Skip to content

Inspect a deploy receipt

Every successful kix deploy writes a receipt to the active Activation’s status. Read it when you need to establish what was deployed without access to the machine that performed the deployment. To turn the same receipt into a signed provenance document, see Attest a deployment from its cluster receipt.

List the cluster’s Activations. The captured output is the receipt from its active record:

Run in kix-examples/ Output excerpt
❱ kubectl get activations -l kix.run/cluster=how-to-application -o json Show output
{
  "activationHash": "aq1zdgf9gsnbdpc8hwkma69l8ipalqpx",
  "builder": {
    "arch": "aarch64",
    "kixVersion": "0.1.0",
    "nixVersion": "nix (Nix) 2.28.5",
    "os": "macos"
  },
  "cluster": "how-to-application",
  "deployedAt": "2026-09-10T00:22:17Z",
  "images": [
    "docker.io/curlimages/curl:8.14.1@sha256:9a1ed35addb45476afa911696297f8e115993df459278ed036182dd2cd22b67b",
    "docker.io/library/nginx:1.27-alpine"
  ],
  "inputs": [
    {
      "name": "crane",
      "narHash": "sha256-SPm9ck7jh3Un9nwPuMGbRU04UroFmOHjLP56T10MOeM=",
      "rev": "7cf72d978629469c4bd4206b95c402514c1f6000"
    },
    {
      "name": "kixpkgs",
      "narHash": "sha256-OrEgd11s09gUbx0+yXcVLyd7abStxLMmsaFcGwLLMuI=",
      "rev": "6cdd93098a0c27e899e3f66531db6e820cf0507e"
    },
    {
      "name": "nixpkgs",
      "narHash": "sha256-7DKWmH23hL2eYdkxCKeqj2i+yljTKuU+3Nk1UPHOnxc=",
      "rev": "d99b013d5d1931ad77fe3912ed218170dec5d9a4"
    }
  ],
  "schema": "kix.run/receipt/v1",
  "source": {
    "flakeLock": "blake3:f4c2f924573deded25b1facea4477145fe7ed8a7439834058cdecbaaed0a21a7",
    "flakeRef": "kix-examples"
  }
}

The label limits the result to Activations for one Kix cluster. The command returns a Kubernetes List. Use jq to select the active Activation and print its receipt:

❱ kubectl get activations -l kix.run/cluster=how-to-application -o json | jq '.items[] | select(.status.phase == "Active") | .status.receipt'

A deployment that finishes with failures marks its Activation as Degraded, but still records a receipt. When investigating a failed deployment, change the select expression to include both Active and Degraded phases.

If you are inspecting another Kubernetes context, add --context to the kubectl command.

The receipt records these top-level fields:

FieldWhat to check
clusterThe Kix cluster name
activationHashThe identity of the deployed Activation
deployedAtWhen the deployment completed
sourceFlake reference, Git revision, lock-file digest, and dirty-tree state when available
builderKix version, Nix version, operating system, and architecture
inputsLocked flake input revisions and NAR hashes
imagesSorted container image references found in the deployment

If source.dirty is true, the recorded Git commit does not contain the complete tree that was deployed. The revision field carries the corresponding dirty suffix.

Use the receipt’s images list when you are tracing a running workload back to its deployment. An image is recorded exactly as it appeared in the rendered manifests. A reference containing @sha256:... identifies immutable image content; a tag alone records only the tag requested by the deployment.