Skip to content

kubectl cheat sheet

The kubectl commands you use most, grouped by task. Add -n <namespace> to any command, or -A for all namespaces.

24 entries

Context & config

kubectl config get-contexts
kubectl config use-context staging

List and switch clusters.

kubectl config set-context --current --namespace=web

Default namespace for the current context.

kubectl cluster-info
kubectl version

Cluster endpoint and versions.

Inspect

kubectl get pods -o wide
kubectl get all -n web

List resources (wide adds node and IP).

kubectl get pods -l app=api --watch

Filter by label and watch changes.

kubectl describe pod api-7d9c-xk2p

Events, conditions and container states: start debugging here.

kubectl get deploy api -o yaml

Full live object as YAML.

kubectl get events --sort-by=.metadata.creationTimestamp

Recent events in order.

kubectl top pods
kubectl top nodes

CPU/memory usage (needs metrics-server).

Logs & shells

kubectl logs -f deploy/api
kubectl logs api-7d9c-xk2p -c sidecar --previous

Follow logs; previous crashed container.

kubectl exec -it api-7d9c-xk2p -- sh

Shell inside a container.

kubectl port-forward svc/api 8080:80

Reach a service from localhost.

kubectl cp api-7d9c-xk2p:/tmp/dump.txt ./dump.txt

Copy files out of a pod.

kubectl debug -it api-7d9c-xk2p --image=busybox --target=api

Ephemeral debug container.

Deploy & change

kubectl apply -f k8s/
kubectl diff -f k8s/

Apply manifests; preview the change first.

kubectl set image deploy/api api=ghcr.io/me/api:1.4.2

Update an image.

kubectl rollout status deploy/api
kubectl rollout history deploy/api
kubectl rollout undo deploy/api

Watch, inspect and roll back.

kubectl rollout restart deploy/api

Restart pods without changing the spec.

kubectl scale deploy/api --replicas=5

Scale manually.

kubectl delete pod api-7d9c-xk2p

Delete a pod (its Deployment replaces it).

Config & secrets

kubectl create configmap app-cfg --from-file=config.yaml

ConfigMap from a file.

kubectl create secret generic db --from-literal=PASSWORD=change-me

Secret (values are base64, not encrypted, by default).

kubectl get secret db -o jsonpath='{.data.PASSWORD}' | base64 -d

Read a secret value.

Minimal manifest

apiVersion: apps/v1
kind: Deployment
metadata:
  name: api
spec:
  replicas: 2
  selector:
    matchLabels: { app: api }
  template:
    metadata:
      labels: { app: api }
    spec:
      containers:
        - name: api
          image: ghcr.io/me/api:1.4.2
          ports: [{ containerPort: 8000 }]
          readinessProbe:
            httpGet: { path: /health, port: 8000 }
---
apiVersion: v1
kind: Service
metadata:
  name: api
spec:
  selector: { app: api }
  ports: [{ port: 80, targetPort: 8000 }]

Deployment + Service; the selector labels must match.

Frequently asked questions

How do I see why a pod is not starting?

Run kubectl describe pod <name> and read the Events at the bottom (image pull errors, failed scheduling, failing probes). Then check kubectl logs <name> --previous for the crashed container’s output.

apply vs create?

kubectl create makes a new object and fails if it exists. kubectl apply creates or updates objects declaratively from files, so it is what you use for manifests kept in git.

What does CrashLoopBackOff mean?

The container starts, exits, and Kubernetes keeps restarting it with increasing delays. The cause is in the container logs (kubectl logs --previous): usually a crash on start-up, a missing config or secret, or a failing command.

Related cheat sheets