Skip to content

Latest commit

 

History

History
144 lines (117 loc) · 5.05 KB

File metadata and controls

144 lines (117 loc) · 5.05 KB
title kosli evaluate input
tag BETA
description Evaluate a local JSON input against a Rego policy.

import CliBetaNotice from "/snippets/cli-beta-notice.mdx";

Synopsis

kosli evaluate input [flags]

Evaluate a local JSON input against a Rego policy. Read JSON from a file or stdin and evaluate it against a Rego policy. The input file should contain the raw JSON object your policy expects — not the wrapper produced by --show-input. Use jq '.input' to extract the policy input from a --show-input --output json capture.

The policy must use package policy and define an allow rule. An optional violations rule (a set of strings) can provide human-readable denial reasons.

By default a deny exits with code 1. Pass --no-assert to print the verdict and exit 0 even on deny, when this command is feeding another tool as a policy decision point.

When --input-file is omitted, JSON is read from stdin.

Use --params to pass configuration data to the policy as data.params. This accepts inline JSON or a file reference (@file.json).

Flags

Flag Type Description
--assert bool [optional] Exit with a non-zero status when the policy denies. This is the current default; pass --assert to lock it in across future releases.
-h, --help bool help for input
-i, --input-file string [optional] Path to a JSON input file. Reads from stdin if omitted.
--no-assert bool [optional] Print the result and always exit 0, even when the policy denies. Use when this command feeds another tool as a policy decision point.
-o, --output string [defaulted] The format of the output. Valid formats are: [table, json]. (default "table")
--params string [optional] Policy parameters as inline JSON or @file.json. Available in policies as data.params.
-p, --policy string Path or http(s):// URL of a Rego policy to evaluate against the input.
--show-input bool [optional] Include the policy input data in the output.

Flags inherited from parent commands

Flag Type Description
-a, --api-token string The Kosli API token.
-c, --config-file string [optional] The Kosli config file path. Config is read from this path or the default only, never implicitly from the current directory. (default "$HOME/.kosli.yml")
--debug bool [optional] Print debug logs to stdout.
-H, --host string [defaulted] The Kosli endpoint. (default "https://app.kosli.com")
--http-proxy string [optional] The HTTP proxy URL including protocol and port number. e.g. http://proxy-server-ip:proxy-port
-r, --max-api-retries int [defaulted] How many times should API calls be retried when the API host is not reachable. (default 3)
--org string The Kosli organization.
-q, --quiet bool [optional] Suppress non-critical warning messages. Errors and normal output are not affected. If both --quiet and --debug are set, --debug wins.

Live Examples in different CI systems

View an example of the `kosli evaluate input` command in GitHub.
In [this YAML file](https://github.com/cyber-dojo/snyk-scanning/blob/30111f180ac4e3611cdbd7d805381a0bb9f53cff/tests/test_rego_rules.sh#L304)
</Tab>

Examples Use Cases

These examples all assume that the flags --api-token, --org, --host, (and --flow, --trail when required), are set/provided.

```shell kosli evaluate trail TRAIL --flow FLOW --policy allow-all.rego --show-input --output json | jq '.input' > trail-data.json
</Accordion>
<Accordion title="then iterate on your policy locally">
```shell
kosli evaluate input 
	--input-file trail-data.json 
	--policy policy.rego

```shell kosli evaluate input --input-file trail-data.json --policy policy.rego --show-input --output json
</Accordion>
<Accordion title="read input from stdin">
```shell
cat trail-data.json | kosli evaluate input 
	--policy policy.rego

```shell kosli evaluate input --input-file trail-data.json --policy policy.rego --params '{"threshold": 3}'
</Accordion>
<Accordion title="evaluate with policy parameters from a file">
```shell
kosli evaluate input 
	--input-file trail-data.json 
	--policy policy.rego 
	--params @params.json

```shell kosli evaluate input --input-file trail-data.json --policy https://policies.example.com/policy.rego
</Accordion>
<Accordion title="evaluate as a decision point (print verdict, never fail the step)">
```shell
kosli evaluate input 
	--input-file trail-data.json 
	--policy policy.rego 
	--no-assert