Skip to content

Fail the build on scorecard findings

This content is for the v0.1 version. Switch to the latest version for up-to-date documentation.

The scorecard runs on every cluster by default, and every finding is capped at scorecard.maxSeverity. The default cap is warning: kix check prints what the rules found, and the cluster still builds. Raise the cap to error when a finding from an error-severity rule should stop the build.

This guide assumes the cluster is defined with kix.buildCluster.

Set the option in the cluster definition:

cluster.nix
scorecard.maxSeverity = "error";

Rules that declare severity = "error", and rules raised to it through ruleOverrides, now fail evaluation at the first finding. Warnings and informational findings are unaffected.

Put the setting in clusterModules so each cluster starts from it:

flake.nix
outputs = inputs: inputs.kixpkgs.lib.mkFlake {
inherit inputs;
clusters.production = ./clusters/production.nix;
clusterModules = [ { scorecard.maxSeverity = "error"; } ];
};

A cluster that needs the default back sets scorecard.maxSeverity = lib.mkForce "warning" in its own modules.

Run the cluster checks:

Run in infrastructure/
❱ kix check production

With the cap raised, an error-severity finding ends the run with a failed assertion that names the rule and the resource. Fix the resource, disable the rule for that package, or lower the rule’s severity with an override.