Skip to main content

Global Flags

Global flags are available to scrubctl commands.

FlagDescription
--configPath to a config file for default flag values
--kubeconfigPath to the kubeconfig file
--contextKubeconfig context to use
-n, --namespaceTarget namespace
`--secret-handling redactomit
--include-kindsComma-separated curated kinds or registry keys to include
--exclude-kindsComma-separated curated kinds or registry keys to exclude
-q, --quietSuppress non-essential output
--log-levelLog level, default info

Config File​

You can define default includeKinds and excludeKinds in a YAML config file and pass it with --config.

# scrubctl.yaml
includeKinds:
- Deployment
- Service
- ConfigMap

excludeKinds:
- Secret
- Route
scrubctl scan my-app --config scrubctl.yaml

Config is only loaded when --config is explicitly provided. There is no auto-discovery from the current directory or home directory.

CLI flags always take precedence over config values.

scrubctl scan my-app --config scrubctl.yaml --include-kinds Deployment,Service