PRODUCT · CLI
kv-cli
The open-source Rust binary that enforces parameter contracts across your data pipelines. It parses Python locally with a tree-sitter AST — no account, no network call in the analysis path — to catch contract breaks, hardcoded secrets, and pinned infrastructure identifiers before they leave your workstation.
Technical specifications
| Spec | Detail |
|---|---|
| Language | Rust — compiles to a single binary with no runtime dependencies. |
| License | MIT |
| Latest version | v0.4.0 |
| Scan latency | < 200ms locally on a 47-file sample repository. |
Install
Prebuilt binary, no toolchain required. Download the archive for your platform from Releases, then:
chmod +x kv-cli && sudo mv kv-cli /usr/local/bin/ kv-cli --version
With Cargo:
cargo install --git https://github.com/kovallent/kv-cli
From source (needs a C compiler for the tree-sitter grammar):
git clone https://github.com/kovallent/kv-cli && cd kv-cli
make release # -> target/release/kv-cli
There is currently no PyPI or Homebrew distribution. pip install kv-cli will not work.
Stack compatibility
| Stack | Detail |
|---|---|
| Python | 3.9, 3.10, 3.11, 3.12+ |
| dbt | def model(dbt, session) model signatures; profiles.yml credential scanning. |
| Apache Airflow | @dag, @task_group, @setup, @teardown, @task governance; Fernet keys; conn_id, pool, queue. |
| PySpark / Databricks | @dlt.table, @dlt.view; PATs; workspace URLs, cluster IDs, DBFS paths. |
| Snowpark | @sproc, @udf; session config account, warehouse, role. |
| Flink | @udf, @udtf, @udaf; broker and JDBC endpoints via pyflink. |
| Polars | storage_options credentials and object-store path identifiers. |
Core commands & workflows
Local audit & contract validation
# Audit the current repository against your parameter contract $ kv-cli audit [✗] KV001 Parameter contract violation ... FAILED └── jobs/raw_ingest.py:42 Missing required schema argument: 'target_environment' [✓] KV002 Hardcoded secret ................ PASSED Result: 1 finding. Run 'kv-cli fix' to resolve, where possible. Exit code: 1
Automated remediation & scaffolding
kv-cli init— Writes a default, fully-commented.kovallent.yamlcontract.--forceoverwrites. Optional — without a contract file, built-in defaults apply.kv-cli fix— Inserts missing contract parameters into the function signature and rewrites hardcoded secrets toos.environ["NAME"]. Backups go to.kvbak. Never rewritesKV003findings, since the right replacement is a deployment decision.kv-cli frameworks— Shows the built-in framework profiles and what each one contributes.kv-cli schema— Prints the JSON payload schema this build emits.
Diagnostics
| Code | Detail |
|---|---|
| KV001 | Parameter contract violation (error). A governed function is missing a contract parameter. |
| KV002 | Hardcoded secret (error). A credential or API key written as a literal. |
| KV003 | Pinned infrastructure identifier (warning by default). A warehouse, catalog, cluster ID, bucket, or endpoint pinned to one environment. |
CI gate exit codes
Exit codes are a documented interface — each escalates to different people. Resolution is first-match-wins in the order 2, 3, 1, 0.
| Code | Meaning | Escalates to |
|---|---|---|
| 0 | Compliant | — |
| 1 | Findings | The pull-request author |
| 2 | Tool error | Whoever operates the gate |
| 3 | Contract drift | Whoever owns the contract |