Kubernetes & Kubectl Quick Reference

Kubernetes & Kubectl Cheat Sheet

Essential kubectl commands for developers and SREs. Searchable directory for pod debugging, zero-downtime rollouts, secrets decoding, node draining, and cluster troubleshooting.

Showing 29 kubectl recipes
pods

List pods across all namespaces with node & IP

Subnet Calculator
kubectl get pods -A -o wide

Lists all running and pending pods across every cluster namespace, including assigned node names and internal Pod IPs.

pods

Stream logs from a specific pod container

kubectl logs -f <pod-name> -c <container-name> --tail=100

Follows real-time standard output and error streams from a designated container inside a multi-container pod.

pods

Open an interactive shell inside a running pod

kubectl exec -it <pod-name> -n <namespace> -- /bin/sh

Spawns an interactive pseudo-TTY session inside the pod. Use /bin/bash for Debian/Ubuntu or /bin/sh for Alpine.

pods

Forward local port directly to a pod

kubectl port-forward pod/<pod-name> 8080:80

Bypasses ingress and services to bind host port 8080 directly to container port 80 for local testing.

pods

View detailed pod events and failure reasons

kubectl describe pod <pod-name> -n <namespace>

Inspects scheduling events, CrashLoopBackOff states, OOMKilled codes, and readiness/liveness probe failures.

pods

Force delete a terminating or stuck pod

kubectl delete pod <pod-name> --grace-period=0 --force

Immediately deletes a pod stuck in Terminating status without waiting for kubelet confirmation.

deployments

Restart a deployment (rolling restart)

kubectl rollout restart deployment/<deployment-name> -n <namespace>

Triggers a zero-downtime rolling restart of all pods by updating the deployment's pod template annotation.

deployments

Scale deployment replica count

kubectl scale deployment/<deployment-name> --replicas=5 -n <namespace>

Adjusts the desired number of running pod instances to 5 without altering configuration YAML files.

deployments

Check rollout status and progress

kubectl rollout status deployment/<deployment-name>

Blocks terminal until all new pods reach Ready status or reports deployment failure/timeout.

deployments

Roll back to previous revision

kubectl rollout undo deployment/<deployment-name>

Reverts the deployment and its ReplicaSet to the previous successful revision.

deployments

View deployment rollout history

kubectl rollout history deployment/<deployment-name>

Inspects recorded revision history numbers and change-cause annotations.

services

List all services with ClusterIP and NodePort

kubectl get svc -A

Displays all internal ClusterIPs, NodePorts, external LoadBalancers, and target ports across all namespaces.

services

Port-forward directly to a Service

kubectl port-forward svc/<service-name> 8080:80 -n <namespace>

Forwards traffic from local port 8080 directly to the service's load-balanced target endpoints.

services

Inspect endpoints backing a Service

kubectl get endpoints <service-name> -n <namespace>

Shows the exact pod IP addresses currently healthy and receiving traffic from the service.

services

List all Ingress rules and hosts

kubectl get ingress -A

Displays configured hostnames, TLS terminations, path routing, and ingress controller IP addresses.

configs

Create ConfigMap from literal key-values

JSON ↔ YAML Converter
kubectl create configmap app-config --from-literal=ENV=production --from-literal=PORT=8080

Generates an in-cluster configuration map without authoring raw YAML documents.

configs

Create Secret from file or literal string

Base64 Encoder
kubectl create secret generic api-secrets --from-literal=API_KEY='secret123'

Encodes and stores sensitive credentials safely in base64 within cluster etcd.

configs

Decode all values from a Secret instantly

Base64 Decoder
kubectl get secret <secret-name> -o json | jq '.data | map_values(@base64d)'

Fetches secret object JSON and decodes all base64-encoded fields into plaintext directly in your terminal.

configs

Export resource to clean YAML without cluster metadata

kubectl get deployment <name> -o yaml | kubectl neat

Exports clean Kubernetes YAML stripped of status, creationTimestamp, resourceVersion, and uid metadata.

namespaces

Set active namespace permanently for current context

kubectl config set-context --current --namespace=<namespace>

Switches default namespace context so subsequent kubectl commands do not require typing -n <namespace>.

namespaces

Switch cluster context

kubectl config use-context <cluster-context-name>

Switches active kubeconfig target between production, staging, and local minikube/kind clusters.

namespaces

List all cluster contexts in kubeconfig

kubectl config get-contexts

Displays all configured cluster endpoints, users, namespaces, and indicates current active context with an asterisk (*).

nodes

Inspect node resource consumption (CPU & RAM)

kubectl top nodes

Outputs live CPU (cores and %) and memory usage across all worker and control-plane nodes (requires Metrics Server).

nodes

Drain a node safely for maintenance

kubectl drain <node-name> --ignore-daemonsets --delete-emptydir-data

Evicts all pods safely from a node so it can be upgraded or decommissioned without breaking service uptime.

nodes

Cordon and uncordon a node

kubectl cordon <node-name> && kubectl uncordon <node-name>

Marks a node as unschedulable (preventing new pods) or removes unschedulable restriction.

debugging

Run temporary busybox pod with curl for DNS & network tests

kubectl run test-dns --rm -it --image=curlimages/curl -- /bin/sh

Spawns an ephemeral container that cleans itself up upon exit (--rm) to verify internal cluster DNS and curl endpoints.

debugging

Attach ephemeral debug container to running pod

kubectl debug -it <pod-name> --image=nicolaka/netshoot --target=<container-name>

Injects a network diagnostic container (tcpdump, nmap, curl, dig) into an existing pod's network namespace.

debugging

Dry-run and validate YAML without applying to cluster

kubectl apply -f manifest.yaml --dry-run=server

Submits manifest to API server admission controllers and webhooks without persisting to etcd database.

debugging

Explain resource API schema and field documentation

kubectl explain deployment.spec.template.spec.containers.resources

Displays built-in API reference and field explanations directly in your CLI terminal.

Frequently Asked Questions About Kubernetes & Kubectl

How do I perform a zero-downtime rolling restart of a Kubernetes deployment?

Run 'kubectl rollout restart deployment/<deployment-name> -n <namespace>'. This increments the pod template's metadata timestamp annotation, causing Kubernetes to spawn new replacement pods before terminating old ones according to your rolling update strategy.

How do I decode all Base64 values inside a Kubernetes Secret in the terminal?

Execute 'kubectl get secret <secret-name> -o json | jq ".data | map_values(@base64d)"'. Alternatively, decode individual values with our client-side zero-server Base64 Decoder tool.

How do I open an interactive shell inside a running pod?

Run 'kubectl exec -it <pod-name> -n <namespace> -- /bin/sh' or replace /bin/sh with /bin/bash if installed. If the pod has multiple containers, specify the target container with '-c <container-name>'.

What is the difference between 'kubectl cordon' and 'kubectl drain'?

'kubectl cordon <node>' simply marks a node as unschedulable so no new pods will be placed on it. 'kubectl drain <node>' cordons the node AND actively evicts all running pods (rescheduling them to other nodes) so the node can undergo safe hardware or OS maintenance.

How do I test internal cluster DNS and network reachability without altering my app?

Run an ephemeral diagnostic container with 'kubectl run dns-test --rm -it --image=curlimages/curl -- /bin/sh'. Once inside, test DNS resolution using 'nslookup <service>.<namespace>.svc.cluster.local' and curl HTTP endpoints directly.