2016-03-07 12:09:02 +00:00
---
2018-05-21 15:55:51 +00:00
title: kubectl Cheat Sheet
reviewers:
2016-07-29 17:36:25 +00:00
- bgrant0607
- erictune
- krousey
2016-10-25 00:56:11 +00:00
- clove
2018-07-12 20:35:26 +00:00
content_template: templates/concept
2016-03-07 12:09:02 +00:00
---
2018-07-12 20:35:26 +00:00
{{% capture overview %}}
2018-03-20 17:05:04 +00:00
See also: [Kubectl Overview ](/docs/reference/kubectl/overview/ ) and [JsonPath Guide ](/docs/reference/kubectl/jsonpath ).
2016-03-07 12:09:02 +00:00
2018-07-12 20:35:26 +00:00
This page is an overview of the `kubectl` command.
{{% /capture %}}
{{% capture body %}}
# kubectl - Cheat Sheet
2016-10-25 00:56:11 +00:00
## Kubectl Autocomplete
2018-07-12 20:35:26 +00:00
### BASH
```bash
source < (kubectl completion bash) # setup autocomplete in bash into the current shell, bash-completion package should be installed first.
echo "source < (kubectl completion bash)" >> ~/.bashrc # add autocomplete permanently to your bash shell.
```
### ZSH
```bash
source < (kubectl completion zsh) # setup autocomplete in zsh into the current shell
echo "if [ $commands[kubectl] ]; then source < (kubectl completion zsh); fi" >> ~/.zshrc # add autocomplete permanently to your zsh shell
2016-10-25 00:56:11 +00:00
```
## Kubectl Context and Configuration
2017-08-15 10:05:06 +00:00
Set which Kubernetes cluster `kubectl` communicates with and modifies configuration
2017-10-05 00:31:51 +00:00
information. See [Authenticating Across Clusters with kubeconfig ](/docs/tasks/access-application-cluster/configure-access-multiple-clusters/ ) documentation for
2016-10-25 00:56:11 +00:00
detailed config file information.
2016-03-07 12:09:02 +00:00
2018-07-12 20:35:26 +00:00
```bash
kubectl config view # Show Merged kubeconfig settings.
2016-03-07 12:09:02 +00:00
2016-10-25 00:56:11 +00:00
# use multiple kubeconfig files at the same time and view merged config
2018-07-12 20:35:26 +00:00
KUBECONFIG=~/.kube/config:~/.kube/kubconfig2 kubectl config view
2016-03-07 12:09:02 +00:00
2016-10-25 00:56:11 +00:00
# Get the password for the e2e user
2018-07-12 20:35:26 +00:00
kubectl config view -o jsonpath='{.users[?(@.name == "e2e")].user.password}'
2016-03-07 12:09:02 +00:00
2018-07-12 20:35:26 +00:00
kubectl config current-context # Display the current-context
kubectl config use-context my-cluster-name # set the default context to my-cluster-name
2016-10-25 00:56:11 +00:00
# add a new cluster to your kubeconf that supports basic auth
2018-07-12 20:35:26 +00:00
kubectl config set-credentials kubeuser/foo.kubernetes.com --username=kubeuser --password=kubepassword
2016-10-25 00:56:11 +00:00
# set a context utilizing a specific username and namespace.
2018-07-12 20:35:26 +00:00
kubectl config set-context gce --user=cluster-admin --namespace=foo \
2016-10-25 00:56:11 +00:00
& & kubectl config use-context gce
```
## Creating Objects
2016-03-07 12:09:02 +00:00
2016-10-25 00:56:11 +00:00
Kubernetes manifests can be defined in json or yaml. The file extension `.yaml` ,
`.yml` , and `.json` can be used.
2018-07-12 20:35:26 +00:00
```bash
kubectl create -f ./my-manifest.yaml # create resource(s)
kubectl create -f ./my1.yaml -f ./my2.yaml # create from multiple files
kubectl create -f ./dir # create resource(s) in all manifest files in dir
kubectl create -f https://git.io/vPieo # create resource(s) from url
kubectl run nginx --image=nginx # start a single instance of nginx
kubectl explain pods,svc # get the documentation for pod and svc manifests
2016-03-07 12:09:02 +00:00
# Create multiple YAML objects from stdin
2018-07-12 20:35:26 +00:00
cat < < EOF | kubectl create -f -
2016-03-07 12:09:02 +00:00
apiVersion: v1
kind: Pod
metadata:
name: busybox-sleep
spec:
containers:
- name: busybox
image: busybox
args:
- sleep
- "1000000"
---
apiVersion: v1
kind: Pod
metadata:
name: busybox-sleep-less
spec:
containers:
- name: busybox
image: busybox
args:
- sleep
- "1000"
EOF
# Create a secret with several keys
2018-07-12 20:35:26 +00:00
cat < < EOF | kubectl create -f -
2016-03-07 12:09:02 +00:00
apiVersion: v1
kind: Secret
metadata:
name: mysecret
type: Opaque
data:
2017-11-16 13:36:45 +00:00
password: $(echo -n "s33msi4" | base64)
username: $(echo -n "jane" | base64)
2016-03-07 12:09:02 +00:00
EOF
```
## Viewing, Finding Resources
2018-07-12 20:35:26 +00:00
```bash
2016-10-25 00:56:11 +00:00
# Get commands with basic output
2018-07-12 20:35:26 +00:00
kubectl get services # List all services in the namespace
kubectl get pods --all-namespaces # List all pods in all namespaces
kubectl get pods -o wide # List all pods in the namespace, with more details
kubectl get deployment my-dep # List a particular deployment
kubectl get pods --include-uninitialized # List all pods in the namespace, including uninitialized ones
2016-03-07 12:09:02 +00:00
2016-10-25 00:56:11 +00:00
# Describe commands with verbose output
2018-07-12 20:35:26 +00:00
kubectl describe nodes my-node
kubectl describe pods my-pod
2016-03-07 12:09:02 +00:00
2018-07-12 20:35:26 +00:00
kubectl get services --sort-by=.metadata.name # List Services Sorted by Name
2016-03-07 12:09:02 +00:00
# List pods Sorted by Restart Count
2018-07-12 20:35:26 +00:00
kubectl get pods --sort-by='.status.containerStatuses[0].restartCount'
2016-03-07 12:09:02 +00:00
# Get the version label of all pods with label app=cassandra
2018-07-12 20:35:26 +00:00
kubectl get pods --selector=app=cassandra rc -o \
2016-10-25 00:56:11 +00:00
jsonpath='{.items[*].metadata.labels.version}'
2016-03-07 12:09:02 +00:00
2017-11-14 19:35:17 +00:00
# Get all running pods in the namespace
2018-07-12 20:35:26 +00:00
kubectl get pods --field-selector=status.phase=Running
2017-11-14 19:35:17 +00:00
2016-03-07 12:09:02 +00:00
# Get ExternalIPs of all nodes
2018-07-12 20:35:26 +00:00
kubectl get nodes -o jsonpath='{.items[*].status.addresses[?(@.type=="ExternalIP")].address}'
2016-03-07 12:09:02 +00:00
# List Names of Pods that belong to Particular RC
2017-03-07 16:20:46 +00:00
# "jq" command useful for transformations that are too complex for jsonpath, it can be found at https://stedolan.github.io/jq/
2018-07-12 20:35:26 +00:00
sel=${$(kubectl get rc my-rc --output=json | jq -j '.spec.selector | to_entries | .[] | "\(.key)=\(.value),"')%?}
echo $(kubectl get pods --selector=$sel --output=jsonpath={.items..metadata.name})
2016-03-07 12:09:02 +00:00
# Check which nodes are ready
2018-07-12 20:35:26 +00:00
JSONPATH='{range .items[*]}{@.metadata.name}:{range @.status.conditions[*]}{@.type}={@.status};{end}{end}' \
2017-09-08 11:14:21 +00:00
& & kubectl get nodes -o jsonpath="$JSONPATH" | grep "Ready=True"
2017-03-07 16:20:46 +00:00
# List all Secrets currently in use by a pod
2018-07-12 20:35:26 +00:00
kubectl get pods -o json | jq '.items[].spec.containers[].env[]?.valueFrom.secretKeyRef.name' | grep -v null | sort | uniq
2018-02-26 15:45:44 +00:00
# List Events sorted by timestamp
2018-07-12 20:35:26 +00:00
kubectl get events --sort-by=.metadata.creationTimestamp
2016-10-25 00:56:11 +00:00
```
## Updating Resources
2018-07-12 20:35:26 +00:00
```bash
kubectl rolling-update frontend-v1 -f frontend-v2.json # Rolling update pods of frontend-v1
kubectl rolling-update frontend-v1 frontend-v2 --image=image:v2 # Change the name of the resource and update the image
kubectl rolling-update frontend --image=image:v2 # Update the pods image of frontend
kubectl rolling-update frontend-v1 frontend-v2 --rollback # Abort existing rollout in progress
cat pod.json | kubectl replace -f - # Replace a pod based on the JSON passed into stdin
2016-10-25 00:56:11 +00:00
# Force replace, delete and then re-create the resource. Will cause a service outage.
2018-07-12 20:35:26 +00:00
kubectl replace --force -f ./pod.json
2016-10-25 00:56:11 +00:00
# Create a service for a replicated nginx, which serves on port 80 and connects to the containers on port 8000
2018-07-12 20:35:26 +00:00
kubectl expose rc nginx --port=80 --target-port=8000
2016-10-25 00:56:11 +00:00
# Update a single-container pod's image version (tag) to v4
2018-07-12 20:35:26 +00:00
kubectl get pod mypod -o yaml | sed 's/\(image: myimage\):.*$/\1:v4/' | kubectl replace -f -
2016-10-25 00:56:11 +00:00
2018-07-12 20:35:26 +00:00
kubectl label pods my-pod new-label=awesome # Add a Label
kubectl annotate pods my-pod icon-url=http://goo.gl/XXBTWq # Add an annotation
kubectl autoscale deployment foo --min=2 --max=10 # Auto scale a deployment "foo"
2016-03-07 12:09:02 +00:00
```
2016-10-25 00:56:11 +00:00
## Patching Resources
2016-03-07 12:09:02 +00:00
2018-07-12 20:35:26 +00:00
```bash
kubectl patch node k8s-node-1 -p '{"spec":{"unschedulable":true}}' # Partially update a node
2016-03-07 12:09:02 +00:00
2016-10-25 00:56:11 +00:00
# Update a container's image; spec.containers[*].name is required because it's a merge key
2018-07-12 20:35:26 +00:00
kubectl patch pod valid-pod -p '{"spec":{"containers":[{"name":"kubernetes-serve-hostname","image":"new image"}]}}'
2016-10-25 00:56:11 +00:00
# Update a container's image using a json patch with positional arrays
2018-07-12 20:35:26 +00:00
kubectl patch pod valid-pod --type='json' -p='[{"op": "replace", "path": "/spec/containers/0/image", "value":"new image"}]'
2017-06-20 22:47:42 +00:00
# Disable a deployment livenessProbe using a json patch with positional arrays
2018-07-12 20:35:26 +00:00
kubectl patch deployment valid-deployment --type json -p='[{"op": "remove", "path": "/spec/template/spec/containers/0/livenessProbe"}]'
2017-10-26 22:05:13 +00:00
# Add a new element to a positional array
2018-07-12 20:35:26 +00:00
kubectl patch sa default --type='json' -p='[{"op": "add", "path": "/secrets/1", "value": {"name": "whatever" } }]'
2016-10-25 00:56:11 +00:00
```
## Editing Resources
The edit any API resource in an editor.
2018-07-12 20:35:26 +00:00
```bash
kubectl edit svc/docker-registry # Edit the service named docker-registry
KUBE_EDITOR="nano" kubectl edit svc/docker-registry # Use an alternative editor
2016-10-25 00:56:11 +00:00
```
## Scaling Resources
2018-07-12 20:35:26 +00:00
```bash
kubectl scale --replicas=3 rs/foo # Scale a replicaset named 'foo' to 3
kubectl scale --replicas=3 -f foo.yaml # Scale a resource specified in "foo.yaml" to 3
kubectl scale --current-replicas=2 --replicas=3 deployment/mysql # If the deployment named mysql's current size is 2, scale mysql to 3
kubectl scale --replicas=5 rc/foo rc/bar rc/baz # Scale multiple replication controllers
2016-10-25 00:56:11 +00:00
```
## Deleting Resources
2018-07-12 20:35:26 +00:00
```bash
kubectl delete -f ./pod.json # Delete a pod using the type and name specified in pod.json
kubectl delete pod,service baz foo # Delete pods and services with same names "baz" and "foo"
kubectl delete pods,services -l name=myLabel # Delete pods and services with label name=myLabel
kubectl delete pods,services -l name=myLabel --include-uninitialized # Delete pods and services, including uninitialized ones, with label name=myLabel
kubectl -n my-ns delete po,svc --all # Delete all pods and services, including uninitialized ones, in namespace my-ns,
2016-03-07 12:09:02 +00:00
```
## Interacting with running Pods
2018-07-12 20:35:26 +00:00
```bash
kubectl logs my-pod # dump pod logs (stdout)
kubectl logs my-pod -c my-container # dump pod container logs (stdout, multi-container case)
kubectl logs -f my-pod # stream pod logs (stdout)
kubectl logs -f my-pod -c my-container # stream pod container logs (stdout, multi-container case)
kubectl run -i --tty busybox --image=busybox -- sh # Run pod as interactive shell
kubectl attach my-pod -i # Attach to Running Container
kubectl port-forward my-pod 5000:6000 # Listen on port 5000 on the local machine and forward to port 6000 on my-pod
kubectl exec my-pod -- ls / # Run command in existing pod (1 container case)
kubectl exec my-pod -c my-container -- ls / # Run command in existing pod (multi-container case)
kubectl top pod POD_NAME --containers # Show metrics for a given pod and its containers
2016-10-25 00:56:11 +00:00
```
## Interacting with Nodes and Cluster
2018-07-12 20:35:26 +00:00
```bash
kubectl cordon my-node # Mark my-node as unschedulable
kubectl drain my-node # Drain my-node in preparation for maintenance
kubectl uncordon my-node # Mark my-node as schedulable
kubectl top node my-node # Show metrics for a given node
kubectl cluster-info # Display addresses of the master and services
kubectl cluster-info dump # Dump current cluster state to stdout
kubectl cluster-info dump --output-directory=/path/to/cluster-state # Dump current cluster state to /path/to/cluster-state
2016-03-07 12:09:02 +00:00
2016-10-25 00:56:11 +00:00
# If a taint with that key and effect already exists, its value is replaced as specified.
2018-07-12 20:35:26 +00:00
kubectl taint nodes foo dedicated=special-user:NoSchedule
2016-03-07 12:09:02 +00:00
```
2016-10-25 00:56:11 +00:00
2018-07-09 20:54:58 +00:00
### Resource types
2016-10-25 00:56:11 +00:00
2018-07-09 20:49:23 +00:00
List all supported resource types along with their shortnames, [API group ](/docs/concepts/overview/kubernetes-api/#api-groups ), whether they are [namespaced ](/docs/concepts/overview/working-with-objects/namespaces ), and [Kind ](/docs/concepts/overview/working-with-objects/kubernetes-objects ):
```console
$ kubectl api-resources
```
2018-07-12 21:00:53 +00:00
### Resource types
List all supported resource types along with their shortnames, [API group ](/docs/concepts/overview/kubernetes-api/#api-groups ), whether they are [namespaced ](/docs/concepts/overview/working-with-objects/namespaces ), and [Kind ](/docs/concepts/overview/working-with-objects/kubernetes-objects ):
```console
kubectl api-resources
```
2018-07-09 20:49:23 +00:00
Other operations for exploring API resources:
```console
2018-07-12 21:00:53 +00:00
kubectl api-resources --namespaced=true # All namespaced resources
kubectl api-resources --namespaced=false # All non-namespaced resources
kubectl api-resources -o name # All resources with simple output (just the resource name)
kubectl api-resources -o wide # All resources with expanded (aka "wide") output
kubectl api-resources --verbs=list,get # All resources that support the "list" and "get" request verbs
kubectl api-resources --api-group=extensions # All resources in the "extensions" API group
2018-07-09 20:49:23 +00:00
```
2016-10-25 00:56:11 +00:00
### Formatting output
To output details to your terminal window in a specific format, you can add either the `-o` or `-output` flags to a supported `kubectl` command.
Output format | Description
--------------| -----------
`-o=custom-columns=<spec>` | Print a table using a comma separated list of custom columns
`-o=custom-columns-file=<filename>` | Print a table using the custom columns template in the `<filename>` file
`-o=json` | Output a JSON formatted API object
2018-03-20 17:05:04 +00:00
`-o=jsonpath=<template>` | Print the fields defined in a [jsonpath ](/docs/reference/kubectl/jsonpath ) expression
`-o=jsonpath-file=<filename>` | Print the fields defined by the [jsonpath ](/docs/reference/kubectl/jsonpath ) expression in the `<filename>` file
2016-10-25 00:56:11 +00:00
`-o=name` | Print only the resource name and nothing else
`-o=wide` | Output in the plain-text format with any additional information, and for pods, the node name is included
`-o=yaml` | Output a YAML formatted API object
2017-06-25 17:22:07 +00:00
### Kubectl output verbosity and debugging
Kubectl verbosity is controlled with the `-v` or `--v` flags followed by an integer representing the log level. General Kubernetes logging conventions and the associated log levels are described [here ](https://github.com/kubernetes/community/blob/master/contributors/devel/logging.md ).
Verbosity | Description
--------------| -----------
`--v=0` | Generally useful for this to ALWAYS be visible to an operator.
`--v=1` | A reasonable default log level if you don't want verbosity.
`--v=2` | Useful steady state information about the service and important log messages that may correlate to significant changes in the system. This is the recommended default log level for most systems.
`--v=3` | Extended information about changes.
`--v=4` | Debug level verbosity.
`--v=6` | Display requested resources.
`--v=7` | Display HTTP request headers.
`--v=8` | Display HTTP request contents.
2018-01-17 20:44:06 +00:00
`--v=9` | Display HTTP request contents without truncation of contents.
2017-06-25 17:22:07 +00:00
2018-07-12 20:35:26 +00:00
{{% /capture %}}
{{% capture whatsnext %}}
* Learn more about [Overview of kubectl ](/docs/reference/kubectl/overview/ ).
* See [kubectl ](/docs/reference/kubectl/kubectl/ ) options.
* Also [kubectl Usage Conventions ](/docs/reference/kubectl/conventions/ ) to understand how to use it in reusable scripts.
{{% /capture %}}