maqpna values
Validate Helm values for the MAQPNA chart offline
Synopsis#
maqpna values validate [-f values.yaml]... [--chart DIR] [--profile production|sovereign|dev] [--strict]
(exit 3 when a value is invalid or a production rule fails)Description#
Values are merged like helm does: the chart's values.yaml (--chart DIR, default deploy/helm/maqpna when it exists here; --chart= disables it), then every -f in order; a null value removes a default. The merge is checked against the chart's values.schema.json (or the schema built into maqpna) and against these rules:
error chart guards: attestation.replicas > 1 or state.counters=shared
need state.backend=postgres; postgres needs state.postgres.dsnSecret;
identity.replicas > 1 needs identity.key.mode helm|existingSecret;
gateway.replicas > 1 needs state.backend=postgres (or
guards.allowIndependentGatewayReplicas, then a prod finding)
prod examples.mcpEcho disabled; identity.key.mode not generate;
attestation.verifier not sample
Production rules are errors with --profile production|sovereign or --strict, warnings by default, and skipped with --profile dev. Exit status: 0 valid (warnings allowed), 3 errors found, 1 unreadable input.
Subcommands#
Examples#
maqpna values validate -f values.yaml
maqpna values validate -f values.yaml --profile production --strictWhat happens when you run it#
- Prints a table by default;
-o jsonor-o yamlprint the data, and--jq EXPRfilters the JSON. - Exits
3when the check fails or a result does not match (see exit codes below), so scripts and CI can act on it.
Exit codes#
| Code | Meaning |
|---|---|
0 | success |
1 | error (the message says what failed, with a hint when there is one) |
2 | usage error: unknown flag, missing argument or bad value; the synopsis is printed |
3 | a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) |