MAQPNADocs

maqpna smoke

Smoke-test a running installation end to end (exit 3 when a step fails)

Operate-o json | yaml

Synopsis#

maqpna smoke [--gateway URL] [--identity URL] [--token T | --oidc-token-file F] [--server echo]
             [--agent-token-file F --allow-tool echo --deny-tool delete_resource] [--sandbox NS/AGENT]
             [--skip ID,...] [--timeout 2m] [-o table|json|yaml]

Description#

Without an admin token the admin-API steps are skipped; without --agent-token-file the allow/deny tool calls are skipped; without --sandbox no AgentSession is created. 'helm test <release>' runs this command in-cluster.

Flags#

FlagTypeDescriptionDefault
--agent-token-filestringfile with an agent session token (enables mcp-allow and mcp-deny)none
--allow-argsstringarguments of the allowed call (JSON){"text":"maqpna-smoke"}
--allow-toolstringtool the agent's policy allowsecho
--deny-argsstringarguments of the denied call (JSON; the default targets kube-system, which the default policy's baseline guardrails deny){"id":"x","namespace":"kube-system"}
--deny-toolstringtool the agent's policy deniesdelete_resource
--gatewaystringgateway base URL (env MAQPNA_GATEWAY_URL; default: the context's gateway)none
--identitystringidentity broker base URL (default: the context's)none
--insecure-skip-tls-verifyswitchdo not verify the gateway's TLS certificate (in-cluster probes only)none
--token-file, --oidc-token-filestringfile holding an OIDC access token for the admin API (env MAQPNA_OIDC_TOKEN_FILE); wins over --tokennone
--sandboxstringNS/AGENT: create an AgentSession for this Agent, wait for Running, delete itnone
--serverstringMCP server name for the tool-call steps (/mcp/NAME)echo
--skipstringstep IDs to skip (comma-separated, repeatable)none
--timeoutdurationoverall timeout2m0s
--tokenstringstatic admin token (env MAQPNA_ADMIN_TOKEN; dev/break-glass)none

The global flags (--context, -o, --no-color, ...) work with every command.

Examples#

maqpna smoke --gateway "$GW"
maqpna smoke --gateway "$GW" --skip sandbox-lifecycle -o json

What happens when you run it#

  • Talks to the gateway: --gateway, else MAQPNA_GATEWAY_URL, else the current context's gateway (maqpna context).
  • Authenticates to the admin API with the token stored by maqpna login, --oidc-token-file, or a static --token (MAQPNA_ADMIN_TOKEN).
  • Prints a table by default; -o json or -o yaml print the data, and --jq EXPR filters the JSON.
  • Exits 3 when the check fails or a result does not match (see exit codes below), so scripts and CI can act on it.

Exit codes#

CodeMeaning
0success
1error (the message says what failed, with a hint when there is one)
2usage error: unknown flag, missing argument or bad value; the synopsis is printed
3a check failed, a change is blocked, or a result did not match (tamper, policy mismatch)

Terminal demo#

maqpna smoke.cast