maqpna doctor
Check the health and security posture of an installation
Synopsis#
maqpna doctor [--gateway URL] [-n NS] [--kube-context C] [--component all|gateway|cluster|...] [--strict] (exit 3 when a check fails)
maqpna doctor --offline --config gateway.json [--sovereignty sovereignty.json]
maqpna doctor ... --accept ID,... (report known risks as accepted, e.g. a dev profile)Flags#
| Flag | Type | Description | Default |
|---|---|---|---|
--accept | string | check IDs to report as accepted risks for this run (comma-separated, repeatable; like gateway posture.accept) | none |
--component | string | checks to run: all, gateway, cluster or components (gateway, audit, state, identity, attest, operator, sandbox, network, license), comma-separated | all |
--config | string | gateway.json to evaluate offline | none |
--gateway | string | gateway base URL (env MAQPNA_GATEWAY_URL); the admin listener when adminListen is set | none |
--kube-context | string | kubeconfig context (default: the maqpna context's) | none |
-n, --namespace | string | namespace MAQPNA is installed in | maqpna-system |
--offline | switch | evaluate --config only (no gateway, no cluster) | none |
--token-file, --oidc-token-file | string | file holding an OIDC access token (auditor or admin role; env MAQPNA_OIDC_TOKEN_FILE) | none |
--sovereignty | string | SovereigntyPolicy spec JSON referenced by the config (offline) | none |
--strict | switch | exit 3 on warnings too | none |
--token | string | static admin token (env MAQPNA_ADMIN_TOKEN; dev/break-glass) | none |
The global flags (--context, -o, --no-color, ...) work with every command.
Examples#
maqpna doctor
maqpna doctor --component gateway --strict
maqpna doctor --offline --config gateway.jsonWhat happens when you run it#
- Uses the Kubernetes API of your kubeconfig (
--kubeconfig,--kube-context, or the current context). - Talks to the gateway:
--gateway, elseMAQPNA_GATEWAY_URL, else the current context's gateway (maqpna context). - Authenticates to the admin API with the token stored by
maqpna login,--oidc-token-file, or a static--token(MAQPNA_ADMIN_TOKEN). - Prints a table by default;
-o jsonor-o yamlprint the data, and--jq EXPRfilters the JSON. - Exits
3when the check fails or a result does not match (see exit codes below), so scripts and CI can act on it.
Exit codes#
| Code | Meaning |
|---|---|
0 | success |
1 | error (the message says what failed, with a hint when there is one) |
2 | usage error: unknown flag, missing argument or bad value; the synopsis is printed |
3 | a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) |
Terminal demo#
This command needs a Kubernetes cluster with MAQPNA installed, so the recording shows its help. Try it against a cluster from Install.