Inspect a deploy receipt
Every successful kix deploy writes a receipt to the active Activation’s
status. Read it when you need to establish what was deployed without access to
the machine that performed the deployment. To turn the same receipt into a
signed provenance document, see
Attest a deployment from its cluster receipt.
Read the active receipt
Section titled “Read the active receipt”List the cluster’s Activations. The captured output is the receipt from its active record:
❱ kubectl get activations -l kix.run/cluster=how-to-application -o json Show output
{
"activationHash": "aq1zdgf9gsnbdpc8hwkma69l8ipalqpx",
"builder": {
"arch": "aarch64",
"kixVersion": "0.1.0",
"nixVersion": "nix (Nix) 2.28.5",
"os": "macos"
},
"cluster": "how-to-application",
"deployedAt": "2026-09-10T00:22:17Z",
"images": [
"docker.io/curlimages/curl:8.14.1@sha256:9a1ed35addb45476afa911696297f8e115993df459278ed036182dd2cd22b67b",
"docker.io/library/nginx:1.27-alpine"
],
"inputs": [
{
"name": "crane",
"narHash": "sha256-SPm9ck7jh3Un9nwPuMGbRU04UroFmOHjLP56T10MOeM=",
"rev": "7cf72d978629469c4bd4206b95c402514c1f6000"
},
{
"name": "kixpkgs",
"narHash": "sha256-OrEgd11s09gUbx0+yXcVLyd7abStxLMmsaFcGwLLMuI=",
"rev": "6cdd93098a0c27e899e3f66531db6e820cf0507e"
},
{
"name": "nixpkgs",
"narHash": "sha256-7DKWmH23hL2eYdkxCKeqj2i+yljTKuU+3Nk1UPHOnxc=",
"rev": "d99b013d5d1931ad77fe3912ed218170dec5d9a4"
}
],
"schema": "kix.run/receipt/v1",
"source": {
"flakeLock": "blake3:f4c2f924573deded25b1facea4477145fe7ed8a7439834058cdecbaaed0a21a7",
"flakeRef": "kix-examples"
}
} The label limits the result to Activations for one Kix cluster. The command
returns a Kubernetes List. Use jq to select the active Activation and print
its receipt:
❱ kubectl get activations -l kix.run/cluster=how-to-application -o json | jq '.items[] | select(.status.phase == "Active") | .status.receipt' A deployment that finishes with failures marks its Activation as Degraded,
but still records a receipt. When investigating a failed deployment, change
the select expression to include both Active and Degraded phases.
If you are inspecting another Kubernetes context, add --context to the
kubectl command.
Check the source and builder
Section titled “Check the source and builder”The receipt records these top-level fields:
| Field | What to check |
|---|---|
cluster | The Kix cluster name |
activationHash | The identity of the deployed Activation |
deployedAt | When the deployment completed |
source | Flake reference, Git revision, lock-file digest, and dirty-tree state when available |
builder | Kix version, Nix version, operating system, and architecture |
inputs | Locked flake input revisions and NAR hashes |
images | Sorted container image references found in the deployment |
If source.dirty is true, the recorded Git commit does not contain the
complete tree that was deployed. The revision field carries the corresponding
dirty suffix.
Check the deployed images
Section titled “Check the deployed images”Use the receipt’s images list when you are tracing a running workload back
to its deployment. An image is recorded exactly as it appeared in the rendered manifests. A
reference containing @sha256:... identifies immutable image content; a tag
alone records only the tag requested by the deployment.