Skip to content
kix /docs
Install the CLI

How-to guide Policy, CI, and compliance

Fail the build on scorecard findings

Raise the scorecard severity cap so an error-severity finding stops kix check, builds, and deploys.

The scorecard runs on every cluster by default, and every finding is capped at scorecard.maxSeverity. The default cap is warning: kix check prints what the rules found, and the cluster still builds. Raise the cap to error when a finding from an error-severity rule should stop the build.

This guide assumes the cluster is defined with kix.buildCluster.

Set the option in the cluster definition:

cluster.nix
scorecard.maxSeverity = "error";

Rules that declare severity = "error", and rules raised to it through ruleOverrides, now produce failed assertions. Kix collects the failed assertions and stops the cluster evaluation. Warnings and informational findings are unaffected.

Put the setting in clusterModules so each cluster starts from it:

flake.nix
outputs = inputs: inputs.kixpkgs.lib.mkFlake {
inherit inputs;
clusters.production = ./clusters/production.nix;
clusterModules = [ { scorecard.maxSeverity = "error"; } ];
};

A cluster that needs the default back sets scorecard.maxSeverity = lib.mkForce "warning" in its own modules.

Run the cluster checks:

infrastructure/
❱ kix check production

With the cap raised, an error-severity finding ends the run with a failed assertion that names the rule and the resource. Fix the resource, disable the rule for that package, or lower the rule’s severity with an override.