Skip to main content
SSH certificate authorities (CAs) let you sign the host keys used by your compute instances so clients can trust them without manually pinning fingerprints. Once a CA is created, you can bind it to an instance via nscale instances create --ssh-ca-id. Aliases: ssh-cas, sshca

Subcommands

  • list — List SSH certificate authorities
  • get — Get SSH certificate authority details
  • create — Create a new SSH certificate authority
  • delete — Delete an SSH certificate authority

list

List SSH certificate authorities, optionally filtered by organization or project.

Flags

FlagDescription
Organization ID
Project ID
Emit the full JSON payload (mutually exclusive with -q)
jq filter for value extraction (see Query output with -q)

Example


get

Get details for a specific SSH certificate authority.

Flags

FlagDescription
SSH certificate authority ID
Organization ID
Emit the full JSON payload (mutually exclusive with -q)
jq filter for value extraction (see Query output with -q)

create

Create a new SSH certificate authority. Accepts input from a JSON file or stdin.

Flags

FlagDescription
Organization ID
Path to a JSON file
Read JSON from standard input
Preview the request payload without persisting
Automatically confirm creation
Emit the full JSON payload (mutually exclusive with -q)
jq filter for value extraction (see Query output with -q)

Examples


delete

Delete an existing SSH certificate authority.

Flags


Instances

Bind a certificate authority when creating an instance with .