MAQPNADocs

maqpna config

Validate a gateway configuration file offline

Operate-o json | yaml

Synopsis#

maqpna config validate FILE [--strict] [--base-dir DIR] [--gateway-binary PATH]

Description#

Checks, offline:

  - JSON syntax and the core gateway rules shared with the gateway (listen and
    adminListen, upstream names and URLs, policyFile, auditPath, identity keys,
    auditFailurePolicy, modelPolicy, tokenExchangeURL, sessionBudgetUSD);
  - unknown top-level keys (a warning; an error with --strict);
  - referenced files (policyFile, identity.publicKeyFiles, pricingFile,
    sovereigntyPolicyFile, upstreamCAFile, ...), resolved against --base-dir
    (default: the current directory, as the gateway resolves them against
    its working directory). A missing file is a warning, because
    in-cluster paths such as /etc/maqpna/... rarely exist locally; with
    --strict it is an error;
  - the policyFile compiles, when it exists;
  - every upstream URL complies with sovereigntyPolicyFile, when it exists;
  - adminAuth: static-token-only admin access is a warning.

--gateway-binary (env MAQPNA_GATEWAY_BIN) also runs "maqpna-gateway -check-config FILE", which applies every gateway rule.

Exit status: 0 valid (warnings allowed), 3 errors (or warnings with --strict).

Subcommands#

Examples#

maqpna config validate gateway.json
maqpna config validate gateway.json --strict

What happens when you run it#

  • Prints a table by default; -o json or -o yaml print the data, and --jq EXPR filters the JSON.

Exit codes#

CodeMeaning
0success
1error (the message says what failed, with a hint when there is one)
2usage error: unknown flag, missing argument or bad value; the synopsis is printed
3a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) (not used by this command)

Terminal demo#

maqpna config.cast