Currently covenant signer only exposes HTTP endpoints to lock and unlock keyring. Given that those commands are designated for program operators, there should be cli commands to accomplish those operations.