Skip to main content

scan

Scan a namespace and print the classification table.

scrubctl scan <namespace>

The namespace argument is optional. If omitted, scrubctl falls back to -n/--namespace and then the active kubeconfig context namespace.

scrubctl scan --namespace my-app

Filtering​

scrubctl scan my-app --include-kinds Deployment,Service,ConfigMap
scrubctl scan my-app --exclude-kinds Secret,Route

--include-kinds and --exclude-kinds filter within the curated resource set.

Config File​

Use --config when you want scan defaults in a YAML file.

includeKinds:
- Deployment
- Service
- ConfigMap

excludeKinds:
- Secret
scrubctl scan my-app --config scrubctl.yaml

CLI flags take precedence over config file values. See Global Flags for the full config behavior.