macOS
brew install roxctllocal Homebrew formula metadata
brew / rank 6269
CLI for Stackrox. Version 4.11.4 via Homebrew; verified 2026-09-14. Also installable with nix: nix profile install nixpkgs#roxctl.
install
brew install roxctllocal Homebrew formula metadata
nix profile install nixpkgs#roxctlnixpkgs package indexes · pkgs/by-name/ro/roxctl/package.nix · source: api.github.com
overview
CLI for Stackrox
history
roxctl is the command-line client for StackRox and Red Hat Advanced Cluster Security for Kubernetes, covering security checks, scanning, deployment management, diagnostics, and interaction with Central.
roxctl originated as the command-line interface for StackRox, the open-source Kubernetes security platform.
Following Red Hat's acquisition and productization of StackRox as Red Hat Advanced Cluster Security for Kubernetes, roxctl continued as the supported administrative and automation CLI. Its commands have evolved alongside RHACS releases, including image scanning, policy checks, SBOM generation, network-policy analysis, and operator-oriented installation workflows.
roxctl is distributed as part of the StackRox/RHACS ecosystem and is packaged independently by Homebrew and Nix, making the security platform's automation client available through general-purpose package managers.
Red Hat documentation positions the CLI for both self-managed RHACS and RHACS Cloud Service workflows.
Users configure a Central endpoint and authenticate using `ROX_API_TOKEN`, a token file, or an authentication-provider login. Common automation commands scan images, check images or deployments against policies, generate manifests, manage secured-cluster registration, and collect diagnostic data.
For RHACS Cloud Service, official guidance uses `ROX_API_TOKEN` and `ROX_ENDPOINT`.
roxctl packages a large Kubernetes security platform's operational API into one automation-friendly binary. It is useful in CI pipelines for policy checks and image scans, while also supporting installation, backup, diagnostics, and cluster-registration workflows.
security posture
No matching local secret-handling manifest was found for roxctl. Package metadata is still published here so future coverage has a stable package URL.
Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.
local files
These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.
Config paths the tool may read or write during local use.
~/.roxctl/roxctl-config$ROX_CONFIG_DIR/roxctl-config$XDG_RUNTIME_DIR/roxctl-configCredential-bearing paths to review before unattended agent runs.
~/.roxctl/roxctl-config$ROX_CONFIG_DIR/roxctl-config$XDG_RUNTIME_DIR/roxctl-configexecutables
| Command | Kind | Exposure | Note |
|---|---|---|---|
roxctl | cli | global executable |
freshness
These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.
https://github.com/stackrox/stackrox
install metadata
| Package key | brew:roxctl |
|---|---|
| Version | 4.11.4 |
| Package manager | Homebrew |
| Package manager page | https://formulae.brew.sh/formula/roxctl |
| Homepage | https://www.stackrox.io/ |
| Repository | https://github.com/stackrox/stackrox |
| Upstream docs | https://www.stackrox.io/ |
| License | Apache-2.0 |
| Source archive | https://github.com/stackrox/stackrox/archive/refs/tags/4.11.3.tar.gz |
| Last updated | 2026-09-14T21:34:41Z |
| Pulse | updated |
| Build dependencies | go |
| Bottle | available (on arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux) |
| Homebrew post-install | not defined |
| Service | none declared |
registry facts
| Source Database | Homebrew formula API |
|---|---|
| Tap | homebrew/core |
| Full Name | roxctl |
| Version Scheme | 0 |
| Revision | 0 |
| Head Version | HEAD |
| Bottle Stable Root URL | https://ghcr.io/v2/homebrew/core |
| Deprecated | no |
| Disabled | no |
| Keg Only | no |
| URL Keys |
|
source database matches
Matches are pulled from external package-manager indexes and kept separate from local Automic Vault package links.
roxctl
nix profile install nixpkgs#roxctlsource trail
This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.
View the package source record on GitHub.