maqpna values validate
Validate Helm values against the chart schema and the production rules
Synopsis#
maqpna values validate [-f values.yaml]... [--chart DIR] [--profile production|sovereign|dev] [--strict]
(exit 3 when a value is invalid or a production rule fails)Description#
From the help of maqpna values:
Values are merged like helm does: the chart's values.yaml (--chart DIR, default deploy/helm/maqpna when it exists here; --chart= disables it), then every -f in order; a null value removes a default. The merge is checked against the chart's values.schema.json (or the schema built into maqpna) and against these rules:
error chart guards: attestation.replicas > 1 or state.counters=shared
need state.backend=postgres; postgres needs state.postgres.dsnSecret;
identity.replicas > 1 needs identity.key.mode helm|existingSecret;
gateway.replicas > 1 needs state.backend=postgres (or
guards.allowIndependentGatewayReplicas, then a prod finding)
prod examples.mcpEcho disabled; identity.key.mode not generate;
attestation.verifier not sample
Production rules are errors with --profile production|sovereign or --strict, warnings by default, and skipped with --profile dev. Exit status: 0 valid (warnings allowed), 3 errors found, 1 unreadable input.
Flags#
| Flag | Type | Description | Default |
|---|---|---|---|
--chart | string | chart directory: its values.yaml are the defaults, its values.schema.json the schema (empty: built-in schema, no defaults) | none |
-f | string | values file (repeatable; later files win) | none |
--profile | string | target profile: production|sovereign (production rules are errors), dev (skipped); default: warnings | none |
--strict | switch | treat production-rule warnings as errors | none |
The global flags (--context, -o, --no-color, ...) work with every command.
Examples#
maqpna values validate -f values.yaml
maqpna values validate -f values.yaml --profile production --strictWhat happens when you run it#
- Prints a table by default;
-o jsonor-o yamlprint the data, and--jq EXPRfilters the JSON. - Exits
3when the check fails or a result does not match (see exit codes below), so scripts and CI can act on it.
Exit codes#
| Code | Meaning |
|---|---|
0 | success |
1 | error (the message says what failed, with a hint when there is one) |
2 | usage error: unknown flag, missing argument or bad value; the synopsis is printed |
3 | a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) |