An open-source, extensible test suite that validates Posit Team deployments are installed correctly and functioning properly.
VIP uses BDD-style tests (pytest-bdd + Playwright) to verify Connect, Workbench, and Package Manager deployments. Results can be viewed from the command-line output or compiled into an HTML report.
Documentation: https://posit-dev.github.io/vip/
uv tool install posit-vip
vip install
vip verify --connect-url https://connect.example.com --interactive-authRun VIP from your own workstation or a CI runner, not the Connect, Workbench,
or Package Manager servers themselves: VIP checks the deployment the way a
real client would (over the same URL, proxy, and TLS termination your users
go through), and --interactive-auth opens a visible browser window that
those servers typically don't have a display for. On a headless server, use
--headless-auth or --api-auth instead (see below).
uv tool install posit-vip resolves the newest versions each release allows. To
install the exact set a release was tested against, pass that release's
constraints file (attached to every GitHub release as constraints-<version>.txt):
uv tool install posit-vip \
-c https://github.com/posit-dev/vip/releases/download/vX.Y.Z/constraints-X.Y.Z.txtReplace X.Y.Z with the release you are installing (see the
releases page).
For a fully pinned, batteries-included environment, use the container image,
which installs from the committed uv.lock:
docker run --rm -v "$PWD/vip.toml:/app/vip.toml" ghcr.io/posit-dev/vip:latestOn a headless server (no display), use --headless-auth instead:
vip verify --config vip.toml --headless-authRun a specific test by name:
vip verify --connect-url https://connect.example.com --filter test_loginWith a configuration file:
cp vip.toml.example vip.toml # edit with your deployment details
vip verify --config vip.tomlFast confidence check — skip the detailed/long-running checks:
vip verify --config vip.toml --basicTo reverse what vip install (or just setup) did:
vip uninstall # dry run; prints the full plan including any sudo command
vip uninstall --yes # remove Playwright cache + manifest; prints the sudo command
# for any system packages so you can remove them yourself
uv tool uninstall posit-vip # remove vip itself once you're donevip uninstall only removes packages and files that vip install recorded
in .vip-install.json; anything that was already on your machine before
running vip install is left alone.
If a Connect URL is configured (in vip.toml or via --connect-url),
vip uninstall chains vip cleanup first to remove _vip_test-tagged
content from Connect.
| Command | Description |
|---|---|
vip verify |
Run verification tests against a Posit Team deployment |
vip status |
Quick health check for each configured product |
vip cleanup |
Delete VIP _vip_test content from Connect |
vip report |
Render the HTML report from test results (requires Quarto CLI) |
vip auth |
Authentication tools (e.g. mint Connect API keys) |
vip version |
Print the vip version and the minimum supported Posit Team version |
vip --version |
Print the installed vip version |
Run vip --help or vip <command> --help for full usage details.
VIP emits machine-readable output for security-ops and CI/CD pipelines.
vip verify always writes report/results.json (and report/failures.json on
failures). Add JUnit XML and/or SARIF with --format:
vip verify --format json,junit,sarif
# report/results.json (always)
# report/junit.xml (--format junit) -> CI test dashboards
# report/results.sarif (--format sarif) -> GitHub code scanning / secopsSkip messages in the JUnit and SARIF output carry the actual skip reason
instead of a generic "skipped" label. results.json also records provenance
for the run (VIP version, duration, Python version, platform, and whether the
slow checks were excluded) so an archived report can be traced back to what
produced it.
The --ci preset bundles all three formats with concise tracebacks (--tb=short)
and overrides --format if both are given. Run it without --interactive-auth/
--headless-auth -- combining them is an error, since --ci is meant for
non-interactive pipelines:
vip verify --ciAn official image is published to ghcr.io/posit-dev/vip. The entrypoint is the
vip CLI; the default subcommand is verify. Because docker run args replace
the default command (they do not append to it), name the verify subcommand
explicitly when passing verify flags:
# bare invocation runs `vip verify`:
docker run --rm -v "$PWD/vip.toml:/app/vip.toml" ghcr.io/posit-dev/vip
# CI preset (name the subcommand so args don't replace it):
docker run --rm -v "$PWD/vip.toml:/app/vip.toml" ghcr.io/posit-dev/vip verify --ci
# other subcommands are reachable too:
docker run --rm -v "$PWD/vip.toml:/app/vip.toml" ghcr.io/posit-dev/vip status --jsonSee docs/development.md for dev setup, linting, and formatting.
For the test architecture and four-layer design, see docs/test-architecture.md.
MIT — see LICENSE.