Skip to main content

Synopsis

Add an artifact to an environment’s allowlist. The artifact fingerprint can be provided directly with the --fingerprint flag, or calculated based on --artifact-type flag. Artifact type can be one of: “file” for files, “dir” for directories, “oci” for container images in registries or “docker” for local docker images. Note: --artifact-type=docker reads the image’s repo digest via the local Docker daemon. The image must have been pushed to or pulled from a registry for a repo digest to exist; a freshly built image (just docker build) will not have one. If the image is already in a registry, prefer --artifact-type=oci, which fetches the digest directly from the registry without needing a local Docker daemon. For --artifact-type=oci (and for --artifact-type=docker when --registry-username is set), registry credentials are resolved as follows:
  1. If --registry-username (and optionally --registry-password) is set, it is used directly.
  2. Otherwise, credentials are discovered automatically from:
    • the Docker config file (~/.docker/config.json, populated by docker login)
    • the Podman/containers auth file (~/.config/containers/auth.json, or $REGISTRY_AUTH_FILE)
    • any Docker credential helper configured in that config (e.g. docker-credential-ecr-login for AWS ECR, docker-credential-gcloud for GCR/Artifact Registry, an ACR helper for Azure, or a local keychain helper), invoked as an external binary on $PATH
    • if none of the above yield credentials, the registry is accessed anonymously, which works for public images --registry-provider is deprecated and no longer used.
To specify paths in a directory artifact that should always be excluded from the SHA256 calculation, you can add a .kosli_ignore file to the root of the artifact. Each line should specify a relative path or path glob to be ignored. You can include comments in this file, using #. The .kosli_ignore file is always treated as part of the artifact: its own entries cannot exclude it, so the exclusion list cannot be changed without changing the fingerprint. Paths the list already matches stay excluded whatever is later added there, so keep its entries as narrow as possible. Excluding the file with --exclude keeps it out of the fingerprint but still applies the paths it lists, which lets a writable directory change the list again. To drop the file from the fingerprint safely, move its entries to --exclude and delete it.

Flags

Flags inherited from parent commands

Last modified on September 11, 2026