Generate SLSA provenance
Use kix compliance attest to describe the cluster build as an in-toto
Statement with a SLSA v1 provenance predicate. The command evaluates the
cluster locally and writes the unsigned statement to stdout.
Generate the statement
Section titled “Generate the statement”In CI, identify the builder with the workflow URL and record the run ID:
❱ kix compliance attest 19-scorecards --builder-id "$BUILD_URL" --invocation-id "$BUILD_ID" > provenance.json This captured excerpt uses fixed example identifiers so you can see the main fields:
❱ kix compliance attest 19-scorecards --builder-id https://ci.example/runs/1842 --invocation-id 1842 Show output
{
"_type": "https://in-toto.io/Statement/v1",
"predicateType": "https://slsa.dev/provenance/v1",
"subject": [
{
"digest": {
"nixStoreHash": "a3k1lgi8qq6cniircdpphwc2bc8gj5a4"
},
"name": "cluster-19-scorecards-activation"
}
],
"predicate": {
"buildDefinition": {
"buildType": "https://kix.run/build/v1",
"externalParameters": {
"cluster": "19-scorecards",
"flakeLock": "blake3:8ef54ccce598d282f28fc5a8d2cd4d49842c921b810bdc93ce635335f1fc2836",
"flakeRef": "kix-examples"
},
"resolvedDependencies": [
{
"digest": {
"gitCommit": "7cf72d978629469c4bd4206b95c402514c1f6000",
"narHash": "sha256-SPm9ck7jh3Un9nwPuMGbRU04UroFmOHjLP56T10MOeM="
},
"uri": "flake-input:crane"
},
{
"digest": {
"gitCommit": "9dcf5b3e33b728ef3fc76a693e4feda2921b1913",
"narHash": "sha256-aXiQ4IWL2o/X4k1ZMLapbHKxLdaYDNyBi6qvaigDXLo="
},
"uri": "flake-input:kixpkgs"
}
]
},
"runDetails": {
"builder": {
"id": "https://ci.example/runs/1842"
},
"metadata": {
"finishedOn": "2026-09-20T14:30:53Z",
"invocationId": "1842",
"startedOn": "2026-09-20T14:30:53Z"
}
}
}
}
Building cluster '19-scorecards'...
Evaluating cluster '19-scorecards'...
Reading package index...
Loading store graph...
Reading 5 packages...
Discovering cluster-level resources...
Computing cross-package dependencies... The Activation identity hash is the statement’s subject. The build definition also records the cluster name, flake reference, lock-file digest, Git source, locked flake inputs, and rendered container images.
Verify the statement
Section titled “Verify the statement”Check the statement and predicate types before passing the file to a signing or evidence-upload step:
❱ jq -e '._type == "https://in-toto.io/Statement/v1" and .predicateType == "https://slsa.dev/provenance/v1"' provenance.json If the working tree is dirty, Kix records that state and prints a warning. The statement remains an honest description of the build, but its Git commit does not contain every input that was evaluated.