hull scan
hull scan looks across a directory of hull packages, finds the values and
templates they have in common, and extracts them into a shared base layer.
When to use it
- When several packages have copy-pasted the same values or boilerplate templates and you want the shared parts factored into one base layer.
- As a one-shot refactor: run it once with
--dry-runto see what it would pull out, then run it for real to write the base and rewrite each package.
Note: this command refactors packages. It does not scan for vulnerabilities —
for a supply-chain document use hull sbom, and for policy checks
use hull policy.
What happens
- You point it at a directory. hull finds the hull packages inside it (at least two are required — commonality needs something to compare).
- It loads each package’s values and templates and computes what they share.
- It prints a report: how many packages were scanned, how many common values and common templates it found.
- If nothing is shared, it says so and stops without writing anything.
- With
--dry-run, it lists the base layer it would create and the packages it would update, but writes no files. - Without
--dry-run, it writes the base layer (into--output, or beside the input by default) and rewrites each package to reference it.
Usage
hull scan <directory> [flags]
Flags
| Flag | Type | Default | Description |
|---|---|---|---|
--dry-run |
— | false |
print the report and the planned changes, but write no files |
-o, --output |
string | (input dir) | write the generated base layer here instead of beside the input |
Inherits the global flags (--debug, --kube-context, --kubeconfig,
-n/--namespace); scan reads only local files, so they have no effect.
Worked example
Preview what scan would extract from a directory of packages:
hull scan ./packages --dry-run
Output:
Hull Scan Report
========================================
Packages scanned: 4
Common values found: 6
Common templates found: 2
[DRY RUN] Would create base layer at: /home/you/packages/base
[DRY RUN] Would update packages:
- web-api (/home/you/packages/web-api)
- web-ui (/home/you/packages/web-ui)
- worker (/home/you/packages/worker)
- cron (/home/you/packages/cron)
Run it for real and write the base into a dedicated directory:
hull scan ./packages -o ./layers
Output:
Hull Scan Report
========================================
Packages scanned: 4
Common values found: 6
Common templates found: 2
Created base layer at: /home/you/layers/base
Updated package: web-api (/home/you/packages/web-api)
Updated package: web-ui (/home/you/packages/web-ui)
Updated package: worker (/home/you/packages/worker)
Updated package: cron (/home/you/packages/cron)
Then confirm each rewritten package still lints:
for p in ./packages/*/; do hull lint "$p"; done
See also
lint— validate the rewritten packagesdependency— manage the layers scan produces