maqpna sovereignty check
Check Agent manifests against a sovereignty policy, offline
Synopsis#
maqpna sovereignty check -f AGENT.yaml|DIR --policy SOVPOL.yaml [--tier TIER.yaml|DIR]... [-o table|json|yaml]Description#
From the help of maqpna sovereignty:
Same checks and violation codes as the operator (and maqpna-sovereign check-agent): image registry and digest, model and tool endpoints against the allowed egress hosts and CIDRs, and the TrustTier jurisdiction. The tier is looked up by spec.tier in the -f and --tier files. Exit 3 when an Agent would be refused (enforcement=enforce).
Flags#
| Flag | Type | Description | Default |
|---|---|---|---|
-f | string | Agent manifest file or directory (repeatable); TrustTiers in these files are used too | none |
--policy | string | SovereigntyPolicy (CR YAML/JSON or bare spec) | none |
--tier | string | TrustTier manifest file or directory (repeatable) | none |
The global flags (--context, -o, --no-color, ...) work with every command.
Examples#
maqpna sovereignty check -f agents/ --policy sovereignty.yaml
maqpna sovereignty check -f coder.yaml --policy sovereignty.yaml --tier tiers/ -o jsonWhat happens when you run it#
- Prints a table by default;
-o jsonor-o yamlprint the data, and--jq EXPRfilters the JSON.
Exit codes#
| Code | Meaning |
|---|---|
0 | success |
1 | error (the message says what failed, with a hint when there is one) |
2 | usage error: unknown flag, missing argument or bad value; the synopsis is printed |
3 | a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) (not used by this command) |