Skip to content

Generate an audit bundle

This content is for the v0.1 version. Switch to the latest version for up-to-date documentation.

Use kix compliance audit when a review or compliance process needs the cluster’s policy findings and build evidence together. The command evaluates the cluster locally and writes five files.

Choose an output directory and, in CI, supply the workflow URL as the builder ID:

Run in kix-examples/
❱ kix compliance audit 19-scorecards --out ./compliance --builder-id https://ci.example/runs/1842
Building cluster '19-scorecards'...
  Evaluating cluster '19-scorecards'...
  Reading package index...
  Loading store graph...
  Reading 5 packages...
  Discovering cluster-level resources...
  Computing cross-package dependencies...

  Wrote audit bundle to ./compliance
    scorecard: 0 errors, 6 warnings, 4 info
    framework: SOC 2

The directory contains five files:

Run in kix-examples/
❱ find compliance -type f | sort
compliance/assessment-results.json
compliance/audit-report.md
compliance/provenance.json
compliance/sbom.json
compliance/scorecard-results.sarif

audit-report.md is the human-readable summary. The other files provide OSCAL Assessment Results, SLSA provenance, a CycloneDX SBOM, and SARIF scorecard findings.

SOC 2 is the default control mapping. Select another supported framework with --framework:

Run in kix-examples/
❱ kix compliance audit 19-scorecards --out ./compliance-iso27001 --framework iso27001

The accepted values are soc2, iso27001, dora, and nis2.

Kix refuses to write over an existing output directory. Pass --force when the job intentionally refreshes that directory:

Run in kix-examples/
❱ kix compliance audit 19-scorecards --out ./compliance --force

Archive or upload the directory as one CI artifact so the files from a single evaluation remain together.