Skip to content

Attest a deployment from its cluster receipt

This content is for the v0.1 version. Switch to the latest version for up-to-date documentation.

Use --from-cluster when the attestation must describe what Kix deployed, rather than a fresh evaluation of the repository. Kix reads the receipt from the active Activation and turns it into an in-toto Statement with a SLSA v1 provenance predicate.

This guide assumes Kix has deployed the cluster at least once and your current Kubernetes context can read its Activation resources.

Pass the same cluster name used for deployment:

Run in kix-examples/ Output excerpt
❱ kix compliance attest how-to-application --from-cluster --builder-id https://ci.example/runs/1842 --invocation-id 1842 Show output
{
  "_type": "https://in-toto.io/Statement/v1",
  "predicateType": "https://slsa.dev/provenance/v1",
  "subject": [
    {
      "digest": {
        "nixStoreHash": "aq1zdgf9gsnbdpc8hwkma69l8ipalqpx"
      },
      "name": "cluster-how-to-application-activation"
    }
  ],
  "buildDefinition": {
    "buildType": "https://kix.run/build/v1",
    "externalParameters": {
      "cluster": "how-to-application",
      "flakeLock": "blake3:f4c2f924573deded25b1facea4477145fe7ed8a7439834058cdecbaaed0a21a7",
      "flakeRef": "kix-examples"
    },
    "resolvedDependencyCount": 5
  },
  "runDetails": {
    "builder": {
      "id": "https://ci.example/runs/1842"
    },
    "metadata": {
      "finishedOn": "2026-09-10T00:21:13Z",
      "invocationId": "1842",
      "startedOn": "2026-09-10T00:21:13Z"
    }
  }
}

--builder-id should identify the system producing the attestation. In CI, a workflow run URL is a useful value. --invocation-id identifies the specific run. Both flags are optional.

The output excerpt shows the statement type, subject, build parameters, and run details. The full statement also contains the source revision, locked flake inputs, and image references recorded at deploy time.

Redirect stdout when the statement will be stored or signed by another tool:

❱ kix compliance attest how-to-application --from-cluster --builder-id "$CI_RUN_URL" --invocation-id "$CI_RUN_ID" > provenance.json

Kix writes an unsigned JSON statement. Signing and publishing can be handled by the attestation system used by your CI environment.

Confirm that the subject names the deployed cluster and has an activation digest:

❱ jq -e '.predicate.buildDefinition.externalParameters.cluster == "how-to-application" and (.subject[0].digest.nixStoreHash | length) > 0' provenance.json

If Kix reports that no receipt exists, deploy the cluster again with a Kix version that writes receipts. If it cannot find an Activation CRD, confirm the Kubernetes context and cluster name before retrying.