DevOps

Kubernetes YAML Validator

Paste a manifest to catch YAML mistakes, missing fields and risky settings before you run kubectl apply. Works with multi-document files.

Kubernetes YAML

Load a sample

41 lines825 characters Β· separate documents with ---

Results

No errors found

0 warnings Β· 0 tips Β· checked Deployment/web

This is a static check in your browser β€” it doesn't contact a cluster. For a full schema check against your cluster's API, run kubectl apply --dry-run=server -f file.yaml.

  • Real YAML parsing

    Indentation, tabs, unclosed quotes and duplicate keys are reported with the exact line β€” click to jump there.

  • Kubernetes rules

    Required fields, apiVersion for each kind, valid names, selector/label mismatches and values that must be strings.

  • Security & best practices

    Flags privileged or root containers, host access, :latest images, missing resource limits and probes.

Kubernetes best practices

Security

  • Run as a non-root user
  • Disable privilege escalation
  • Avoid privileged containers
  • Keep Secrets out of git

Performance

  • Set CPU/memory requests and limits
  • Add readiness and liveness probes
  • Spread replicas with anti-affinity
  • Use a HorizontalPodAutoscaler

Reliability

  • Run more than one replica
  • Add a PodDisruptionBudget
  • Use PersistentVolumes for state
  • Log to stdout/stderr

Maintenance

  • Pin image versions (no :latest)
  • Use consistent, descriptive labels
  • Keep config in ConfigMaps and Secrets
  • Store manifests in version control

Free Kubernetes manifest validator

A single wrong space can stop a deployment. This validator parses your Kubernetes YAML and points out common mistakes that would break a deploy β€” plus the settings that work today but cause trouble in production. It runs entirely in your browser, so you can safely check manifests from private projects.

What it checks

  • YAML syntax: tabs used for indentation, misaligned lines, unclosed quotes and brackets, duplicate keys, and trailing whitespace (with one-click fixes for tabs and whitespace).
  • Structure: apiVersion, kind and metadata.name, the right apiVersion for built-in kinds (e.g. apps/v1 for Deployments), valid resource names, and selectors that match the pod template labels.
  • Type mistakes: unquoted numbers or yes/no in labels, env values and ConfigMap data β€” Kubernetes rejects them because these fields must be strings.
  • Best practices: pinned image tags, resource requests and limits, health probes and replica counts.
  • Security: privileged containers, running as root, privilege escalation, host network/PID/IPC, hostPath volumes and risky Linux capabilities.

How to use it

  1. Paste your manifest, or load a sample to see how it works.
  2. Results update as you type. Errors come first, then warnings and tips.
  3. Tap β€œGo to line” to jump to the problem, fix it, and watch the result turn green.

This is a fast static check, not a replacement for your cluster: custom resources (CRDs) only get the generic checks, and admission policies aren't evaluated. Before deploying, run kubectl apply --dry-run=server for a full server-side validation.

Private by design. Everything runs in your browser β€” nothing you enter is uploaded or stored by AISeekho.