maqpna policy lint
Check policy files for errors and risky rules
Synopsis#
maqpna policy lint FILE|DIR... [--strict] [-o table|json]Description#
From the help of maqpna policy:
Policy files: ToolPolicy custom resources (YAML or JSON, several per file, or a List) and the operator-rendered policies.json bundle are both accepted. ToolPolicies are rendered with the operator's own renderer (pkg/policyload), so a test evaluates exactly what the gateway would load. A ToolPolicy that the operator would refuse to publish (bad regex, timezone, Cedar, ...) is an error.
Suite mode: policy test DIR runs every maqpna-test.yaml under DIR (FILE runs that suite). A suite is:
apiVersion: maqpna.com/v1alpha1
kind: PolicyTest
name: coder # optional
policies: [../policies/] # files or dirs, relative to the suite
defaults: {namespace: team-a, agent: coder, user: alice@acme.eu}
cases: # one tool call each
- name: prod writes blocked
server: kubernetes
tool: delete
args: {namespace: prod-eu}
expect: deny
expectRule: k8s-no-prod-mutations
tasks: [] # optional multi-step tasks (maqpna eval format)
Exit status 3 when a case fails (or, with --require-tests, a policy file is not covered by any suite).
Flags#
| Flag | Type | Description | Default |
|---|---|---|---|
--strict | switch | treat warnings as errors | none |
The global flags (--context, -o, --no-color, ...) work with every command.
Examples#
maqpna policy lint policies/ --strictWhat happens when you run it#
- Prints a table by default;
-o jsonor-o yamlprint the data, and--jq EXPRfilters the JSON.
Exit codes#
| Code | Meaning |
|---|---|
0 | success |
1 | error (the message says what failed, with a hint when there is one) |
2 | usage error: unknown flag, missing argument or bad value; the synopsis is printed |
3 | a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) (not used by this command) |