Skip to content
kix /docs
Install the CLI

How-to guide Operate a cluster

Export audit-preserving YAML

Export rendered manifests with Kix provenance annotations and deployment records intact.

Use the audit export mode when the exported manifests need to retain the Kix metadata that connects resources to packages, dependencies, and an activation. This export is intended as evidence or as input to an audit process.

Pass --for audit and choose an output directory:

kix-examples/
❱ kix export how-to-application --for audit --out ./audit-export
Building cluster 'how-to-application'...
  Evaluating cluster 'how-to-application'...
  Reading package index...
  Loading store graph...
  Reading 4 packages...
  Computing cross-package dependencies...

  Exported 17 resources to ./audit-export (audit (kix provenance preserved))

Kix evaluates and builds the cluster locally. The export includes every rendered resource, including Activation and PackageInstance custom resources, and preserves its kix.run/* annotations.

Search the exported files for Kix annotations:

kix-examples/ offline capture
❱ grep -rn 'kix.run/\(identity-hash\|depends-on\|package\)' ./audit-export/
Show outputHide output · 64 lines
./audit-export/how-to-app/ConfigMap-preview.yaml:8:    kix.run/depends-on: '8767b7nzgc1x5bpfa9gv71cpk9z8h0iw'
./audit-export/how-to-app/ConfigMap-preview.yaml:9:    kix.run/identity-hash: asa4ywz8yjjql7grm2rnm774q96ncs3m
./audit-export/how-to-app/ConfigMap-preview.yaml:10:    kix.run/package: preview
./audit-export/how-to-app/ConfigMap-preview.yaml:11:    kix.run/package-namespace: how-to-app
./audit-export/how-to-app/Service-preview.yaml:5:    kix.run/depends-on: '8767b7nzgc1x5bpfa9gv71cpk9z8h0iw,hd2br513fjyfgbl9sf97ank37hqzrmzl'
./audit-export/how-to-app/Service-preview.yaml:6:    kix.run/identity-hash: '91lbws8gjsbxfvr8p7kjx0dc7nzybhqs'
./audit-export/how-to-app/Service-preview.yaml:7:    kix.run/package: preview
./audit-export/how-to-app/Service-preview.yaml:8:    kix.run/package-namespace: how-to-app
./audit-export/how-to-app/Deployment-preview.yaml:5:    kix.run/depends-on: '8767b7nzgc1x5bpfa9gv71cpk9z8h0iw,asa4ywz8yjjql7grm2rnm774q96ncs3m'
./audit-export/how-to-app/Deployment-preview.yaml:6:    kix.run/identity-hash: hd2br513fjyfgbl9sf97ank37hqzrmzl
./audit-export/how-to-app/Deployment-preview.yaml:7:    kix.run/package: preview
./audit-export/how-to-app/Deployment-preview.yaml:8:    kix.run/package-namespace: how-to-app
./audit-export/how-to-app/PackageInstance-production.yaml:5:    kix.run/depends-on: '67bgr7ggiw82bhlc2c3ddxma573vpibj,8767b7nzgc1x5bpfa9gv71cpk9z8h0iw,cd3l507fvaf0wg5azfza49x6wjsiiynz,requires:pk4hih6jm4yj336rlaqk2qycz2k46xvs'
./audit-export/how-to-app/PackageInstance-production.yaml:6:    kix.run/identity-hash: avvdnz5yy5602xd1095ga9z40qbfkkwc
./audit-export/how-to-app/PackageInstance-production.yaml:8:    kix.run/package: _cluster
./audit-export/how-to-app/PackageInstance-production.yaml:9:    kix.run/package-namespace: _cluster
./audit-export/how-to-app/PackageInstance-preview.yaml:5:    kix.run/depends-on: '8767b7nzgc1x5bpfa9gv71cpk9z8h0iw,91lbws8gjsbxfvr8p7kjx0dc7nzybhqs,requires:pk4hih6jm4yj336rlaqk2qycz2k46xvs'
./audit-export/how-to-app/PackageInstance-preview.yaml:6:    kix.run/identity-hash: '84pfjn0kg74qqvp291b01dzd35ngql6z'
./audit-export/how-to-app/PackageInstance-preview.yaml:7:    kix.run/package: _cluster
./audit-export/how-to-app/PackageInstance-preview.yaml:8:    kix.run/package-namespace: _cluster
./audit-export/how-to-app/ConfigMap-production-health-script.yaml:28:    kix.run/depends-on: '8767b7nzgc1x5bpfa9gv71cpk9z8h0iw'
./audit-export/how-to-app/ConfigMap-production-health-script.yaml:29:    kix.run/identity-hash: dlzbv1nahmar8f7b9jm6rmyvmqczmzdb
./audit-export/how-to-app/ConfigMap-production-health-script.yaml:30:    kix.run/package: production
./audit-export/how-to-app/ConfigMap-production-health-script.yaml:31:    kix.run/package-namespace: how-to-app
./audit-export/how-to-app/ConfigMap-production.yaml:8:    kix.run/depends-on: '8767b7nzgc1x5bpfa9gv71cpk9z8h0iw'
./audit-export/how-to-app/ConfigMap-production.yaml:9:    kix.run/identity-hash: '4x75h2z7rsj3dvrdg9vzqc8l789xvm4w'
./audit-export/how-to-app/ConfigMap-production.yaml:10:    kix.run/package: production
./audit-export/how-to-app/ConfigMap-production.yaml:11:    kix.run/package-namespace: how-to-app
./audit-export/how-to-app/Job-production-health.yaml:5:    kix.run/depends-on: '8767b7nzgc1x5bpfa9gv71cpk9z8h0iw,cd3l507fvaf0wg5azfza49x6wjsiiynz,dlzbv1nahmar8f7b9jm6rmyvmqczmzdb,requires:jh345cnnffy1bnj4cz5x0hwq6ibxvkkr'
./audit-export/how-to-app/Job-production-health.yaml:6:    kix.run/identity-hash: '67bgr7ggiw82bhlc2c3ddxma573vpibj'
./audit-export/how-to-app/Job-production-health.yaml:7:    kix.run/package: production
./audit-export/how-to-app/Job-production-health.yaml:8:    kix.run/package-namespace: how-to-app
./audit-export/how-to-app/Service-production.yaml:5:    kix.run/depends-on: '8767b7nzgc1x5bpfa9gv71cpk9z8h0iw,kr7i34wz1ja58c0vf9gizx8161ji0idk'
./audit-export/how-to-app/Service-production.yaml:6:    kix.run/identity-hash: cd3l507fvaf0wg5azfza49x6wjsiiynz
./audit-export/how-to-app/Service-production.yaml:7:    kix.run/package: production
./audit-export/how-to-app/Service-production.yaml:8:    kix.run/package-namespace: how-to-app
./audit-export/how-to-app/Deployment-production.yaml:5:    kix.run/depends-on: '4x75h2z7rsj3dvrdg9vzqc8l789xvm4w,8767b7nzgc1x5bpfa9gv71cpk9z8h0iw'
./audit-export/how-to-app/Deployment-production.yaml:6:    kix.run/identity-hash: kr7i34wz1ja58c0vf9gizx8161ji0idk
./audit-export/how-to-app/Deployment-production.yaml:7:    kix.run/package: production
./audit-export/how-to-app/Deployment-production.yaml:8:    kix.run/package-namespace: how-to-app
./audit-export/kube-system/PackageInstance-platform-dns.yaml:5:    kix.run/depends-on: sj0fv5bs2hnh9zcqdh62ph34l2wm0b1m,requires:pk4hih6jm4yj336rlaqk2qycz2k46xvs
./audit-export/kube-system/PackageInstance-platform-dns.yaml:6:    kix.run/identity-hash: jh345cnnffy1bnj4cz5x0hwq6ibxvkkr
./audit-export/kube-system/PackageInstance-platform-dns.yaml:12:    kix.run/package: _cluster
./audit-export/kube-system/PackageInstance-platform-dns.yaml:13:    kix.run/package-namespace: _cluster
./audit-export/kube-system/PackageInstance-platform-storage.yaml:5:    kix.run/depends-on: sj0fv5bs2hnh9zcqdh62ph34l2wm0b1m,requires:pk4hih6jm4yj336rlaqk2qycz2k46xvs
./audit-export/kube-system/PackageInstance-platform-storage.yaml:6:    kix.run/identity-hash: r5sgwjk8w3m41l0xaj0s16xxsacd0nk6
./audit-export/kube-system/PackageInstance-platform-storage.yaml:11:    kix.run/package: _cluster
./audit-export/kube-system/PackageInstance-platform-storage.yaml:12:    kix.run/package-namespace: _cluster
./audit-export/_cluster/Activation-how-to-application-pwzvpn447s7d.yaml:6:    kix.run/depends-on: '84pfjn0kg74qqvp291b01dzd35ngql6z,avvdnz5yy5602xd1095ga9z40qbfkkwc,jh345cnnffy1bnj4cz5x0hwq6ibxvkkr,r5sgwjk8w3m41l0xaj0s16xxsacd0nk6,requires:gvrlspcfgh9a2qnsx5kqxw9f4l3x52jj'
./audit-export/_cluster/Activation-how-to-application-pwzvpn447s7d.yaml:7:    kix.run/identity-hash: pwzvpn447s7diyf7rkm62qxws9j7fb3b
./audit-export/_cluster/Activation-how-to-application-pwzvpn447s7d.yaml:8:    kix.run/package: _cluster
./audit-export/_cluster/Activation-how-to-application-pwzvpn447s7d.yaml:9:    kix.run/package-namespace: _cluster
./audit-export/_cluster/Namespace-how-to-app.yaml:5:    kix.run/identity-hash: '8767b7nzgc1x5bpfa9gv71cpk9z8h0iw'
./audit-export/_cluster/Namespace-how-to-app.yaml:6:    kix.run/package: _cluster
./audit-export/_cluster/Namespace-how-to-app.yaml:7:    kix.run/package-namespace: _cluster
./audit-export/_cluster/CustomResourceDefinition-packageinstances.kix.run.yaml:5:    kix.run/identity-hash: pk4hih6jm4yj336rlaqk2qycz2k46xvs
./audit-export/_cluster/CustomResourceDefinition-packageinstances.kix.run.yaml:6:    kix.run/package: _cluster
./audit-export/_cluster/CustomResourceDefinition-packageinstances.kix.run.yaml:7:    kix.run/package-namespace: _cluster
./audit-export/_cluster/CustomResourceDefinition-activations.kix.run.yaml:5:    kix.run/identity-hash: gvrlspcfgh9a2qnsx5kqxw9f4l3x52jj
./audit-export/_cluster/CustomResourceDefinition-activations.kix.run.yaml:6:    kix.run/package: _cluster
./audit-export/_cluster/CustomResourceDefinition-activations.kix.run.yaml:7:    kix.run/package-namespace: _cluster
./audit-export/_cluster/Namespace-kube-system.yaml:5:    kix.run/identity-hash: sj0fv5bs2hnh9zcqdh62ph34l2wm0b1m
./audit-export/_cluster/Namespace-kube-system.yaml:6:    kix.run/package: _cluster
./audit-export/_cluster/Namespace-kube-system.yaml:7:    kix.run/package-namespace: _cluster

The annotations record resource identity, package membership, and dependency edges. The Activation resource provides the root of the rendered deployment graph.

You can also inspect the internal records directly:

kix-examples/
❱ find ./audit-export -name 'Activation-*.yaml' -o -name 'PackageInstance-*.yaml'
./audit-export/how-to-app/PackageInstance-production.yaml
./audit-export/how-to-app/PackageInstance-preview.yaml
./audit-export/kube-system/PackageInstance-platform-dns.yaml
./audit-export/kube-system/PackageInstance-platform-storage.yaml
./audit-export/_cluster/Activation-how-to-application-pwzvpn447s7d.yaml

Do not use the audit export when another deployment system needs ordinary application manifests. Its internal custom resources and Kix annotations are part of the evidence being preserved.

Use the default mode for that workflow:

kix-examples/
❱ kix export how-to-application --out ./handoff