Sanitization
Sanitization removes data that should not be committed as desired state.
Common cleanup includes:
| Area | Examples |
|---|---|
| Server-assigned metadata | uid, resourceVersion, generation, creationTimestamp, managedFields, selfLink, ownerReferences |
| Runtime state | status fields |
| Runtime defaults | Empty securityContext: {} and affinity: {} maps |
| Runtime annotations | Volume provisioner state, OpenShift operator state, build annotations, generated host annotations |
Secrets are handled by policy:
| Mode | Behavior |
|---|---|
redact | Replace Secret values with redacted placeholders |
omit | Omit Secrets from the export |
include | Include Secret values in output |
redact is the default. Use include only when the resulting archive is handled as sensitive material.