v0.4.0

Deploy

CI NHIM gate

Merge-blocking NHIM cluster audit in GitHub Actions and CI pipelines.

View as Markdown

Block merges when agent infrastructure drifts from NHIM posture. Pair with CI/CD integration smoke for MCP config verification.

GitHub Actions

Copy ci/github-actions/[nhim-audit](/docs/definitions/nhim-audit) or use the action inline:

name: NHIM posture gate

on:
  pull_request:
  push:
    branches: [main]

jobs:
  nhim-audit:
    runs-on: ubuntu-latest
    steps:
      - uses: blekline/nhim-audit-action@v1
        with:
          kubeconfig: ${{ secrets.KUBECONFIG }}
          fail-on: high
          min-score: "75"
          output: nhim-audit.json

      - uses: actions/upload-artifact@v4
        with:
          name: nhim-audit-report
          path: nhim-audit.json

Store KUBECONFIG in GitHub Secrets only — never commit cluster credentials or reports with real cluster names if policy requires redaction.

CLI flags

FlagPurpose
--fail-on critical|high|anySeverity threshold for exit 1
--min-score <n>Minimum posture score (0–100)
--baseline <path>Fail only on new findings vs baseline
--format sarifSARIF 2.1 for GitHub Advanced Security
-o <path>Artifact output path
npx @blekline/nhim-audit audit --format sarif -o nhim-audit.sarif

Exit codes

CodeMeaning
0Pass
1Fail / baseline regression
2RBAC or config error
3Cluster unreachable

RBAC prerequisite

Apply the reader ClusterRole before CI runs:

kubectl apply -f https://raw.githubusercontent.com/Blekline/blekline-oss/main/packages/nhim-audit/deploy/rbac/nhim-audit-reader.yaml

Blekline integration gate (optional)

For MCP and integration config verification on the same PR:

- name: Verify integration configs
  run: node scripts/verify-integration-configs.mjs

- name: MCP smoke
  if: ${{ secrets.BLEKLINE_WORKSPACE_TOKEN != '' }}
  env:
    BLEKLINE_WORKSPACE_TOKEN: ${{ secrets.BLEKLINE_WORKSPACE_TOKEN }}
    BLEKLINE_API_URL: ${{ secrets.BLEKLINE_API_URL || 'https://app.blekline.com' }}
    BLEKLINE_CLIENT_SURFACE: sdk
  run: node scripts/mcp-smoke.mjs

Template: ci/github-actions/blekline-gate.yml.example

  • [NHIM audit quickstart](/docs/get-started/nhim-audit-quickstart)
  • [NHIM Audit CLI](/docs/tools/nhim-audit) — full rule reference and probe access
  • Compliance evidence

Disclaimer: Evidence enablement only — not certification.