Developer Tools
Check Kubernetes YAML for missing keys and exposed secrets
Paste your manifests. Each document is checked for apiVersion and kind, and keys like password, token or api_key with a plain-text value are flagged with document and line number. The check runs in this page and contacts no cluster.
Findings
3 documents checked · 2 errors
- ErrorDoc 2, line 15kind is missing
- ErrorDoc 2, line 20db_password has a plain-text value
- NoteDoc 3, line 27api_key uses a placeholder, so it is not flagged
Secret values are never shown here, only key names. A clean result does not mean the manifests will apply: there is no schema or cluster check.
Need the files for a ticket or pipeline? Run the full job
Upload a YAML file and download a package with the same checks written out:
normalized-source.yaml: your source with a # Source line and Unix line endingsfindings.csv: severity, code and evidence for each findingmanifest.json: which file was read and a summary of the run
- YAML / YML
- Up to 5,000 objects
- Result kept 24 hours
or drop it here
From paste to fix in three steps
- 1
Paste or open YAML
Paste manifests into the box or open a .yaml file. The text is read in this page.
- 2
Fix what is listed
Each finding names the document and line: a missing apiVersion or kind, or a secret-like key with a plain-text value.
- 3
Keep a record if you need one
Upload the file to the full job for findings.csv and the other download files. It uses one of your 3 free jobs a day.
A first check of Kubernetes YAML before you commit
What it reads
Plain YAML, one or many documents separated by --- lines. Rendered Helm charts and kustomize output work. Templates with placeholders that were not rendered fail to parse in the full job, so render them first. No cluster is contacted, and you do not need a kubeconfig or credentials.
What it flags
Every document must carry apiVersion and kind. A document missing one is listed with its number and first line. Keys named like password, passwd, token, secret or api_key, alone or with a prefix such as db_password, are flagged when they hold a literal value. Placeholders such as ${API_KEY} or {{ .Values.key }} are skipped. Base64 inside a Secret and values pulled from external stores are not decoded.
What only your cluster can confirm
This check does not validate against a schema for a cluster version, and it does not test admission policies or custom resources. A clean result does not mean the manifests will apply. After this pass, run a server-side dry run against the matching cluster version and your usual policy checks in your pipeline.
Questions before you run it
Is the YAML I paste uploaded?
No. The paste check runs in this page, and the text stays in your browser. Only the full job sends a file to the server, and only when you upload one.
Does it connect to my cluster?
No. It only reads the YAML you paste or upload, so there is no kubeconfig, no credentials and no call to an API server. Admission policies and custom-resource validation stay for a server-side dry run.
What does it check in each manifest?
Multi-document YAML is split at --- lines, and every document must carry apiVersion and kind. A document missing one is listed with its document number and first line. The full job lists them in findings.csv with the document number.
How does it spot secrets in a manifest?
By key name. A key such as password, db_password, token, secret or api_key with a literal value is flagged. Placeholders like ${API_KEY} or {{ .Values.key }} are skipped. Env entries written as name and value pairs are not matched, base64 inside a Secret is not decoded, and values from external stores are not resolved.
Is this a replacement for a server-side dry run or a schema linter?
No. Schema validation against a specific cluster version is not claimed here. Use it as a first pass before committing, then run version-matched validation in your pipeline.
Can I send a rendered Helm chart or kustomize output?
Yes, as long as it is plain YAML. Paste it, or upload it to the full job, which splits multi-document files per object, up to 5,000 objects per run. Templates with unrendered placeholders fail to parse in the full job, so render first.