Skip to content

Generate SLSA provenance

This content is for the v0.1 version. Switch to the latest version for up-to-date documentation.

Use kix compliance attest to describe the cluster build as an in-toto Statement with a SLSA v1 provenance predicate. The command evaluates the cluster locally and writes the unsigned statement to stdout.

In CI, identify the builder with the workflow URL and record the run ID:

Run in kix-examples/
❱ kix compliance attest 19-scorecards --builder-id "$BUILD_URL" --invocation-id "$BUILD_ID" > provenance.json

This captured excerpt uses fixed example identifiers so you can see the main fields:

Run in kix-examples/ Output excerpt
❱ kix compliance attest 19-scorecards --builder-id https://ci.example/runs/1842 --invocation-id 1842 Show output
{
  "_type": "https://in-toto.io/Statement/v1",
  "predicateType": "https://slsa.dev/provenance/v1",
  "subject": [
    {
      "digest": {
        "nixStoreHash": "a3k1lgi8qq6cniircdpphwc2bc8gj5a4"
      },
      "name": "cluster-19-scorecards-activation"
    }
  ],
  "predicate": {
    "buildDefinition": {
      "buildType": "https://kix.run/build/v1",
      "externalParameters": {
        "cluster": "19-scorecards",
        "flakeLock": "blake3:8ef54ccce598d282f28fc5a8d2cd4d49842c921b810bdc93ce635335f1fc2836",
        "flakeRef": "kix-examples"
      },
      "resolvedDependencies": [
        {
          "digest": {
            "gitCommit": "7cf72d978629469c4bd4206b95c402514c1f6000",
            "narHash": "sha256-SPm9ck7jh3Un9nwPuMGbRU04UroFmOHjLP56T10MOeM="
          },
          "uri": "flake-input:crane"
        },
        {
          "digest": {
            "gitCommit": "9dcf5b3e33b728ef3fc76a693e4feda2921b1913",
            "narHash": "sha256-aXiQ4IWL2o/X4k1ZMLapbHKxLdaYDNyBi6qvaigDXLo="
          },
          "uri": "flake-input:kixpkgs"
        }
      ]
    },
    "runDetails": {
      "builder": {
        "id": "https://ci.example/runs/1842"
      },
      "metadata": {
        "finishedOn": "2026-09-20T14:30:53Z",
        "invocationId": "1842",
        "startedOn": "2026-09-20T14:30:53Z"
      }
    }
  }
}
Building cluster '19-scorecards'...
  Evaluating cluster '19-scorecards'...
  Reading package index...
  Loading store graph...
  Reading 5 packages...
  Discovering cluster-level resources...
  Computing cross-package dependencies...

The Activation identity hash is the statement’s subject. The build definition also records the cluster name, flake reference, lock-file digest, Git source, locked flake inputs, and rendered container images.

Check the statement and predicate types before passing the file to a signing or evidence-upload step:

Run in kix-examples/
❱ jq -e '._type == "https://in-toto.io/Statement/v1" and .predicateType == "https://slsa.dev/provenance/v1"' provenance.json

If the working tree is dirty, Kix records that state and prints a warning. The statement remains an honest description of the build, but its Git commit does not contain every input that was evaluated.