Command Reference
Complete reference for every scrubctl subcommand, flag, and supported resource kind.
Cluster-facing subcommands (scan, export, generate argocd) read your active kubeconfig the same way kubectl or oc do. The scrub subcommand and stdin pipe mode work on local YAML only, so they need no cluster access.
Usage
Sanitize live manifests and generate GitOps export artifacts
Usage:
scrubctl [flags]
scrubctl [command]
Available Commands:
completion Generate the autocompletion script for the specified shell
export Export a namespace scan as a ZIP archive
generate Generate GitOps manifests
help Help about any command
scan Scan a namespace and print the classification table
scrub Scrub a single YAML resource from file or stdin
version Print the CLI version
Flags:
--config string Path to a config file for default flag values
--context string Kubeconfig context to use
--exclude-kinds string Comma-separated curated kinds or registry keys to exclude
-h, --help help for scrubctl
--include-kinds string Comma-separated curated kinds or registry keys to include
--kubeconfig string Path to the kubeconfig file
--log-level string Log level (default "info")
-n, --namespace string Target namespace
-q, --quiet Suppress non-essential output
--secret-handling string Secret handling mode: redact, omit, or include (default "redact")
Commands
| Command | Description |
|---|---|
scrub | Scrub a single YAML resource from file or stdin |
scan | Scan a namespace and print the classification table |
export | Export a namespace scan as a ZIP archive |
generate argocd | Generate Argo CD Application YAML |
version | Print the CLI version |
completion | Generate shell autocompletion scripts |
OpenShift and oc
scrubctl works naturally alongside oc.
oc get deploy/<name> -n <namespace> -o yaml | scrubctl
oc get route/<name> -n <namespace> -o yaml | scrubctl
Use -n or --namespace to target a namespace directly when running scan or export against an OpenShift cluster with an active oc session.