First Namespace Scan
Use scan to inspect a namespace and print the classification table.
scrubctl scan my-app
Cluster-facing commands read your active kubeconfig the same way kubectl or oc do. You can pass --kubeconfig, --context, or -n/--namespace when you need an explicit target.
scrubctl scan my-app --context dev-cluster
If you do not pass a namespace argument, scrubctl falls back to -n/--namespace and then the active kubeconfig context namespace.
Filter Resource Kinds
scan works with the curated export set. You can narrow that set with --include-kinds and --exclude-kinds.
scrubctl scan my-app --include-kinds Deployment,Service,ConfigMap
scrubctl scan my-app --exclude-kinds Secret,Route