Policy Gate
Purpose
Policy Gate — Assurance surface.
When to use it
- Operate Policy Gate when your job matches this surface
- Prefer dry-run / doctor before mutating repairs on disks
- Shut down the guest before write operations
How to get there
- Doc id:
policy - Nav: Assurance → Policy Gate
- Primary interface:
guestkit policy check IMAGE
Operate from CLI / TUI (UX)
guestkit policy check IMAGE.policy check IMAGE --example-policy.policy check IMAGE --policy FILE.yaml.- Or
--benchmark cis. -f json -o report.json.- Gate pipelines on non-zero /
--strict; pair with passport verify. - Empty / fail: Missing policy file; expressions fail if evidence fields absent.
- Success: Pass/fail per rule; JSON report written.
Host needs Linux + qemu-img / losetup / qemu-nbd; mount/repair often need root. GuestKit does not invent disk contents.