maqpna validate
Validate MAQPNA manifests offline (schemas, policies, sovereignty, references)
Synopsis#
maqpna validate -f FILE|DIR [-f ...] [--sovereignty POLICY] [--strict] [-o table|json|yaml|junit]Description#
Checks every YAML/JSON document under the given files and directories, with no cluster access:
- MAQPNA resources against the embedded CRD OpenAPI schemas and CEL rules
(as the API server would on create), including unknown fields;
- ToolPolicies compile as the operator renders them for the gateway;
- with --sovereignty, Agents (with their TrustTier) and MCPServer URLs
against the SovereigntyPolicy, with the operator's violation codes;
- references resolve within the files: Agent spec.policyRef, spec.tier
and tools[].serverRef.
Documents of other API groups are skipped. Unresolved references and skipped documents are informational, or warnings with --strict. Exit status: 0 valid, 3 errors (or warnings with --strict), 1/2 failure.
Flags#
| Flag | Type | Description | Default |
|---|---|---|---|
-f, --filename | string | file or directory (repeatable, comma-separated; directories are walked) | none |
--sovereignty | string | SovereigntyPolicy (CR YAML/JSON or bare spec) Agents and MCPServers must comply with | none |
--strict | switch | fail on warnings too; unresolved references and non-MAQPNA documents become warnings | none |
The global flags (--context, -o, --no-color, ...) work with every command.
Examples#
maqpna validate -f manifests/
maqpna validate -f manifests/ --sovereignty sovereignty.yaml --strict -o junit > validate.xmlWhat happens when you run it#
- Prints a table by default;
-o jsonor-o yamlprint the data, and--jq EXPRfilters the JSON.
Exit codes#
| Code | Meaning |
|---|---|
0 | success |
1 | error (the message says what failed, with a hint when there is one) |
2 | usage error: unknown flag, missing argument or bad value; the synopsis is printed |
3 | a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) (not used by this command) |