CerbIA

CLI reference

Use the CerbIA CLI to validate YAML pipelines and scan text or files from the command line.

reference
cli
commands

Install the command-line interface with pip install "cerbia[cli]". The executable provides scan and validate.

cerbia validate CONFIG.yaml

Validate one YAML configuration file, construct its Runner, and print the configured pipeline. This command does not load entries or execute scanners.

cerbia validate examples/cli-usage/config.cerbia.yaml
Input Meaning

config

Required path to one YAML configuration file. Directories are not supported.

--log-level

DEBUG, INFO, WARNING, ERROR, or CRITICAL.

--log-file

Write logs to this path instead of standard error.

Exit code 0 means the file parsed and its pipeline could be constructed. Missing or malformed configuration files exit 2; a configuration that parses but cannot construct its pipeline exits 1 for CerbIAError or 2 for TypeError.

cerbia scan --config CONFIG.yaml

Run one configured pipeline and render a result for each loaded entry.

cerbia scan --config examples/cli-usage/config.cerbia.yaml --text "Text to scan"
Option Meaning

--config, -c

Required path to one YAML configuration file.

--text, -t

Repeatable inline input. Any supplied values replace configured loaders.

--file, -f

Repeatable file input. Any supplied values replace configured loaders.

--output, -o

Write JSON results to a path ending in .json.

--threshold

Override the YAML threshold for this invocation.

--unsafe-only

Show and serialize only unsafe entry results. It does not change scanner execution.

--log-level

DEBUG, INFO, WARNING, ERROR, or CRITICAL. At INFO, scan logs the fixed Starting scan milestone.

--log-file

Write logs to this path instead of standard error.

The --unsafe-only option filters console output and entry_results in JSON; it does not change scan execution or exit codes.

Inline text and file options replace every loader configured in YAML. When no override is supplied, the configuration’s loaders are used. The command rejects a run with no loaders after this selection.

FileLoader treats missing paths and extension-filtered paths as no entries, so a --file value can produce an empty, safe result rather than an error. With no explicit logging options, the standalone command preserves the host logging setup when one exists. In a standalone process with no root handlers it installs an INFO stderr handler for that CLI process; if a root handler already exists, it installs nothing. This CLI-owned behavior differs from reusing CerbIA as a library import, which has no logging-configuration side effects. Explicit logging options control that CLI invocation.

Output and exit codes

The terminal output groups findings by entry. Each scanner row shows its outcome; skipped scanners are retained in the entry result so routing and error policy decisions remain visible.

--output serializes a ScanResult with entry_results, is_safe, total_findings, and unsafe_entries. Every entry result includes the entry metadata, aggregated_score, rationale, findings, and skipped scanners. Raw entry text is included in the serialized entry, so treat JSON output as potentially sensitive and store it accordingly.

Exit code Meaning

0

Every resulting entry is safe, including an empty result set.

1

At least one resulting entry is unsafe.

2

Usage, configuration, input selection, output-path, or handled execution error.

Examples

# Use loaders from the configuration.
cerbia scan --config examples/cli-usage/config.cerbia.yaml

# Scan two inline values instead of configured loaders.
cerbia scan -c examples/cli-usage/config.cerbia.yaml -t "first input" -t "second input"

# Scan local files and write only unsafe entry results to JSON.
cerbia scan -c examples/cli-usage/config.cerbia.yaml -f input.txt --unsafe-only -o results.json

# Inspect a configuration before running it.
cerbia validate examples/cli-usage/config.cerbia.yaml --log-level DEBUG