All Rules
The Kubernetes lexicon provides 57 rules: 6 lint rules and 51 post-synth checks.
Lint Rules
Section titled “Lint Rules”| ID | Severity | Category | Description |
|---|---|---|---|
ARGO001 | warning | correctness | Production Application must not enable automated prune |
ARGO004 | warning | correctness | ApplicationSet template must scope to a single AppProject |
FLUX001 | warning | correctness | GitRepository must pin spec.ref |
WK8001 | warning | correctness | Hardcoded Namespace |
WK8002 | warning | security | Latest Image Tag |
WK8003 | warning | correctness | Missing Resource Limits |
Post-Synth Checks
Section titled “Post-Synth Checks”Post-synth checks validate the serialized output after the build pipeline completes.
| ID | Description |
|---|---|
ARGO002 | Application.spec.project must reference a declared AppProject (or the built-in default) |
ARGO003 | Application.spec.destination must reference a registered cluster or the in-cluster target |
ARGO005 | Application source.path should resolve to an existing directory under the build root |
FLUX002 | Kustomization.spec.sourceRef must reference a declared source (or the bootstrap flux-system repo) |
FLUX003 | Kustomization.spec.dependsOn entries should name Kustomizations declared in the build |
WK8005 | Hardcoded secrets in env vars — sensitive environment variables should use secretKeyRef |
WK8006 | No :latest or untagged images — container images should use explicit version tags |
WK8041 | Hardcoded API keys — detects well-known API key patterns in env var values |
WK8042 | Private keys in ConfigMap — private keys should be stored in Secrets, not ConfigMaps |
WK8101 | Deployment selector must match template labels — mismatched selectors cause runtime failures |
WK8102 | Resources should have metadata labels — labels enable filtering and operational tooling |
WK8103 | Containers must have name — the name field is required by the Kubernetes API |
WK8104 | Ports should be named — named ports improve Service and NetworkPolicy configuration |
WK8105 | ImagePullPolicy should be explicit — avoids surprising default behavior |
WK8201 | Resource limits required — containers should have CPU and memory limits |
WK8202 | No privileged containers — privileged mode grants full host access |
WK8203 | ReadOnlyRootFilesystem recommended — prevents runtime modification of the container image |
WK8204 | RunAsNonRoot recommended — running as root increases container breakout risk |
WK8205 | Drop ALL capabilities — containers should drop all capabilities and add only what is needed |
WK8207 | No hostNetwork — using host network bypasses network isolation |
WK8208 | No hostPID — sharing host PID namespace allows visibility into all host processes |
WK8209 | No hostIPC — sharing host IPC namespace can expose shared memory segments |
WK8301 | Probes required — containers should have livenessProbe and readinessProbe |
WK8302 | Replicas >= 2 recommended — single-replica Deployments have no high availability |
WK8303 | PDB recommended for HA Deployments — ensures availability during voluntary disruptions |
WK8304 | SSL redirect without certificate — ssl-redirect annotation requires a valid certificate-arn and HTTPS listen-ports |
WK8305 | Ingress port not matching Service — backend port must match a declared Service port |
WK8306 | Container command starts with flag — first element should be a binary, not a flag |
WK8401 | shmSize must not exceed the container memory limit — pod will not schedule if it does |
WK8402 | RayCluster should set spec.rayVersion so KubeRay selects the correct autoscaler image |
WK8403 | spec.rayVersion should match the Ray version in the head container image tag |
WK8404 | GPU request without a matching nvidia.com/gpu toleration |
WK8405 | Serving workload (InferenceService / serving Deployment) has no PodDisruptionBudget |
WK8406 | GPU-requesting container has no cpu/memory resource limits |
WK8407 | InferenceService model storageUri has no explicit version segment |
WK8501 | Custom resource spec contains a field its CRD schema does not declare |
WK8502 | Custom resource spec field has the wrong type or a value outside its enum |
WK8503 | Workload consumes a Secret nothing in the output produces — produce it (Secret, ExternalSecret, InfisicalSecret, Certificate) or declare its provenance with declareSecret() |
WK8504 | committed-encrypted secret declaration does not resolve — the declared file is missing, is not the named Secret, or is not encrypted |
WK8505 | committed-encrypted secret with no Flux decryption wiring — add decryption: ‘sops’ to the FluxAppFor reconciling the path that carries it. Sees one build root at a time, so it goes silent when that Kustomization lives in a different build root (chant #1939). |
WK8601 | OpenTelemetry Collector runs tail_sampling as a per-node DaemonSet; each agent sees only its node’s spans, so decisions are made on partial traces. Sees one build root at a time (chant #1939). |
WK8602 | OpenTelemetry Collector gateway runs tail_sampling on more than one replica, but collectors send it traces without a loadbalancing exporter routed by traceID. Sees one build root at a time (chant #1939). |
WK8603 | OpenTelemetry Collector runs the k8s_cluster receiver in a DaemonSet or multi-replica workload without a k8s_leader_elector; every copy reports every cluster object. Sees one build root at a time (chant #1939). |
WK8604 | OpenTelemetry Collector config in a ConfigMap or an OpenTelemetryCollector’s spec.config fails the otel lexicon’s config checks; findings are reported under their OTEL1xx ids, naming the ConfigMap and key, or the OpenTelemetryCollector. |
WK8605 | OpenTelemetry Collector config reads the node (k8sattributes filtered to its node, kubeletstats, hostmetrics root_path, filelog) but its workload doesn’t set the node name variable or mount the host paths. Sees one build root at a time (chant #1939). |
WK8606 | A PrometheusRule’s groups fail the prometheus lexicon’s rule-file checks; findings are reported under their PROM ids, naming the PrometheusRule. |
WK8701 | A PrometheusRule that no Prometheus or ThanosRuler in the build selects through ruleSelector and ruleNamespaceSelector is never evaluated. A null selector matches nothing, {} matches all. Silent when the build has no Prometheus or ThanosRuler. |
WK8702 | A ServiceMonitor, PodMonitor, Probe or ScrapeConfig that no Prometheus or PrometheusAgent in the build selects is never scraped. A null selector matches nothing, {} matches all. Silent when the build has no Prometheus or PrometheusAgent. |
WK8703 | An AlertmanagerConfig that no Alertmanager in the build selects through alertmanagerConfigSelector and alertmanagerConfigNamespaceSelector never routes an alert. A null selector matches nothing, {} matches all. Silent when the build has no Alertmanager. |
WK8704 | A ServiceMonitor whose selector matches no Service in the build, or whose endpoints[].port names no port on the matched Services; the same for a PodMonitor against pod container ports. Needs no Prometheus in the build. Sees one build root at a time (chant #1939). |
WK8705 | A Prometheus whose serviceMonitorSelector, podMonitorSelector, probeSelector and scrapeConfigSelector are all null selects no monitor, so the operator scrapes nothing from ServiceMonitors, PodMonitors, Probes or ScrapeConfigs. |