Skip to main content

Scrub Modes

Direct Scrub​

Direct scrub mode reads a single YAML or JSON resource from a file or stdin.

scrubctl scrub -f deployment.yaml
oc get deploy/web -n my-app -o yaml | scrubctl

Use this mode for quick cleanup, inspection, or pipeline steps that already select the resource.

Direct scrub mode accepts any Kubernetes kind. Resources that would be excluded in a scan context, such as runtime-generated resources, are still sanitized and emitted for review.

Curated Scan and Export​

Namespace scan and export commands operate on a curated set of namespaced resources.

scrubctl scan my-app
scrubctl export my-app -o ./out

Use this mode when you want scrubctl to discover application resources, classify them, and produce a structured export.

Kinds outside the curated set are excluded with kind not in curated resource set.