maqpna smoke
Smoke-test a running installation end to end (exit 3 when a step fails)
Synopsis#
maqpna smoke [--gateway URL] [--identity URL] [--token T | --oidc-token-file F] [--server echo]
[--agent-token-file F --allow-tool echo --deny-tool delete_resource] [--sandbox NS/AGENT]
[--skip ID,...] [--timeout 2m] [-o table|json|yaml]Description#
Without an admin token the admin-API steps are skipped; without --agent-token-file the allow/deny tool calls are skipped; without --sandbox no AgentSession is created. 'helm test <release>' runs this command in-cluster.
Flags#
| Flag | Type | Description | Default |
|---|---|---|---|
--agent-token-file | string | file with an agent session token (enables mcp-allow and mcp-deny) | none |
--allow-args | string | arguments of the allowed call (JSON) | {"text":"maqpna-smoke"} |
--allow-tool | string | tool the agent's policy allows | echo |
--deny-args | string | arguments of the denied call (JSON; the default targets kube-system, which the default policy's baseline guardrails deny) | {"id":"x","namespace":"kube-system"} |
--deny-tool | string | tool the agent's policy denies | delete_resource |
--gateway | string | gateway base URL (env MAQPNA_GATEWAY_URL; default: the context's gateway) | none |
--identity | string | identity broker base URL (default: the context's) | none |
--insecure-skip-tls-verify | switch | do not verify the gateway's TLS certificate (in-cluster probes only) | none |
--token-file, --oidc-token-file | string | file holding an OIDC access token for the admin API (env MAQPNA_OIDC_TOKEN_FILE); wins over --token | none |
--sandbox | string | NS/AGENT: create an AgentSession for this Agent, wait for Running, delete it | none |
--server | string | MCP server name for the tool-call steps (/mcp/NAME) | echo |
--skip | string | step IDs to skip (comma-separated, repeatable) | none |
--timeout | duration | overall timeout | 2m0s |
--token | string | static admin token (env MAQPNA_ADMIN_TOKEN; dev/break-glass) | none |
The global flags (--context, -o, --no-color, ...) work with every command.
Examples#
maqpna smoke --gateway "$GW"
maqpna smoke --gateway "$GW" --skip sandbox-lifecycle -o jsonWhat happens when you run it#
- Talks to the gateway:
--gateway, elseMAQPNA_GATEWAY_URL, else the current context's gateway (maqpna context). - Authenticates to the admin API with the token stored by
maqpna login,--oidc-token-file, or a static--token(MAQPNA_ADMIN_TOKEN). - Prints a table by default;
-o jsonor-o yamlprint the data, and--jq EXPRfilters the JSON. - Exits
3when the check fails or a result does not match (see exit codes below), so scripts and CI can act on it.
Exit codes#
| Code | Meaning |
|---|---|
0 | success |
1 | error (the message says what failed, with a hint when there is one) |
2 | usage error: unknown flag, missing argument or bad value; the synopsis is printed |
3 | a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) |