Reference Cluster module
scorecard
Configure build-time policy rules, severity overrides, and the threshold that turns findings into failed assertions.
The scorecard evaluates policy rules while Kix builds a cluster. It scores the resources that ship, including resources derived by compiler plugins such as PodDisruptionBudgets and network policies.
scorecard = { enable = true; maxSeverity = "error"; ruleOverrides.byRule."reliability.hasProbes".severity = "error";};Options
Section titled “Options”| Field | Type | Default | Meaning |
|---|---|---|---|
enable | boolean | true | Run the scorecard. When false, no report or scorecard diagnostics are produced. |
rules | nested attribute set | kix.rules | Complete active rule set, grouped by category. Setting this field replaces the built-in set. |
maxSeverity | info, warning, or error | warning | Highest severity any finding may retain after defaults and overrides. |
ruleDefaults | attribute set | { } | Defaults for rules that omit a field. Currently supports severity. |
ruleOverrides | attribute set | { } | Per-rule, owner, and namespace overrides. |
knownAnnotationDomains | list of strings | [ ] | External annotation domains accepted by architecture.annotationDomainOwnership. |
Severity cap
Section titled “Severity cap”Every finding is lowered to maxSeverity when its resolved severity is
higher. With the default warning cap, a rule declared as error reports a
warning and the cluster still builds. Set the cap to error to turn
error-severity findings into failed assertions.
Kix collects failed scorecard assertions with other build assertions and
reports them together. An evaluation that fails this way does not produce a
scorecard report for kix check; the command reports the assertion failure in
its eval step.
Replacing the rule set
Section titled “Replacing the rule set”scorecard.rules defaults to all categories under kix.rules. Assigning it
does not add to that default. Name every category you want active:
scorecard.rules = { inherit (kix.rules) reliability security; organization = myRules;};Use ruleOverrides.byRule.<name>.enabled = false when you want to disable one
rule without replacing its category.
See Rule schema for custom rules and Severity override schema for matching and precedence.