Red Hat documentation positions the CLI for both self-managed RHACS and RHACS Cloud Service workflows.

How it is used

Users configure a Central endpoint and authenticate using `ROX_API_TOKEN`, a token file, or an authentication-provider login. Common automation commands scan images, check images or deployments against policies, generate manifests, manage secured-cluster registration, and collect diagnostic data.

For RHACS Cloud Service, official guidance uses `ROX_API_TOKEN` and `ROX_ENDPOINT`.

Why package nerds care

roxctl packages a large Kubernetes security platform's operational API into one automation-friendly binary. It is useful in CI pipelines for policy checks and image scans, while also supporting installation, backup, diagnostics, and cluster-registration workflows.

Timeline

  • StackRox era: roxctl developed as the platform's administrative CLI.
  • Red Hat era: roxctl retained as the CLI for Red Hat Advanced Cluster Security for Kubernetes.
  • 2023: Browser-based authentication and locally stored access and refresh tokens were documented in the RHACS CLI workflow.
  • 2024–2026: RHACS releases continued adding and revising roxctl scanning, SBOM, registration, and installation commands.

Related projects

  • StackRox is the upstream platform repository containing roxctl.
  • Red Hat Advanced Cluster Security for Kubernetes is the supported product in which roxctl is documented.
  • Kubernetes and OpenShift are its principal deployment environments.

security posture

No protected-tool coverage found yet

No matching local secret-handling manifest was found for roxctl. Package metadata is still published here so future coverage has a stable package URL.

Install behavior

  • No Homebrew post-install hook is recorded in formula metadata.
  • Homebrew bottle metadata is available for 6 platform targets.
  • Build metadata lists 1 build dependencies.

Recommended review

Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

Unix
~/.roxctl/roxctl-config$ROX_CONFIG_DIR/roxctl-config$XDG_RUNTIME_DIR/roxctl-config

Credential files

Credential-bearing paths to review before unattended agent runs.

Unix
~/.roxctl/roxctl-config$ROX_CONFIG_DIR/roxctl-config$XDG_RUNTIME_DIR/roxctl-config

executables

Installed executables

CommandKindExposureNote
roxctlcliglobal executable

freshness

Version and freshness

These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.

page generated2026-09-19
manager version4.11.4
manager updated2026-09-14
local dataok
upstreamcurrent
latest detected4.11.3

https://github.com/stackrox/stackrox

  • okNo freshness warnings were generated.

install metadata

Package metadata

Package keybrew:roxctl
Version4.11.4
Package managerHomebrew
Package manager pagehttps://formulae.brew.sh/formula/roxctl
Homepagehttps://www.stackrox.io/
Repositoryhttps://github.com/stackrox/stackrox
Upstream docshttps://www.stackrox.io/
LicenseApache-2.0
Source archivehttps://github.com/stackrox/stackrox/archive/refs/tags/4.11.3.tar.gz
Last updated2026-09-14T21:34:41Z
Pulseupdated
Build dependenciesgo
Bottleavailable (on arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux)
Homebrew post-installnot defined
Servicenone declared

registry facts

Source database details

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Nameroxctl
Version Scheme0
Revision0
Head VersionHEAD
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • head
  • stable

source database matches

Other package-manager records

Matches are pulled from external package-manager indexes and kept separate from local Automic Vault package links.

Nix95%

roxctl

nix profile install nixpkgs#roxctl
  • normalized package name match
  • Matched by: Roxctl
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/ro/roxctl/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1

source trail

Generated from repository data

This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.

Used sources

  • Geiger risk classifier
  • cross-ecosystem install command graph
  • curated configuration and credential file locations
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment
  • pkg.so package database
  • pkgdb category and tag curation