maqpna evidence generate
Generate a signed evidence pack for one framework, system and period
Synopsis#
maqpna evidence generate --framework eu-ai-act|dora|iso42001 --system NS/AGENT|namespace:NS|tenant:NAME
(--period 2027-Q1|2027-01|2027 | --from DATE --to DATE) [--ledger FILE | --gateway URL]
--key KEYURI [--jwks URL|FILE] [--checkpoints FILE] [--license FILE] [--no-cluster] [--out DIR|FILE.zip]
signed evidence pack: manifest.json, report.html/.md, CSV workpapers (needs the evidence-packs licence)Description#
From the help of maqpna evidence:
generate builds a signed, auditor-ready evidence pack for one framework, one system and one period from the audit ledger and the configuration in force (paid: the evidence-packs licence feature or the Sovereign edition). verify checks a pack offline and needs no licence. frameworks lists the control mappings. A pack supports, and does not certify, compliance (docs/evidence-packs.md).
The register lists every external MCP server, model endpoint and A2A peer with first and last use, call counts, residency and cost (DORA Art. 28(3) register of information).
Flags#
| Flag | Type | Description | Default |
|---|---|---|---|
--checkpoints | string | signed checkpoint file (default: LEDGER.checkpoints.jws) | none |
--framework | string | eu-ai-act | dora | iso42001 | none |
--from | string | period start (RFC3339 or YYYY-MM-DD; with --to) | none |
--gateway | string | gateway base URL (env MAQPNA_GATEWAY_URL; default: the context's gateway) | none |
--jwks | string | JWKS (file or URL) to verify the ledger's signed checkpoints | none |
--key | string | signing key: the audit-checkpoint key (file path, file:///…, pkcs11:… or kms://…; env MAQPNA_EVIDENCE_KEY) | none |
--ledger | string | read the audit ledger from FILE instead of the gateway | none |
--license | string | licence file (default: $MAQPNA_LICENSE_FILE, else the licence installed in the cluster) | none |
--no-cluster | switch | do not read the cluster (agents, tools, policies, tiers, sovereignty); the pack marks those controls partial | none |
--oidc-token-file | string | file holding an OIDC access token for the admin API (env MAQPNA_OIDC_TOKEN_FILE); wins over --token | none |
--out | string | output directory, or FILE.zip (default evidence-FRAMEWORK-SYSTEM-PERIOD) | none |
--period | string | quarter YYYY-Qn, month YYYY-MM or year YYYY (UTC) | none |
--system | string | NS/AGENT (agent), namespace:NS, or tenant:NAME | none |
--to | string | period end, exclusive (RFC3339 or YYYY-MM-DD) | none |
--token | string | static admin token (env MAQPNA_ADMIN_TOKEN; dev/break-glass) | none |
The global flags (--context, -o, --no-color, ...) work with every command.
Examples#
maqpna evidence generate --framework eu-ai-act --system team-a/coder --period 2027-Q1 --gateway "$GW" --key checkpoint.key --out pack.zipWhat happens when you run it#
- Talks to the gateway:
--gateway, elseMAQPNA_GATEWAY_URL, else the current context's gateway (maqpna context). - Authenticates to the admin API with the token stored by
maqpna login,--oidc-token-file, or a static--token(MAQPNA_ADMIN_TOKEN). - Reads the audit ledger offline with
--ledger FILE: read the audit ledger from FILE instead of the gateway. - Prints a table by default;
-o jsonor-o yamlprint the data, and--jq EXPRfilters the JSON.
Exit codes#
| Code | Meaning |
|---|---|
0 | success |
1 | error (the message says what failed, with a hint when there is one) |
2 | usage error: unknown flag, missing argument or bad value; the synopsis is printed |
3 | a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) (not used by this command) |