Guides
Read your first report
A scan prints one report: who it ran on, a grade, and each problem with its fix. This page walks through it from the top.
$ sudo kiyesi scan
Kiyesi 0.1 · read-only scan · nothing leaves this server
checkout-api-prod · Ubuntu 22.04 · 22 checks in 6.4 s
GRADE D 55/100 2 critical · 3 warnings · 17 passed
CRITICAL
FAIL Redis is open to the internet on port 6379 · likely
Fix: bind the port to 127.0.0.1 in docker-compose.yml, then
docker compose up -d redis
FAIL The node process was killed for using too much memory at 10:41
Fix: sudo fallocate -l 1G /swapfile && sudo chmod 600 /swapfile &&
sudo mkswap /swapfile && sudo swapon /swapfile &&
echo '/swapfile none swap sw 0 0' | sudo tee -a /etc/fstab
WARNING
WARN SSL certificate for api.example.com expires in 9 days
WARN SSH allows password login
WARN Newest backup is 31 hours old
DATA LOCATION
Server DigitalOcean, London, UK confirmed outside Nigeria
Database redis (this server) confirmed outside Nigeria
Database checkout-db-prod:5432 likely outside Nigeria
Full report with every fix command: /var/lib/kiyesi/report-2026-10-08.txt
The header
Section titled “The header”The first two lines say what ran and where: the Kiyesi version, that the scan is read-only and sends nothing, the server’s name, its system, and how many checks ran and how long they took.
If the system is not one Kiyesi is tested on, the header says untested. The scan still runs.
The grade
Section titled “The grade”Every scan starts at 100. Each critical finding takes off 15, and each warning takes off 5. The letter follows the score:
| Grade | Score |
|---|---|
| A | 90 and above |
| B | 75 to 89 |
| C | 60 to 74 |
| D | 40 to 59 |
| F | below 40 |
The line under the grade counts critical findings, warnings and checks that passed.
Based on N of 22 checks
Section titled “Based on N of 22 checks”When a check is skipped, or not built yet, the grade line says how many checks it is based on, such as based on 17 of 22 checks. A skipped check never counts as passed.
A check is skipped when it cannot read what it needs. Most often that is because the scan ran without root; the report then says needs root: run sudo kiyesi scan. The five data-location checks arrive in a later release, so every report for now is based on at most 17 checks.
Critical findings
Section titled “Critical findings”A critical finding is something that is hurting the server now, or lets anyone in. Each one shows its fix right under it, so you can copy it and run it.
Warnings
Section titled “Warnings”A warning is worth fixing soon. To keep the report short, warnings show only their sentence. Every fix is in the saved report file.
The saved report
Section titled “The saved report”Each scan saves a full report, with every finding, why it matters, and its fix:
/var/lib/kiyesi/report-<date>.txtwhen the scan runs as root~/.local/state/kiyesi/when it runs without root
The last 30 reports are kept.
For scripts and pipelines
Section titled “For scripts and pipelines”Print the result as JSON instead of the report:
sudo kiyesi scan --jsonMake the command fail when there is a critical finding, so a pipeline can stop:
sudo kiyesi scan --fail-on criticalColour is turned off when the output goes to a file or a pipe. To turn it off anywhere, set NO_COLOR:
sudo NO_COLOR=1 kiyesi scanExit codes
Section titled “Exit codes”| Code | Meaning |
|---|---|
0 |
The scan ran. Nothing matched what you asked it to fail on. |
1 |
The scan found something you asked it to fail on, such as --fail-on critical. |
2 |
The command has a mistake in it, such as an unknown flag. |
3 |
Kiyesi could not reach the service, or was not allowed to do what was asked. |