How-to guide Policy, CI, and compliance
Generate a CycloneDX SBOM
Create a CycloneDX inventory of a cluster's packages, container images, and flake inputs.
Use kix compliance sbom to produce a CycloneDX 1.6 software bill of
materials from a rendered cluster. The command evaluates the cluster locally
and does not need Kubernetes access.
Generate the SBOM
Section titled “Generate the SBOM”Pass the cluster name and redirect stdout to a file:
❱ kix compliance sbom 19-scorecards > sbom.json The output is JSON by default. This captured excerpt shows the document type, cluster component, component counts, and dependency count:
❱ kix compliance sbom 19-scorecards Show outputHide output · 44 lines
{
"bomFormat": "CycloneDX",
"specVersion": "1.6",
"metadata": {
"component": {
"bom-ref": "cluster-19-scorecards",
"description": "kix cluster 19-scorecards",
"name": "cluster-19-scorecards",
"properties": [
{
"name": "kix:activation-hash",
"value": "03lwg2rc2h1m1x5y1fx5nnq8m0saj5pi"
},
{
"name": "kix:flake-ref",
"value": "kix-examples"
}
],
"type": "platform",
"version": "activation-03lwg2rc2h1m1x5y1fx5nnq8m0saj5pi"
}
},
"componentTypes": [
{
"type": "application",
"count": 6
},
{
"type": "container",
"count": 2
},
{
"type": "library",
"count": 3
}
],
"dependencyCount": 7
}
Building cluster '19-scorecards'...
Evaluating cluster '19-scorecards'...
Reading package index...
Loading store graph...
Reading 6 packages...
Computing cross-package dependencies... The complete file contains:
- One
platformcomponent for the cluster. - One
applicationcomponent for each package instance. - One deduplicated
containercomponent for each image reference. - One
librarycomponent for each locked flake input. - Dependency edges between the cluster, packages, images, and inputs.
An image component includes a SHA-256 hash when its rendered reference has an
@sha256: digest.
Verify the file
Section titled “Verify the file”Check that the command produced a CycloneDX 1.6 document:
❱ jq -e '.bomFormat == "CycloneDX" and .specVersion == "1.6"' sbom.json The capture pipeline runs this same assertion on every regeneration, so a change to the emitted CycloneDX version fails the docs build rather than reaching you as a surprise.
Use --output yaml if the receiving system expects YAML:
❱ kix --output yaml compliance sbom 19-scorecards > sbom.yaml