Export audit-preserving YAML
Use the audit export mode when the exported manifests need to retain the Kix metadata that connects resources to packages, dependencies, and an activation. This export is intended as evidence or as input to an audit process.
Create the audit export
Section titled “Create the audit export”Pass --for audit and choose an output directory:
❱ kix export how-to-application --for audit --out ./audit-export
Building cluster 'how-to-application'...
Evaluating cluster 'how-to-application'...
Reading package index...
Loading store graph...
Reading 3 packages...
Discovering cluster-level resources...
Computing cross-package dependencies...
Exported 16 resources to ./audit-export (audit (kix provenance preserved)) Kix evaluates and builds the cluster locally. The export includes every
rendered resource, including Activation and PackageInstance custom
resources, and preserves its kix.run/* annotations.
Inspect the provenance metadata
Section titled “Inspect the provenance metadata”Search the exported files for Kix annotations:
❱ grep -rn 'kix.run/\(identity-hash\|depends-on\|package\)' ./audit-export/ Show output
./audit-export/how-to-app/ConfigMap-preview.yaml:8: kix.run/depends-on: '8767b7nzgc1x5bpfa9gv71cpk9z8h0iw'
./audit-export/how-to-app/ConfigMap-preview.yaml:9: kix.run/identity-hash: asa4ywz8yjjql7grm2rnm774q96ncs3m
./audit-export/how-to-app/ConfigMap-preview.yaml:10: kix.run/package: preview
./audit-export/how-to-app/ConfigMap-preview.yaml:11: kix.run/package-namespace: how-to-app
./audit-export/how-to-app/Service-preview.yaml:5: kix.run/depends-on: '8767b7nzgc1x5bpfa9gv71cpk9z8h0iw,hd2br513fjyfgbl9sf97ank37hqzrmzl'
./audit-export/how-to-app/Service-preview.yaml:6: kix.run/identity-hash: '91lbws8gjsbxfvr8p7kjx0dc7nzybhqs'
./audit-export/how-to-app/Service-preview.yaml:7: kix.run/package: preview
./audit-export/how-to-app/Service-preview.yaml:8: kix.run/package-namespace: how-to-app
./audit-export/how-to-app/Deployment-preview.yaml:5: kix.run/depends-on: '8767b7nzgc1x5bpfa9gv71cpk9z8h0iw,asa4ywz8yjjql7grm2rnm774q96ncs3m'
./audit-export/how-to-app/Deployment-preview.yaml:6: kix.run/identity-hash: hd2br513fjyfgbl9sf97ank37hqzrmzl
./audit-export/how-to-app/Deployment-preview.yaml:7: kix.run/package: preview
./audit-export/how-to-app/Deployment-preview.yaml:8: kix.run/package-namespace: how-to-app
./audit-export/how-to-app/PackageInstance-production.yaml:5: kix.run/depends-on: '67bgr7ggiw82bhlc2c3ddxma573vpibj,8767b7nzgc1x5bpfa9gv71cpk9z8h0iw,cd3l507fvaf0wg5azfza49x6wjsiiynz,requires:pk4hih6jm4yj336rlaqk2qycz2k46xvs'
./audit-export/how-to-app/PackageInstance-production.yaml:6: kix.run/identity-hash: avvdnz5yy5602xd1095ga9z40qbfkkwc
./audit-export/how-to-app/PackageInstance-production.yaml:8: kix.run/package: _cluster
./audit-export/how-to-app/PackageInstance-production.yaml:9: kix.run/package-namespace: _cluster
./audit-export/how-to-app/PackageInstance-preview.yaml:5: kix.run/depends-on: '8767b7nzgc1x5bpfa9gv71cpk9z8h0iw,91lbws8gjsbxfvr8p7kjx0dc7nzybhqs,requires:pk4hih6jm4yj336rlaqk2qycz2k46xvs'
./audit-export/how-to-app/PackageInstance-preview.yaml:6: kix.run/identity-hash: '84pfjn0kg74qqvp291b01dzd35ngql6z'
./audit-export/how-to-app/PackageInstance-preview.yaml:7: kix.run/package: _cluster
./audit-export/how-to-app/PackageInstance-preview.yaml:8: kix.run/package-namespace: _cluster
./audit-export/how-to-app/ConfigMap-production-health-script.yaml:28: kix.run/depends-on: '8767b7nzgc1x5bpfa9gv71cpk9z8h0iw'
./audit-export/how-to-app/ConfigMap-production-health-script.yaml:29: kix.run/identity-hash: dlzbv1nahmar8f7b9jm6rmyvmqczmzdb
./audit-export/how-to-app/ConfigMap-production-health-script.yaml:30: kix.run/package: production
./audit-export/how-to-app/ConfigMap-production-health-script.yaml:31: kix.run/package-namespace: how-to-app
./audit-export/how-to-app/ConfigMap-production.yaml:8: kix.run/depends-on: '8767b7nzgc1x5bpfa9gv71cpk9z8h0iw'
./audit-export/how-to-app/ConfigMap-production.yaml:9: kix.run/identity-hash: '4x75h2z7rsj3dvrdg9vzqc8l789xvm4w'
./audit-export/how-to-app/ConfigMap-production.yaml:10: kix.run/package: production
./audit-export/how-to-app/ConfigMap-production.yaml:11: kix.run/package-namespace: how-to-app
./audit-export/how-to-app/Job-production-health.yaml:5: kix.run/depends-on: '8767b7nzgc1x5bpfa9gv71cpk9z8h0iw,cd3l507fvaf0wg5azfza49x6wjsiiynz,dlzbv1nahmar8f7b9jm6rmyvmqczmzdb,requires:jh345cnnffy1bnj4cz5x0hwq6ibxvkkr'
./audit-export/how-to-app/Job-production-health.yaml:6: kix.run/identity-hash: '67bgr7ggiw82bhlc2c3ddxma573vpibj'
./audit-export/how-to-app/Job-production-health.yaml:7: kix.run/package: production
./audit-export/how-to-app/Job-production-health.yaml:8: kix.run/package-namespace: how-to-app
./audit-export/how-to-app/Service-production.yaml:5: kix.run/depends-on: '8767b7nzgc1x5bpfa9gv71cpk9z8h0iw,kr7i34wz1ja58c0vf9gizx8161ji0idk'
./audit-export/how-to-app/Service-production.yaml:6: kix.run/identity-hash: cd3l507fvaf0wg5azfza49x6wjsiiynz
./audit-export/how-to-app/Service-production.yaml:7: kix.run/package: production
./audit-export/how-to-app/Service-production.yaml:8: kix.run/package-namespace: how-to-app
./audit-export/how-to-app/Deployment-production.yaml:5: kix.run/depends-on: '4x75h2z7rsj3dvrdg9vzqc8l789xvm4w,8767b7nzgc1x5bpfa9gv71cpk9z8h0iw'
./audit-export/how-to-app/Deployment-production.yaml:6: kix.run/identity-hash: kr7i34wz1ja58c0vf9gizx8161ji0idk
./audit-export/how-to-app/Deployment-production.yaml:7: kix.run/package: production
./audit-export/how-to-app/Deployment-production.yaml:8: kix.run/package-namespace: how-to-app
./audit-export/kube-system/PackageInstance-platform-dns.yaml:5: kix.run/depends-on: sj0fv5bs2hnh9zcqdh62ph34l2wm0b1m,requires:pk4hih6jm4yj336rlaqk2qycz2k46xvs
./audit-export/kube-system/PackageInstance-platform-dns.yaml:6: kix.run/identity-hash: jh345cnnffy1bnj4cz5x0hwq6ibxvkkr
./audit-export/kube-system/PackageInstance-platform-dns.yaml:12: kix.run/package: _cluster
./audit-export/kube-system/PackageInstance-platform-dns.yaml:13: kix.run/package-namespace: _cluster
./audit-export/_cluster/Activation-how-to-application-gb5d6ry45b5l.yaml:6: kix.run/depends-on: '84pfjn0kg74qqvp291b01dzd35ngql6z,avvdnz5yy5602xd1095ga9z40qbfkkwc,jh345cnnffy1bnj4cz5x0hwq6ibxvkkr,requires:gvrlspcfgh9a2qnsx5kqxw9f4l3x52jj'
./audit-export/_cluster/Activation-how-to-application-gb5d6ry45b5l.yaml:7: kix.run/identity-hash: gb5d6ry45b5ll664ahagxldh9na9z3y5
./audit-export/_cluster/Activation-how-to-application-gb5d6ry45b5l.yaml:8: kix.run/package: _cluster
./audit-export/_cluster/Activation-how-to-application-gb5d6ry45b5l.yaml:9: kix.run/package-namespace: _cluster
./audit-export/_cluster/Namespace-how-to-app.yaml:5: kix.run/identity-hash: '8767b7nzgc1x5bpfa9gv71cpk9z8h0iw'
./audit-export/_cluster/Namespace-how-to-app.yaml:6: kix.run/package: _cluster
./audit-export/_cluster/Namespace-how-to-app.yaml:7: kix.run/package-namespace: _cluster
./audit-export/_cluster/CustomResourceDefinition-packageinstances.kix.run.yaml:5: kix.run/identity-hash: pk4hih6jm4yj336rlaqk2qycz2k46xvs
./audit-export/_cluster/CustomResourceDefinition-packageinstances.kix.run.yaml:6: kix.run/package: _cluster
./audit-export/_cluster/CustomResourceDefinition-packageinstances.kix.run.yaml:7: kix.run/package-namespace: _cluster
./audit-export/_cluster/CustomResourceDefinition-activations.kix.run.yaml:5: kix.run/identity-hash: gvrlspcfgh9a2qnsx5kqxw9f4l3x52jj
./audit-export/_cluster/CustomResourceDefinition-activations.kix.run.yaml:6: kix.run/package: _cluster
./audit-export/_cluster/CustomResourceDefinition-activations.kix.run.yaml:7: kix.run/package-namespace: _cluster
./audit-export/_cluster/Namespace-kube-system.yaml:5: kix.run/identity-hash: sj0fv5bs2hnh9zcqdh62ph34l2wm0b1m
./audit-export/_cluster/Namespace-kube-system.yaml:6: kix.run/package: _cluster
./audit-export/_cluster/Namespace-kube-system.yaml:7: kix.run/package-namespace: _cluster The annotations record resource identity, package membership, and dependency edges. The Activation resource provides the root of the rendered deployment graph.
You can also inspect the internal records directly:
❱ find ./audit-export -name 'Activation-*.yaml' -o -name 'PackageInstance-*.yaml'
./audit-export/how-to-app/PackageInstance-production.yaml
./audit-export/how-to-app/PackageInstance-preview.yaml
./audit-export/kube-system/PackageInstance-platform-dns.yaml
./audit-export/_cluster/Activation-how-to-application-gb5d6ry45b5l.yaml Keep audit and handoff exports separate
Section titled “Keep audit and handoff exports separate”Do not use the audit export when another deployment system needs ordinary application manifests. Its internal custom resources and Kix annotations are part of the evidence being preserved.
Use the default mode for that workflow:
❱ kix export how-to-application --out ./handoff