Skip to main content

scrubctl

A standalone Go CLI for scrubbing Kubernetes and OpenShift manifests, scanning namespaces, and exporting GitOps-ready artifacts. Use it from a terminal or automation pipeline when live cluster output needs to become clean, reviewable YAML.

License: Apache-2.0GitHub releaseRelease workflow

Demo​

The demo shows a namespace scan workflow and the classification output scrubctl produces before export.

Quick Start​

# Scrub a single resource file, no cluster access needed
scrubctl scrub -f deployment.yaml

# Scrub YAML from stdin
scrubctl < resource.yaml

When invoked with no subcommand and YAML on stdin, scrubctl scrubs the resource directly.

Install​

go build -o scrubctl ./cmd/scrubctl
sudo mv scrubctl /usr/local/bin/
scrubctl version

Builds from source require Go 1.24 or newer.

Explore​

scrubctl shares classification and sanitization logic with the GitOps Export OpenShift console plugin. Both tools produce identical output for the same input, verified by shared golden test fixtures.