ToolAssay

Audit Kubernetes manifests against a contract

Audit Kubernetes manifests against a contract. Reports a missing memory limit, where one container can take down the node it shares, a missing readiness probe, where traffic arrives before the container is ready, an unpinned image tag, a privileged container, added capabilities, a secret written literally into an env value rather than a valueFrom reference, and missing required labels. A CronJob’s nested pod template is read correctly rather than reported as having no containers.

Answeringour last check, 2026-10-04
1 of 1checks answered this week
2478 msmedian answer time
$0.15listed price per call
$0.15price it asked us

Paid test badge: not yet. The checks above are free: we call the tool without paying and read the payment request it sends back. The Verified badge needs paid calls whose answers match the promised output, and nobody can buy a badge.

Endpoint

POST https://api.zfinia.com/x402/v1/kubernetes-manifest-contract-audit

CategoryImage and media
Provider hostapi.zfinia.com
Networkseip155:8453
Payment schemesexact
Self-reported calls, 30 days1 from 1 payers (the provider's figure, not ours)

Our checks, last 30 days

DayResultHTTPAskedTime
2026-10-04 valid payment request 402$0.15 2478 ms

Example input (from the provider)

{
  "body": {
    "contract": {
      "require_non_root": true,
      "require_replicas": true,
      "required_labels": [
        "app",
        "team"
      ]
    },
    "resources": [
      {
        "apiVersion": "apps/v1",
        "kind": "Deployment",
        "metadata": {
          "labels": {
            "app": "orders-api"
          },
          "name": "orders-api"
        },
        "spec": {
          "template": {
            "spec": {
              "containers": [
                {
                  "env": [
                    {
                      "name": "DATABASE_PASSWORD",
                      "value": "not-a-real-password"
                    },
                    {
                      "name": "LOG_LEVEL",
                      "value": "info"
                    }
                  ],
                  "image": "ghcr.io/example/orders-api:latest",
                  "name": "api",
                  "resources": {
                    "requests": {
                      "cpu": "100m"
                    }
                  }
                }
              ]
            }
          }
        }
      },
      {
        "apiVersion": "batch/v1",
        "kind": "CronJob",
        "metadata": {
          "labels": {
            "app": "orders-api",
            "team": "payments"
          },
          "name": "nightly-reconcile"
        },
        "spec": {
          "jobTemplate": {
            "spec": {
              "template": {
                "spec": {
                  "containers": [
                    {
                      "image": "ghcr.io/example/reconcile@sha256:1111111111111111111111111111111111111111111111111111111111111111",
                      "name": "reconcile",
                      "resources": {
                        "limits": {
                          "cpu": "500m",
                          "memory": "512Mi"
                        }
                      },
                      "securityContext": {
                        "runAsNonRoot": true
                      }
                    }
                  ]
                }
              }
            }
          }
        }
      },
      {
        "apiVersion": "v1",
        "kind": "Service",
        "metadata": {
          "name": "orders-api"
        },
        "spec": {
          "ports": [
            {
              "port": 80
            }
          ]
        }
      }
    ]
  },
  "bodyType": "json",
  "method": "POST",
  "type": "http"
}

Promised output schema (from the provider)

{
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "properties": {
    "input": {
      "additionalProperties": false,
      "properties": {
        "body": {
          "additionalProperties": false,
          "properties": {
            "contract": {
              "additionalProperties": false,
              "properties": {
                "forbid_latest_tag": {
                  "type": "boolean"
                },
                "forbid_privileged": {
                  "type": "boolean"
                },
                "require_non_root": {
                  "type": "boolean"
                },
                "require_probes": {
                  "type": "boolean"
                },
                "require_replicas": {
                  "type": "boolean"
                },
                "require_resource_limits": {
                  "type": "boolean"
                },
                "required_labels": {
                  "items": {
                    "maxLength": 128,
                    "type": "string"
                  },
                  "maxItems": 50,
                  "minItems": 1,
                  "type": "array"
                }
              },
              "type": "object"
            },
            "resources": {
              "items": {
                "type": "object"
              },
              "maxItems": 2000,
              "minItems": 1,
              "type": "array"
            }
          },
          "required": [
            "resources"
          ],
          "type": "object"
        },
        "bodyType": {
          "enum": [
            "json",
            "form-data",
            "text"
          ],
          "type": "string"
        },
        "method": {
          "enum": [
            "POST"
          ],
          "type": "string"
        },
        "type": {
          "const": "http",
          "type": "string"
        }
      },
      "required": [
        "type",
        "method",
        "bodyType",
        "body"
      ],
      "type": "object"
    },
    "output": {
      "properties": {
        "example": {
          "type": "object"
        },
        "type": {
          "type": "string"
        }
      },
      "required": [
        "type"
      ],
      "type": "object"
    }
  },
  "required": [
    "input"
  ],
  "type": "object"
}

This page as JSON