maqpna sovereignty
Check Agent manifests against a sovereignty policy offline
Synopsis#
maqpna sovereignty check -f AGENT.yaml|DIR --policy SOVPOL.yaml [--tier TIER.yaml|DIR]... [-o table|json|yaml]Description#
Same checks and violation codes as the operator (and maqpna-sovereign check-agent): image registry and digest, model and tool endpoints against the allowed egress hosts and CIDRs, and the TrustTier jurisdiction. The tier is looked up by spec.tier in the -f and --tier files. Exit 3 when an Agent would be refused (enforcement=enforce).
Subcommands#
Examples#
maqpna sovereignty check -f agents/ --policy sovereignty.yaml
maqpna sovereignty check -f coder.yaml --policy sovereignty.yaml --tier tiers/ -o jsonWhat happens when you run it#
- Prints a table by default;
-o jsonor-o yamlprint the data, and--jq EXPRfilters the JSON.
Exit codes#
| Code | Meaning |
|---|---|
0 | success |
1 | error (the message says what failed, with a hint when there is one) |
2 | usage error: unknown flag, missing argument or bad value; the synopsis is printed |
3 | a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) (not used by this command) |