Skip to content

All Rules

The Kubernetes lexicon provides 57 rules: 6 lint rules and 51 post-synth checks.

IDSeverityCategoryDescription
ARGO001warningcorrectnessProduction Application must not enable automated prune
ARGO004warningcorrectnessApplicationSet template must scope to a single AppProject
FLUX001warningcorrectnessGitRepository must pin spec.ref
WK8001warningcorrectnessHardcoded Namespace
WK8002warningsecurityLatest Image Tag
WK8003warningcorrectnessMissing Resource Limits

Post-synth checks validate the serialized output after the build pipeline completes.

IDDescription
ARGO002Application.spec.project must reference a declared AppProject (or the built-in default)
ARGO003Application.spec.destination must reference a registered cluster or the in-cluster target
ARGO005Application source.path should resolve to an existing directory under the build root
FLUX002Kustomization.spec.sourceRef must reference a declared source (or the bootstrap flux-system repo)
FLUX003Kustomization.spec.dependsOn entries should name Kustomizations declared in the build
WK8005Hardcoded secrets in env vars — sensitive environment variables should use secretKeyRef
WK8006No :latest or untagged images — container images should use explicit version tags
WK8041Hardcoded API keys — detects well-known API key patterns in env var values
WK8042Private keys in ConfigMap — private keys should be stored in Secrets, not ConfigMaps
WK8101Deployment selector must match template labels — mismatched selectors cause runtime failures
WK8102Resources should have metadata labels — labels enable filtering and operational tooling
WK8103Containers must have name — the name field is required by the Kubernetes API
WK8104Ports should be named — named ports improve Service and NetworkPolicy configuration
WK8105ImagePullPolicy should be explicit — avoids surprising default behavior
WK8201Resource limits required — containers should have CPU and memory limits
WK8202No privileged containers — privileged mode grants full host access
WK8203ReadOnlyRootFilesystem recommended — prevents runtime modification of the container image
WK8204RunAsNonRoot recommended — running as root increases container breakout risk
WK8205Drop ALL capabilities — containers should drop all capabilities and add only what is needed
WK8207No hostNetwork — using host network bypasses network isolation
WK8208No hostPID — sharing host PID namespace allows visibility into all host processes
WK8209No hostIPC — sharing host IPC namespace can expose shared memory segments
WK8301Probes required — containers should have livenessProbe and readinessProbe
WK8302Replicas >= 2 recommended — single-replica Deployments have no high availability
WK8303PDB recommended for HA Deployments — ensures availability during voluntary disruptions
WK8304SSL redirect without certificate — ssl-redirect annotation requires a valid certificate-arn and HTTPS listen-ports
WK8305Ingress port not matching Service — backend port must match a declared Service port
WK8306Container command starts with flag — first element should be a binary, not a flag
WK8401shmSize must not exceed the container memory limit — pod will not schedule if it does
WK8402RayCluster should set spec.rayVersion so KubeRay selects the correct autoscaler image
WK8403spec.rayVersion should match the Ray version in the head container image tag
WK8404GPU request without a matching nvidia.com/gpu toleration
WK8405Serving workload (InferenceService / serving Deployment) has no PodDisruptionBudget
WK8406GPU-requesting container has no cpu/memory resource limits
WK8407InferenceService model storageUri has no explicit version segment
WK8501Custom resource spec contains a field its CRD schema does not declare
WK8502Custom resource spec field has the wrong type or a value outside its enum
WK8503Workload consumes a Secret nothing in the output produces — produce it (Secret, ExternalSecret, InfisicalSecret, Certificate) or declare its provenance with declareSecret()
WK8504committed-encrypted secret declaration does not resolve — the declared file is missing, is not the named Secret, or is not encrypted
WK8505committed-encrypted secret with no Flux decryption wiring — add decryption: ‘sops’ to the FluxAppFor reconciling the path that carries it. Sees one build root at a time, so it goes silent when that Kustomization lives in a different build root (chant #1939).
WK8601OpenTelemetry Collector runs tail_sampling as a per-node DaemonSet; each agent sees only its node’s spans, so decisions are made on partial traces. Sees one build root at a time (chant #1939).
WK8602OpenTelemetry Collector gateway runs tail_sampling on more than one replica, but collectors send it traces without a loadbalancing exporter routed by traceID. Sees one build root at a time (chant #1939).
WK8603OpenTelemetry Collector runs the k8s_cluster receiver in a DaemonSet or multi-replica workload without a k8s_leader_elector; every copy reports every cluster object. Sees one build root at a time (chant #1939).
WK8604OpenTelemetry Collector config in a ConfigMap or an OpenTelemetryCollector’s spec.config fails the otel lexicon’s config checks; findings are reported under their OTEL1xx ids, naming the ConfigMap and key, or the OpenTelemetryCollector.
WK8605OpenTelemetry Collector config reads the node (k8sattributes filtered to its node, kubeletstats, hostmetrics root_path, filelog) but its workload doesn’t set the node name variable or mount the host paths. Sees one build root at a time (chant #1939).
WK8606A PrometheusRule’s groups fail the prometheus lexicon’s rule-file checks; findings are reported under their PROM ids, naming the PrometheusRule.
WK8701A PrometheusRule that no Prometheus or ThanosRuler in the build selects through ruleSelector and ruleNamespaceSelector is never evaluated. A null selector matches nothing, {} matches all. Silent when the build has no Prometheus or ThanosRuler.
WK8702A ServiceMonitor, PodMonitor, Probe or ScrapeConfig that no Prometheus or PrometheusAgent in the build selects is never scraped. A null selector matches nothing, {} matches all. Silent when the build has no Prometheus or PrometheusAgent.
WK8703An AlertmanagerConfig that no Alertmanager in the build selects through alertmanagerConfigSelector and alertmanagerConfigNamespaceSelector never routes an alert. A null selector matches nothing, {} matches all. Silent when the build has no Alertmanager.
WK8704A ServiceMonitor whose selector matches no Service in the build, or whose endpoints[].port names no port on the matched Services; the same for a PodMonitor against pod container ports. Needs no Prometheus in the build. Sees one build root at a time (chant #1939).
WK8705A Prometheus whose serviceMonitorSelector, podMonitorSelector, probeSelector and scrapeConfigSelector are all null selects no monitor, so the operator scrapes nothing from ServiceMonitors, PodMonitors, Probes or ScrapeConfigs.