calicoctl validate
This sections describes the calicoctl validate command.
Read the calicoctl command line interface user reference for a full list of calicoctl commands.
The validate command works offline and does not require access to a datastore. It validates resource structure, syntax, and Calico-specific validation rules without applying changes to the cluster.
Displaying the help text for 'calicoctl validate' command
Run calicoctl validate --help to display the following help menu for the command.
Validate one or more Calico resources from a file, directory, or stdin without
applying them. Validation runs entirely offline - checking syntax, structure,
and schema without touching the datastore - so it's useful for catching errors
before you apply resources to a cluster.
Usage:
calicoctl validate [flags]
Examples:
# Validate resources in a file.
calicoctl validate -f ./policy.yaml
Flags:
-c, --config string Path to the file containing connection configuration in YAML or JSON format. (default "/etc/calico/calicoctl.cfg")
-f, --filename string Filename to use to create/apply/replace/delete the resource. Use '-' for stdin.
-h, --help help for validate
-n, --namespace string Namespace of the resource.
-R, --recursive Process the filename specified in -f recursively.
--skip-empty Do not error if files contain no data.
Global Flags:
--allow-version-mismatch Allow client and cluster versions mismatch
--context string The name of the kubeconfig context to use
-l, --log-level string Set the log level (panic, fatal, error, warn, info, debug) (default "panic")
Examples
-
Validate a single policy file.
calicoctl validate -f ./network-policy.yamlResults indicate successful validation.
Successfully validated 1 'NetworkPolicy' resource(s) -
Validate resources from stdin.
cat resources.yaml | calicoctl validate -f -Results indicate successful validation of multiple resources.
Successfully validated 3 resource(s) -
Validate all resource files in a directory recursively.
calicoctl validate -f ./calico-resources/ --recursiveResults indicate validation failure.
Failed to validate 'NetworkPolicy' resource: [error with field Selector = 'invalid@selector' (Reason: failed to validate Field: Selector because of Tag: selector )] -
Validation with invalid selector example.
calicoctl validate -f policy-with-invalid-selector.yamlResults show Calico-specific validation error.
Failed to validate 'NetworkPolicy' resource: [error with field Selector = 'ga@rb"ag'e' (Reason: failed to validate Field: Selector because of Tag: selector )] -
Validation with invalid IP address example.
calicoctl validate -f bgppeer-with-invalid-ip.yamlResults show IP validation error.
Failed to validate 'BGPPeer' resource: [error with field PeerIP = '999.999.999.999' (Reason: failed to validate Field: PeerIP because of Tag: IP:port )]
Options
-f, --filename string Filename to use to create/apply/replace/delete the resource. Use '-' for stdin.
-R, --recursive Process the filename specified in -f recursively.
--skip-empty Do not error if files contain no data.
See also
- Installing calicoctl
- Resources for details on all valid resources, including file format and schema
- NetworkPolicy for details on the Calico selector-based policy model