Reference Scorecard
Built-in reliability rules
The built-in checks for resource bounds, probes, graceful shutdown, and valid volume sources.
The reliability rule set lives in kix.rules.reliability. Its manifest rules
apply to Deployments, StatefulSets, and DaemonSets.
| Rule | Declared severity | What it checks |
|---|---|---|
reliability.boundedResources | warning | Every regular and init container has CPU and memory under both resources.requests and resources.limits. |
reliability.hasResourceLimits | warning | Every regular and init container has a resources.limits attribute. |
reliability.hasResourceRequests | warning | Every regular and init container has a resources.requests attribute. |
reliability.hasProbes | warning | Every regular container has both livenessProbe and readinessProbe. Init containers are not checked. |
reliability.gracefulShutdown | info | terminationGracePeriodSeconds is present and not zero. |
reliability.volumeHasSource | error | Every rendered pod volume has a source. |
boundedResources checks the four individual CPU and memory fields.
hasResourceLimits and hasResourceRequests check only that their containing
attributes exist, so the bounded rule is the stricter policy.
volumeHasSource
Section titled “volumeHasSource”A volume with a name and no source is rejected by the Kubernetes API server. The rule normalizes each volume as the renderer will before inspecting it. This catches a less obvious case: a helper builds a source from optional arguments, every argument is null, and normalization removes the empty wrapper.
Write a literal empty attribute set for a source whose empty form has meaning:
volumes = [ { name = "tmp"; emptyDir = { }; }];When a constructor’s result must remain present even if all of its members
are null, wrap it in kix.keep.