Kubernetes & Kubectl Cheat Sheet
Essential kubectl commands for developers and SREs. Searchable directory for pod debugging, zero-downtime rollouts, secrets decoding, node draining, and cluster troubleshooting.
List pods across all namespaces with node & IP
kubectl get pods -A -o wideLists all running and pending pods across every cluster namespace, including assigned node names and internal Pod IPs.
Stream logs from a specific pod container
kubectl logs -f <pod-name> -c <container-name> --tail=100Follows real-time standard output and error streams from a designated container inside a multi-container pod.
Open an interactive shell inside a running pod
kubectl exec -it <pod-name> -n <namespace> -- /bin/shSpawns an interactive pseudo-TTY session inside the pod. Use /bin/bash for Debian/Ubuntu or /bin/sh for Alpine.
Forward local port directly to a pod
kubectl port-forward pod/<pod-name> 8080:80Bypasses ingress and services to bind host port 8080 directly to container port 80 for local testing.
View detailed pod events and failure reasons
kubectl describe pod <pod-name> -n <namespace>Inspects scheduling events, CrashLoopBackOff states, OOMKilled codes, and readiness/liveness probe failures.
Force delete a terminating or stuck pod
kubectl delete pod <pod-name> --grace-period=0 --forceImmediately deletes a pod stuck in Terminating status without waiting for kubelet confirmation.
Restart a deployment (rolling restart)
kubectl rollout restart deployment/<deployment-name> -n <namespace>Triggers a zero-downtime rolling restart of all pods by updating the deployment's pod template annotation.
Scale deployment replica count
kubectl scale deployment/<deployment-name> --replicas=5 -n <namespace>Adjusts the desired number of running pod instances to 5 without altering configuration YAML files.
Check rollout status and progress
kubectl rollout status deployment/<deployment-name>Blocks terminal until all new pods reach Ready status or reports deployment failure/timeout.
Roll back to previous revision
kubectl rollout undo deployment/<deployment-name>Reverts the deployment and its ReplicaSet to the previous successful revision.
View deployment rollout history
kubectl rollout history deployment/<deployment-name>Inspects recorded revision history numbers and change-cause annotations.
List all services with ClusterIP and NodePort
kubectl get svc -ADisplays all internal ClusterIPs, NodePorts, external LoadBalancers, and target ports across all namespaces.
Port-forward directly to a Service
kubectl port-forward svc/<service-name> 8080:80 -n <namespace>Forwards traffic from local port 8080 directly to the service's load-balanced target endpoints.
Inspect endpoints backing a Service
kubectl get endpoints <service-name> -n <namespace>Shows the exact pod IP addresses currently healthy and receiving traffic from the service.
List all Ingress rules and hosts
kubectl get ingress -ADisplays configured hostnames, TLS terminations, path routing, and ingress controller IP addresses.
Create ConfigMap from literal key-values
kubectl create configmap app-config --from-literal=ENV=production --from-literal=PORT=8080Generates an in-cluster configuration map without authoring raw YAML documents.
Create Secret from file or literal string
kubectl create secret generic api-secrets --from-literal=API_KEY='secret123'Encodes and stores sensitive credentials safely in base64 within cluster etcd.
Decode all values from a Secret instantly
kubectl get secret <secret-name> -o json | jq '.data | map_values(@base64d)'Fetches secret object JSON and decodes all base64-encoded fields into plaintext directly in your terminal.
Export resource to clean YAML without cluster metadata
kubectl get deployment <name> -o yaml | kubectl neatExports clean Kubernetes YAML stripped of status, creationTimestamp, resourceVersion, and uid metadata.
Set active namespace permanently for current context
kubectl config set-context --current --namespace=<namespace>Switches default namespace context so subsequent kubectl commands do not require typing -n <namespace>.
Switch cluster context
kubectl config use-context <cluster-context-name>Switches active kubeconfig target between production, staging, and local minikube/kind clusters.
List all cluster contexts in kubeconfig
kubectl config get-contextsDisplays all configured cluster endpoints, users, namespaces, and indicates current active context with an asterisk (*).
Inspect node resource consumption (CPU & RAM)
kubectl top nodesOutputs live CPU (cores and %) and memory usage across all worker and control-plane nodes (requires Metrics Server).
Drain a node safely for maintenance
kubectl drain <node-name> --ignore-daemonsets --delete-emptydir-dataEvicts all pods safely from a node so it can be upgraded or decommissioned without breaking service uptime.
Cordon and uncordon a node
kubectl cordon <node-name> && kubectl uncordon <node-name>Marks a node as unschedulable (preventing new pods) or removes unschedulable restriction.
Run temporary busybox pod with curl for DNS & network tests
kubectl run test-dns --rm -it --image=curlimages/curl -- /bin/shSpawns an ephemeral container that cleans itself up upon exit (--rm) to verify internal cluster DNS and curl endpoints.
Attach ephemeral debug container to running pod
kubectl debug -it <pod-name> --image=nicolaka/netshoot --target=<container-name>Injects a network diagnostic container (tcpdump, nmap, curl, dig) into an existing pod's network namespace.
Dry-run and validate YAML without applying to cluster
kubectl apply -f manifest.yaml --dry-run=serverSubmits manifest to API server admission controllers and webhooks without persisting to etcd database.
Explain resource API schema and field documentation
kubectl explain deployment.spec.template.spec.containers.resourcesDisplays built-in API reference and field explanations directly in your CLI terminal.
Frequently Asked Questions About Kubernetes & Kubectl
How do I perform a zero-downtime rolling restart of a Kubernetes deployment?
Run 'kubectl rollout restart deployment/<deployment-name> -n <namespace>'. This increments the pod template's metadata timestamp annotation, causing Kubernetes to spawn new replacement pods before terminating old ones according to your rolling update strategy.
How do I decode all Base64 values inside a Kubernetes Secret in the terminal?
Execute 'kubectl get secret <secret-name> -o json | jq ".data | map_values(@base64d)"'. Alternatively, decode individual values with our client-side zero-server Base64 Decoder tool.
How do I open an interactive shell inside a running pod?
Run 'kubectl exec -it <pod-name> -n <namespace> -- /bin/sh' or replace /bin/sh with /bin/bash if installed. If the pod has multiple containers, specify the target container with '-c <container-name>'.
What is the difference between 'kubectl cordon' and 'kubectl drain'?
'kubectl cordon <node>' simply marks a node as unschedulable so no new pods will be placed on it. 'kubectl drain <node>' cordons the node AND actively evicts all running pods (rescheduling them to other nodes) so the node can undergo safe hardware or OS maintenance.
How do I test internal cluster DNS and network reachability without altering my app?
Run an ephemeral diagnostic container with 'kubectl run dns-test --rm -it --image=curlimages/curl -- /bin/sh'. Once inside, test DNS resolution using 'nslookup <service>.<namespace>.svc.cluster.local' and curl HTTP endpoints directly.