cub run vet-disruption
cub run vet-disruption
Validates how disruptive a pending change is, by comparing registered per-severity paths against the last-applied revision. Registering a path under disruption-critical / -high / -medium / -low grades a change to it; the score-threshold decides which severities fail. Unlike vet-immutable this is graded rather than binary, so one rule can block a destructive change while merely reporting a benign one. Validation passes when there is no baseline, because creating a resource is not replacing one. Validating. Supported toolchains: AppConfig/Env, AppConfig/INI, AppConfig/JSON, AppConfig/Properties, AppConfig/TOML, AppConfig/Text, AppConfig/YAML, ConfigHub/YAML, Kubernetes/YAML
cub run vet-disruption [flags]
Options
--attribute-prefix string Prefix of the per-severity attributes whose registered paths are checked; "disruption" by default, meaning disruption-critical, disruption-high, disruption-medium and disruption-low.
-h, --help help for vet-disruption
--score-threshold string (required) Fail when a change's disruption reaches this severity or worse. Possible values: "Critical", "High", "Medium", "Low".
Options inherited from parent commands
--change-desc string change description
--changeset string changeset to associate units with
--context string The context to use for this command
--debug Debug output
--dry-run dry run mode: execute functions but skip updating configuration data
--executor-space string Space ID or slug whose executor to use for builtin functions (org-level only)
--filter string filter to apply (slug, space/filter, or UUID)
--livestate-type string Invoke the function on the live state and use the flag value as the toolchain type for live state.
-o, --output string Output format. One of: json, yaml, name, wide, mutations, jq=<expr>, yq=<expr>, custom-columns=<spec>
--preserve-protection keep the stored protection of the paths this change writes instead of recording new ones: each path keeps the protection it already has, and a new path is left unprotected
--quiet No output
--resource-type string resource-type filter
--show string Select which part of the function response to display. One of: output, values, data
--space string space ID to perform command on
--toolchain string Toolchain type for the function invocations (default "Kubernetes/YAML")
--unit strings target specific units by slug or UUID (can be repeated or comma-separated)
--wait wait for completion
--where string where filter
--where-data string where data filter
--where-resource string filter which resources the function operates on
--worker string worker to execute the function
SEE ALSO
- cub run - invoke a function