MAQPNADocs

maqpna validate

Validate MAQPNA manifests offline (schemas, policies, sovereignty, references)

Run agents-o json | yaml

Synopsis#

maqpna validate -f FILE|DIR [-f ...] [--sovereignty POLICY] [--strict] [-o table|json|yaml|junit]

Description#

Checks every YAML/JSON document under the given files and directories, with no cluster access:

  - MAQPNA resources against the embedded CRD OpenAPI schemas and CEL rules
    (as the API server would on create), including unknown fields;
  - ToolPolicies compile as the operator renders them for the gateway;
  - with --sovereignty, Agents (with their TrustTier) and MCPServer URLs
    against the SovereigntyPolicy, with the operator's violation codes;
  - references resolve within the files: Agent spec.policyRef, spec.tier
    and tools[].serverRef.

Documents of other API groups are skipped. Unresolved references and skipped documents are informational, or warnings with --strict. Exit status: 0 valid, 3 errors (or warnings with --strict), 1/2 failure.

Flags#

FlagTypeDescriptionDefault
-f, --filenamestringfile or directory (repeatable, comma-separated; directories are walked)none
--sovereigntystringSovereigntyPolicy (CR YAML/JSON or bare spec) Agents and MCPServers must comply withnone
--strictswitchfail on warnings too; unresolved references and non-MAQPNA documents become warningsnone

The global flags (--context, -o, --no-color, ...) work with every command.

Examples#

maqpna validate -f manifests/
maqpna validate -f manifests/ --sovereignty sovereignty.yaml --strict -o junit > validate.xml

What happens when you run it#

  • Prints a table by default; -o json or -o yaml print the data, and --jq EXPR filters the JSON.

Exit codes#

CodeMeaning
0success
1error (the message says what failed, with a hint when there is one)
2usage error: unknown flag, missing argument or bad value; the synopsis is printed
3a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) (not used by this command)

Terminal demo#

maqpna validate.cast