Reference
CLI reference
Generated from the source tree by cmd/docsgen. Do not edit: your change would be overwritten on the next run, and the point of this page is that it cannot disagree with the binary.
One binary, several entrypoints. Everything below is walked from the command tree the binary itself prints, so a flag listed here exists and a flag that exists is listed.
garboard export
Render the RCD into a managed block of CLAUDE.md / AGENTS.md / cursor rules
Writes the repository's conventions INSIDE a managed block — between `<!-- garboard:begin … -->` and `<!-- garboard:end -->` — and never touches a byte outside it. A target that does not exist is created with the block; one that exists without a block gets it appended; one that has a block gets that block refreshed. Running it twice changes nothing.
garboard export [path] [flags]
| Flag | Default | What it does |
|---|---|---|
--check | — | write nothing; exit 1 if any target's block is missing or stale (for CI), 0 if every target is up to date |
--format | all | claude-md | agents-md | cursor-rules | all |
--out | . | output directory |
--rcd | — | read this rcd.json instead of scanning (default: .garboard/rcd.json or a fresh scan) |
--stdout | — | print the file as it would be written (existing content merged with a fresh block) instead of writing it; needs a single --format |
garboard gate
Run the review gate over infra files; exit non-zero on a blocking finding (CI/CD)
Runs the same deterministic checks a pull request gets — SecOps + reliability rules on HCL (Terraform/OpenTofu), the Crossplane XRD/Composition/Claim gate on YAML, and the repo's own sandboxed WASM rules from .garboard/rules — and exits 1 when any block-severity finding is present. Offline; no API key required. --plan additionally reads a `terraform show -json` plan artifact (produced by the customer's own credentialed CI step; Deltz never runs terraform and the file never leaves their pipeline) and adds plan.stateful_destroy / plan.stateful_replace / plan.blast_radius findings — the plan wins over any static finding it can attribute to the same resource. --rendered additionally reads `crossplane render` output (a file or directory) and gates the composed managed resources it actually produces, which can differ from a compliant Composition base once patches apply. --rendered-diff <base-dir> <head-dir> compares two rendered trees (the same claims rendered against a base ref and head ref) and flags a changed field the Crossplane immutable table says forces replacement (SPEC §5j). --changed gates the CHANGE in the current directory's git work tree instead of the whole tree: the changed set is committed on the branch since merge-base(--base, HEAD), plus staged, unstaged and untracked files, narrowed to infrastructure paths (and to the pathspecs, when given); the whole tree is still read as context, findings and coverage are narrowed to the changed set exactly as the pull request's are, and a deleted file is a `removed` coverage row. --base defaults to origin/HEAD, then main.
garboard gate [path] | gate --changed [--base <ref>] [pathspec...] | gate --rendered-diff <base-dir> <head-dir> [flags]
| Flag | Default | What it does |
|---|---|---|
--advisory-errors | — | also fail the gate on advisory findings (status becomes blocked, exit 1) |
--allow-incomplete | — | exit 0 instead of 2 when the tree was only PARTLY evaluated (status incomplete). The status and coverage still say incomplete and clean stays false |
--base | — | with --changed: the ref the branch is compared against (default: the remote's default branch, origin/HEAD, then main). |
--changed | — | gate only the files this change touched, computed from git in the current directory: `git diff --name-only <merge-base(--base, HEAD)>..HEAD` plus staged, unstaged and untracked (unignored) files, de-duplicated, sorted, restricted to the positional pathspecs when given and to paths an infrastructure frontend could own. |
--format | human | output format: human | json | json-findings | sarif. json is ONE object on stdout |
--plan | — | path to a `terraform show -json` plan artifact |
--profile | — | also enforce a curated catalog profile, e.g. |
--pulumi-preview | — | path to a `pulumi preview --json` artifact |
--rendered-diff | — | compare two `crossplane render` output directories, given as the two positional args <base-dir> <head-dir> |
--rendered | — | path to a `crossplane render` output file or directory |
--require-complete | — | accepted for compatibility and now the default: an unevaluated document already exits 2. |
--rule | — | also enforce individual catalog rules by id, e.g. |
--rules | — | directory of custom WASM rules (default: <path>/.garboard/rules, skipped when absent) |
--via | — | identify the caller as <skill>@<version> (e.g. |
garboard hook
Harness hook adapters installed by `garboard init --hooks`
garboard hook
garboard hook claude-code
PreToolUse adapter: run the gate before `git push` / `gh pr create` / `glab mr create`
Reads a Claude Code PreToolUse event on stdin. For a Bash command that is a `git push`, `gh pr create` or `glab mr create`, runs `garboard gate --changed --format json` in the event's cwd and: gate exit 0 → prints nothing, exits 0 (the push proceeds) gate exit 1|2 → prints the documented permissionDecision: deny JSON, with the envelope's findings (or what was not evaluated) as the reason, exits 0 — except an exit 2 whose changed set is empty and whose coverage is empty (the push touches no infrastructure): nothing in scope, nothing said, exit 0 gate exit 3 → prints why on stderr, exits 1 (non-blocking: the gate could not run) Any other command, or any other tool, is ignored. This is feedback, not enforcement.
garboard hook claude-code
garboard init
Wire a coding agent (Claude Code, Codex, Cursor) to this repository's review gate
Sets a repository up so a coding agent reads its infrastructure conventions before writing and runs the review gate before pushing. In order, printing each step:
garboard init [path] [flags]
| Flag | Default | What it does |
|---|---|---|
--dry-run | — | print every file that would be written and its diff; write nothing |
--harness | all | claude-code | codex | cursor | all (comma-separated to pick several) |
--hooks | — | also install the pre-commit hook and, for claude-code, the PreToolUse push hook (feedback, not enforcement) |
garboard library
Browse the curated rule catalog shipped with this binary
Lists, searches and explains the lib.* rules this build ships. The catalog is embedded, so every subcommand works offline. Rules are not enforced until an org adopts them; this command only shows what is available and what each rule checks.
garboard library
garboard library adopt
Explain where a rule is adopted, and how to enforce one in CI today
garboard library adopt <rule-id|profile-id>
garboard library ignore
Explain where a rule is declined, and what declining means
garboard library ignore <rule-id>
garboard library list
List catalog rules
garboard library list [flags]
| Flag | Default | What it does |
|---|---|---|
--category | — | filter by category |
--provider | — | filter by provider (aws, azure, gcp) |
--severity | — | filter by severity (critical, warn, info) |
garboard library profiles
List the curated rule bundles this build ships
Profiles are curated, pinned bundles of catalog rules (SPEC §5f-bis) — not filters over the catalog. Pass one to `garboard gate --profile <id>` to enforce it in CI, or adopt it through the server for the hosted review.
garboard library profiles
garboard library recommend
Rank the catalog for one repo: which rules to adopt first, and why
Scores every catalog rule against the Terraform in [dir] (default ".") using facts the parser already produces: which resource types the repo actually uses, how many resources would fail each rule as the tree stands, the rule's severity, and whether a built-in already enforces it. Every line carries the numbers behind its score.
garboard library recommend [dir] [flags]
| Flag | Default | What it does |
|---|---|---|
--all | — | also list the rules that were NOT recommended, with the reason |
--limit | 20 | print at most this many recommendations, and say on stderr how many were held back (0 or less prints all) |
garboard library search
Search rules by rule id, upstream check id, title or body
Searches the embedded catalog with library.Index (WIN-85). The query is free text: the words of the problem ("encryption at rest"), an upstream check id (CKV_AWS_16), or one of our own rule ids. Results are grouped by WHY they matched — an exact upstream id is a different kind of answer from a word found in a body — and the tier is printed so that is visible. Fully offline: no key, no network, and the same query always returns the same order.
garboard library search <query> [flags]
| Flag | Default | What it does |
|---|---|---|
--limit | 10 | maximum results to print (at least 1) |
garboard library show
Show one rule in full: what it checks, why, and where it came from
garboard library show <rule-id>
garboard mcp
Expose the RCD to coding agents over MCP (read-only)
garboard mcp [flags]
| Flag | Default | What it does |
|---|---|---|
--rcd | .garboard/rcd.json | RCD file written by `garboard scan` |
--transport | stdio | stdio (the only transport this build implements; http is served by `garboard serve`) |
garboard plugin
Render the coding-agent plugins (Claude Code, Codex) from this binary
garboard plugin
garboard plugin build
Write <dir>/claude-code and <dir>/codex: skills, hooks and MCP config generated from this binary
Renders a plugin per harness under <dir>, whole, every run:
garboard plugin build <dir> [flags]
| Flag | Default | What it does |
|---|---|---|
--harness | all | claude-code | codex | all (comma-separated to pick several) |
garboard receipt
Work with signed receipts
Verify an exported receipt bundle offline, or generate a signing key. Verification reads only the files you give it — it never contacts the Deltz server, so the check does not depend on the party being audited.
garboard receipt
garboard receipt keygen
Generate an ed25519 receipt signing seed
Prints a new signing seed and its public key. Put the seed in your secret store as GARBOARD_RECEIPT_KEY and publish the public key. This command does NOT write anything: a key this tool could overwrite is a key it could destroy, and regenerating one invalidates verification of every receipt it already signed.
garboard receipt keygen
garboard receipt verify
Verify an exported receipt chain offline
Reads a receipts JSON array (as produced by the evidence bundle) and reports one of four states: verified, unsigned, chain_broken, no_records.
garboard receipt verify <receipts.json> [flags]
| Flag | Default | What it does |
|---|---|---|
--keys | — | published key set JSON (from /.well-known/garboard-receipts.json). |
garboard scan
Parse a repo, derive conventions with evidence, and write its RCD
garboard scan [path] [flags]
| Flag | Default | What it does |
|---|---|---|
--json | — | emit the RCD as JSON |
--no-llm | — | facts-only mode: no network calls except git clone |
--no-recommend | — | skip the catalog-rule suggestions printed after the summary |
--out | .garboard | directory to write rcd.json into |
garboard schema
Manage the pinned provider CRD schema cache (grounds the gate and Forge)
Fetches public, versioned Crossplane provider CRD schemas, pins them to an explicit release tag, and caches a compact index locally. The gate and Forge read only this cache; an empty cache means they behave exactly as without schemas. No cloud credentials are ever used — provider schemas are public metadata.
garboard schema
garboard schema ls
List synced schema packages (pinned version, kind count, skipped files)
garboard schema ls [flags]
| Flag | Default | What it does |
|---|---|---|
--dir | .garboard/schemas | schema cache directory |
garboard schema sync
Fetch and pin a provider package's CRD schemas into the local cache
Downloads the provider's GitHub release tarball at the EXACT tag given by --version (pinning is the point — there is no floating latest), extracts package/crds/*.yaml, and writes a compact schema index under the cache directory. This is the only network call in the schema path; reviews replay deterministically from the cache afterwards.
garboard schema sync [flags]
| Flag | Default | What it does |
|---|---|---|
--dir | .garboard/schemas | schema cache directory |
--lock | schemas.lock | lockfile path (with --locked) |
--locked | — | sync every pin in the lockfile instead of --pkg/--version |
--pkg | crossplane-contrib/provider-upjet-aws | provider package as GitHub owner/repo |
--version | — | release tag to pin, e.g. |
garboard serve
Run the GitHub App webhook + Connect-RPC API server
garboard serve [flags]
| Flag | Default | What it does |
|---|---|---|
--addr | :8080 | listen address |
garboard version
Print the garboard version
garboard version