DevOps
Kubernetes YAML Validator
Paste a manifest to catch YAML mistakes, missing fields and risky settings before you run kubectl apply. Works with multi-document files.
Kubernetes YAML
Load a sample
41 lines825 characters Β· separate documents with ---
Results
No errors found
0 warnings Β· 0 tips Β· checked Deployment/web
This is a static check in your browser β it doesn't contact a cluster. For a full schema check against your cluster's API, run kubectl apply --dry-run=server -f file.yaml.
Real YAML parsing
Indentation, tabs, unclosed quotes and duplicate keys are reported with the exact line β click to jump there.
Kubernetes rules
Required fields, apiVersion for each kind, valid names, selector/label mismatches and values that must be strings.
Security & best practices
Flags privileged or root containers, host access, :latest images, missing resource limits and probes.
Kubernetes best practices
Security
- Run as a non-root user
- Disable privilege escalation
- Avoid privileged containers
- Keep Secrets out of git
Performance
- Set CPU/memory requests and limits
- Add readiness and liveness probes
- Spread replicas with anti-affinity
- Use a HorizontalPodAutoscaler
Reliability
- Run more than one replica
- Add a PodDisruptionBudget
- Use PersistentVolumes for state
- Log to stdout/stderr
Maintenance
- Pin image versions (no :latest)
- Use consistent, descriptive labels
- Keep config in ConfigMaps and Secrets
- Store manifests in version control
Free Kubernetes manifest validator
A single wrong space can stop a deployment. This validator parses your Kubernetes YAML and points out common mistakes that would break a deploy β plus the settings that work today but cause trouble in production. It runs entirely in your browser, so you can safely check manifests from private projects.
What it checks
- YAML syntax: tabs used for indentation, misaligned lines, unclosed quotes and brackets, duplicate keys, and trailing whitespace (with one-click fixes for tabs and whitespace).
- Structure:
apiVersion,kindandmetadata.name, the right apiVersion for built-in kinds (e.g.apps/v1for Deployments), valid resource names, and selectors that match the pod template labels. - Type mistakes: unquoted numbers or
yes/noin labels, env values and ConfigMap data β Kubernetes rejects them because these fields must be strings. - Best practices: pinned image tags, resource requests and limits, health probes and replica counts.
- Security: privileged containers, running as root, privilege escalation, host network/PID/IPC, hostPath volumes and risky Linux capabilities.
How to use it
- Paste your manifest, or load a sample to see how it works.
- Results update as you type. Errors come first, then warnings and tips.
- Tap βGo to lineβ to jump to the problem, fix it, and watch the result turn green.
This is a fast static check, not a replacement for your cluster: custom resources (CRDs) only get the generic checks, and admission policies aren't evaluated. Before deploying, run kubectl apply --dry-run=server for a full server-side validation.
Private by design. Everything runs in your browser β nothing you enter is uploaded or stored by AISeekho.
More free tools
- DNS LookupFetch A, AAAA, CNAME, MX, NS and TXT records for any domain.
- SSL Certificate CheckerCheck a site's SSL certificate, issuer, chain and expiry date.
- Docker GeneratorGenerate Dockerfiles, docker run commands and docker-compose files.
- Cron Expression GeneratorBuild cron schedules, read them in plain English and see the next runs.