maqpna config validate
Validate a gateway configuration file offline
Synopsis#
maqpna config validate FILE [--strict] [--base-dir DIR] [--gateway-binary PATH]Description#
From the help of maqpna config:
Checks, offline:
- JSON syntax and the core gateway rules shared with the gateway (listen and
adminListen, upstream names and URLs, policyFile, auditPath, identity keys,
auditFailurePolicy, modelPolicy, tokenExchangeURL, sessionBudgetUSD);
- unknown top-level keys (a warning; an error with --strict);
- referenced files (policyFile, identity.publicKeyFiles, pricingFile,
sovereigntyPolicyFile, upstreamCAFile, ...), resolved against --base-dir
(default: the current directory, as the gateway resolves them against
its working directory). A missing file is a warning, because
in-cluster paths such as /etc/maqpna/... rarely exist locally; with
--strict it is an error;
- the policyFile compiles, when it exists;
- every upstream URL complies with sovereigntyPolicyFile, when it exists;
- adminAuth: static-token-only admin access is a warning.
--gateway-binary (env MAQPNA_GATEWAY_BIN) also runs "maqpna-gateway -check-config FILE", which applies every gateway rule.
Exit status: 0 valid (warnings allowed), 3 errors (or warnings with --strict).
Flags#
| Flag | Type | Description | Default |
|---|---|---|---|
--base-dir | string | directory relative file paths are resolved against (default: the current directory, like the gateway) | none |
--gateway-binary | string | maqpna-gateway binary: also run its -check-config (env MAQPNA_GATEWAY_BIN) | none |
--strict | switch | treat warnings (unknown keys, missing files, static admin token) as errors | none |
The global flags (--context, -o, --no-color, ...) work with every command.
Examples#
maqpna config validate gateway.json
maqpna config validate gateway.json --strictWhat happens when you run it#
- Prints a table by default;
-o jsonor-o yamlprint the data, and--jq EXPRfilters the JSON.
Exit codes#
| Code | Meaning |
|---|---|
0 | success |
1 | error (the message says what failed, with a hint when there is one) |
2 | usage error: unknown flag, missing argument or bad value; the synopsis is printed |
3 | a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) (not used by this command) |