Skip to content
SHC Docs

shc cert ls

list the certificates you can see (RBAC-filtered)

List the certificate authorities visible to you: a tenant session sees only its own CA, an admin session sees the global root, the cluster CA, and every tenant. Columns: name, kind, fingerprint, expiry. -o json emits the machine shape. —cert includes the PEM. —nodes (admin) enriches with the live per-node leaf certs.

shc cert ls [flags]
--cert include each cert's PEM body
-h, --help help for ls
--nodes (admin) also list the live per-node leaf certs
--config stringArray extra YAML config file to layer on top of auto-discovered config; repeatable, later files win
-d, --debug enable debug mode (default: $SHC_DEBUG)
-e, --environment string environment name (default: $SHC_ENVIRONMENT)
--exclude string comma-separated dotted paths to drop
--fields string comma-separated columns/keys to show (and their order)
--filter string comma-separated dotted paths to keep (drops everything else)
-o, --output string output format: tty|text|json|yaml (default: $SHC_OUTPUT)
-s, --stack string stack name (default: $SHC_STACK)
-t, --tenant string tenant name (default: $SHC_TENANT)
-v, --verbose verbose output (default: $SHC_VERBOSE)
  • shc cert - inspect certificates (RBAC-filtered)