> ## Documentation Index
> Fetch the complete documentation index at: https://kosli-docs-snapshot-deployment-diffs.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# kosli allow artifact

> Add an artifact to an environment's allowlist.  

## Synopsis

```shell theme={null}
kosli allow artifact [IMAGE-NAME | FILE-PATH | DIR-PATH] [flags]
```

Add an artifact to an environment's allowlist.

The artifact fingerprint can be provided directly with the `--fingerprint` flag, or
calculated based on `--artifact-type` flag.

Artifact type can be one of: "file" for files, "dir" for directories, "oci" for container
images in registries or "docker" for local docker images.

Note: `--artifact-type=docker` reads the image's repo digest via the local Docker daemon.
The image must have been pushed to or pulled from a registry for a repo digest to exist;
a freshly built image (just `docker build`) will not have one. If the image is already in
a registry, prefer `--artifact-type=oci`, which fetches the digest directly from the
registry without needing a local Docker daemon.

For `--artifact-type=oci` (and for `--artifact-type=docker` when `--registry-username`
is set), registry credentials are resolved as follows:

1. If `--registry-username` (and optionally `--registry-password`) is set, it is used directly.
2. Otherwise, credentials are discovered automatically from:
   * the Docker config file (`~/.docker/config.json`, populated by `docker login`)
   * the Podman/containers auth file (`~/.config/containers/auth.json`, or `$REGISTRY_AUTH_FILE`)
   * any Docker credential helper configured in that config (e.g. `docker-credential-ecr-login`
     for AWS ECR, `docker-credential-gcloud` for GCR/Artifact Registry, an ACR helper for Azure,
     or a local keychain helper), invoked as an external binary on `$PATH`
   * if none of the above yield credentials, the registry is accessed anonymously, which works
     for public images
     `--registry-provider` is deprecated and no longer used.

To specify paths in a directory artifact that should always be excluded from the SHA256 calculation, you can add a `.kosli_ignore` file to the root of the artifact.
Each line should specify a relative path or path glob to be ignored. You can include comments in this file, using `#`.
The `.kosli_ignore` file is always treated as part of the artifact: its own entries cannot exclude it, so the exclusion list cannot be changed without changing the fingerprint.
Paths the list already matches stay excluded whatever is later added there, so keep its entries as narrow as possible.
Excluding the file with `--exclude` keeps it out of the fingerprint but still applies the paths it lists, which lets a writable directory change the list again.
To drop the file from the fingerprint safely, move its entries to `--exclude` and delete it.

## Flags

| Flag                    | Type    | Description                                                                                                                                                                                                                                            |
| :---------------------- | :------ | :----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `-t`, `--artifact-type` | string  | The type of the artifact to calculate its SHA256 fingerprint. One of: \[oci, docker, file, dir]. Only required if you want Kosli to calculate the fingerprint for you (i.e. when you don't specify '`--fingerprint`' on commands that allow it).       |
| `-D`, `--dry-run`       | bool    | \[optional] Run in dry-run mode. When enabled, no data is sent to Kosli and the CLI exits with 0 exit code regardless of any errors.                                                                                                                   |
| `-e`, `--environment`   | string  | The environment name for which the artifact is allowlisted.                                                                                                                                                                                            |
| `-x`, `--exclude`       | strings | \[optional] The comma separated list of directories and files to exclude from fingerprinting. Can take glob patterns. Only applicable for `--artifact-type` dir.                                                                                       |
| `-F`, `--fingerprint`   | string  | \[conditional] The SHA256 fingerprint of the artifact. Only required if you don't specify '`--artifact-type`'.                                                                                                                                         |
| `-h`, `--help`          | bool    | help for artifact                                                                                                                                                                                                                                      |
| `--reason`              | string  | The reason why this artifact is allowlisted.                                                                                                                                                                                                           |
| `--registry-password`   | string  | \[conditional] The container registry password or access token. Only required if you want to read container image SHA256 digest from a remote container registry and it is not already accessible via Docker/Podman auth files or a credential helper. |
| `--registry-provider`   | string  | \[deprecated] The docker registry provider or url. Only required if you want to read docker image SHA256 digest from a remote docker registry. (DEPRECATED: no longer used)                                                                            |
| `--registry-username`   | string  | \[conditional] The container registry username. Only required if you want to read container image SHA256 digest from a remote container registry and it is not already accessible via Docker/Podman auth files or a credential helper.                 |

## Flags inherited from parent commands

| Flag                      | Type   | Description                                                                                                                                                           |
| :------------------------ | :----- | :-------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `-a`, `--api-token`       | string | The Kosli API token.                                                                                                                                                  |
| `-c`, `--config-file`     | string | \[optional] The Kosli config file path. Config is read from this path or the default only, never implicitly from the current directory. (default "\$HOME/.kosli.yml") |
| `--debug`                 | bool   | \[optional] Print debug logs to stdout.                                                                                                                               |
| `-H`, `--host`            | string | \[defaulted] The Kosli endpoint. (default "[https://app.kosli.com](https://app.kosli.com)")                                                                           |
| `--http-proxy`            | string | \[optional] The HTTP proxy URL including protocol and port number. e.g. `http://proxy-server-ip:proxy-port`                                                           |
| `-r`, `--max-api-retries` | int    | \[defaulted] How many times should API calls be retried when the API host is not reachable. (default 3)                                                               |
| `--org`                   | string | The Kosli organization.                                                                                                                                               |
| `-q`, `--quiet`           | bool   | \[optional] Suppress non-critical warning messages. Errors and normal output are not affected. If both `--quiet` and `--debug` are set, `--debug` wins.               |
