.kanman/verify.json
Every key of the verify manifest: the local verify command for each change, and the names of the CI variables an executor may receive.
The verify manifest declares how a change is checked locally before it is handed to CI and to the outcome gate. It lives at .kanman/verify.json in the repository root, next to .kanman/acceptance.json.
The verify command is meant to run after the executor finishes an attempt, before the pull request is opened or updated. Its result is the verify_local gate in the evidence pack.
Coming in a later release
kanman reads .kanman/verify.json and runs the verify_local gate in a later release. Until then the file has no effect: the change is checked by the acceptance spec, your CI and the reviewer run. You can add the file now so it is in place.
Example
The manifest of the demo repository kanman-ai/pilot-sandbox:
{
"version": 1,
"cwd": ".",
"setup": "npm ci",
"command": "npm run lint && npm run typecheck && npm test",
"env": {
"CI": "true"
},
"ci_var_keys": []
}
Keys
| Key | Type | Required | Default | Description |
|---|---|---|---|---|
version |
number | yes | Always 1. |
|
cwd |
string | no | . |
Working directory for setup and command, relative to the repository root. Useful in monorepos. |
setup |
string | no | Command run once before command, for example installing dependencies. |
|
command |
string | yes | The local verify command, for example npm run lint && npm test. A non-zero exit code fails the verify_local gate. |
|
env |
object of strings | no | {} |
Plain environment variables for setup and command. Never put secrets here. |
ci_var_keys |
array of strings | no | [] |
Names of CI variables the executor may receive. Names only: the values stay in your CI or vault and are injected at run time. |
timeout_seconds |
integer | no | 600 |
Maximum run time of setup plus command. Maximum 1800. |
Unknown keys are ignored.
Secrets and CI variables
Coming in a later release
Passing CI variables to the executor arrives in a later release. Until then the executor receives no secrets from ci_var_keys or secret_names.
ci_var_keys lists the only variables kanman may pass to the executor. The list is intersected with the team policy’s secret_names (see Policy settings): a variable must be allowed in both places. Values are never stored in the manifest, in the run record, in the evidence pack or in the audit log; only the names appear.
{
"version": 1,
"command": "make lint test",
"ci_var_keys": ["NPM_TOKEN", "SENTRY_DSN_TEST"],
"timeout_seconds": 900
}
Warning
Prefer an empty ci_var_keys. A verify command that needs production credentials is a sign that tests reach outside the sandbox. See Sandbox and secrets.
Without a verify manifest
The manifest is optional. Without it, kanman relies on your CI status and the reviewer run. Once the verify_local gate is available, the manifest catches lint and type errors before a pull request exists, which saves CI minutes and rework attempts.
Related
Last updated: January 1, 0001
Open kanman