MAQPNADocs

maqpna doctor

Check the health and security posture of an installation

Operate-o json | yaml

Synopsis#

maqpna doctor [--gateway URL] [-n NS] [--kube-context C] [--component all|gateway|cluster|...] [--strict]   (exit 3 when a check fails)
maqpna doctor --offline --config gateway.json [--sovereignty sovereignty.json]
maqpna doctor ... --accept ID,...   (report known risks as accepted, e.g. a dev profile)

Flags#

FlagTypeDescriptionDefault
--acceptstringcheck IDs to report as accepted risks for this run (comma-separated, repeatable; like gateway posture.accept)none
--componentstringchecks to run: all, gateway, cluster or components (gateway, audit, state, identity, attest, operator, sandbox, network, license), comma-separatedall
--configstringgateway.json to evaluate offlinenone
--gatewaystringgateway base URL (env MAQPNA_GATEWAY_URL); the admin listener when adminListen is setnone
--kube-contextstringkubeconfig context (default: the maqpna context's)none
-n, --namespacestringnamespace MAQPNA is installed inmaqpna-system
--offlineswitchevaluate --config only (no gateway, no cluster)none
--token-file, --oidc-token-filestringfile holding an OIDC access token (auditor or admin role; env MAQPNA_OIDC_TOKEN_FILE)none
--sovereigntystringSovereigntyPolicy spec JSON referenced by the config (offline)none
--strictswitchexit 3 on warnings toonone
--tokenstringstatic admin token (env MAQPNA_ADMIN_TOKEN; dev/break-glass)none

The global flags (--context, -o, --no-color, ...) work with every command.

Examples#

maqpna doctor
maqpna doctor --component gateway --strict
maqpna doctor --offline --config gateway.json

What happens when you run it#

  • Uses the Kubernetes API of your kubeconfig (--kubeconfig, --kube-context, or the current context).
  • Talks to the gateway: --gateway, else MAQPNA_GATEWAY_URL, else the current context's gateway (maqpna context).
  • Authenticates to the admin API with the token stored by maqpna login, --oidc-token-file, or a static --token (MAQPNA_ADMIN_TOKEN).
  • Prints a table by default; -o json or -o yaml print the data, and --jq EXPR filters the JSON.
  • Exits 3 when the check fails or a result does not match (see exit codes below), so scripts and CI can act on it.

Exit codes#

CodeMeaning
0success
1error (the message says what failed, with a hint when there is one)
2usage error: unknown flag, missing argument or bad value; the synopsis is printed
3a check failed, a change is blocked, or a result did not match (tamper, policy mismatch)

Terminal demo#

maqpna doctor --help.cast

This command needs a Kubernetes cluster with MAQPNA installed, so the recording shows its help. Try it against a cluster from Install.