Skip to main content

Command Reference

Complete reference for every scrubctl subcommand, flag, and supported resource kind.

Cluster-facing subcommands (scan, export, generate argocd) read your active kubeconfig the same way kubectl or oc do. The scrub subcommand and stdin pipe mode work on local YAML only, so they need no cluster access.

Usage​

Sanitize live manifests and generate GitOps export artifacts

Usage:
scrubctl [flags]
scrubctl [command]

Available Commands:
completion Generate the autocompletion script for the specified shell
export Export a namespace scan as a ZIP archive
generate Generate GitOps manifests
help Help about any command
scan Scan a namespace and print the classification table
scrub Scrub a single YAML resource from file or stdin
version Print the CLI version

Flags:
--config string Path to a config file for default flag values
--context string Kubeconfig context to use
--exclude-kinds string Comma-separated curated kinds or registry keys to exclude
-h, --help help for scrubctl
--include-kinds string Comma-separated curated kinds or registry keys to include
--kubeconfig string Path to the kubeconfig file
--log-level string Log level (default "info")
-n, --namespace string Target namespace
-q, --quiet Suppress non-essential output
--secret-handling string Secret handling mode: redact, omit, or include (default "redact")

Commands​

CommandDescription
scrubScrub a single YAML resource from file or stdin
scanScan a namespace and print the classification table
exportExport a namespace scan as a ZIP archive
generate argocdGenerate Argo CD Application YAML
versionPrint the CLI version
completionGenerate shell autocompletion scripts

OpenShift and oc​

scrubctl works naturally alongside oc.

oc get deploy/<name> -n <namespace> -o yaml | scrubctl
oc get route/<name> -n <namespace> -o yaml | scrubctl

Use -n or --namespace to target a namespace directly when running scan or export against an OpenShift cluster with an active oc session.