The Cloudsmith CLI can now update itself, so you can upgrade quickly and get back to work. The CLI also authenticates Terraform to your Cloudsmith registries without storing a token, reads your workspace settings from a new --workspace option, and keeps single sign-on (SSO) sessions alive through temporary network failures.
Update the CLI with a single command
v1.28.0 adds cloudsmith update, along with a daily check that tells you when a new version is available.
To update the CLI to the latest released version, run:
cloudsmith update
cloudsmith upgrade is an alias for cloudsmith update.
The CLI detects how it was installed and acts accordingly:
- Standalone binary on Linux and macOS: The CLI downloads the latest release, verifies its SHA-256 checksum, and replaces itself in place.
- pip, pipx, uv, Homebrew, and Docker: The CLI prints the upgrade command for that install method, for example,
brew update && brew upgrade cloudsmith-cli or pipx upgrade cloudsmith-cli.
A standalone update asks for confirmation first. Pass -y or --yes to skip the prompt. If the update fails partway, including when you press Ctrl+C, the CLI restores the version you had.
Note: On Windows, a standalone binary can't replace itself because the running executable is locked. Instead, the command prints the archive URL and SHA-256 checksum so you can download and replace it manually.
Background update check
The CLI checks for a newer version at most once a day, in the background. When an update is available, it prints a short notice to stderr with the upgrade command for your install method and a link to the release notes. The check never fails your command and never delays it by more than a second.
The notice appears only in an interactive terminal. The CLI skips the check in CI (when the CI environment variable is set), and hides the notice for machine-readable output (-F json).
Disable the update check
Disable the daily background check using any of the following:
- Per command: Pass
--no-check-update before the command name, for example, cloudsmith --no-check-update whoami. - Environment variable: Set
CLOUDSMITH_NO_UPDATE_CHECK=true. - Config file: Set
check_for_update=false under [default] (or a profile) in config.ini.
Disabling the background check doesn't affect cloudsmith update, which always checks for a newer version when you run it.
For more details, see Updating in the Cloudsmith documentation.
v1.27.0 adds Terraform to the CLI's credential helpers, alongside Docker, Cargo, and pnpm.
Running cloudsmith credential-helper install terraform installs a terraform-credentials-cloudsmith helper and registers it in ~/.terraformrc.
After that, terraform init authenticates to your Cloudsmith registries, including custom domains, with the CLI's existing credentials. No token is stored in your Terraform configuration.
The helper uses the same profile and workspace you installed it with. For hosts other than Cloudsmith, Terraform falls back to its own credential sources.
To remove the helper, run cloudsmith credential-helper uninstall terraform.
For more details, see Authenticate Terraform with the Cloudsmith credential helper in the Cloudsmith documentation.
Set your workspace once
v1.27.0 adds -w/--workspace as an option for your Cloudsmith workspace, alongside --org. Authentication, OpenID Connect (OIDC), and custom domain discovery all read it. Set CLOUDSMITH_WORKSPACE in your environment, or workspace in config.ini, and every command uses it.
Existing scripts keep working: --org, --oidc-org, and CLOUDSMITH_ORG are still accepted.
Other improvements
cloudsmith auth reuses an existing SSO session when it can renew it, and SSO sessions no longer end unexpectedly after a temporary network failure (v1.27.0).cloudsmith auth reports when your access token expires, in both normal and JSON output (v1.27.0).- Security Assertion Markup Language (SAML) sign-in no longer fails when its default callback port is in use (v1.27.0).
- SAML two-factor codes stay visible as you type them (v1.27.0).
--color {auto,always,never} controls American National Standards Institute (ANSI) color output, and the CLI respects NO_COLOR, CLOUDSMITH_FORCE_COLOR, and TERM=dumb (v1.27.0).- A failed OIDC token exchange prints the workspace, service, API host, Cloudsmith OIDC vendor detector, and decoded token claims to help diagnose the failure, without printing the raw token (v1.27.0).
- The CLI no longer asks for a keyring password in CI or when no terminal is available (v1.28.0).
- Tables no longer wrap when CLI output is piped to a file or another command (v1.28.0).
For a more detailed list of changes, see the changelog on GitHub.