Skip to content

show policy displays a Policy's target, assertion, message, owning Policy Pack, and source location. It reads the project-selected Policy Pack by default. Repeat --policy-pack with local authoring roots to overlay Policy Packs of the same names for this invocation. Other selected Policy Packs remain active. Use a qualified identifier such as tutorial.policy.subnet-network-context, or a bare name when unambiguous.

Usage

rootform show policy <identifier> [options]
SHELL

Options

Output

FlagTypeDefaultDescription
--formatstring""output format: text|json; default: text

Rootform project

FlagTypeDefaultDescription
--policy-packstringArray[]add or replace the Policy Pack at path, a source directory or a compiled file, for this command only; repeatable
--projectstring""read rootform.lock from project dir; paths stay relative to the working directory; default: the working directory

Global options

FlagTypeDefaultDescription
-h, --helpboolfalseshow how to use rootform show policy
--colormodeautocolor human output: auto|always|never; default: auto
--no-pagerboolfalseprint a long report in full instead of opening it in less

From a checkout of the repository, inspect one baseline definition. The command shows its target and assertion without evaluating a plan.

rootform show policy cluster-network-context --policy-pack ./policy-packs/baseline
rootform show policy baseline.policy.cluster-network-context --policy-pack ./policy-packs/baseline --format json
Shell

The definition names rf.concept.kubernetes-cluster as its target. Text or JSON goes to standard output, diagnostics to standard error. Status 0 means the definition was shown, 1 means the named definition was not found, 2 means the command was used incorrectly, 3 means the selection was unavailable or the name was ambiguous, and 4 means the definition could not be written. This does not evaluate the Policy. Use explain policy with --result to explain an outcome that check recorded in a saved Policy result, or see Understand Policy outcomes for a full report. See the check CLI reference.