How-to guide Policy, CI, and compliance
Fail the build on scorecard findings
Raise the scorecard severity cap so an error-severity finding stops kix check, builds, and deploys.
The scorecard runs on every cluster by default, and every finding is capped at
scorecard.maxSeverity. The default cap is warning: kix check prints what
the rules found, and the cluster still builds. Raise the cap to error when a
finding from an error-severity rule should stop the build.
This guide assumes the cluster is defined with kix.buildCluster.
Raise the cap on one cluster
Section titled “Raise the cap on one cluster”Set the option in the cluster definition:
scorecard.maxSeverity = "error";Rules that declare severity = "error", and rules raised to it through
ruleOverrides, now produce failed assertions. Kix collects the failed
assertions and stops the cluster evaluation. Warnings and informational
findings are unaffected.
Raise the cap on every cluster in a flake
Section titled “Raise the cap on every cluster in a flake”Put the setting in clusterModules so each cluster starts from it:
outputs = inputs: inputs.kixpkgs.lib.mkFlake { inherit inputs; clusters.production = ./clusters/production.nix; clusterModules = [ { scorecard.maxSeverity = "error"; } ];};A cluster that needs the default back sets scorecard.maxSeverity = lib.mkForce "warning" in its own modules.
Check the result
Section titled “Check the result”Run the cluster checks:
❱ kix check production With the cap raised, an error-severity finding ends the run with a failed assertion that names the rule and the resource. Fix the resource, disable the rule for that package, or lower the rule’s severity with an override.