PRODUCT · CLI

kv-cli

The open-source Rust binary that enforces parameter contracts across your data pipelines. It parses Python locally with a tree-sitter AST — no account, no network call in the analysis path — to catch contract breaks, hardcoded secrets, and pinned infrastructure identifiers before they leave your workstation.

Technical specifications

SpecDetail
LanguageRust — compiles to a single binary with no runtime dependencies.
LicenseMIT
Latest versionv0.4.0
Scan latency< 200ms locally on a 47-file sample repository.

Install

Prebuilt binary, no toolchain required. Download the archive for your platform from Releases, then:

chmod +x kv-cli && sudo mv kv-cli /usr/local/bin/
kv-cli --version

With Cargo:

cargo install --git https://github.com/kovallent/kv-cli

From source (needs a C compiler for the tree-sitter grammar):

git clone https://github.com/kovallent/kv-cli && cd kv-cli
make release          # -> target/release/kv-cli

There is currently no PyPI or Homebrew distribution. pip install kv-cli will not work.

Stack compatibility

StackDetail
Python3.9, 3.10, 3.11, 3.12+
dbtdef model(dbt, session) model signatures; profiles.yml credential scanning.
Apache Airflow@dag, @task_group, @setup, @teardown, @task governance; Fernet keys; conn_id, pool, queue.
PySpark / Databricks@dlt.table, @dlt.view; PATs; workspace URLs, cluster IDs, DBFS paths.
Snowpark@sproc, @udf; session config account, warehouse, role.
Flink@udf, @udtf, @udaf; broker and JDBC endpoints via pyflink.
Polarsstorage_options credentials and object-store path identifiers.

Core commands & workflows

Local audit & contract validation

# Audit the current repository against your parameter contract
$ kv-cli audit

[✗] KV001 Parameter contract violation ... FAILED
    └── jobs/raw_ingest.py:42
        Missing required schema argument: 'target_environment'
[✓] KV002 Hardcoded secret ................ PASSED

Result: 1 finding. Run 'kv-cli fix' to resolve, where possible.
Exit code: 1

Automated remediation & scaffolding

  • kv-cli init — Writes a default, fully-commented .kovallent.yaml contract. --force overwrites. Optional — without a contract file, built-in defaults apply.
  • kv-cli fix — Inserts missing contract parameters into the function signature and rewrites hardcoded secrets to os.environ["NAME"]. Backups go to .kvbak. Never rewrites KV003 findings, since the right replacement is a deployment decision.
  • kv-cli frameworks — Shows the built-in framework profiles and what each one contributes.
  • kv-cli schema — Prints the JSON payload schema this build emits.

Diagnostics

CodeDetail
KV001Parameter contract violation (error). A governed function is missing a contract parameter.
KV002Hardcoded secret (error). A credential or API key written as a literal.
KV003Pinned infrastructure identifier (warning by default). A warehouse, catalog, cluster ID, bucket, or endpoint pinned to one environment.

CI gate exit codes

Exit codes are a documented interface — each escalates to different people. Resolution is first-match-wins in the order 2, 3, 1, 0.

CodeMeaningEscalates to
0Compliant—
1FindingsThe pull-request author
2Tool errorWhoever operates the gate
3Contract driftWhoever owns the contract

Join the waitlist for the Control Plane dashboard →