Kubernetes YAML Checker
Validate and explain Kubernetes manifests
Paste Kubernetes YAML to check structure and best practices: resource limits, image tags, probes, security context and more.
- Kubernetes
- YAML
- k8s
How to use Kubernetes YAML Checker
- Paste one or more Kubernetes manifests (separate them with
---), drop a file on the box, or use Open file. Example loads a sample with several problems. - Read the Resources table for what was found: kind, name, namespace and key details such as replicas, ports or the cron schedule.
- Go through the Findings. Each one has a severity (error, warning or tip), an explanation and, where there is a standard fix, a snippet you can copy. Use the filter to show only errors or warnings.
- Fix the manifest and the results update as you type.
How it works
The text is parsed with the yaml package as a multi-document stream (alias expansion is capped at 100 to refuse "billion laughs" input). Each document is read as a Kubernetes object, kind: List items are unpacked, and the checker looks at three things.
Structure: apiVersion, kind and metadata.name exist; the apiVersion fits the kind and has not been removed (extensions/v1beta1, apps/v1beta1, batch/v1beta1, policy/v1beta1, autoscaling/v2beta1 and similar); a workload selector matches its pod template labels; a Service selector matches a workload in the paste and each targetPort matches a containerPort (by number or name); Ingress backends point at a Service in the paste with that port; HPA, PodDisruptionBudget and role bindings point at things that exist.
Best practice: missing resource requests and limits, :latest or untagged images, missing readiness and liveness probes, containers that may run as root, allow privilege escalation, are privileged, have a writable root filesystem or keep default capabilities, hostNetwork, hostPID, hostPath and hostPort, passwords in plain env values, Secrets whose values sit in the manifest (a masked, decoded preview is shown), single-replica Deployments, workloads without a PodDisruptionBudget and wildcard RBAC rules. CronJob schedules are parsed with the Cron Builder parser and explained in words.
Limits
- Input is limited to about 1 MB and 300 documents. Alias expansion above 100 is rejected.
- It is a static linter for the common built-in kinds. Custom resources are listed but only their basic structure is checked, and field names are not validated against the full OpenAPI schema.
- Cross-resource checks only see what you pasted. A Service, ServiceAccount or Role defined elsewhere is reported as missing, usually as a warning or tip.
- Values are not rendered by Helm or Kustomize: paste rendered YAML (
helm template,kubectl kustomize). Template syntax such as{{ .Values.x }}is not valid YAML. - The security checks look at the container and pod
securityContextonly; Pod Security Admission, policy engines and admission webhooks in your cluster may add or relax rules.
Privacy
Everything is checked in your browser; your manifests are never uploaded or stored. Secret values are only decoded in memory and shown masked. Share copies a link with your YAML in the URL’s # fragment, which browsers do not send to servers, but anyone with the link can read it, so do not share manifests that contain real credentials. If you receive text from another tool, it is handed over through this tab’s session storage and removed as soon as it is read.
Frequently asked questions
Why is a missing readiness probe a warning but a missing liveness probe only a tip?
A missing readiness probe sends traffic to pods that are not ready and makes rollouts unsafe. A bad liveness probe can restart healthy pods, so it is only suggested.
Is base64 in a Secret safe?
No. base64 is an encoding, anyone can decode it. Keep Secret manifests out of Git, or encrypt them with Sealed Secrets, SOPS or an external secret store.
Why does it say my Service selector matches nothing?
The selector labels must equal labels on the workload’s pod template (spec.template.metadata.labels), not just the workload’s own metadata.labels. The check only compares workloads in the same paste and namespace.
Does it replace kubectl --dry-run?
No. It catches common mistakes and explains them, but only the API server knows your cluster version, CRDs and admission rules. Run kubectl apply --dry-run=server as well.
More tools
- Clean Image: Inspect and remove hidden image metadata
- JWT Decoder: Decode and verify JSON Web Tokens
- Diff Checker: Compare two texts line by line
- JS Runner: Run JavaScript and TypeScript in your browser
- JSON Formatter: Format, validate and minify JSON
- Encode / Decode: Base64, URL, HTML entity and hex
- Hash Generator: MD5, SHA and HMAC of any text
- UUID Generator: Generate UUID v4 and v7 in bulk
- Timestamp Converter: Unix time ↔ human dates
- Regex Tester: Test regular expressions live
- URL Parser: Break a URL into its parts
- HTTP Status Codes: Look up any HTTP status code
- MIME Type Lookup: File extension ↔ MIME type
- Password Generator: Strong random passwords and passphrases
- Random String Generator: Random tokens, IDs and keys
- Slug Generator: Turn titles into URL slugs
- Case Converter: camelCase, snake_case, Title Case and more
- Word Counter: Count words, characters and reading time
- JSON to TypeScript: Generate TypeScript types from JSON
- JSON Diff: Compare two JSON documents structurally
- JSON to SQL: Turn JSON arrays into SQL inserts
- YAML ↔ JSON: Convert between YAML and JSON
- XML ↔ JSON: Convert between XML and JSON
- CSV ↔ JSON: Convert between CSV and JSON
- CSV Viewer: View, sort and filter CSV files
- SQL Formatter: Format and beautify SQL queries
- cURL ↔ Fetch: Convert cURL commands to fetch and back
- Markdown Editor: Write Markdown with a live preview
- Text Cleaner: Remove duplicate lines, empty lines and extra spaces
- Find & Replace: Find and replace in any text
- Cron Expression Builder: Build and explain cron schedules
- User-Agent Parser: Identify browser, OS and device from a user agent
- HTTP Headers Inspector: Paste response headers and get them explained
- JWT Generator: Create and sign test JSON Web Tokens
- Certificate Inspector: Decode PEM certificates and keys
- Meta Tag Inspector: Check a page's SEO and social tags
- UTM Builder: Build campaign URLs with UTM parameters
- URL Cleaner: Strip tracking parameters from links
- Robots.txt Generator: Create and test a robots.txt file
- Sitemap Generator: Create an XML sitemap from a list of URLs
- Image Compressor: Shrink JPEG, WebP and AVIF images in your browser
- Image Resizer: Resize images by pixels, percentage or to fit a box
- Image Converter: Convert between PNG, JPEG, WebP and AVIF
- Image to Base64: Encode images as Base64 data URIs and decode them back
- SVG Optimizer: Minify and sanitize SVG files
- Favicon Generator: Make favicon.ico, Apple and Android icons from an image or emoji
- Color Converter: HEX, RGB, HSL, OKLCH and contrast checks
- Number Base Converter: Binary, octal, decimal, hex and float bits
- IP / CIDR Calculator: Subnets, masks and IP ranges for IPv4 and IPv6
- JSONPath Query: Query JSON with JSONPath expressions
- JSON Schema Validator: Validate JSON against a schema, or generate one
- Semver Checker: Check versions against semver ranges
- chmod Calculator: Unix permissions: rwx ↔ octal
- .env Diff: Compare and validate .env files
- TOTP Generator: Generate and verify 2FA codes
- String Escaper: Escape and unescape strings for any language
- Unicode Inspector: See every character, code point and hidden symbol
- Mock Data Generator: Generate realistic fake data
- QR Code Generator: Create QR codes for links, Wi-Fi and contacts
- Lorem Ipsum Generator: Placeholder text in paragraphs, sentences or words
- Date Calculator: Date differences, business days and durations
- Unit Converter: Convert bytes, lengths, weights, temperatures and more
- Query CSV with SQL: Run SQL queries on CSV files
- PDF Merge & Split: Merge, split, reorder and rotate PDFs
- PDF Metadata Cleaner: See and remove hidden PDF metadata
- Office Metadata Cleaner: Remove author and revision data from Word, Excel and PowerPoint
- Images to PDF: Combine images into one PDF
- Image Editor: Crop, rotate, resize and adjust images
- Encrypt / Decrypt Text: Encrypt text with a passphrase (AES-GCM)
- SSH Key Generator: Generate Ed25519 and RSA SSH keys locally
- Email Header Analyzer: Trace an email's path and check SPF, DKIM and DMARC
- JSON to Code: Generate Go, Python, Rust, Java, C# and Kotlin models from JSON
- docker run ↔ Compose: Convert docker run commands to docker-compose and back
- Color Palette Extractor: Pull the dominant colours out of any image
- Password Strength Checker: How long would your password take to crack?
- SPF / DKIM / DMARC Checker: Validate and explain email DNS records
- .gitignore Generator: Build a .gitignore from presets
- CSP Builder: Build and check a Content-Security-Policy
- JSON-LD Generator: Create schema.org structured data
- Open Graph Image Generator: Make 1200×630 social preview images
- CSS Generator: Gradients, shadows, clamp() and more
- Time Zone Meeting Planner: Find meeting times across time zones