Skip to main content

Sanitization

Sanitization removes data that should not be committed as desired state.

Common cleanup includes:

AreaExamples
Server-assigned metadatauid, resourceVersion, generation, creationTimestamp, managedFields, selfLink, ownerReferences
Runtime statestatus fields
Runtime defaultsEmpty securityContext: {} and affinity: {} maps
Runtime annotationsVolume provisioner state, OpenShift operator state, build annotations, generated host annotations

Secrets are handled by policy:

ModeBehavior
redactReplace Secret values with redacted placeholders
omitOmit Secrets from the export
includeInclude Secret values in output

redact is the default. Use include only when the resulting archive is handled as sensitive material.