Reference CLI
check
Evaluate a cluster, report each validation step as pass, fail, or skip, and optionally write scorecard findings as SARIF.
kix check evaluates a cluster and reports the result of each validation step
in a table. It does not contact a cluster. Use it as the local and CI gate
before a deploy.
This page is hand-maintained. Check cli/kix-cli/src/cli.rs and
cli/kix-cli/src/commands/check.rs when in doubt.
Synopsis
Section titled “Synopsis”kix check <CLUSTER> [--sarif] [-o text|json|yaml] [--flake <FLAKE>] [--override-input <INPUT> <URL>]... [--no-cache]| Argument or flag | Default | Meaning |
|---|---|---|
<CLUSTER> | Cluster name to evaluate. | |
--sarif | Off | Print SARIF 2.1.0 JSON instead of the table. Overrides -o. |
-o, --output | text | text prints a TOOL, RESULT, DETAILS table. json and yaml print an array of { tool, result, details }. |
--flake <FLAKE> | . | Flake to evaluate. |
--override-input <INPUT> <URL> | None | Override a flake input for the evaluation. Repeatable. |
--no-cache | Off | Evaluate from Nix instead of reading the eval cache. |
| Tool | What it reports |
|---|---|
eval | pass with the number of manifests, or fail with the evaluation error. Evaluation runs the constructor validators, the cross-resource checks, and every error-severity scorecard rule, so a failure in any of them appears here. |
scorecard | The counts of error, warning, and info findings. fail when there is at least one error, skip when the cluster does not enable the scorecard. |
When eval fails, the scorecard step does not run.
kix check does not validate the rendered manifests against Kubernetes
schemas or check them for deprecated API versions. Schema validation runs in
nix flake check: a flake built with mkFlake exports a
schema-cluster-<name> check per cluster that runs kubeconform -strict over
the rendered manifests and skips kinds with no published schema.
SARIF output
Section titled “SARIF output”With --sarif, each scorecard finding becomes a SARIF result with its rule
ID, level (error, warning, or note), message, and a logical location of
the form namespace/instance/resource. A cluster with no findings, or with
the scorecard disabled, produces an empty run.
An error-severity finding stops evaluation, so there is no report to convert.
Kix then writes the evaluation failure as one error result. Its rule ID is
scorecard/<rule> when the error message names a scorecard rule, and
kix/eval-failure otherwise.
Examples
Section titled “Examples”❱ kix check demo❱ kix check demo --sarif > kix-results.sarif Exit status
Section titled “Exit status”| Code | Meaning |
|---|---|
0 | No step reported fail |
1 | A step reported fail, or the cluster was not found. The same with --sarif, after the SARIF document is printed. |