MAQPNADocs

maqpna sovereignty

Check Agent manifests against a sovereignty policy offline

Govern-o json | yaml

Synopsis#

maqpna sovereignty check -f AGENT.yaml|DIR --policy SOVPOL.yaml [--tier TIER.yaml|DIR]... [-o table|json|yaml]

Description#

Same checks and violation codes as the operator (and maqpna-sovereign check-agent): image registry and digest, model and tool endpoints against the allowed egress hosts and CIDRs, and the TrustTier jurisdiction. The tier is looked up by spec.tier in the -f and --tier files. Exit 3 when an Agent would be refused (enforcement=enforce).

Subcommands#

Examples#

maqpna sovereignty check -f agents/ --policy sovereignty.yaml
maqpna sovereignty check -f coder.yaml --policy sovereignty.yaml --tier tiers/ -o json

What happens when you run it#

  • Prints a table by default; -o json or -o yaml print the data, and --jq EXPR filters the JSON.

Exit codes#

CodeMeaning
0success
1error (the message says what failed, with a hint when there is one)
2usage error: unknown flag, missing argument or bad value; the synopsis is printed
3a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) (not used by this command)

Terminal demo#

maqpna sovereignty.cast