Pass a Policy name and the JSON Policy result written by rootform check as
--result. The explanation reports why the Policy passed, was violated,
remained indeterminate, or had no target: the Requirement the Policy declares,
with its assertion and target, then each evaluation's recorded evidence and
conclusion. Nothing is evaluated again. Name the Policy by the identity list
and show print, <pack>.policy.<name>, or as PACK/NAME or an
unambiguous bare name.
For a comparison result, --side before or --side after selects one recorded
side; the default covers every recorded side.
Optional --input reads the Form as run does and describes the evidence
inspected by the recorded evaluation. Its Form digest must match the digest
in the Policy result. Omit --input to inspect the recorded outcome alone;
the explanation then says which evidence the result cannot describe and how to
pass the Form. A Form with a different digest is refused.
rootform explain policy <policy> --result <file> [options]From the commerce plan, save a Form, check it, and explain one recorded Policy outcome:
rootform run examples/playground/commerce-platform/head/plan.json \ --plan-file examples/playground/commerce-platform/head/plan.tfplan \ --no-serve -o analysis.jsonrootform check analysis.json --policy-pack policy-packs/baseline \ -o results.json --color alwaysrootform explain policy baseline.policy.cluster-network-context \ --result results.json --input analysis.json --color alwaysPolicy explainedPolicy baseline.policy.cluster-network-contextResult results.jsonInput analysis.jsonEvaluations 1Passed 1Outcome PASSEDRequirement Kubernetes clusters must belong to a network context. Assertion exists(contexts(rf.context.network, rf.concept.virtual-network)) || exists(contexts(rf.context.network, rf.concept.subnet)) Target Concept rf.concept.kubernetes-clusterThe evaluation passed.The explanation goes to standard output, while progress and errors go to
standard error. Status 0 means the Policy outcome was explained; 1 means
the result records no Policy with that name; 2 means incorrect usage; 3
means the result or input was refused, the name is ambiguous, the side is not
recorded, the check recorded no outcome for this Policy, or the input is not
the Form the result was computed from; 4 means the result or input file
could not be read. To inspect the definition, use
show policy. For evaluation, see the
check CLI reference.