Global Flags
Global flags are available to scrubctl commands.
| Flag | Description |
|---|---|
--config | Path to a config file for default flag values |
--kubeconfig | Path to the kubeconfig file |
--context | Kubeconfig context to use |
-n, --namespace | Target namespace |
| `--secret-handling redact | omit |
--include-kinds | Comma-separated curated kinds or registry keys to include |
--exclude-kinds | Comma-separated curated kinds or registry keys to exclude |
-q, --quiet | Suppress non-essential output |
--log-level | Log level, default info |
Config File
You can define default includeKinds and excludeKinds in a YAML config file and pass it with --config.
# scrubctl.yaml
includeKinds:
- Deployment
- Service
- ConfigMap
excludeKinds:
- Secret
- Route
scrubctl scan my-app --config scrubctl.yaml
Config is only loaded when --config is explicitly provided. There is no auto-discovery from the current directory or home directory.
CLI flags always take precedence over config values.
scrubctl scan my-app --config scrubctl.yaml --include-kinds Deployment,Service