Compare Puppet catalogs from PuppetDB against candidates compiled for the change under test
409
Puppet Impact Assessment & Change Explorer. Compare the catalog PuppetDB holds for a node against a catalog compiled for a candidate environment, and report exactly what a change does before it reaches an agent.
One statically linked, CGO-free binary. No Ruby, no Puppet agent, no Facter, no package manager, and no dependency resolution at run time.
| Tag | Contents |
|---|---|
0.2.1, latest | linux/amd64 and linux/arm64 |
<major>.<minor>.<patch> | Every release. Pin one in CI |
latest moves with every full release and never with a prerelease.
gcr.io/distroless/static-debian12:nonroot plus one binary. No shell, no
package manager, no git. The CA bundle is there because piace explain
verifies an inference service against the system roots; the compiler and
PuppetDB transports trust only the CA bundle named in your own services file.
/usr/local/bin/piace/worknonroot, uid 65532The binary is not compiled during the image build. It is the release artifact published on GitHub, byte for certifies, copied in.
It runs as a non-root user our workspace there and pass your own uid. Without both, writing a report into the mount fails with a permission error.
docker run --rm \
--user "$(id -u):$(id -g)"
--volume "$PWD:/work" \
example42/piace:0.2.1 \
compare --targets targets.yaml --services services.yaml \
--json-out report.j
The optional, advisory change assessment is a second, independent step over a stored result document. It iscontacts anything other than your compiler and PuppetDB:
docker run --rm \
--user "$(id -u):$(id -g)" \
--volume "$PWD:/work" \
--env PIACE_INFERENCE_TOKEN \
example42/piace:0.2.1 \
explain --json-in report.json --services services-explain.yaml \
--ai-out assessmentml
Every path inside targets.yaml and services.yaml (CA bundle, client
certificate, private key, snaesolved inside the
container, so keep them under the mount. TLS paths in a services file
resolve against the process wnst the file itself.
| Code | Meaning |
|---|---|
0 | No differences, or al |
10 | A fail_on_diff target had a non-excluded difference |
20 | A candidate did not r environment did not verify |
30 | Config, TLS, retrieval, snapshot or normalization failure |
It has no shell, and its entrypoint is the binary. GitLab's docker executor
runs a job script by passing e, and GitHub Actions
container: jobs expect a shell too, so neither can use this image as a job
image. In a pipeline, installry into whatever image
your job already uses. See
docs/ci.md for
copy-ready GitHub Actions and GitLab CI jobs.
docker run --rm example42/pia
The reported version comes from the -X main.toolVersion stamp the release
workflow applied and assertedand again on the image
before pushing it. For the binaries and their checksum manifest, see
docs/release.md.
Content type
Image
Digest
sha256:2e7c080b3…
Size
4 MB
Last updated
25 days ago
docker pull example42/piace