WoluTools

Developer Tools

Check Kubernetes YAML for missing keys and exposed secrets

Paste your manifests. Each document is checked for apiVersion and kind, and keys like password, token or api_key with a plain-text value are flagged with document and line number. The check runs in this page and contacts no cluster.

Findings update as you type. Opened files are read in this page and are not uploaded.

Result of the check

Findings

3 documents checked · 2 errors

  • ErrorDoc 2, line 15kind is missing
  • ErrorDoc 2, line 20db_password has a plain-text value
  • NoteDoc 3, line 27api_key uses a placeholder, so it is not flagged

Secret values are never shown here, only key names. A clean result does not mean the manifests will apply: there is no schema or cluster check.

Need the files for a ticket or pipeline? Run the full job

Upload a YAML file and download a package with the same checks written out:

  • normalized-source.yaml: your source with a # Source line and Unix line endings
  • findings.csv: severity, code and evidence for each finding
  • manifest.json: which file was read and a summary of the run
Standard toolIncluded · 3 free jobs a dayFree: 3 jobs a dayPro: up to 200 jobs a day · €12.99/month or €89.99/year
  • YAML / YML
  • Up to 5,000 objects
  • Result kept 24 hours

or drop it here

YAML, YML · Up to 5,000 objects
Free account needed for your 3 free jobs a day

No file at hand? Use the paste check above

BringPasted YAML, or .yaml and .yml files
GetFindings with document and line; the full job adds three download files
PrivacyPaste check stays in your browser · full job: encrypted source, 24-hour result

From paste to fix in three steps

  1. 1

    Paste or open YAML

    Paste manifests into the box or open a .yaml file. The text is read in this page.

  2. 2

    Fix what is listed

    Each finding names the document and line: a missing apiVersion or kind, or a secret-like key with a plain-text value.

  3. 3

    Keep a record if you need one

    Upload the file to the full job for findings.csv and the other download files. It uses one of your 3 free jobs a day.

A first check of Kubernetes YAML before you commit

What it reads

Plain YAML, one or many documents separated by --- lines. Rendered Helm charts and kustomize output work. Templates with placeholders that were not rendered fail to parse in the full job, so render them first. No cluster is contacted, and you do not need a kubeconfig or credentials.

What it flags

Every document must carry apiVersion and kind. A document missing one is listed with its number and first line. Keys named like password, passwd, token, secret or api_key, alone or with a prefix such as db_password, are flagged when they hold a literal value. Placeholders such as ${API_KEY} or {{ .Values.key }} are skipped. Base64 inside a Secret and values pulled from external stores are not decoded.

What only your cluster can confirm

This check does not validate against a schema for a cluster version, and it does not test admission policies or custom resources. A clean result does not mean the manifests will apply. After this pass, run a server-side dry run against the matching cluster version and your usual policy checks in your pipeline.

Questions before you run it

Is the YAML I paste uploaded?

No. The paste check runs in this page, and the text stays in your browser. Only the full job sends a file to the server, and only when you upload one.

Does it connect to my cluster?

No. It only reads the YAML you paste or upload, so there is no kubeconfig, no credentials and no call to an API server. Admission policies and custom-resource validation stay for a server-side dry run.

What does it check in each manifest?

Multi-document YAML is split at --- lines, and every document must carry apiVersion and kind. A document missing one is listed with its document number and first line. The full job lists them in findings.csv with the document number.

How does it spot secrets in a manifest?

By key name. A key such as password, db_password, token, secret or api_key with a literal value is flagged. Placeholders like ${API_KEY} or {{ .Values.key }} are skipped. Env entries written as name and value pairs are not matched, base64 inside a Secret is not decoded, and values from external stores are not resolved.

Is this a replacement for a server-side dry run or a schema linter?

No. Schema validation against a specific cluster version is not claimed here. Use it as a first pass before committing, then run version-matched validation in your pipeline.

Can I send a rendered Helm chart or kustomize output?

Yes, as long as it is plain YAML. Paste it, or upload it to the full job, which splits multi-document files per object, up to 5,000 objects per run. Templates with unrendered placeholders fail to parse in the full job, so render first.