Skip to content
kix /docs
Install the CLI

Reference CLI

check

Evaluate a cluster, report each validation step as pass, fail, or skip, and optionally write scorecard findings as SARIF.

kix check evaluates a cluster and reports the result of each validation step in a table. It does not contact a cluster. Use it as the local and CI gate before a deploy.

This page is hand-maintained. Check cli/kix-cli/src/cli.rs and cli/kix-cli/src/commands/check.rs when in doubt.

kix check <CLUSTER> [--sarif] [-o text|json|yaml] [--flake <FLAKE>]
[--override-input <INPUT> <URL>]... [--no-cache]
Argument or flagDefaultMeaning
<CLUSTER>Cluster name to evaluate.
--sarifOffPrint SARIF 2.1.0 JSON instead of the table. Overrides -o.
-o, --outputtexttext prints a TOOL, RESULT, DETAILS table. json and yaml print an array of { tool, result, details }.
--flake <FLAKE>.Flake to evaluate.
--override-input <INPUT> <URL>NoneOverride a flake input for the evaluation. Repeatable.
--no-cacheOffEvaluate from Nix instead of reading the eval cache.
ToolWhat it reports
evalpass with the number of manifests, or fail with the evaluation error. Evaluation runs the constructor validators, the cross-resource checks, and every error-severity scorecard rule, so a failure in any of them appears here.
scorecardThe counts of error, warning, and info findings. fail when there is at least one error, skip when the cluster does not enable the scorecard.

When eval fails, the scorecard step does not run.

kix check does not validate the rendered manifests against Kubernetes schemas or check them for deprecated API versions. Schema validation runs in nix flake check: a flake built with mkFlake exports a schema-cluster-<name> check per cluster that runs kubeconform -strict over the rendered manifests and skips kinds with no published schema.

With --sarif, each scorecard finding becomes a SARIF result with its rule ID, level (error, warning, or note), message, and a logical location of the form namespace/instance/resource. A cluster with no findings, or with the scorecard disabled, produces an empty run.

An error-severity finding stops evaluation, so there is no report to convert. Kix then writes the evaluation failure as one error result. Its rule ID is scorecard/<rule> when the error message names a scorecard rule, and kix/eval-failure otherwise.

❱ kix check demo
❱ kix check demo --sarif > kix-results.sarif
CodeMeaning
0No step reported fail
1A step reported fail, or the cluster was not found. The same with --sarif, after the SARIF document is printed.