CLI Reference
The qhx command line tool is used to test and operate QHx.
It is divided into the following subcommands:
qhx curl
Section titled “qhx curl”Usage: qhx curl [flags] <url>
Make HTTP requests using a curl-like interface, with optional validation of QHx workload identity and request notarization data.
Notarization
Section titled “Notarization”To select the notarization level, pass -n (--notarization-level) with one of the supported values:
workload: Validate workload identity statement only. This provides the lowest overhead.logRequest: Validate workload identity statement only. The request is logged by the notary.signRequest: Validate workload identity statement and signed request receipt. The request is logged by the notary. This provides the highest notarization level.
The command will exit with a non-zero exit code if the notarization data does not validate.
The --print-workload flag (and, when using signRequest, the
--print-receipt flag) can be used to print the notarization data for the
request.
Other flags function identically to the identically named flags in curl.
This command implements a subset of the functionality of curl.
The following flags are supported:
| Flag | Description |
|---|---|
-d, --data <str> | Specify HTTP POST data |
-H, --header <str> | Add HTTP header to request |
-n, --notarization-level <level> | Select notarization level (workload, logRequest or signRequest) (default workload) |
--print-workload | Print workload identity statement |
--print-receipt | Print request notarization receipt |
-X, --request <method> | Select HTTP request method (e.g. GET, POST) |
-i, --show-headers | Show HTTP headers in response |
-s, --silent | Be less verbose |
--validate <bool> | Require workload statement verification (default true) |
Global Flags
Section titled “Global Flags”| Flag | Description |
|---|---|
--log-devel | Enable development logging (console output, debug level) |
--log-format {text | json} | Log output format (text or json) (default text) |
--log-stacktrace | |
--spiffe-socket-path <path> | Path to the Workload API socket (default unix:///spiffe-workload-api/agent.sock) |
-v, --verbose <int> | Log verbosity level (higher is more verbose) (default -2) |