Reference Scorecard
Built-in governance rules
The built-in checks for package ownership, descriptions, and standard workload labels.
The governance rule set lives in kix.rules.governance.
| Rule | Level | Declared severity | What it checks |
|---|---|---|---|
governance.hasOwner | package | warning | meta.owner is not null. |
governance.hasDescription | package | info | meta.description is present and not an empty string. |
governance.labelStandards | manifest | info | A Deployment, StatefulSet, or DaemonSet has app.kubernetes.io/name and app.kubernetes.io/managed-by in metadata.labels. |
labelStandards checks workload metadata, not the pod-template labels. Scope
workload builders add the managed-by label and the standard application name;
raw or imported manifests may need them supplied explicitly.
The table shows declared severities before scorecard.maxSeverity is applied.
See Override scorecard severity
to change one rule for a cluster, owner, or namespace.