.kanman/verify.json

Every key of the verify manifest: the local verify command for each change, and the names of the CI variables an executor may receive.

The verify manifest declares how a change is checked locally before it is handed to CI and to the outcome gate. It lives at .kanman/verify.json in the repository root, next to .kanman/acceptance.json.

The verify command is meant to run after the executor finishes an attempt, before the pull request is opened or updated. Its result is the verify_local gate in the evidence pack.

Coming in a later release

kanman reads .kanman/verify.json and runs the verify_local gate in a later release. Until then the file has no effect: the change is checked by the acceptance spec, your CI and the reviewer run. You can add the file now so it is in place.

Example

The manifest of the demo repository kanman-ai/pilot-sandbox:

{
  "version": 1,
  "cwd": ".",
  "setup": "npm ci",
  "command": "npm run lint && npm run typecheck && npm test",
  "env": {
    "CI": "true"
  },
  "ci_var_keys": []
}

Keys

Key Type Required Default Description
version number yes Always 1.
cwd string no . Working directory for setup and command, relative to the repository root. Useful in monorepos.
setup string no Command run once before command, for example installing dependencies.
command string yes The local verify command, for example npm run lint && npm test. A non-zero exit code fails the verify_local gate.
env object of strings no {} Plain environment variables for setup and command. Never put secrets here.
ci_var_keys array of strings no [] Names of CI variables the executor may receive. Names only: the values stay in your CI or vault and are injected at run time.
timeout_seconds integer no 600 Maximum run time of setup plus command. Maximum 1800.

Unknown keys are ignored.

Secrets and CI variables

Coming in a later release

Passing CI variables to the executor arrives in a later release. Until then the executor receives no secrets from ci_var_keys or secret_names.

ci_var_keys lists the only variables kanman may pass to the executor. The list is intersected with the team policy’s secret_names (see Policy settings): a variable must be allowed in both places. Values are never stored in the manifest, in the run record, in the evidence pack or in the audit log; only the names appear.

{
  "version": 1,
  "command": "make lint test",
  "ci_var_keys": ["NPM_TOKEN", "SENTRY_DSN_TEST"],
  "timeout_seconds": 900
}

Warning

Prefer an empty ci_var_keys. A verify command that needs production credentials is a sign that tests reach outside the sandbox. See Sandbox and secrets.

Without a verify manifest

The manifest is optional. Without it, kanman relies on your CI status and the reviewer run. Once the verify_local gate is available, the manifest catches lint and type errors before a pull request exists, which saves CI minutes and rework attempts.

Last updated: January 1, 0001

Open kanman