v0.4.0GitHub

Enterprise

NHIM verification

Public verification checklist for NHIM sidecar and Kubernetes deployments.

View as Markdown

Use after deploying the Blekline sidecar — locally, via Helm, or with auto-inject webhook.

1. Sidecar health

curl -s http://127.0.0.1:8787/health

Expect ok: true, trustVault: true, lineage: true when NHIM image is used.

2. Authentication

Unauthenticated POST /v1/enforce-tool-call401. With Authorization: Bearer $BLEKLINE_SIDECAR_AUTH200.

3. Trust Vault round-trip

Tokenize a test secret; confirm placeholder in model context; hydrate with matching sessionId + toolName.

4. SPIFFE bind (optional)

Tokenize with spiffeId or header x-spiffe-id. Hydrate without matching ID → 403.

5. Lineage block

POST /v1/lineage/contaminate then enforce a destructive tool → block.

6. Log hygiene

Confirm SIEM/Activity exports are metadata-only; no raw secrets in stdout.

7. Network posture

Sidecar reachable only from agent pods / localhost — never public Ingress on port 8787.

Kubernetes

After Helm install:

kubectl -n blekline apply -f deploy/k8s/verify/nhim-smoke-job.yaml
kubectl -n blekline wait --for=condition=complete job/blekline-nhim-smoke

Full guide: Kubernetes deployment

Local quick start

bash scripts/local-sidecar-env.sh

See [Trust Vault sidecar](/docs/enterprise/trust-vault-sidecar), Lineage enforcement, and K8s deployment.