Dockerfile, GitHub Actions & Kubernetes Linter

Choose the configuration type and run the static rules. Findings need context and do not replace deployment tests or organization-specific policy checks.

Runs locally in your browser
Configuration files are parsed locally in your browser. Do not paste production secrets; use the existing ENV Validator to review those separately.
Configuration input

The rules are intentionally conservative. Review every finding against the image, cluster policy, workflow permissions, and environment you actually use.

Configuration review
  • Choose a configuration type and run the local linter.

Review deployment configuration before it reaches CI

This local ruleset looks for common practical mistakes, not full policy compliance. Use it alongside image scanning, admission controls, CI policy checks, and your organization’s security review.

Recent tools: