Skip to content
kix /docs
Install the CLI

Reference CLI

compliance commands

Produce a CycloneDX SBOM, an unsigned SLSA provenance statement, or a full audit bundle from a cluster build.

kix compliance turns data Kix already has about a cluster build into formats auditors and compliance tools read. sbom and attest print one document to stdout; audit writes a directory of files. None of them changes the cluster.

This page is hand-maintained. Check cli/kix-cli/src/cli.rs and cli/kix-cli/src/commands/compliance/ when in doubt.

SubcommandOutput
sbom <CLUSTER>CycloneDX 1.6 Software Bill of Materials on stdout
attest <CLUSTER>Unsigned in-toto statement with a SLSA v1 provenance predicate on stdout
audit <CLUSTER>SARIF, SBOM, SLSA provenance, OSCAL assessment results, and a Markdown summary in a directory

sbom, attest (without --from-cluster), and audit build the cluster from the flake. See Global flags for --flake and --override-input. Only audit reads the eval cache, so --no-cache affects only audit.

kix compliance sbom <CLUSTER> [-o json|yaml]

The SBOM has a platform component for the cluster, one application component per package (pkg:kix/<namespace>/<name>@<version>), one container component per unique image, and one library component per flake input in flake.lock (pkg:nix/<name>@<rev>). Dependencies follow the packages’ cross-package references and image use. Output is JSON by default, YAML with -o yaml; text and markdown print JSON.

kix compliance attest <CLUSTER> [--builder-id <URI>] [--invocation-id <ID>]
[--from-cluster] [--context <CONTEXT>] [-o json|yaml]
Argument or flagMeaning
<CLUSTER>Cluster name.
--builder-id <URI>SLSA builder ID. In CI, pass the workflow run URL.
--invocation-id <ID>Invocation ID, such as the CI run ID.
--from-clusterRead the deploy receipt from the cluster’s active Activation instead of building. The statement then describes what was deployed, and the command works on a machine that never built the cluster. Needs cluster access.
--context <CONTEXT>Kubeconfig context for --from-cluster.

The statement’s subject is the activation identity hash. It records the flake reference, a digest of flake.lock, the Git commit and whether the working tree was dirty, every flake input, and every container image (with a sha256 digest only when the reference carries one). A build from a dirty tree prints a warning and marks the statement dirty. The statement is not signed. Output is JSON by default, YAML with -o yaml.

kix compliance audit <CLUSTER> [--out <DIR>] [--force]
[--framework soc2|iso27001|dora|nis2] [--builder-id <URI>]
Argument or flagMeaning
<CLUSTER>Cluster name.
--out <DIR>Output directory, created if missing. Default ./compliance.
--forceWrite into an existing output directory. Files with the same names are overwritten; other files are left in place. Without it, an existing directory is an error.
--framework <NAME>Framework whose controls the OSCAL assessment maps findings to: soc2 (default), iso27001, dora, or nis2.
--builder-id <URI>Builder ID for the SLSA provenance, as for attest.

The directory contains:

FileContent
scorecard-results.sarifScorecard findings as SARIF 2.1.0
sbom.jsonThe same SBOM as kix compliance sbom
provenance.jsonThe same statement as kix compliance attest
assessment-results.jsonOSCAL assessment results. A control is not-satisfied when an error-level scorecard finding matches one of the rules it requires.
audit-report.mdA Markdown summary suitable for a pull request comment
CodeMeaning
0The document or bundle was written
1Evaluation or build failed, the output directory exists without --force, or --from-cluster found no Activation or no receipt
❱ kix compliance sbom demo > sbom.json
❱ kix compliance attest demo --from-cluster --builder-id "$RUN_URL"
❱ kix compliance audit demo --framework iso27001 --out audit/