Install the host bootstrap tools and the pinned HSM container image. The host uses step and step-kms-plugin to initialize the CA; the container runs the online CA.
Install operating-system packages
Confirm that Docker is running:
The command exits with status 0 when the Docker daemon is ready.
Install step CLI 0.30.6
The output includes Smallstep CLI/0.30.6.
Install step-kms-plugin 0.17.0
The output includes step-kms-plugin/0.17.0.
Pull the HSM image
The second command reports Smallstep CA/0.30.2.
Do not substitute smallstep/step-ca:0.30.2 or an ordinary step-ca package. The -hsm image is the CGO-enabled build that supports a native PKCS #11 module.
Register the plugin for the CA workspace
Create the CA workspace and plugin link:
Confirm that step discovers the plugin:
The command exits with status 0 when the KMS commands are available.