Registry stack documentation: machine-readable Markdown.
Index of all pages: https://docs.registrystack.org/v/0.38.0/llms.txt
Full corpus: https://docs.registrystack.org/v/0.38.0/llms-full.txt

# evidence check command reference

> Generated syntax and options for evidence check.

{/* Generated from Clap command definitions by scripts/generate-cli-reference.mjs. Run npm run generate. */}

Validate and compile the complete immutable bundle, and validate the mounted secret material exactly as startup does.

## Contract status

This page is generated from the public Clap command tree for Registry Stack source version `0.38.0` and catalog SHA-256 `cd13c658f65af295f9df3c6db86dc045ac06e9e040afc1f5f5b27c3184ab653d`. Hidden implementation commands are omitted.

## Usage

```text
evidence check [OPTIONS] --runtime-config <FILE>
```

## Constraints

| Condition | Requirement |
| --- | --- |
| `--require-audit-under <ABSOLUTE_DIRECTORY>` is present | `--require-runtime-dependencies` is required. |
| `--without-audit-lock` is present | `--require-runtime-dependencies` is required. |

## Options

| Option | Always required | Default | Values | Environment | Description |
| --- | --- | --- | --- | --- | --- |
| `--runtime-config <FILE>` | Yes | n/a | n/a | n/a | The closed operator runtime file that binds the governed bundle |
| `--require-runtime-dependencies` | No | n/a | n/a | n/a | Also prove audit writability, signer readiness, source credentials, and access-token JWKS reachability in the target runtime context |
| `--require-audit-under <ABSOLUTE_DIRECTORY>` | No | n/a | n/a | n/a | Also prove the configured audit sink resolves inside this absolute directory, which the deployment declares persistent. The declared root is a storage boundary, not a second audit setting. Evidence resolves its own configured destination exactly as startup resolves it and refuses when the result is not at or below the root, which is what stops a container from mounting durable storage at the conventional prefix while writing audit entries somewhere ephemeral. |
| `--without-audit-lock` | No | n/a | n/a | n/a | Prove the audit destination without taking its single-writer lock, for a candidate staged beside the running instance that holds it. Modes, write access, and a complete final entry in the active file are still proved, and every other dependency is proved as without this flag. A second writer is not detected, so `serve` still refuses to start while one holds the lock. |
| `-h, --help` | No | n/a | n/a | n/a | Print help (see a summary with '-h') |

## Generation contract

Run `npm run generate` from `docs/site` after changing a public command, argument, option, default, environment binding, or help description.