Skip to content

Guides

Read your first report

A scan prints one report: who it ran on, a grade, and each problem with its fix. This page walks through it from the top.

Terminal · deploy@checkout-api-prod
$ sudo kiyesi scan

Kiyesi 0.1 · read-only scan · nothing leaves this server
checkout-api-prod · Ubuntu 22.04 · 22 checks in 6.4 s

GRADE  D  55/100     2 critical · 3 warnings · 17 passed

CRITICAL
 FAIL  Redis is open to the internet on port 6379 · likely
       Fix: bind the port to 127.0.0.1 in docker-compose.yml, then
            docker compose up -d redis
 FAIL  The node process was killed for using too much memory at 10:41
       Fix: sudo fallocate -l 1G /swapfile && sudo chmod 600 /swapfile &&
            sudo mkswap /swapfile && sudo swapon /swapfile &&
            echo '/swapfile none swap sw 0 0' | sudo tee -a /etc/fstab

WARNING
 WARN  SSL certificate for api.example.com expires in 9 days
 WARN  SSH allows password login
 WARN  Newest backup is 31 hours old

DATA LOCATION
 Server     DigitalOcean, London, UK     confirmed   outside Nigeria
 Database   redis (this server)          confirmed   outside Nigeria
 Database   checkout-db-prod:5432        likely      outside Nigeria

Full report with every fix command: /var/lib/kiyesi/report-2026-10-08.txt

The first two lines say what ran and where: the Kiyesi version, that the scan is read-only and sends nothing, the server’s name, its system, and how many checks ran and how long they took.

If the system is not one Kiyesi is tested on, the header says untested. The scan still runs.

Every scan starts at 100. Each critical finding takes off 15, and each warning takes off 5. The letter follows the score:

Grade Score
A 90 and above
B 75 to 89
C 60 to 74
D 40 to 59
F below 40

The line under the grade counts critical findings, warnings and checks that passed.

When a check is skipped, or not built yet, the grade line says how many checks it is based on, such as based on 17 of 22 checks. A skipped check never counts as passed.

A check is skipped when it cannot read what it needs. Most often that is because the scan ran without root; the report then says needs root: run sudo kiyesi scan. The five data-location checks arrive in a later release, so every report for now is based on at most 17 checks.

A critical finding is something that is hurting the server now, or lets anyone in. Each one shows its fix right under it, so you can copy it and run it.

A warning is worth fixing soon. To keep the report short, warnings show only their sentence. Every fix is in the saved report file.

Each scan saves a full report, with every finding, why it matters, and its fix:

  • /var/lib/kiyesi/report-<date>.txt when the scan runs as root
  • ~/.local/state/kiyesi/ when it runs without root

The last 30 reports are kept.

Print the result as JSON instead of the report:

Terminal window
sudo kiyesi scan --json

Make the command fail when there is a critical finding, so a pipeline can stop:

Terminal window
sudo kiyesi scan --fail-on critical

Colour is turned off when the output goes to a file or a pipe. To turn it off anywhere, set NO_COLOR:

Terminal window
sudo NO_COLOR=1 kiyesi scan
Code Meaning
0 The scan ran. Nothing matched what you asked it to fail on.
1 The scan found something you asked it to fail on, such as --fail-on critical.
2 The command has a mistake in it, such as an unknown flag.
3 Kiyesi could not reach the service, or was not allowed to do what was asked.