pulumi policy analyze | CLI commands
Generated for Pulumi CLI v3.253.0.
Analyze existing resource state against policy packs
Synopsis
Analyze existing resource state against one or more local policy packs.
This command runs policy analysis against existing resource state without
executing the Pulumi program or making provider calls. Pass –stack to analyze
a stack (defaulting to the current stack), or –file to analyze a state file
(as produced by pulumi stack export) without requiring a stack or backend login.
Secrets in the file that can’t be decrypted offline are redacted to the
string [secret] for analysis, regardless of their original type.
If any remediation policy fires, the change is reported but the state is not modified. Exits with a non-zero status if any mandatory violations are found.
pulumi policy analyze [flags]
Options
--diff Display policy diagnostics as a rich diff instead of grouped progress output
--file pulumi stack export Analyze a state file (as produced by pulumi stack export) instead of a live stack
-h, --help help for analyze
-j, --json Serialize policy analysis events as JSON
--policy-pack stringArray Path to a policy pack to run during analysis
--policy-pack-config stringArray Path to a JSON config file for the corresponding --policy-pack
-s, --stack string The name of the stack to analyze. Defaults to the current stack
Options inherited from parent commands
--color string Colorize output. Choices are: always, never, raw, auto (default "auto")
-C, --cwd string Run pulumi as if it had been started in another directory
--disable-integrity-checking Disable integrity checking of checkpoint files
-e, --emoji Enable emojis in the output
-Q, --fully-qualify-stack-names Show fully-qualified stack names
--logflow Flow log settings to child processes (like plugins)
--logtostderr Log to stderr instead of to files
--memprofilerate int Enable more precise (and expensive) memory allocation profiles by setting runtime.MemProfileRate
--non-interactive Disable interactive mode for all commands
--otel-traces string Export OpenTelemetry traces to the specified endpoint. Use file:// for local JSON files, grpc:// for remote collectors
--profiling string Emit CPU and memory profiles and an execution trace to '[filename].[pid].{cpu,mem,trace}', respectively
--tracing file: Emit tracing to the specified endpoint. Use the file: scheme to write tracing data to a local file
-v, --verbose int Enable verbose logging (e.g., v=3); anything >3 is very verbose
SEE ALSO
- pulumi policy - Manage resource policies