Override scorecard severity
Use a severity override to promote a finding to an error or reduce it to a
warning or informational result. Valid severities are error, warning, and
info.
This guide assumes the target rule is in the active set. The built-in rules
are, by default; a custom rule must be present under scorecard.rules.
A cluster caps every finding at scorecard.maxSeverity, which defaults to
warning. An override above the cap is reported at the cap, so raising a
rule to error only stops the build once the cap is error as well. See
Fail the build on scorecard findings.
Override one rule everywhere
Section titled “Override one rule everywhere”Use the full rule name under ruleOverrides.byRule:
scorecard = { maxSeverity = "error"; ruleOverrides.byRule."reliability.hasProbes".severity = "error";};Every reliability.hasProbes finding is now an error, so kix check, builds,
and deploys stop when a workload lacks the required probes.
Override selected namespaces or owners
Section titled “Override selected namespaces or owners”Use byNamespace when a policy should differ for part of the cluster:
scorecard.ruleOverrides.byNamespace."kube-system" = { "reliability.hasProbes".severity = "info";};Use byOwner to apply an override to packages whose meta.owner matches the
given value:
scorecard.ruleOverrides.byOwner."platform" = { "reliability.hasProbes".severity = "error";};Namespace and owner keys, as well as rule names within them, may end with *
to match a prefix. Keep exact names when you only need one exception.
Set a default for rules without a severity
Section titled “Set a default for rules without a severity”ruleDefaults.severity applies only when a rule does not declare its own
severity and no override matches:
scorecard.ruleDefaults.severity = "warning";Check the result
Section titled “Check the result”Run the cluster checks and confirm that the finding has the intended severity:
❱ kix check 19-scorecards
TOOL RESULT DETAILS
eval pass 23 manifests evaluated
kubeconform pass skipped (this validation tool is not yet integrated with Kix)
pluto pass skipped (this validation tool is not yet integrated with Kix)
kyverno pass skipped (this validation tool is not yet integrated with Kix)
scorecard pass 0 errors, 6 warnings, 4 info If several overrides match, a direct byRule override wins. Owner overrides
then take precedence over namespace overrides, followed by the rule’s declared
severity and ruleDefaults. The cluster’s maxSeverity cap applies last.