MAQPNADocs

maqpna values

Validate Helm values for the MAQPNA chart offline

Operate-o json | yaml

Synopsis#

maqpna values validate [-f values.yaml]... [--chart DIR] [--profile production|sovereign|dev] [--strict]
                       (exit 3 when a value is invalid or a production rule fails)

Description#

Values are merged like helm does: the chart's values.yaml (--chart DIR, default deploy/helm/maqpna when it exists here; --chart= disables it), then every -f in order; a null value removes a default. The merge is checked against the chart's values.schema.json (or the schema built into maqpna) and against these rules:

  error    chart guards: attestation.replicas > 1 or state.counters=shared
           need state.backend=postgres; postgres needs state.postgres.dsnSecret;
           identity.replicas > 1 needs identity.key.mode helm|existingSecret;
           gateway.replicas > 1 needs state.backend=postgres (or
           guards.allowIndependentGatewayReplicas, then a prod finding)
  prod     examples.mcpEcho disabled; identity.key.mode not generate;
           attestation.verifier not sample

Production rules are errors with --profile production|sovereign or --strict, warnings by default, and skipped with --profile dev. Exit status: 0 valid (warnings allowed), 3 errors found, 1 unreadable input.

Subcommands#

Examples#

maqpna values validate -f values.yaml
maqpna values validate -f values.yaml --profile production --strict

What happens when you run it#

  • Prints a table by default; -o json or -o yaml print the data, and --jq EXPR filters the JSON.
  • Exits 3 when the check fails or a result does not match (see exit codes below), so scripts and CI can act on it.

Exit codes#

CodeMeaning
0success
1error (the message says what failed, with a hint when there is one)
2usage error: unknown flag, missing argument or bad value; the synopsis is printed
3a check failed, a change is blocked, or a result did not match (tamper, policy mismatch)

Terminal demo#

maqpna values.cast