Download · v0.1.0

Download MAQPNA

Command-line tools for Linux, macOS and Windows, server binaries, Linux packages, multi-arch container images and the Helm chart. Every file has a SHA256 checksum, a cosign keyless signature and an SBOM, built reproducibly from the tagged source.

Quick install

The install scripts download the CLIs (maqpna and maqpna-sovereign) for your platform from the GitHub release, check the SHA256 against the release's checksums.txt and — if cosign is installed — the signature, and install them to /usr/local/bin (or ~/.local/bin) or %LOCALAPPDATA%\Programs\maqpna\bin.

Linux and macOS

sh
curl -fsSL https://maqpna.com/install.sh | sh
# a specific version, one binary, require a cosign signature:
curl -fsSL https://maqpna.com/install.sh | sh -s -- --version v0.1.0 --bin maqpna --cosign
# from the dl.maqpna.com mirror instead of GitHub:
curl -fsSL https://maqpna.com/install.sh | sh -s -- --mirror

Windows (PowerShell)

PowerShell
irm https://maqpna.com/install.ps1 | iex

Package managers

PlatformCommand
Homebrew (macOS, Linux)brew install azmxai/maqpna/maqpna
winget (Windows)winget install MAQPNA.maqpna
Scoop (Windows)scoop bucket add maqpna https://github.com/AzmxAI/scoop-maqpna
scoop install maqpna/maqpna
Debian, Ubuntu (.deb)curl -LO https://github.com/AzmxAI/maqpna-releases/releases/download/v0.1.0/maqpna_0.1.0_linux_amd64.deb
sudo apt install ./maqpna_0.1.0_linux_amd64.deb
RHEL, Fedora, SUSE (.rpm)sudo dnf install https://github.com/AzmxAI/maqpna-releases/releases/download/v0.1.0/maqpna_0.1.0_linux_amd64.rpm
Alpine (.apk)curl -LO https://github.com/AzmxAI/maqpna-releases/releases/download/v0.1.0/maqpna_0.1.0_linux_amd64.apk
sudo apk add --allow-untrusted ./maqpna_0.1.0_linux_amd64.apk

The Homebrew tap (AzmxAI/homebrew-maqpna) serves the formula from the first public release. The Scoop bucket (AzmxAI/scoop-maqpna), the winget package and the signed apt / yum repositories are planned and open later. Until then use the install scripts, the packages above or the binaries below. Package files for other architectures are listed under Linux packages.

Binaries

Every file is a GitHub release asset: https://github.com/AzmxAI/maqpna-releases/releases/download/<version>/<binary>_<os>_<arch> (.exe on Windows), with its cosign signature bundle next to it as <file>.sigstore.json and its digest in the release's checksums.txt. The mirror at https://dl.maqpna.com serves the same files in the dl.k8s.io layout, https://dl.maqpna.com/<version>/bin/<os>/<arch>/<binary>, each with a .sha256 (the hex digest) and a .sigstore.json. All binaries are static (CGO_ENABLED=0).

Linux 22 files

CLIs for amd64, arm64, ppc64le and s390x; servers for amd64 and arm64.

BinaryArchitectureDownloadVerifyMirrorSize
maqpnaamd64 (x86-64)maqpna_linux_amd6472.8 MiB
maqpnaarm64maqpna_linux_arm64
maqpnappc64lemaqpna_linux_ppc64le
maqpnas390xmaqpna_linux_s390x75.1 MiB
maqpna-sovereignamd64 (x86-64)maqpna-sovereign_linux_amd649.8 MiB
maqpna-sovereignarm64maqpna-sovereign_linux_arm649.1 MiB
maqpna-sovereignppc64lemaqpna-sovereign_linux_ppc64le9.6 MiB
maqpna-sovereigns390xmaqpna-sovereign_linux_s390x10.1 MiB
maqpna-gatewayamd64 (x86-64)maqpna-gateway_linux_amd6416.5 MiB
maqpna-gatewayarm64maqpna-gateway_linux_arm6415.2 MiB
maqpna-identityamd64 (x86-64)maqpna-identity_linux_amd64
maqpna-identityarm64maqpna-identity_linux_arm64
maqpna-operatoramd64 (x86-64)maqpna-operator_linux_amd64
maqpna-operatorarm64maqpna-operator_linux_arm64
maqpna-attestamd64 (x86-64)maqpna-attest_linux_amd6411.2 MiB
maqpna-attestarm64maqpna-attest_linux_arm6410.6 MiB
maqpna-attest-agentamd64 (x86-64)maqpna-attest-agent_linux_amd646.3 MiB
maqpna-attest-agentarm64maqpna-attest-agent_linux_arm645.9 MiB
maqpna-execamd64 (x86-64)maqpna-exec_linux_amd646.1 MiB
maqpna-execarm64maqpna-exec_linux_arm645.6 MiB
maqpna-egress-relayamd64 (x86-64)maqpna-egress-relay_linux_amd645.3 MiB
maqpna-egress-relayarm64maqpna-egress-relay_linux_arm644.9 MiB
macOS 10 files

Apple silicon (arm64), Intel (amd64) and universal CLIs; gateway and identity for local development.

BinaryArchitectureDownloadVerifyMirrorSize
maqpnaamd64 (x86-64)maqpna_darwin_amd6475.0 MiB
maqpnaarm64maqpna_darwin_arm64
maqpnauniversal (arm64 and amd64)maqpna_darwin_universal145.0 MiB
maqpna-sovereignamd64 (x86-64)maqpna-sovereign_darwin_amd6410.1 MiB
maqpna-sovereignarm64maqpna-sovereign_darwin_arm649.3 MiB
maqpna-sovereignuniversal (arm64 and amd64)maqpna-sovereign_darwin_universal19.4 MiB
maqpna-gatewayamd64 (x86-64)maqpna-gateway_darwin_amd6417.0 MiB
maqpna-gatewayarm64maqpna-gateway_darwin_arm6415.7 MiB
maqpna-identityamd64 (x86-64)maqpna-identity_darwin_amd64
maqpna-identityarm64maqpna-identity_darwin_arm64
Windows 8 files

CLIs for amd64 and arm64; gateway and identity for local development.

BinaryArchitectureDownloadVerifyMirrorSize
maqpnaamd64 (x86-64)maqpna_windows_amd64.exe74.5 MiB
maqpnaarm64maqpna_windows_arm64.exe
maqpna-sovereignamd64 (x86-64)maqpna-sovereign_windows_amd64.exe10.0 MiB
maqpna-sovereignarm64maqpna-sovereign_windows_arm64.exe9.1 MiB
maqpna-gatewayamd64 (x86-64)maqpna-gateway_windows_amd64.exe16.9 MiB
maqpna-gatewayarm64maqpna-gateway_windows_arm64.exe15.4 MiB
maqpna-identityamd64 (x86-64)maqpna-identity_windows_amd64.exe
maqpna-identityarm64maqpna-identity_windows_arm64.exe

On the mirror, binaries larger than 25 MiB are served as a .tar.gz (or .zip) of the single binary plus LICENSE and README; GitHub serves every raw binary.

Archives and SBOMs 46 files

maqpna_<version>_* holds both CLIs (used by Homebrew, Scoop and winget); the other archives hold one binary each. macOS and Windows archives are .zip, Linux .tar.gz. Every archive has an SPDX SBOM.

ArchiveVerifySBOMMirrorSize
kubectl-maqpna_0.1.0_darwin_amd64.tar.gzSPDX23.5 MiB
kubectl-maqpna_0.1.0_darwin_arm64.tar.gzSPDX21.0 MiB
kubectl-maqpna_0.1.0_linux_amd64.tar.gzSPDX22.4 MiB
kubectl-maqpna_0.1.0_linux_arm64.tar.gzSPDX20.0 MiB
kubectl-maqpna_0.1.0_windows_amd64.zipSPDX22.6 MiB
kubectl-maqpna_0.1.0_windows_arm64.zipSPDX19.7 MiB
maqpna-attest-agent_0.1.0_linux_amd64.tar.gzSPDX2.7 MiB
maqpna-attest-agent_0.1.0_linux_arm64.tar.gzSPDX2.4 MiB
maqpna-attest_0.1.0_linux_amd64.tar.gzSPDX4.2 MiB
maqpna-attest_0.1.0_linux_arm64.tar.gzSPDX3.8 MiB
maqpna-egress-relay_0.1.0_linux_amd64.tar.gzSPDX2.3 MiB
maqpna-egress-relay_0.1.0_linux_arm64.tar.gzSPDX2.0 MiB
maqpna-exec_0.1.0_linux_amd64.tar.gzSPDX2.6 MiB
maqpna-exec_0.1.0_linux_arm64.tar.gzSPDX2.3 MiB
maqpna-gateway_0.1.0_darwin_amd64.zipSPDX6.4 MiB
maqpna-gateway_0.1.0_darwin_arm64.zipSPDX5.8 MiB
maqpna-gateway_0.1.0_linux_amd64.tar.gzSPDX6.2 MiB
maqpna-gateway_0.1.0_linux_arm64.tar.gzSPDX5.6 MiB
maqpna-gateway_0.1.0_windows_amd64.zipSPDX6.3 MiB
maqpna-gateway_0.1.0_windows_arm64.zipSPDX5.6 MiB
maqpna-identity_0.1.0_darwin_amd64.zipSPDX9.5 MiB
maqpna-identity_0.1.0_darwin_arm64.zipSPDX8.4 MiB
maqpna-identity_0.1.0_linux_amd64.tar.gzSPDX9.2 MiB
maqpna-identity_0.1.0_linux_arm64.tar.gzSPDX8.0 MiB
maqpna-identity_0.1.0_windows_amd64.zipSPDX9.3 MiB
maqpna-identity_0.1.0_windows_arm64.zipSPDX7.9 MiB
maqpna-operator_0.1.0_linux_amd64.tar.gzSPDX11.4 MiB
maqpna-operator_0.1.0_linux_arm64.tar.gzSPDX10.0 MiB
maqpna-sovereign_0.1.0_darwin_amd64.zipSPDX3.9 MiB
maqpna-sovereign_0.1.0_darwin_arm64.zipSPDX3.5 MiB
maqpna-sovereign_0.1.0_darwin_universal.zipSPDX7.4 MiB
maqpna-sovereign_0.1.0_linux_amd64.tar.gzSPDX3.7 MiB
maqpna-sovereign_0.1.0_linux_arm64.tar.gzSPDX3.4 MiB
maqpna-sovereign_0.1.0_linux_ppc64le.tar.gzSPDX3.4 MiB
maqpna-sovereign_0.1.0_linux_s390x.tar.gzSPDX3.6 MiB
maqpna-sovereign_0.1.0_windows_amd64.zipSPDX3.8 MiB
maqpna-sovereign_0.1.0_windows_arm64.zipSPDX3.3 MiB
maqpna_0.1.0_darwin_amd64.zipSPDX27.3 MiB
maqpna_0.1.0_darwin_arm64.zipSPDX24.5 MiB
maqpna_0.1.0_darwin_universal.zipSPDX51.8 MiB
maqpna_0.1.0_linux_amd64.tar.gzSPDX26.1 MiB
maqpna_0.1.0_linux_arm64.tar.gzSPDX23.4 MiB
maqpna_0.1.0_linux_ppc64le.tar.gzSPDX23.3 MiB
maqpna_0.1.0_linux_s390x.tar.gzSPDX25.1 MiB
maqpna_0.1.0_windows_amd64.zipSPDX26.4 MiB
maqpna_0.1.0_windows_arm64.zipSPDX23.0 MiB
Linux packages 12 files

The maqpna package installs both CLIs to /usr/bin.

PackageVerifyMirrorSize
maqpna_0.1.0_linux_amd64.apk27.4 MiB
maqpna_0.1.0_linux_amd64.deb26.2 MiB
maqpna_0.1.0_linux_amd64.rpm26.2 MiB
maqpna_0.1.0_linux_arm64.apk24.4 MiB
maqpna_0.1.0_linux_arm64.deb23.4 MiB
maqpna_0.1.0_linux_arm64.rpm23.4 MiB
maqpna_0.1.0_linux_ppc64le.apk24.3 MiB
maqpna_0.1.0_linux_ppc64le.deb23.3 MiB
maqpna_0.1.0_linux_ppc64le.rpm23.3 MiB
maqpna_0.1.0_linux_s390x.apk26.7 MiB
maqpna_0.1.0_linux_s390x.deb25.1 MiB
maqpna_0.1.0_linux_s390x.rpm25.1 MiB

Verify downloads

Checksum

Linux
curl -LO https://github.com/AzmxAI/maqpna-releases/releases/download/v0.1.0/maqpna_linux_amd64
curl -LO https://github.com/AzmxAI/maqpna-releases/releases/download/v0.1.0/checksums.txt
grep ' maqpna_linux_amd64$' checksums.txt | sha256sum --check
macOS
curl -LO https://github.com/AzmxAI/maqpna-releases/releases/download/v0.1.0/maqpna_darwin_arm64
curl -LO https://github.com/AzmxAI/maqpna-releases/releases/download/v0.1.0/checksums.txt
grep ' maqpna_darwin_arm64$' checksums.txt | shasum -a 256 --check
Windows (PowerShell)
Invoke-WebRequest https://github.com/AzmxAI/maqpna-releases/releases/download/v0.1.0/maqpna_windows_amd64.exe -OutFile maqpna_windows_amd64.exe
Invoke-WebRequest https://github.com/AzmxAI/maqpna-releases/releases/download/v0.1.0/checksums.txt -OutFile checksums.txt
$want = ((Select-String -Path checksums.txt -Pattern ' maqpna_windows_amd64\.exe$').Line -split '\s+')[0]
(Get-FileHash .\maqpna_windows_amd64.exe -Algorithm SHA256).Hash -eq $want   # True

On the mirror every file has a .sha256 next to it (the hex digest), e.g. https://dl.maqpna.com/v0.1.0/bin/linux/amd64/maqpna.sha256; its SHA256SUMS is the release's checksums.txt.

Signature (cosign keyless)

Release files are signed in GitHub Actions with Sigstore keyless signing: the certificate binds the signature to the workflow that built and signed the release (the identity below). There is no long-lived signing key. Verify with cosign 2.x or later:

sh
curl -LO https://github.com/AzmxAI/maqpna-releases/releases/download/v0.1.0/maqpna_linux_amd64.sigstore.json
cosign verify-blob maqpna_linux_amd64 \
  --bundle maqpna_linux_amd64.sigstore.json \
  --certificate-identity-regexp '^https://github\.com/AzmxAI/azmx-ai/\.github/workflows/maqpna-signed-release\.yml@refs/.+$' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com

checksums.txt lists every release asset and is signed the same way:

sh
curl -LO https://github.com/AzmxAI/maqpna-releases/releases/download/v0.1.0/checksums.txt
curl -LO https://github.com/AzmxAI/maqpna-releases/releases/download/v0.1.0/checksums.txt.sigstore.json
cosign verify-blob checksums.txt --bundle checksums.txt.sigstore.json \
  --certificate-identity-regexp '^https://github\.com/AzmxAI/azmx-ai/\.github/workflows/maqpna-signed-release\.yml@refs/.+$' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com
sha256sum --ignore-missing --check checksums.txt

Build provenance and SBOMs

Archives and packages carry SLSA build provenance attestations generated by GitHub Actions. Check one with the GitHub CLI:

sh
gh attestation verify maqpna_0.1.0_linux_amd64.tar.gz --owner AzmxAI

Every archive has an SPDX 2.3 SBOM next to it (<archive>.spdx.json); container images carry their SBOM as a signed cosign attestation.

Container images

Multi-arch images (linux/amd64, linux/arm64) are published to ghcr.io/azmxai/maqpna. The runtime images are distroless and run as UID 65532.

ImagePlatformsDigest
ghcr.io/azmxai/maqpna/maqpna-operator:0.1.0linux/amd64, linux/arm645fe44700001a
ghcr.io/azmxai/maqpna/maqpna-gateway:0.1.0linux/amd64, linux/arm647ac0e3592ad7
ghcr.io/azmxai/maqpna/maqpna-identity:0.1.0linux/amd64, linux/arm646b6bf6dacb01
ghcr.io/azmxai/maqpna/maqpna-attest:0.1.0linux/amd64, linux/arm6453f35a46b6d5
ghcr.io/azmxai/maqpna/maqpna-attest-agent:0.1.0linux/amd64, linux/arm641fad4bb710a8
ghcr.io/azmxai/maqpna/maqpna-exec:0.1.0linux/amd64, linux/arm64b8b20fc9510d
ghcr.io/azmxai/maqpna/maqpna-egress-relay:0.1.0linux/amd64, linux/arm64bcf54db26d62
ghcr.io/azmxai/maqpna/maqpna-browser:0.1.0linux/amd64, linux/arm6434eac01d0969
ghcr.io/azmxai/maqpna/maqpna-code-interpreter:0.1.0linux/amd64, linux/arm64e6f3363be0b6
ghcr.io/azmxai/maqpna/maqpna-cli:0.1.0linux/amd64, linux/arm647965b5bb1de2
ghcr.io/azmxai/maqpna/mcp-echo:0.1.0linux/amd64, linux/arm64d34ee9b3d41e

Pin images by digest in production. Verify the signature and the SBOM attestation:

sh
cosign verify ghcr.io/azmxai/maqpna/maqpna-gateway:0.1.0 \
  --certificate-identity https://github.com/AzmxAI/maqpna/.github/workflows/release.yml@refs/tags/v0.1.0 \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com
cosign verify-attestation --type spdxjson ghcr.io/azmxai/maqpna/maqpna-gateway:0.1.0 \
  --certificate-identity https://github.com/AzmxAI/maqpna/.github/workflows/release.yml@refs/tags/v0.1.0 \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com

Helm chart

The chart is published as an OCI artifact. The values-sovereign-eu.yaml profile ships inside the chart.

sh
helm pull oci://ghcr.io/azmxai/maqpna/charts/maqpna --version 0.1.0 --untar
helm install maqpna ./maqpna \
  --namespace maqpna-system --create-namespace \
  --set image.registry=ghcr.io/azmxai/maqpna \
  -f maqpna/values-sovereign-eu.yaml

Platform guides: Azure AKS · Amazon EKS · Google GKE · OpenShift · k3s and kind. Air-gapped clusters: see air-gapped install.

macOS notes

Release builds of the macOS binaries are code-signed with an Apple Developer ID (hardened runtime) and the .zip archives are notarized by Apple. Homebrew, the install script and curl do not set the quarantine attribute in any case. If you have an unsigned build (for example a development snapshot) and macOS refuses to open a binary downloaded with a browser, verify the checksum and signature first, then clear the attribute:

macOS
xattr -d com.apple.quarantine ./maqpna
chmod +x ./maqpna

Older releases

v0.1.0 is the first release. Older versions will be listed here, and stay available on github.com/AzmxAI/maqpna-releases/releases and at https://dl.maqpna.com/<version>/….