> ## Documentation Index
> Fetch the complete documentation index at: https://docs.kosli.com/llms.txt
> Use this file to discover all available pages before exploring further.

# kosli begin trail

> Begin or update a Kosli flow trail.

## Synopsis

```shell theme={"theme":"dracula","languages":{"custom":["/languages/rego.json"]}}
kosli begin trail TRAIL-NAME [flags]
```

Begin or update a Kosli flow trail.

You can optionally associate the trail to a git commit using `--commit` (requires access to a git repo). And you
can optionally redact some of the git commit data sent to Kosli using `--redact-commit-info`.
To record repository information, all three of `--repo-id`, `--repo-url`, and `--repository` must be set together.
These are automatically set in GitHub Actions, GitLab CI, Bitbucket Pipelines, and Azure DevOps.
In other CI systems, set them explicitly to capture repository metadata.

`TRAIL-NAME`s must start with a letter or number, and only contain letters, numbers, `.`, `-`, `_`, and `~`.

## Flags

| Flag | Type | Description |
| :- | :- | :- |
| `-g`, `--commit` | string | \[defaulted] The git commit from which the trail is begun. (defaulted in some CIs: [docs](/integrations/ci_cd), otherwise unset ). If both `--commit` and `--repo-root` are left at their defaults and the commit cannot be read from the repository, a warning is printed and the trail is begun without commit info. |
| `--description` | string | \[optional] The Kosli trail description. |
| `-D`, `--dry-run` | bool | \[optional] Run in dry-run mode. When enabled, no data is sent to Kosli and the CLI exits with 0 exit code regardless of any errors. |
| `--external-fingerprint` | stringToString | \[optional] A SHA256 fingerprint of an external attachment represented by `--external-url`. The format is label=fingerprint (labels cannot contain '.' or '='). This flag can be set multiple times. There must be an external url with a matching label for each external fingerprint. |
| `--external-url` | stringToString | \[optional] Add labeled reference URL for an external resource. The format is label=url (labels cannot contain '.' or '='). This flag can be set multiple times. If the resource is a file or dir, you can optionally add its fingerprint via `--external-fingerprint` |
| `--flow` | string | The Kosli flow name. |
| `-h`, `--help` | bool | help for trail |
| `-o`, `--origin-url` | string | \[optional] The url pointing to where the attestation came from or is related. (defaulted to the CI url in some CIs: [docs](/integrations/ci_cd/#defaulted-kosli-command-flags-from-ci-variables) ). |
| `--redact-commit-info` | strings | \[optional] The list of commit info to be redacted before sending to Kosli. Allowed values are one or more of \[author, message, branch]. |
| `--repo-id` | string | \[conditional] The stable, unique identifier for the repository in your VCS provider (e.g. a numeric ID). Do not use the repository name as it can change if the repo is renamed. All three of `--repo-id`, `--repo-url` and `--repository` must be set to record repository information (defaulted in some CIs: [docs](/integrations/ci_cd) ). |
| `--repo-provider` | string | \[optional] The source code hosting provider. One of: github, gitlab, bitbucket, bitbucket\_cloud, bitbucket\_dc, azure-devops, azure\_devops\_services, azure\_devops\_server, git, subversion (defaulted in some CIs: [docs](/integrations/ci_cd) ). |
| `--repo-root` | string | \[defaulted] The directory where the source git repository is available. Only used if `--commit` is used or defaulted in CI, see [docs](/integrations/ci_cd/#defaulted-kosli-command-flags-from-ci-variables) . (default ".") |
| `--repo-url` | string | \[conditional] The URL of the repository. Must be a valid URL. All three of `--repo-id`, `--repo-url` and `--repository` must be set to record repository information (defaulted in some CIs: [docs](/integrations/ci_cd) ). |
| `--repository` | string | \[conditional] The name of the repository (e.g. owner/repo-name). All three of `--repo-id`, `--repo-url` and `--repository` must be set to record repository information (defaulted in some CIs: [docs](/integrations/ci_cd) ). |
| `-f`, `--template-file` | string | \[optional] The path to a yaml template file. |
| `-u`, `--user-data` | string | \[optional] The path to a JSON file containing additional data you would like to attach to the flow trail. The maximum JSON payload size is 1MB. |

## Flags inherited from parent commands

| Flag | Type | Description |
| :- | :- | :- |
| `-a`, `--api-token` | string | The Kosli API token. |
| `-c`, `--config-file` | string | \[optional] The Kosli config file path. Config is read from this path or the default only, never implicitly from the current directory. (default "\$HOME/.kosli.yml") |
| `--debug` | bool | \[optional] Print debug logs to stdout. |
| `-H`, `--host` | string | \[defaulted] The Kosli endpoint. (default "[https://app.kosli.com](https://app.kosli.com)") |
| `--http-proxy` | string | \[optional] The HTTP proxy URL including protocol and port number. e.g. `http://proxy-server-ip:proxy-port` |
| `-r`, `--max-api-retries` | int | \[defaulted] How many times should API calls be retried when the API host is not reachable. (default 3) |
| `--org` | string | The Kosli organization. |
| `-q`, `--quiet` | bool | \[optional] Suppress non-critical warning messages. Errors and normal output are not affected. If both `--quiet` and `--debug` are set, `--debug` wins. |

## Live Examples in different CI systems

<Tabs>
  <Tab title="GitHub">
    View an example of the `kosli begin trail` command in GitHub.

    In [this YAML file](https://github.com/cyber-dojo/runner/blob/6131d764b41b449d77e436598c953691d23eaced/.github/workflows/main.yml#L78), which created [this Kosli Event](https://app.kosli.com/cyber-dojo/flows/runner-ci/trails/6131d764b41b449d77e436598c953691d23eaced?attestation_id=1).
  </Tab>

  <Tab title="GitLab">
    View an example of the `kosli begin trail` command in GitLab.

    In [this YAML file](https://gitlab.com/cyber-dojo/creator/-/blob/65fd2bfa2478534ea4bc5ccf30f6bfc6aab7550c/.gitlab/workflows/main.yml#L55), which created [this Kosli Event](https://app.kosli.com/cyber-dojo/flows/creator-ci/trails/10ed49777abb7b3c7be0da1bd536c6b44f34533c?attestation_id=1).
  </Tab>
</Tabs>

## Examples Use Cases

These examples all assume that the flags  `--api-token`, `--org`, `--host`, (and `--flow`, `--trail` when required), are [set/provided](/getting_started/install/#assigning-flags-via-environment-variables).

<AccordionGroup>
  <Accordion title="begin/update a Kosli flow trail">
    ```shell theme={"theme":"dracula","languages":{"custom":["/languages/rego.json"]}}
    kosli begin trail yourTrailName 
    	--description yourTrailDescription 
    	--template-file /path/to/your/template/file.yml 
    	--user-data /path/to/your/user-data/file.json 
    ```
  </Accordion>
</AccordionGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.