Skip to content
kix /docs
Install the CLI

How-to guide Policy, CI, and compliance

Generate SLSA provenance

Create an unsigned SLSA provenance statement for a rendered cluster.

Use kix compliance attest to describe the cluster build as an in-toto Statement with a SLSA v1 provenance predicate. The command evaluates the cluster locally and writes the unsigned statement to stdout.

In CI, identify the builder with the workflow URL and record the run ID:

kix-examples/
❱ kix compliance attest 19-scorecards --builder-id "$BUILD_URL" --invocation-id "$BUILD_ID" > provenance.json

This captured excerpt uses fixed example identifiers so you can see the main fields:

kix-examples/ output excerpt offline capture
❱ kix compliance attest 19-scorecards --builder-id https://ci.example/runs/1842 --invocation-id 1842
Show outputHide output · 54 lines
{
  "_type": "https://in-toto.io/Statement/v1",
  "predicateType": "https://slsa.dev/provenance/v1",
  "subject": [
    {
      "digest": {
        "nixStoreHash": "03lwg2rc2h1m1x5y1fx5nnq8m0saj5pi"
      },
      "name": "cluster-19-scorecards-activation"
    }
  ],
  "predicate": {
    "buildDefinition": {
      "buildType": "https://kix.run/build/v1",
      "externalParameters": {
        "cluster": "19-scorecards",
        "flakeLock": "blake3:8ef54ccce598d282f28fc5a8d2cd4d49842c921b810bdc93ce635335f1fc2836",
        "flakeRef": "kix-examples"
      },
      "resolvedDependencies": [
        {
          "digest": {
            "gitCommit": "7cf72d978629469c4bd4206b95c402514c1f6000",
            "narHash": "sha256-SPm9ck7jh3Un9nwPuMGbRU04UroFmOHjLP56T10MOeM="
          },
          "uri": "flake-input:crane"
        },
        {
          "digest": {
            "gitCommit": "9dcf5b3e33b728ef3fc76a693e4feda2921b1913",
            "narHash": "sha256-aXiQ4IWL2o/X4k1ZMLapbHKxLdaYDNyBi6qvaigDXLo="
          },
          "uri": "flake-input:kixpkgs"
        }
      ]
    },
    "runDetails": {
      "builder": {
        "id": "https://ci.example/runs/1842"
      },
      "metadata": {
        "finishedOn": "2026-10-08T10:55:57Z",
        "invocationId": "1842",
        "startedOn": "2026-10-08T10:55:57Z"
      }
    }
  }
}
Building cluster '19-scorecards'...
  Evaluating cluster '19-scorecards'...
  Reading package index...
  Loading store graph...
  Reading 6 packages...
  Computing cross-package dependencies...

The Activation identity hash is the statement’s subject. The build definition also records the cluster name, flake reference, lock-file digest, Git source, locked flake inputs, and rendered container images.

Check the statement and predicate types before passing the file to a signing or evidence-upload step:

kix-examples/
❱ jq -e '._type == "https://in-toto.io/Statement/v1" and .predicateType == "https://slsa.dev/provenance/v1"' provenance.json

If the working tree is dirty, Kix records that state and prints a warning. The statement remains an honest description of the build, but its Git commit does not contain every input that was evaluated.