MAQPNADocs

maqpna sovereignty check

Check Agent manifests against a sovereignty policy, offline

Govern-o json | yaml

Synopsis#

maqpna sovereignty check -f AGENT.yaml|DIR --policy SOVPOL.yaml [--tier TIER.yaml|DIR]... [-o table|json|yaml]

Description#

From the help of maqpna sovereignty:

Same checks and violation codes as the operator (and maqpna-sovereign check-agent): image registry and digest, model and tool endpoints against the allowed egress hosts and CIDRs, and the TrustTier jurisdiction. The tier is looked up by spec.tier in the -f and --tier files. Exit 3 when an Agent would be refused (enforcement=enforce).

Flags#

FlagTypeDescriptionDefault
-fstringAgent manifest file or directory (repeatable); TrustTiers in these files are used toonone
--policystringSovereigntyPolicy (CR YAML/JSON or bare spec)none
--tierstringTrustTier manifest file or directory (repeatable)none

The global flags (--context, -o, --no-color, ...) work with every command.

Examples#

maqpna sovereignty check -f agents/ --policy sovereignty.yaml
maqpna sovereignty check -f coder.yaml --policy sovereignty.yaml --tier tiers/ -o json

What happens when you run it#

  • Prints a table by default; -o json or -o yaml print the data, and --jq EXPR filters the JSON.

Exit codes#

CodeMeaning
0success
1error (the message says what failed, with a hint when there is one)
2usage error: unknown flag, missing argument or bad value; the synopsis is printed
3a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) (not used by this command)

Terminal demo#

maqpna sovereignty check.cast