Skip to content
kix /docs
Install the CLI

Reference Scorecard

Finding schema

The fields in each scorecard finding and the summary stored with a cluster build.

An enabled scorecard produces a report with findings and summary:

{
"findings": [
{
"rule": "reliability.hasProbes",
"severity": "warning",
"level": "manifest",
"namespace": "apps",
"instance": "web",
"resource": "web",
"message": "container 'web' has no livenessProbe",
"tags": ["reliability", "observability"]
}
],
"summary": {
"total": 1,
"errors": 0,
"warnings": 1,
"info": 0,
"byNamespace": { "apps": 1 },
"byRule": { "reliability.hasProbes": 1 }
}
}
FieldTypeMeaning
rulestringFull <category>.<rule> name.
severityinfo, warning, or errorEffective severity after defaults, overrides, and maxSeverity.
levelmanifest, package, namespace, or clusterEvaluation level of the rule.
namespacestring or nullAffected namespace when the rule has one.
instancestring or nullAffected package instance for manifest and package rules.
resourcestring or nullResource name for manifest rules, or an identity supplied by a cluster rule.
messagestringRule result. Defaults to check failed when the rule omits it.
tagslist of stringsTags copied from the rule definition.

Summary counts use the effective severity. byNamespace groups a null namespace under unknown; byRule uses the full rule name.

The activation build contains this report as kix-scorecard.json. kix check uses it for the scorecard row and converts its findings to SARIF with --sarif. When an error-severity finding fails evaluation, no build report is produced; kix check --sarif converts the evaluation failure into one SARIF error result instead.