Skip to content

Add Policy Packs to rootform.lock.

Usage

rootform add policy-packs <source>... [options]
SHELL

Options

FlagTypeDefaultDescription
--dry-runboolfalseprint the planned change and write nothing
--formatstring""output format: text|json; default: text
--offlineboolfalseuse no network; accept local and installed sources
--projectstring""change rootform.lock and vendored copies in project dir; paths stay relative to the working directory; default: the working directory

Global options

FlagTypeDefaultDescription
-h, --helpboolfalseshow how to use rootform add policy-packs
--colormodeautocolor human output: auto|always|never; default: auto
--no-pagerboolfalseprint a long report in full instead of opening it in less

Behavior

Add Policy Packs to rootform.lock. Each source is a local directory (./path) or a registry reference with a tag or digest.

Rootform compiles and verifies every source, records its exact identity, and writes rootform.lock once, or not at all. A registry source is installed in the Rootform home. A tag is resolved once and never recorded.

When the project vendors this family under .rootform/, the vendored copy changes together with rootform.lock.

The summary goes to standard output. Diagnostics go to standard error.

Exit status

StatusDescription
0rootform.lock matches the request
1a source is invalid or a named selection is absent
2the command was used incorrectly
3rootform.lock is invalid, selections conflict, or --offline needs content that is not installed
4a file, Rootform home, or network operation failed

Examples

rootform add policy-packs ./policies
rootform add policy-packs \
registry.example.com/acme/policies:policy-pack-baseline-0.1.0
rootform add policy-packs ./policies --dry-run
Shell