Francisco Giraldo

kubectl Cheat Sheet

Published Sun, 11 Oct 2026 00:00:00 GMT 8 min read

Quick reference for everyday kubectl commands.

Context & Cluster Info

kubectl config get-contexts          # List contexts
kubectl config current-context       # Show active context
kubectl config use-context <name>    # Switch context
kubectl cluster-info                 # Cluster endpoints
kubectl get nodes                    # List nodes
kubectl get namespaces               # List namespaces

Namespaces

kubectl get all -n <namespace>       # All resources in a namespace
kubectl get all -A                   # All resources, all namespaces
kubectl create namespace <name>
kubectl delete namespace <name>

Tip: set a default namespace for your context:

kubectl config set-context --current --namespace=<namespace>

Pods

kubectl get pods
kubectl get pods -o wide             # Include node + IP
kubectl get pods -A                  # All namespaces
kubectl get pod <name> -o yaml
kubectl describe pod <name>
kubectl delete pod <name>
kubectl delete pod <name> --force --grace-period=0

Create / run

kubectl run nginx --image=nginx
kubectl run debug --image=busybox -it --rm --restart=Never -- sh

Exec & copy

kubectl exec -it <pod> -- /bin/sh
kubectl exec -it <pod> -c <container> -- /bin/bash
kubectl cp <pod>:/path/file ./local-file
kubectl cp ./local-file <pod>:/path/file

Deployments

kubectl get deployments
kubectl describe deployment <name>
kubectl create deployment <name> --image=<image>
kubectl scale deployment <name> --replicas=3
kubectl set image deployment/<name> <container>=<image>:<tag>
kubectl rollout status deployment/<name>
kubectl rollout history deployment/<name>
kubectl rollout undo deployment/<name>
kubectl rollout undo deployment/<name> --to-revision=2
kubectl delete deployment <name>

Services

kubectl get svc
kubectl describe svc <name>
kubectl expose deployment <name> --port=80 --target-port=8080 --type=ClusterIP
kubectl expose deployment <name> --type=LoadBalancer --port=80
kubectl port-forward svc/<name> 8080:80
kubectl delete svc <name>
Type Use case
ClusterIP Internal only (default)
NodePort Expose on each node
LoadBalancer Cloud load balancer
ExternalName DNS alias to external host

Logs & Debugging

kubectl logs <pod>
kubectl logs <pod> -c <container>
kubectl logs <pod> --previous         # Previous crashed container
kubectl logs <pod> -f                 # Follow (tail -f)
kubectl logs <pod> --tail=100
kubectl logs -l app=<label>           # By label
kubectl top pods                      # Resource usage (needs metrics-server)
kubectl top nodes
kubectl get events --sort-by=.lastTimestamp

Apply / Diff / Delete Manifests

kubectl apply -f manifest.yaml
kubectl apply -f ./folder/
kubectl apply -k ./overlays/prod/     # Kustomize
kubectl diff -f manifest.yaml
kubectl delete -f manifest.yaml
kubectl get -f manifest.yaml

Dry-run before creating:

kubectl apply -f manifest.yaml --dry-run=client -o yaml
kubectl create deployment nginx --image=nginx --dry-run=client -o yaml > deploy.yaml

Labels & Selectors

kubectl get pods -l app=api
kubectl get pods -l 'env in (prod,staging)'
kubectl label pod <name> env=prod
kubectl label pod <name> env-           # Remove label

ConfigMaps & Secrets

kubectl get configmaps
kubectl get secrets
kubectl create configmap <name> --from-literal=KEY=value
kubectl create configmap <name> --from-file=./config.env
kubectl create secret generic <name> --from-literal=password=s3cret
kubectl create secret docker-registry regcred \
  --docker-server=<registry> \
  --docker-username=<user> \
  --docker-password=<pass>
kubectl get secret <name> -o jsonpath='{.data.password}' | base64 -d

Jobs & CronJobs

kubectl get jobs
kubectl get cronjobs
kubectl create job <name> --image=<image> -- <command>
kubectl create job --from=cronjob/<cronjob-name> <job-name>
kubectl delete job <name>

Nodes & Cordoning

kubectl get nodes
kubectl describe node <name>
kubectl cordon <node>                 # Mark unschedulable
kubectl drain <node> --ignore-daemonsets --delete-emptydir-data
kubectl uncordon <node>

Useful Output Formats

kubectl get pods -o wide
kubectl get pods -o yaml
kubectl get pods -o json
kubectl get pods -o jsonpath='{.items[*].metadata.name}'
kubectl get pods -o custom-columns=NAME:.metadata.name,STATUS:.status.phase
kubectl get pods --show-labels

Shorthand Resource Names

Short Full
po pods
deploy deployments
svc services
ns namespaces
cm configmaps
ing ingresses
rs replicasets
sts statefulsets
ds daemonsets
pv / pvc persistentvolumes / claims
kubectl get po,svc,deploy -n default

Common Debugging Flow

# 1. What's failing?
kubectl get pods
kubectl describe pod <name>
kubectl get events --sort-by=.lastTimestamp

# 2. Check logs
kubectl logs <pod> --previous
kubectl logs <pod> -c <container>

# 3. Shell in
kubectl exec -it <pod> -- /bin/sh

# 4. Network / service
kubectl get endpoints <svc>
kubectl port-forward pod/<name> 8080:80

Useful Links




Keep reading other of my blog posts!