Skip to content

Commit e450fac

Browse files
tookyclaude
andcommitted
Release: docs: clarify --artifact-type=docker requires registry digest (#834)
* docs: clarify --artifact-type=docker requires registry digest A customer hit "repo digest unavailable for the image, has it been pushed to or pulled from a registry?" after kosli attest artifact with --artifact-type=docker in CI, where the image was built but never pushed. The constraint that the docker artifact type requires a registry-resident image was only stated in the error itself. Add a note to the long descriptions of attest commands (via fingerprintDesc) and kosli fingerprint, covering the constraint and pointing at oci and dir as alternatives. Help-text only; no behaviour change. Auto-generated docs in kosli-dev/docs will pick this up on the next CLI release. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs: drop dir suggestion from artifact-type=docker note Source-dir fingerprinting only works as an end-to-end identity if the runtime side also fingerprints the source dir. Standard Kosli runtime reporters fingerprint the running image, so suggesting dir as a generic swap is misleading — the attested and running artifacts would never link. Push and oci are the safe answers for the typical case. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
1 parent 7790a04 commit e450fac

103 files changed

Lines changed: 341 additions & 115 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1 +1 @@
1-
{"currentversion": "v2.17.1"}
1+
{"currentversion": "v2.17.2"}

‎docs.kosli.com/content/client_reference/kosli_allow_artifact.md‎

Lines changed: 7 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -15,12 +15,18 @@ kosli allow artifact [IMAGE-NAME | FILE-PATH | DIR-PATH] [flags]
1515

1616
Add an artifact to an environment's allowlist.
1717

18-
The artifact fingerprint can be provided directly with the `--fingerprint` flag, or
18+
The artifact fingerprint can be provided directly with the `--fingerprint` flag, or
1919
calculated based on `--artifact-type` flag.
2020

2121
Artifact type can be one of: "file" for files, "dir" for directories, "oci" for container
2222
images in registries or "docker" for local docker images.
2323

24+
Note: `--artifact-type=docker` reads the image's repo digest via the local Docker daemon.
25+
The image must have been pushed to or pulled from a registry for a repo digest to exist;
26+
a freshly built image (just `docker build`) will not have one. If the image is already in
27+
a registry, prefer `--artifact-type=oci`, which fetches the digest directly from the
28+
registry without needing a local Docker daemon.
29+
2430

2531

2632
## Flags

‎docs.kosli.com/content/client_reference/kosli_assert_approval.md‎

Lines changed: 7 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -16,12 +16,18 @@ kosli assert approval [IMAGE-NAME | FILE-PATH | DIR-PATH] [flags]
1616
Assert an artifact in Kosli has been approved for deployment.
1717
Exits with non-zero code if the artifact has not been approved.
1818

19-
The artifact fingerprint can be provided directly with the `--fingerprint` flag, or
19+
The artifact fingerprint can be provided directly with the `--fingerprint` flag, or
2020
calculated based on `--artifact-type` flag.
2121

2222
Artifact type can be one of: "file" for files, "dir" for directories, "oci" for container
2323
images in registries or "docker" for local docker images.
2424

25+
Note: `--artifact-type=docker` reads the image's repo digest via the local Docker daemon.
26+
The image must have been pushed to or pulled from a registry for a repo digest to exist;
27+
a freshly built image (just `docker build`) will not have one. If the image is already in
28+
a registry, prefer `--artifact-type=oci`, which fetches the digest directly from the
29+
registry without needing a local Docker daemon.
30+
2531

2632

2733
## Flags

‎docs.kosli.com/content/client_reference/kosli_attest_artifact.md‎

Lines changed: 7 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -15,12 +15,18 @@ kosli attest artifact {IMAGE-NAME | FILE-PATH | DIR-PATH} [flags]
1515

1616
Attest an artifact creation to a Kosli flow.
1717

18-
The artifact fingerprint can be provided directly with the `--fingerprint` flag, or
18+
The artifact fingerprint can be provided directly with the `--fingerprint` flag, or
1919
calculated based on `--artifact-type` flag.
2020

2121
Artifact type can be one of: "file" for files, "dir" for directories, "oci" for container
2222
images in registries or "docker" for local docker images.
2323

24+
Note: `--artifact-type=docker` reads the image's repo digest via the local Docker daemon.
25+
The image must have been pushed to or pulled from a registry for a repo digest to exist;
26+
a freshly built image (just `docker build`) will not have one. If the image is already in
27+
a registry, prefer `--artifact-type=oci`, which fetches the digest directly from the
28+
registry without needing a local Docker daemon.
29+
2430
To specify paths in a directory artifact that should always be excluded from the SHA256 calculation, you can add a `.kosli_ignore` file to the root of the artifact.
2531
Each line should specify a relative path or path glob to be ignored. You can include comments in this file, using `#`.
2632
The `.kosli_ignore` will be treated as part of the artifact like any other file, unless it is explicitly ignored itself.

‎docs.kosli.com/content/client_reference/kosli_create_flow.md‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -47,9 +47,9 @@ You can specify flow parameters in flags.
4747

4848
{{< tabs "live-examples" "col-no-wrap" >}}{{< tab "GitHub" >}}View an example of the `kosli create flow` command in GitHub.
4949

50-
In [this YAML file](https://app.kosli.com/api/v2/livedocs/cyber-dojo/yaml?ci=github&command=kosli%2Bcreate%2Bflow){{< /tab >}}{{< tab "GitLab" >}}View an example of the `kosli create flow` command in GitLab.
50+
In [this YAML file](https://app.kosli.com/api/v2/livedocs/cyber-dojo/yaml?ci=github&command=kosli%2Bcreate%2Bflow), which created [this Kosli Event](https://app.kosli.com/api/v2/livedocs/cyber-dojo/event?ci=github&command=kosli%2Bcreate%2Bflow).{{< /tab >}}{{< tab "GitLab" >}}View an example of the `kosli create flow` command in GitLab.
5151

52-
In [this YAML file](https://app.kosli.com/api/v2/livedocs/cyber-dojo/yaml?ci=gitlab&command=kosli%2Bcreate%2Bflow){{< /tab >}}{{< /tabs >}}
52+
In [this YAML file](https://app.kosli.com/api/v2/livedocs/cyber-dojo/yaml?ci=gitlab&command=kosli%2Bcreate%2Bflow), which created [this Kosli Event](https://app.kosli.com/api/v2/livedocs/cyber-dojo/event?ci=gitlab&command=kosli%2Bcreate%2Bflow).{{< /tab >}}{{< /tabs >}}
5353

5454
## Examples Use Cases
5555

‎docs.kosli.com/content/client_reference/kosli_evaluate_input.md‎

Lines changed: 18 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
title: "kosli evaluate input"
33
beta: false
44
deprecated: false
5-
summary: "Evaluate a local JSON input against a Rego policy."
5+
summary: "[BETA] Evaluate a local JSON input against a Rego policy."
66
---
77

88
# kosli evaluate input
@@ -13,15 +13,18 @@ summary: "Evaluate a local JSON input against a Rego policy."
1313
kosli evaluate input [flags]
1414
```
1515

16-
Evaluate a local JSON input against a Rego policy.
16+
[BETA] Evaluate a local JSON input against a Rego policy.
1717
Read JSON from a file or stdin and evaluate it against a Rego policy.
1818
The input file should contain the raw JSON object your policy expects —
1919
not the wrapper produced by `--show-input`. Use `jq '.input'` to extract
2020
the policy input from a `--show-input --output json` capture.
2121

2222
The policy must use `package policy` and define an `allow` rule.
2323
An optional `violations` rule (a set of strings) can provide human-readable denial reasons.
24-
The command exits with code 0 when allowed and code 1 when denied.
24+
25+
By default a deny exits with code 1. Pass `--no-assert` to print the verdict
26+
and exit 0 even on deny, when this command is feeding another tool as a
27+
policy decision point.
2528

2629
When `--input-file` is omitted, JSON is read from stdin.
2730

@@ -31,8 +34,10 @@ This accepts inline JSON or a file reference (`@file.json`).
3134
## Flags
3235
| Flag | Description |
3336
| :--- | :--- |
37+
| --assert | [optional] Exit with a non-zero status when the policy denies. This is the current default; pass --assert to lock it in across future releases. |
3438
| -h, --help | help for input |
3539
| -i, --input-file string | [optional] Path to a JSON input file. Reads from stdin if omitted. |
40+
| --no-assert | [optional] Print the result and always exit 0, even when the policy denies. Use when this command feeds another tool as a policy decision point. |
3641
| -o, --output string | [defaulted] The format of the output. Valid formats are: [table, json]. (default "table") |
3742
| --params string | [optional] Policy parameters as inline JSON or @file.json. Available in policies as data.params. |
3843
| -p, --policy string | Path to a Rego policy file to evaluate against the input. |
@@ -109,5 +114,15 @@ kosli evaluate input
109114
--input-file trail-data.json
110115
--policy policy.rego
111116
--params @params.json
117+
118+
```
119+
120+
##### evaluate as a decision point (print verdict, never fail the step)
121+
122+
```shell
123+
kosli evaluate input
124+
--input-file trail-data.json
125+
--policy policy.rego
126+
--no-assert
112127
```
113128

‎docs.kosli.com/content/client_reference/kosli_evaluate_trail.md‎

Lines changed: 19 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
title: "kosli evaluate trail"
33
beta: false
44
deprecated: false
5-
summary: "Evaluate a trail against a policy."
5+
summary: "[BETA] Evaluate a trail against a policy."
66
---
77

88
# kosli evaluate trail
@@ -13,7 +13,7 @@ summary: "Evaluate a trail against a policy."
1313
kosli evaluate trail TRAIL-NAME [flags]
1414
```
1515

16-
Evaluate a trail against a policy.
16+
[BETA] Evaluate a trail against a policy.
1717
Fetch a single trail from Kosli and evaluate it against a Rego policy.
1818
The trail data is passed to the policy as `input.trail`.
1919

@@ -24,9 +24,11 @@ full data structure available to the policy. Use `--output json` for structured
2424
## Flags
2525
| Flag | Description |
2626
| :--- | :--- |
27+
| --assert | [optional] Exit with a non-zero status when the policy denies. This is the current default; pass --assert to lock it in across future releases. |
2728
| --attestations strings | [optional] Limit which attestations are included. Plain name for trail-level, dot-qualified (artifact.name) for artifact-level. |
2829
| -f, --flow string | The Kosli flow name. |
2930
| -h, --help | help for trail |
31+
| --no-assert | [optional] Print the result and always exit 0, even when the policy denies. Use when this command feeds another tool as a policy decision point. |
3032
| -o, --output string | [defaulted] The format of the output. Valid formats are: [table, json]. (default "table") |
3133
| --params string | [optional] Policy parameters as inline JSON or @file.json. Available in policies as data.params. |
3234
| -p, --policy string | Path to a Rego policy file to evaluate against the trail. |
@@ -45,6 +47,12 @@ full data structure available to the policy. Use `--output json` for structured
4547
| --org string | The Kosli organization. |
4648

4749

50+
## Live Examples in different CI systems
51+
52+
{{< tabs "live-examples" "col-no-wrap" >}}{{< tab "GitHub" >}}View an example of the `kosli evaluate trail` command in GitHub.
53+
54+
In [this YAML file](https://app.kosli.com/api/v2/livedocs/cyber-dojo/yaml?ci=github&command=kosli%2Bevaluate%2Btrail){{< /tab >}}{{< /tabs >}}
55+
4856
## Examples Use Cases
4957

5058
These examples all assume that the flags `--api-token`, `--org`, `--host`, (and `--flow`, `--trail` when required), are [set/provided](https://docs.kosli.com/getting_started/install/#assigning-flags-via-environment-variables).
@@ -91,5 +99,14 @@ kosli evaluate trail yourTrailName
9199
kosli evaluate trail yourTrailName
92100
--policy yourPolicyFile.rego
93101
--params @params.json
102+
103+
```
104+
105+
##### evaluate a trail as a decision point (print verdict, never fail the step)
106+
107+
```shell
108+
kosli evaluate trail yourTrailName
109+
--policy yourPolicyFile.rego
110+
--no-assert
94111
```
95112

‎docs.kosli.com/content/client_reference/kosli_evaluate_trails.md‎

Lines changed: 13 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
title: "kosli evaluate trails"
33
beta: false
44
deprecated: false
5-
summary: "Evaluate multiple trails against a policy."
5+
summary: "[BETA] Evaluate multiple trails against a policy."
66
---
77

88
# kosli evaluate trails
@@ -13,7 +13,7 @@ summary: "Evaluate multiple trails against a policy."
1313
kosli evaluate trails TRAIL-NAME [TRAIL-NAME...] [flags]
1414
```
1515

16-
Evaluate multiple trails against a policy.
16+
[BETA] Evaluate multiple trails against a policy.
1717
Fetch multiple trails from Kosli and evaluate them together against a Rego policy.
1818
The trail data is passed to the policy as `input.trails` (an array), unlike
1919
`evaluate trail` which passes `input.trail` (a single object).
@@ -25,9 +25,11 @@ full data structure available to the policy. Use `--output json` for structured
2525
## Flags
2626
| Flag | Description |
2727
| :--- | :--- |
28+
| --assert | [optional] Exit with a non-zero status when the policy denies. This is the current default; pass --assert to lock it in across future releases. |
2829
| --attestations strings | [optional] Limit which attestations are included. Plain name for trail-level, dot-qualified (artifact.name) for artifact-level. |
2930
| -f, --flow string | The Kosli flow name. |
3031
| -h, --help | help for trails |
32+
| --no-assert | [optional] Print the result and always exit 0, even when the policy denies. Use when this command feeds another tool as a policy decision point. |
3133
| -o, --output string | [defaulted] The format of the output. Valid formats are: [table, json]. (default "table") |
3234
| --params string | [optional] Policy parameters as inline JSON or @file.json. Available in policies as data.params. |
3335
| -p, --policy string | Path to a Rego policy file to evaluate against the trails. |
@@ -83,5 +85,14 @@ kosli evaluate trails yourTrailName1 yourTrailName2
8385
kosli evaluate trails yourTrailName1 yourTrailName2
8486
--policy yourPolicyFile.rego
8587
--params '{"min_approvers": 2}'
88+
89+
```
90+
91+
##### evaluate trails as a decision point (print verdict, never fail the step)
92+
93+
```shell
94+
kosli evaluate trails yourTrailName1 yourTrailName2
95+
--policy yourPolicyFile.rego
96+
--no-assert
8697
```
8798

‎docs.kosli.com/content/client_reference/kosli_fingerprint.md‎

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -21,6 +21,11 @@ images in registries or "docker" for local docker images.
2121
Fingerprinting container images can be done using the local docker daemon or the fingerprint can be fetched
2222
from a remote registry.
2323

24+
Note: `--artifact-type=docker` reads the image's repo digest via the local Docker daemon, so
25+
the image must have been pushed to or pulled from a registry. A freshly built image (just
26+
`docker build`) does not have a repo digest. For images already in a registry, prefer
27+
`--artifact-type=oci` to fetch the digest directly from the registry.
28+
2429
When fingerprinting a 'dir' artifact, you can exclude certain paths from fingerprint calculation
2530
using the `--exclude` flag.
2631
Excluded paths are relative to the DIR-PATH and can be literal paths or glob patterns.

‎docs.kosli.com/content/client_reference/kosli_report_approval.md‎

Lines changed: 7 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -15,12 +15,18 @@ kosli report approval [IMAGE-NAME | FILE-PATH | DIR-PATH] [flags]
1515

1616
Report an approval of deploying an artifact to an environment to Kosli.
1717

18-
The artifact fingerprint can be provided directly with the `--fingerprint` flag, or
18+
The artifact fingerprint can be provided directly with the `--fingerprint` flag, or
1919
calculated based on `--artifact-type` flag.
2020

2121
Artifact type can be one of: "file" for files, "dir" for directories, "oci" for container
2222
images in registries or "docker" for local docker images.
2323

24+
Note: `--artifact-type=docker` reads the image's repo digest via the local Docker daemon.
25+
The image must have been pushed to or pulled from a registry for a repo digest to exist;
26+
a freshly built image (just `docker build`) will not have one. If the image is already in
27+
a registry, prefer `--artifact-type=oci`, which fetches the digest directly from the
28+
registry without needing a local Docker daemon.
29+
2430

2531

2632
## Flags

0 commit comments

Comments
 (0)