check is the Policy gate. It evaluates selected Policies against a plan's
Planned architecture, a state's Recorded architecture, or both sides of a
comparison Form by default, then exits with one verdict. The input is a
plan or state export, compiled with the project's Dialects, or a saved Form,
loaded without compiling it again. check never serves, never changes the
Form, and writes a Policy result that is separate from the Form.
rootform check <input> [options]From a checkout of the repository, save the reviewed commerce plan as a Form, then check it against the example Policy Pack and keep every report:
rootform run examples/playground/commerce-platform/head/plan.json \ --plan-file examples/playground/commerce-platform/head/plan.tfplan \ --no-serve -o analysis.jsonrootform check analysis.json --policy-pack policy-packs/baseline \ -o results.json -o report.md -o results.sarifPolicy check completed
Input analysis.jsonOrigin Plan (saved Form)Stage PlannedPolicies 2 selected
Evaluations 2Passed 2Violated 0Indeterminate 0
Verdict PASSED
All selected evaluations passed.Loading analysis.json (saved Form; no recompilation) on standard error
confirms that the saved Form was evaluated as written. results.json is the
Policy result, report.md the review report, and results.sarif a SARIF
2.1.0 log. Each report is written whatever the verdict.
A plan is checked on Planned and a state on Recorded. A comparison Form is
checked on both Before and After by default, each at the stage selected in the
saved comparison for that side. --side before or --side after limits the check to
one side; --side both names the default. --stage selects another stage of
the input, or of the one side a comparison check names with --side before or
--side after: refreshed when the plan has one, never a plan's
reconstructed recorded stage. An absent stage stops the check with
STAGE_UNAVAILABLE; Rootform never falls back to another stage. Comparisons,
drift, and the drift report are never evaluated as architectures.
The active Policy Packs come from rootform.lock. --policy-pack adds or
replaces one pack for this command without changing the lock, and --locked
refuses it. Without --policy, check selects every Policy of the
--policy-pack packs, or every Policy of every active pack when none is
given. Each --policy selector (PACK/*, PACK/NAME, PACK.policy.NAME,
or a unique NAME) narrows that selection before anything is linked; an
unknown or ambiguous selector exits 2. Only packs holding a selected Policy
are linked, against the semantics recorded in the Form.
Reports name each Policy by the identity list and show print,
PACK.policy.NAME; SARIF rule IDs keep PACK/NAME. A violation or an
indeterminate evaluation lists the Policy, the resource, the Requirement the
Policy declares, and the recorded Evidence that decided it.
Each requested report records the Policy result or review format for this
check. See Outputs and exit status for exact formats,
-o and --format behavior, stream separation, and output failures.
A violation takes precedence over indeterminate results. Standard output
states the verdict once, in the summary or in the --format output. Standard
error carries progress, plus a code when the check stops before evaluating,
such as STAGE_UNAVAILABLE or POLICY_UNAVAILABLE, or when a report cannot
be written (OUTPUT_FAILED).
Understand Policy outcomes walks through each
outcome, and Policies and Policy Packs explains
what a result proves.