Synopsis
- Against an environment. When
--environmentis specified, asserts against all policies currently attached to the given environment. - Against one or more policies. When
--policyis specified, asserts against all the given policies. - Against flow templates. When neither
--environmentnor--policyis specified, asserts against the template files of the flows the artifact is found in.
--environment and --policy are mutually exclusive.
--flow can be combined with any of the above to narrow the lookup
to a specific flow. Without --flow, all flows containing the artifact
(by fingerprint) are considered.
Exits with zero code if the artifact has compliant status,
non-zero code if non-compliant status.
To specify paths in a directory artifact that should always be excluded from the SHA256 calculation, you can add a .kosli_ignore file to the root of the artifact.
Each line should specify a relative path or path glob to be ignored. You can include comments in this file, using #.
The .kosli_ignore file is always treated as part of the artifact: its own entries cannot exclude it, so the exclusion list cannot be changed without changing the fingerprint.
Paths the list already matches stay excluded whatever is later added there, so keep its entries as narrow as possible.
Excluding the file with --exclude keeps it out of the fingerprint but still applies the paths it lists, which lets a writable directory change the list again.
To drop the file from the fingerprint safely, move its entries to --exclude and delete it.
Flags
Flags inherited from parent commands
Live Examples in different CI systems
- GitHub
- GitLab
View an example of the
kosli assert artifact command in GitHub.In this YAML fileExamples Use Cases
These examples all assume that the flags--api-token, --org, --host, (and --flow, --trail when required), are set/provided.
assert that an artifact meets all compliance requirements for an environment
assert that an artifact meets all compliance requirements for an environment
assert that an artifact meets a set of policies
assert that an artifact meets a set of policies
fail if an artifact has a non-compliant status in a single flow (using the artifact fingerprint)
fail if an artifact has a non-compliant status in a single flow (using the artifact fingerprint)
fail if an artifact has a non-compliant status in any flow (using the artifact name and type)
fail if an artifact has a non-compliant status in any flow (using the artifact name and type)