Skip to content

Override scorecard severity

This content is for the v0.1 version. Switch to the latest version for up-to-date documentation.

Use a severity override to promote a finding to an error or reduce it to a warning or informational result. Valid severities are error, warning, and info.

This guide assumes the target rule is in the active set. The built-in rules are, by default; a custom rule must be present under scorecard.rules.

A cluster caps every finding at scorecard.maxSeverity, which defaults to warning. An override above the cap is reported at the cap, so raising a rule to error only stops the build once the cap is error as well. See Fail the build on scorecard findings.

Use the full rule name under ruleOverrides.byRule:

cluster.nix
scorecard = {
maxSeverity = "error";
ruleOverrides.byRule."reliability.hasProbes".severity = "error";
};

Every reliability.hasProbes finding is now an error, so kix check, builds, and deploys stop when a workload lacks the required probes.

Use byNamespace when a policy should differ for part of the cluster:

cluster.nix
scorecard.ruleOverrides.byNamespace."kube-system" = {
"reliability.hasProbes".severity = "info";
};

Use byOwner to apply an override to packages whose meta.owner matches the given value:

cluster.nix
scorecard.ruleOverrides.byOwner."platform" = {
"reliability.hasProbes".severity = "error";
};

Namespace and owner keys, as well as rule names within them, may end with * to match a prefix. Keep exact names when you only need one exception.

Set a default for rules without a severity

Section titled “Set a default for rules without a severity”

ruleDefaults.severity applies only when a rule does not declare its own severity and no override matches:

cluster.nix
scorecard.ruleDefaults.severity = "warning";

Run the cluster checks and confirm that the finding has the intended severity:

Run in kix-examples/
❱ kix check 19-scorecards
 TOOL         RESULT  DETAILS                                                       
 eval         pass    23 manifests evaluated                                        
 kubeconform  pass    skipped (this validation tool is not yet integrated with Kix) 
 pluto        pass    skipped (this validation tool is not yet integrated with Kix) 
 kyverno      pass    skipped (this validation tool is not yet integrated with Kix) 
 scorecard    pass    0 errors, 6 warnings, 4 info

If several overrides match, a direct byRule override wins. Owner overrides then take precedence over namespace overrides, followed by the rule’s declared severity and ruleDefaults. The cluster’s maxSeverity cap applies last.