Skip to content
kix /docs
Install the CLI

How-to guide Policy, CI, and compliance

Override scorecard severity

Change how a scorecard rule is reported across a cluster or for selected workloads.

Use a severity override to promote a finding to an error or reduce it to a warning or informational result. Valid severities are error, warning, and info.

This guide assumes the target rule is in the active set. The built-in rules are, by default; a custom rule must be present under scorecard.rules.

A cluster caps every finding at scorecard.maxSeverity, which defaults to warning. An override above the cap is reported at the cap, so raising a rule to error only stops the build once the cap is error as well. See Fail the build on scorecard findings.

Use the full rule name under ruleOverrides.byRule:

cluster.nix
scorecard = {
maxSeverity = "error";
ruleOverrides.byRule."reliability.hasProbes".severity = "error";
};

Every reliability.hasProbes finding is now an error, so kix check, builds, and deploys stop when a workload lacks the required probes.

Use byNamespace when a policy should differ for part of the cluster:

cluster.nix
scorecard.ruleOverrides.byNamespace."kube-system" = {
"reliability.hasProbes".severity = "info";
};

Use byOwner to apply an override to packages whose meta.owner matches the given value:

cluster.nix
scorecard.ruleOverrides.byOwner."platform" = {
"reliability.hasProbes".severity = "error";
};

Namespace and owner keys, as well as rule names within them, may end with * to match a prefix. Keep exact names when you only need one exception.

Set a default for rules without a severity

Section titled “Set a default for rules without a severity”

ruleDefaults.severity applies only when a rule does not declare its own severity and no override matches:

cluster.nix
scorecard.ruleDefaults.severity = "warning";

Run the cluster checks and confirm that the finding has the intended severity:

kix-examples/
❱ kix check 19-scorecards
 TOOL       RESULT  DETAILS                      
 eval       pass    24 manifests evaluated       
 scorecard  pass    0 errors, 6 warnings, 2 info

If several overrides match, a direct byRule override wins. Owner overrides then take precedence over namespace overrides, followed by the rule’s declared severity and ruleDefaults. The cluster’s maxSeverity cap applies last.