Output Formats¶
Standard subcommands¶
For pods, nodes, namespace, pv, pvc, jobs, cronjobs, service, deploy, and events, the -o flag works identically to kubectl get:
kubectl audit pods -o wide
kubectl audit nodes -o json
kubectl audit ns -o json
kubectl audit pvc -o yaml
kubectl audit jobs -o custom-columns=NAME:.metadata.name
kubectl audit service -o json
kubectl audit events -o wide
kubectl audit deploy -o jsonpath='{.items[*].metadata.name}'
containers subcommand¶
The containers subcommand uses a dedicated printer with limited format support:
| Format | Output |
|---|---|
| (default) | Table: POD, NAME, READY, STATUS, RESTARTS, AGE, TYPE |
-o wide |
Adds PORTS, IMAGE, PULLPOLICY |
-o json |
Full JSON |
-o yaml |
Full YAML |
-o name |
namespace/pod-name lines |
Unsupported formats for containers
custom-columns, jsonpath, and Go templates are not supported and will return a clear error. Use -o json | jq instead:
Audit summary line¶
Every audit writes a summary to stderr, keeping stdout clean for piping:
Redirect as needed:
kubectl audit pods -o json 2>/dev/null | jq ... # suppress summary
kubectl audit pods 2>&1 | tee audit.log # capture both
Custom columns example¶
kubectl audit deploy -o custom-columns=\
NAME:.metadata.name,\
NAMESPACE:.metadata.namespace,\
DESIRED:.spec.replicas,\
READY:.status.readyReplicas
Machine-readable scripting¶
# Count unhealthy pods
kubectl audit pods -A -o json 2>/dev/null | jq '.items | length'
# Names of flagged services
kubectl audit service -A -o json 2>/dev/null \
| jq -r '.items[] | "\(.metadata.namespace)/\(.metadata.name)"'
See the CI/CD integration guide for complete scripting patterns.