Quick start
This walks one sample release through validate → hash → import an eval → certify → verify. Everything runs offline on your machine; no account is needed.
1. Install the CLI
The CLI is the Cargo package cloakpipe-cli; it installs a binary named cloakpipe. You need a Rust toolchain (rustup).
Everything on this page is on main:
cargo install --git https://github.com/rohansx/cloakpipe cloakpipe-cli --locked
Check it: cloakpipe --help should list release and eval among the commands.
2. Write a release manifest
A release pins every behaviour-affecting component to an immutable version. Save this as release.yaml:
apiVersion: cloakpipe.co/v1alpha1
kind: AgentRelease
metadata:
agent: support-agent
version: "184"
labels:
team: support
spec:
code:
repository: acme/support
commit: 8fd29ac
prompts:
- ref: prompt:support-answer@31
model:
ref: model:openai/gpt-5@2026-08-01
parameters:
temperature: 0.2
max_tokens: 1200
tools:
- ref: tool:lookup-customer@7
- ref: tool:refund@4
mcpServers:
- ref: mcp:crm@12
retrieval:
ref: retrieval:support@22
policies:
- ref: policy:support-prod@11
runtime:
image: registry.acme.dev/support-agent@sha256:9f86d081884c7d659a2feaa0c55ad015a3bf4f1b2b0b822cd15d6c15b0f00a08
region: in-south
dependencies:
- name: orchestrator
version: 2.4.1
The field rules are in Agent releases.
3. Validate and hash it
cloakpipe release validate release.yaml
# valid sha256:28b40cf5db41c164624094de4df3943e3a5f1d7238e78727af9eb5c88be2efea support-agent@184
cloakpipe release hash release.yaml
# sha256:28b40cf5db41c164624094de4df3943e3a5f1d7238e78727af9eb5c88be2efea
A manifest with a moving reference is refused with the field path, exit code 1:
invalid: 1 issue(s)
spec.prompts[0].ref: "prompt:support-answer@latest" is not pinned to an immutable version
4. Import an evaluation
Run your tests however you already do, writing JUnit XML (pytest --junitxml=report.xml, Jest, Go, cargo-nextest). Then bind the report to the release:
cloakpipe eval import --junit report.xml --release release.yaml \
--suite support-critical@23 --covers privacy,functional --critical 'privacy::*' --out run.json
run.json is a native EvaluationRun whose release is the manifest hash. Braintrust and Langfuse are covered in Evaluation import.
5. Certify
Create a signing key, write a policy, and certify:
cloakpipe release keygen --out key.json # mode 0600; prints only keyid and publicKey
policy.yaml:
apiVersion: cloakpipe.co/v1alpha1
kind: CertificationPolicy
name: support-prod
version: "11"
validityDays: 30
rules:
maxNewCriticalFailures: 0
blockPersistingCriticalFailures: true
minPassRate: 0.95
minCoverage: 1.0
metrics:
- metric: latency_ms
aggregate: p95
op: lte
value: 2000
cloakpipe release certify release.yaml --policy policy.yaml --run run.json \
--require privacy,functional --environment production --issuer ci:acme/support --key key.json
CERTIFIED
release sha256:28b40cf5…2efea support-agent@184
policy support-prod@11 sha256:…
required functional, privacy
runs 1
envelope release.cert.dsse.json
Exit code 0 means certified; a BLOCKED decision exits 1 and lists one reason per line. With a previous release, pass --baseline previous.yaml --baseline-run previous-run.json and the required suites come from the diff. See Certification.
6. Verify the certification
Anyone with the public key can check the envelope offline:
cloakpipe release verify-cert release.cert.dsse.json --trust key.json --release release.yaml
VALID
outcome certified
release sha256:28b40cf5…2efea
statement 78ba8788…
certified yes
Next
- Gate an agent’s tool calls on this certification: MCP tool gate.
- Run certification in CI: the GitHub Action.
- Register the release with CloakPipe Cloud:
cloakpipe release register.
Just want the privacy proxy?
The proxy is on main. From a clone of the repository:
git clone https://github.com/rohansx/cloakpipe
cd cloakpipe
export OPENAI_API_KEY=sk-...
cargo run -p cloakpipe-cli -- start # listens on 127.0.0.1:8900
export OPENAI_BASE_URL=http://127.0.0.1:8900/v1