Skip to content
kix /docs
Install the CLI

Reference Scorecard

Rule schema

The fields, evaluation levels, contexts, and finding shape of a scorecard rule.

Rules are grouped by category under scorecard.rules. Their full name is <category>.<attribute>:

scorecard.rules.organization.requiresOwner = {
description = "Packages must declare an owner";
level = "package";
severity = "warning";
tags = [ "governance" ];
appliesTo = { meta, ... }: (meta.deprecated or null) == null;
check = { meta, ... }:
if (meta.owner or null) == null then
[ { message = "package has no owner"; } ]
else
[ ];
};
FieldRequiredMeaning
descriptionnoHuman-readable rule description used by reference and reporting tools.
levelyesmanifest, package, namespace, or cluster. An unknown or missing value is an evaluation error.
severitynoinfo, warning, or error. Falls back to scorecard.ruleDefaults.severity, then warning.
tagsnoList copied to every finding. Default [ ].
appliesTonoFunction from the level context to a boolean. The rule is skipped when it returns false.
checkyesFunction from the level context to a list of finding records. Return [ ] when the input passes.

A finding record normally sets message. When omitted, Kix uses check failed. Cluster-level findings may also set namespace and resource to identify an affected manifest.

LevelMain context fieldsFinding location supplied by Kix
manifestresource, meta, instanceName, namespaceNamenamespace, instance, and resource name
packageresources, parts, config, meta, instanceName, namespaceNamenamespace and instance
namespaceinstances, resources, namespaceName, networkPolicyKindsnamespace
clusterallInstances, allResources, clusterConfig, externalNamesnone, unless the finding supplies namespace and resource

Package context also includes the annotation-domain and resolved-dependency indexes used by built-in architecture rules. These are compiler-facing data; custom package rules usually need only the fields in the table.

resources at package level includes the package’s shipped resources, not just the objects written directly in its build function. This lets a rule see derived resources associated with the instance.

The effective severity is resolved before appliesTo or check runs. A disabled rule therefore calls neither function.