Scrub Modes
Direct Scrub
Direct scrub mode reads a single YAML or JSON resource from a file or stdin.
scrubctl scrub -f deployment.yaml
oc get deploy/web -n my-app -o yaml | scrubctl
Use this mode for quick cleanup, inspection, or pipeline steps that already select the resource.
Direct scrub mode accepts any Kubernetes kind. Resources that would be excluded in a scan context, such as runtime-generated resources, are still sanitized and emitted for review.
Curated Scan and Export
Namespace scan and export commands operate on a curated set of namespaced resources.
scrubctl scan my-app
scrubctl export my-app -o ./out
Use this mode when you want scrubctl to discover application resources, classify them, and produce a structured export.
Kinds outside the curated set are excluded with kind not in curated resource set.