Kubernetes Resource Name Validator (RFC 1123)

Check any Kubernetes object name against the exact RFC 1123 label rules — length, allowed characters, start/end constraints — with every failing rule explained.

Parsed 100% in your browser — nothing you type is transmitted or stored.

How to Use the Kubernetes Resource Name Validator

  1. Type a candidate Kubernetes object name (a Pod, Service, Deployment, namespace, ConfigMap name — anything) into the box.
  2. Click Parse. The tool checks it against Kubernetes' exact RFC 1123 rules instantly in your browser.
  3. Read the result: a Valid badge if every rule passes, or a full list of every specific rule that failed — not just the first one.
  4. Nothing you type is uploaded anywhere — this is pure regex/string validation running as JavaScript in your browser tab.

The Exact Rules (RFC 1123 DNS Label)

Most Kubernetes object names must be a valid RFC 1123 DNS label. The rules are precise and this tool enforces every one of them:

  1. At most 63 characters. This isn't an arbitrary Kubernetes choice — it's inherited from the DNS label length limit, since Kubernetes names frequently end up embedded in DNS names and hostnames.
  2. Lowercase alphanumeric characters or
    -
    only.
    No uppercase letters, no underscores, no spaces, no other punctuation.
  3. Must start with an alphanumeric character. A name cannot begin with a hyphen.
  4. Must end with an alphanumeric character. A name cannot end with a hyphen either.

The exact regular expression Kubernetes itself uses to enforce this is:

[a-z0-9]([-a-z0-9]*[a-z0-9])?

This tool implements that identical pattern, plus separate, explicit checks for each individual rule — so a name that fails is reported with which specific rule(s) it broke (too long, contains uppercase, starts with a hyphen, contains an invalid character like

_
), rather than a bare "invalid."

A Second, Longer Rule Set: RFC 1123 Subdomain

A smaller set of Kubernetes fields (most notably some CRD- and annotation-adjacent names) instead allow the RFC 1123 subdomain form — the same character rules, but:

  • up to 253 characters instead of 63
  • dots (
    .
    ) are allowed as segment separators, with each dot-separated segment individually following the same label rules (so
    my-app..prod
    is still invalid — two consecutive dots imply an empty segment)

The regex for this longer form is:

[a-z0-9]([-a-z0-9]*[a-z0-9])?(\.[a-z0-9]([-a-z0-9]*[a-z0-9])?)*

Most day-to-day Kubernetes object names (Pods, Services, Deployments, namespaces) use the shorter 63-character label rule, not the subdomain form — the subdomain form mainly shows up for a handful of specific fields where the Kubernetes API documentation explicitly calls it out.

Worked Examples

Valid:

my-service-01
— lowercase, alphanumeric-and-hyphen only, starts and ends with a letter/digit, well under 63 characters.

Invalid, multiple ways at once:

  • -bad-start
    fails the "must start with an alphanumeric character" rule.
  • bad-end-
    fails the "must end with an alphanumeric character" rule.
  • BadName
    fails the "must be lowercase" rule (uppercase letters aren't allowed even though they're technically alphanumeric).
  • bad_name
    fails the "allowed characters" rule (underscore isn't
    -
    , and isn't alphanumeric).
  • A name of 64 or more characters fails the length rule outright.

This tool reports every one of these independently, since a real name is often broken in more than one way at once (e.g.

Bad_Name-
breaks the lowercase rule, the allowed-characters rule, AND the end-with-alphanumeric rule simultaneously).

Why This Matters Beyond Just "Kubernetes Rejects It"

A name that violates these rules doesn't just get politely rejected with a clean error — depending on the tool generating it (Helm charts, Terraform, CI/CD pipelines that template names from branch names or commit SHAs), an invalid name can fail deep inside a deploy pipeline with a confusing downstream error. Validating a name before it's templated into a manifest catches the problem at its actual source.

What This Tool Does NOT Do

This is a grammar-only validator. It does not connect to any Kubernetes cluster or API server, and it cannot tell you whether a grammatically valid name is already in use in your specific namespace/cluster — that check requires an actual

kubectl get
against a real cluster.

Frequently Asked Questions

Why can't Kubernetes names use underscores, when so many other systems allow them? Because Kubernetes names frequently get embedded directly into DNS names (for Services, this is literal — a Service name becomes part of its DNS hostname), and underscores aren't valid in DNS labels.

Does this apply to namespace names too? Yes — Kubernetes namespaces follow the same RFC 1123 label rule as most other object names.

Is my input uploaded or stored anywhere? No. The validation runs entirely as JavaScript inside your browser tab — nothing is sent to a server, logged, or stored.

Is this tool free? Yes, completely free, no login, no limit.

A free browser tool by Toolzer Hub. It runs on your device; files you add are not uploaded. More free tools