Skip to main content

Synopsis

Assert the compliance status of an artifact in Kosli. There are three ways to choose what to assert against:
  1. Against an environment. When --environment is specified, asserts against all policies currently attached to the given environment.
  2. Against one or more policies. When --policy is specified, asserts against all the given policies.
  3. Against flow templates. When neither --environment nor --policy is specified, asserts against the template files of the flows the artifact is found in.
--environment and --policy are mutually exclusive. --flow can be combined with any of the above to narrow the lookup to a specific flow. Without --flow, all flows containing the artifact (by fingerprint) are considered. Exits with zero code if the artifact has compliant status, non-zero code if non-compliant status. To specify paths in a directory artifact that should always be excluded from the SHA256 calculation, you can add a .kosli_ignore file to the root of the artifact. Each line should specify a relative path or path glob to be ignored. You can include comments in this file, using #. The .kosli_ignore file is always treated as part of the artifact: its own entries cannot exclude it, so the exclusion list cannot be changed without changing the fingerprint. Paths the list already matches stay excluded whatever is later added there, so keep its entries as narrow as possible. Excluding the file with --exclude keeps it out of the fingerprint but still applies the paths it lists, which lets a writable directory change the list again. To drop the file from the fingerprint safely, move its entries to --exclude and delete it.

Flags

Flags inherited from parent commands

Live Examples in different CI systems

View an example of the kosli assert artifact command in GitHub.In this YAML file

Examples Use Cases

These examples all assume that the flags --api-token, --org, --host, (and --flow, --trail when required), are set/provided.
Last modified on September 11, 2026