Synopsis
- Against an environment. When
--environmentis specified, asserts against all policies currently attached to the given environment. - Against one or more policies. When
--policyis specified, asserts against all the given policies. - Against flow templates. When neither
--environmentnor--policyis specified, asserts against the template files of the flows the artifact is found in.
--environment and --policy are mutually exclusive.
--flow can be combined with any of the above to narrow the lookup
to a specific flow. Without --flow, all flows containing the artifact
(by fingerprint) are considered.
Exits with zero code if the artifact has compliant status,
non-zero code if non-compliant status.
To specify paths in a directory artifact that should always be excluded from the SHA256 calculation, you can add a .kosli_ignore file to the root of the artifact.
Each line should specify a relative path or path glob to be ignored. You can include comments in this file, using #.
The .kosli_ignore will be treated as part of the artifact like any other file, unless it is explicitly ignored itself.
Flags
Flags inherited from parent commands
Live Examples in different CI systems
- GitHub
- GitLab
View an example of the
kosli assert artifact command in GitHub.In this YAML fileExamples Use Cases
These examples all assume that the flags--api-token, --org, --host, (and --flow, --trail when required), are set/provided.
assert that an artifact meets all compliance requirements for an environment
assert that an artifact meets all compliance requirements for an environment
assert that an artifact meets a set of policies
assert that an artifact meets a set of policies
fail if an artifact has a non-compliant status in a single flow (using the artifact fingerprint)
fail if an artifact has a non-compliant status in a single flow (using the artifact fingerprint)
fail if an artifact has a non-compliant status in any flow (using the artifact name and type)
fail if an artifact has a non-compliant status in any flow (using the artifact name and type)