Skip to content

Validate a Policy definition.

Usage

rootform validate policy <identifier> [options]
SHELL

Options

FlagTypeDefaultDescription
--dialectstringArray[]use Dialect source dir for this command only; repeatable
--formatstring""output format: text|json; default: text
--policy-packstringArray[]add or replace the Policy Pack at path, a source directory or a compiled file, for this command only; repeatable
--projectstring""read rootform.lock from project dir; paths stay relative to the working directory; default: the working directory

Global options

FlagTypeDefaultDescription
-h, --helpboolfalseshow how to use rootform validate policy
--colormodeautocolor human output: auto|always|never; default: auto
--no-pagerboolfalseprint a long report in full instead of opening it in less

Behavior

Validate a Policy definition in its selected Policy Pack.

The project must select the Policy Pack that owns the Policy, or --policy-pack must name its source directory for this command only. Use <policy-pack>.policy.<name>, <policy-pack>/<name>, or a bare name when it resolves unambiguously.

The text or JSON result goes to standard output. Diagnostics go to standard error.

Exit status

StatusDescription
0the definition is valid
1the definition is not valid, or no definition has that name
2the command was used incorrectly
3rootform.lock is invalid or the name is ambiguous
4rootform.lock or definitions could not be read, or the report could not be written

Examples

rootform validate policy baseline.policy.cluster-network-context
rootform validate policy cluster-network-context
rootform validate policy cluster-network-context --policy-pack ./policies
rootform validate policy baseline.policy.cluster-network-context --format json
Shell