Advanced Functionalities
Bulk certificate operations with HCQL queries and metadata updates using the Horizon Client.
This page covers advanced horizon-cli capabilities: bulk operations for managing certificates at scale, and metadata updates for individual certificates.
Bulk Operations
The horizon-cli bulk commands allow mass operations on certificates matched by a Horizon Certificate Query Language (HCQL) query. All bulk commands prompt for confirmation before proceeding unless --confirm is passed.
Bulk update
Update metadata across many certificates at once.
horizon-cli bulk update \
--query 'module equals "est" and status is valid' \
--owner "myuser" \
--team "myteam" \
--labels "mylabel:myvalue" \
--contact-email "unset"Use the value "unset" to clear an existing field.
| Parameter | Description |
|---|---|
--query | HCQL query. The update applies to all matching certificates. |
--confirm | Skip the confirmation prompt. |
--owner | Owner to set. Optional. |
--team | Team to set. Optional. |
--labels | Labels in key:value form, comma-separated. Optional. |
--contact-email | Contact email to set. Optional. |
Bulk migrate
Migrate certificates from one profile to another, optionally updating metadata in the same operation.
horizon-cli bulk migrate \
--query 'module equals "est" and status is valid' \
--profile new-est-profile \
--team myteam \
--labels "mylabel:myvalue"Use "unset" to clear a field during migration.
| Parameter | Description |
|---|---|
--query | HCQL query. The migration applies to all matching certificates. |
--confirm | Skip the confirmation prompt. |
--profile | Target profile for the migration. Required. |
--owner | Owner to set. Optional. |
--team | Team to set. Optional. |
--labels | Labels in key:value form, comma-separated. Optional. |
--contact-email | Contact email to set. Optional. |
Bulk revoke
Revoke all certificates matching a query.
horizon-cli bulk revoke \
--query 'team equals "myterminatedteam" and status is valid' \
--confirm| Parameter | Description |
|---|---|
--query | HCQL query. Revocation applies to all matching certificates. |
--confirm | Skip the confirmation prompt. Recommended for automated pipelines. |
Writing HCQL queries
HCQL field names are always lowercase. Common fields:
| Field | Example |
|---|---|
status | status is valid |
module | module equals "est" |
team | team equals "myteam" |
owner | owner equals "myuser" |
valid.until | valid.until before "2025-01-01" |
For full HCQL syntax, see the Horizon documentation or use horizon-cli translate-to-hql --help.
Updating a Certificate
The horizon-cli update-cert command modifies the metadata associated with a certificate in Horizon - owner, team, contact email, labels, and technical metadata. It does not change the certificate itself.
Requirements
To update a local certificate (one stored on the machine running the client), the profile it belongs to must have the Update (pop) common configuration permission enabled.
To update a certificate referenced on Horizon by ID, the client's API account must have update permissions on that certificate.
Usage
Interactive mode
horizon-cli update-cert --cert=/path/to/cert --key=/path/to/key --promptIn --prompt mode, you are asked for each field. Press Enter to keep an existing value unchanged.
Non-interactive mode
Pass updated values directly. Set a field to an empty string ("") to delete it.
# Update the owner of a local certificate
horizon-cli update-cert --cert=/path/to/cert --key=/path/to/key --owner=newowner
# Remove the team from a certificate in a JKS keystore
horizon-cli update-cert --cert=/path/to/cert.jks --jks-pwd=<password> --team=""
# Update labels and metadata for a certificate in the Windows store
horizon-cli update-cert --cert=<thumbprint> \
--labels="label1:value1,label2:value2" \
--metadata="metadata1:value1,metadata2:value2"
# Update the contact email of a certificate referenced on Horizon by ID
horizon-cli update-cert --id=<certificate-id> --contact-email="[email protected]"Parameter reference
General parameters
| Parameter | Description |
|---|---|
--confirm | Skip the confirmation prompt after changes are computed. |
--prompt | Prompt for all fields interactively. |
Update parameters
| Parameter | Description |
|---|---|
--owner | New owner. Use "" to delete. |
--team | New team. Use "" to delete. |
--contact-email | New contact email. Use "" to delete. |
--labels | Labels in key:value form, comma-separated. Use "" to delete. |
--metadata | Technical metadata in key:value form. Use "" to delete. |
Local certificate selection
| Parameter | Description |
|---|---|
--cert | Path to the certificate (PEM, PKCS#12, JKS) or Windows store thumbprint. |
--key | Path to the private key (PEM only). |
--pfx-pwd | PKCS#12 password. |
--jks-pwd | JKS password. |
--jks-alias | JKS alias. |
--jks-alias-pwd | JKS alias password. |
Remote certificate selection
| Parameter | Description |
|---|---|
--id | Certificate ID on the Horizon server. |