Skip to content

cub run vet-disruption

cub run vet-disruption

Validates how disruptive a pending change is, by comparing registered per-severity paths against the last-applied revision. Registering a path under disruption-critical / -high / -medium / -low grades a change to it; the score-threshold decides which severities fail. Unlike vet-immutable this is graded rather than binary, so one rule can block a destructive change while merely reporting a benign one. Validation passes when there is no baseline, because creating a resource is not replacing one. Validating. Supported toolchains: AppConfig/Env, AppConfig/INI, AppConfig/JSON, AppConfig/Properties, AppConfig/TOML, AppConfig/Text, AppConfig/YAML, ConfigHub/YAML, Kubernetes/YAML

cub run vet-disruption [flags]

Options

      --attribute-prefix string   Prefix of the per-severity attributes whose registered paths are checked; "disruption" by default, meaning disruption-critical, disruption-high, disruption-medium and disruption-low.
  -h, --help                      help for vet-disruption
      --score-threshold string    (required) Fail when a change's disruption reaches this severity or worse. Possible values: "Critical", "High", "Medium", "Low".

Options inherited from parent commands

      --change-desc string      change description
      --changeset string        changeset to associate units with
      --context string          The context to use for this command
      --debug                   Debug output
      --dry-run                 dry run mode: execute functions but skip updating configuration data
      --executor-space string   Space ID or slug whose executor to use for builtin functions (org-level only)
      --filter string           filter to apply (slug, space/filter, or UUID)
      --livestate-type string   Invoke the function on the live state and use the flag value as the toolchain type for live state.
  -o, --output string           Output format. One of: json, yaml, name, wide, mutations, jq=<expr>, yq=<expr>, custom-columns=<spec>
      --preserve-protection     keep the stored protection of the paths this change writes instead of recording new ones: each path keeps the protection it already has, and a new path is left unprotected
      --quiet                   No output
      --resource-type string    resource-type filter
      --show string             Select which part of the function response to display. One of: output, values, data
      --space string            space ID to perform command on
      --toolchain string        Toolchain type for the function invocations (default "Kubernetes/YAML")
      --unit strings            target specific units by slug or UUID (can be repeated or comma-separated)
      --wait                    wait for completion
      --where string            where filter
      --where-data string       where data filter
      --where-resource string   filter which resources the function operates on
      --worker string           worker to execute the function

SEE ALSO