Generate an audit bundle
Use kix compliance audit when a review or compliance process needs the
cluster’s policy findings and build evidence together. The command evaluates
the cluster locally and writes five files.
Write the bundle
Section titled “Write the bundle”Choose an output directory and, in CI, supply the workflow URL as the builder ID:
❱ kix compliance audit 19-scorecards --out ./compliance --builder-id https://ci.example/runs/1842
Building cluster '19-scorecards'...
Evaluating cluster '19-scorecards'...
Reading package index...
Loading store graph...
Reading 5 packages...
Discovering cluster-level resources...
Computing cross-package dependencies...
Wrote audit bundle to ./compliance
scorecard: 0 errors, 6 warnings, 4 info
framework: SOC 2 The directory contains five files:
❱ find compliance -type f | sort
compliance/assessment-results.json
compliance/audit-report.md
compliance/provenance.json
compliance/sbom.json
compliance/scorecard-results.sarif audit-report.md is the human-readable summary. The other files provide OSCAL
Assessment Results, SLSA provenance, a CycloneDX SBOM, and SARIF scorecard
findings.
Select a framework
Section titled “Select a framework”SOC 2 is the default control mapping. Select another supported framework with
--framework:
❱ kix compliance audit 19-scorecards --out ./compliance-iso27001 --framework iso27001 The accepted values are soc2, iso27001, dora, and nis2.
Replace an existing bundle
Section titled “Replace an existing bundle”Kix refuses to write over an existing output directory. Pass --force when
the job intentionally refreshes that directory:
❱ kix compliance audit 19-scorecards --out ./compliance --force Archive or upload the directory as one CI artifact so the files from a single evaluation remain together.