Kubernetes YAML validator (online, private, in-browser)

Paste one or more Kubernetes manifests and get every problem with its line number and a plain-English fix. The checks run in your browser, so the YAML never leaves the tab.

By , Founder at SeaGit

Separate multiple objects with a line containing three dashes (---).

Private by design: this check runs in your browser. The YAML you paste is never uploaded, stored or logged.

Results

Paste manifests above to check them.

What this checks

The validator reads each document separated by --- and reports findings at three levels. Errors are things the API server rejects or that stop a deploy. Warnings are valid YAML that often causes trouble later. Info notes are suggestions.

  • Syntax: tabs used for indentation, bad indentation, unclosed quotes and duplicate keys.
  • Identity: apiVersion and kind are present, the apiVersion is valid for the kind, and it is not a removed version. metadata.name is present and follows the naming rule for its kind.
  • Labels and selectors: label keys and values are valid, values are strings, and a Deployment selector matches its pod template.
  • Containers: each container has a name and an image, images without a tag or with :latest are flagged, resource quantities are well formed, requests do not exceed limits, and env entries have a valid shape.
  • Services and Ingress: ports are between 1 and 65535, named target ports are valid, Services have a selector and ports, and each Ingress path has a pathType and a complete backend.

Object names follow the rules on the Kubernetes names page: lowercase letters, digits, dots (for most kinds) and -. Most kinds allow up to 253 characters. Services, Namespaces and container names are limited to 63, and a Service name must start with a letter.

What it cannot check

This is a static check on the text you paste. It does not connect to a cluster, so it cannot see the API groups your cluster has enabled, the custom resource definitions installed in it, admission webhooks that mutate or reject objects, RBAC permissions, or whether a namespace or image exists. Custom kinds are reported as not checked.

For the cluster-side answer, run kubectl apply --dry-run=server -f manifest.yaml. The server applies its real schema, defaulting and admission rules without creating anything. In CI, kubeconform validates manifests against Kubernetes JSON schemas for the version you choose, and it can be given schemas for your custom resources.

kubectl apply --dry-run=server -f manifest.yaml

Common mistakes

These are the findings that show up most often in manifests copied from old tutorials or generated by templates.

MistakeWhat happensFix
apiVersion: extensions/v1beta1 on an IngressRemoved in Kubernetes 1.22. Rejected by current clusters.Use networking.k8s.io/v1, and change backend.serviceName and servicePort to backend.service.
apiVersion: policy/v1beta1 on a PodDisruptionBudgetRemoved in Kubernetes 1.25.Use policy/v1. An empty selector now matches every pod in the namespace.
selector.matchLabels that differs from the pod template labelsThe API rejects the Deployment, because its pods would not match its own selector.Make the two sets of labels identical.
version: 1.0 or enabled: true as a labelYAML reads these as a number and a boolean. Labels must be strings.Quote them: version: "1.0". The same applies to env values such as PORT: "8080".
memory: 512MB or memory: 512mbNot a valid Kubernetes quantity.Use binary units: 512Mi or 1Gi. CPU uses m for millicores, so 250m is a quarter of a core.
containerPort: "8080" with quotesPorts are integers from 1 to 65535.Remove the quotes: containerPort: 8080.
image: nginx:latestThe same manifest can pull different code on different days.Pin a version tag such as nginx:1.27.2, or a digest.
A tab character used to indentYAML does not allow tabs for indentation, so the file will not parse.Replace the tab with spaces. Most editors can show whitespace.

How to use it

Paste the manifests, then fix findings from the top down. Each line number refers to the text you pasted, so the first error is the best place to start. Some findings cause others: a bad indentation can make the rest of a document look wrong. Fix syntax errors first, then rerun the check. Use the example button to see every severity level on a small set of objects.

If you are moving Ingress resources to Gateway API, the ingress-nginx end of life guide covers the conversion path, and the Kubernetes Ingress fields that this validator checks are the ones that change in that move.

Frequently asked questions

Does this replace kubectl apply --dry-run=server?

No. This page checks structure and common mistakes using rules it knows. It cannot see your cluster, its enabled API groups, custom resource definitions, admission webhooks or RBAC. Run kubectl apply --dry-run=server against the real cluster for the final check, and use kubeconform for schema checks in CI.

Is my YAML uploaded anywhere?

No. The validator is JavaScript that runs in your browser tab. The page does not send the text you paste to SeaGit or any other service, and it does not store it. You can confirm this in your browser’s network panel while you type.

Why does it flag an apiVersion that my cluster still accepts?

Kubernetes removes an API version in a specific release. An older cluster may still serve it, but a cluster at or after the removal release rejects it. The tool reports the release that removed it, so you can plan the change before an upgrade breaks your deploy.

Which removals does it know about?

The removal table follows the official Deprecated API Migration Guide. It includes Ingress extensions/v1beta1 and networking.k8s.io/v1beta1 (removed in 1.22), policy/v1beta1 PodDisruptionBudget, batch/v1beta1 CronJob and EndpointSlice v1beta1 (removed in 1.25), and autoscaling/v2beta2 HorizontalPodAutoscaler (removed in 1.26). If a kind is not in the table, the tool says it cannot check its fields.

Why is a missing resource request only a warning?

Kubernetes accepts a container without requests or limits, so the API does not reject it. The tool flags it because the scheduler then has no size to plan around and one container can take a whole node. Set requests and a memory limit for production workloads, and treat the warning as the default to change.

Sources

Checked 10 October 2026.

  1. Deprecated API Migration Guide (Kubernetes documentation) — the release each removed apiVersion stopped being served in, and its replacement
  2. Object Names and IDs (Kubernetes documentation) — the RFC 1123 label rule for object names