--all check every identity
--allow-region stringArray a region these identities may act in; repeatable (default: --region alone)
--artifact-key string KMS key ARN protecting sealed artifacts; the runner writes it, the unsealer reads it
--ci-role string GitHub OIDC role that builds the plane's own cluster on day zero (trust policy only)
--external-id string binds a target-account role to one tenant (trust policy only)
-h, --help help for verify
--hosted-zone string Route53 zone the build may publish records in
--identity string which identity to check
--operator stringArray ARN of a user or role that may assume the build role directly, for a laptop build; repeatable (trust policy only)
--plane-account string AWS account the management plane runs in
--region string primary region, substituted into resource ARNs
--role string the role carrying it (default: derived from the account flags and the identity's role name)
--stack-key string KMS key ARN protecting the Pulumi checkpoint; the build both writes and reads it
--state-backend string Pulumi state backend, e.g. s3://bucket/prefix
--target-account string AWS account a cluster is built into (default: the plane's own)
--tenant stringArray a tenant the artifact roles seal for: the cloud connection's namespace (kubox-system for Kubox's own account); repeatable, and required for the tenant artifact identities
--workload-issuer string the identity plane's issuer, e.g. https://oidc-exp.kubox.cloud; required