scrubctl

A standalone Go CLI for scrubbing Kubernetes and OpenShift manifests, scanning namespaces, and exporting GitOps-ready artifacts. Use it from a terminal or automation pipeline when live cluster output needs to become clean, reviewable YAML.
Demo
The demo shows a namespace scan workflow and the classification output scrubctl produces before export.
Quick Start
- Local YAML
- OpenShift / Kubernetes
- GitOps export
# Scrub a single resource file, no cluster access needed
scrubctl scrub -f deployment.yaml
# Scrub YAML from stdin
scrubctl < resource.yaml
# Pipe a live resource through scrubctl
oc get deploy/web -n my-app -o yaml | scrubctl
# Scan a namespace and print a classification table
scrubctl scan my-app
# Export a namespace as a ZIP archive
scrubctl export my-app -o ./out
# Generate an Argo CD Application manifest
scrubctl generate argocd my-app \
--repo-url https://github.com/example/repo.git \
--revision main \
--path manifests/overlays/install
When invoked with no subcommand and YAML on stdin, scrubctl scrubs the resource directly.
Install
- Build from source
- go install
- Release archive
go build -o scrubctl ./cmd/scrubctl
sudo mv scrubctl /usr/local/bin/
scrubctl version
go install github.com/turbra/scrubctl/cmd/scrubctl@latest
export PATH="$(go env GOPATH)/bin:$PATH"
hash -r
scrubctl version
go install writes the binary to $(go env GOBIN) if set, otherwise $(go env GOPATH)/bin.
tar -xzf scrubctl-<version>-linux-<arch>.tar.gz
sudo mv scrubctl /usr/local/bin/
scrubctl version
Download archives from the GitHub Releases page.
Builds from source require Go 1.24 or newer.
Explore
Related
scrubctl shares classification and sanitization logic with the GitOps Export OpenShift console plugin. Both tools produce identical output for the same input, verified by shared golden test fixtures.