📖 Read-only preview — lessons, diagrams, and quizzes only. The hands-on labs, live grading, and progress tracking require running the real course locally against a Kubernetes cluster.Run it locally →

Reference

kubectl Cheat Sheet

Every command taught across the course. In the real app this grows as you complete lessons — here, the full sheet is shown.

Cluster & control plane

kubectl cluster-info

Show the API server and core service endpoints for the current context.

kubectl get nodes -o wide

List nodes with their roles, versions, and internal IPs.

kubectl describe node <name>

Full detail on a node: capacity, conditions, and the pods scheduled to it.

kubectl get pods -n kube-system

See the control plane's own pods (API server, scheduler, controller-manager, CoreDNS) if they run as pods.

kubectl config current-context

Show which cluster/context kubectl is currently pointed at.

kubectl version

Show both client (kubectl) and server (API server) versions — check for skew.

Watching reconciliation happen

kubectl get pods -w

Watch pods in real time as controllers create, reschedule, or delete them.

kubectl get events --sort-by=.lastTimestamp

See the cluster's own narration of what just happened, oldest first.

kubectl explain deployment.spec

Look up what a field in a resource's spec means, straight from the API's built-in docs.

kubectl delete pod <name>

Delete a single pod — if it's controller-managed, watch the reconciliation loop recreate it.

Pods & namespaces

kubectl run <name> --image=<image>

Quickly create a single standalone pod (no controller) for a one-off test.

kubectl get pods -A

List pods across every namespace (short for --all-namespaces).

kubectl create namespace <name>

Create a new namespace to organize and isolate a set of objects.

kubectl config set-context --current --namespace=<ns>

Stop typing -n <ns> on every command by setting a default namespace for your context.

kubectl get pod <name> -o yaml

Dump a pod's full spec and live status as YAML.

Labels & selectors

kubectl label pod <name> <key>=<value>

Attach (or overwrite, with --overwrite) a label on an existing object.

kubectl get pods -l <key>=<value>

Filter objects by a label selector — the same mechanism Services and Deployments use internally.

kubectl get pods --show-labels

List pods with all of their current labels visible.

kubectl logs <pod>

Print a pod's stdout/stderr — your first stop when a pod is crashing.

kubectl describe pod <pod>

Show events, container statuses, and restart counts — the second stop when diagnosing CrashLoopBackOff.

Deployments & ReplicaSets

kubectl create deployment <name> --image=<image>

Create a Deployment (and its ReplicaSet and pods) in one shot.

kubectl scale deployment <name> --replicas=<n>

Change the desired replica count; the ReplicaSet controller reconciles the rest.

kubectl get rs

List ReplicaSets — notice one per revision of a Deployment, old ones scaled to 0.

kubectl get deploy -o wide

See a Deployment's desired/current/up-to-date/available replica counts at a glance.

Rolling updates & rollbacks

kubectl set image deployment/<name> <container>=<image>

Trigger a rolling update by changing a container's image.

kubectl rollout status deployment/<name>

Block and report on the progress of an in-flight rollout.

kubectl rollout history deployment/<name>

List revisions kept for this Deployment.

kubectl rollout undo deployment/<name>

Roll back to the previous revision (add --to-revision=<n> for a specific one).

kubectl rollout pause|resume deployment/<name>

Pause a rollout mid-flight (e.g. to inspect canary pods) and resume it later.

Services

kubectl get svc -A

List all Services across every namespace, with their type and ClusterIP.

kubectl get endpointslice -l kubernetes.io/service-name=<svc>

See which pod IPs a Service is actually routing to right now — empty means a selector mismatch.

kubectl describe svc <svc>

Show a Service's selector, ports, and endpoints together in one view.

Cluster DNS

kubectl exec <pod> -- nslookup <name>

Resolve a Service name from inside a pod, exactly as the app would see it.

kubectl exec <pod> -- cat /etc/resolv.conf

See the DNS server and search domains Kubernetes wrote into this pod.

kubectl get svc <name> -n <namespace>

Confirm which namespace a Service actually lives in before assuming a DNS bug.

ConfigMaps

kubectl create configmap <name> --from-literal=key=value

Create a ConfigMap from literal key-value pairs without writing a YAML file.

kubectl get configmap <name> -n <ns> -o yaml

See a ConfigMap's actual keys — the fastest way to catch a key-name mismatch.

kubectl exec <pod> -n <ns> -- printenv <VAR>

Check what an env var actually resolved to inside a running container.

Secrets

kubectl create secret generic <name> --from-literal=key=value

Create an Opaque Secret from literal key-value pairs.

kubectl get secret <name> -n <ns> -o jsonpath='{.data.<key>}' | base64 -d

Decode a Secret value — proof it's encoding, not encryption.

kubectl get pod <pod> -n <ns> -o jsonpath='{.status.containerStatuses[0].state}'

See the exact reason a container won't start, e.g. CreateContainerConfigError.

Probes

kubectl describe pod <name> -n <ns>

Check the Events section for 'Unhealthy'/probe-failed messages — the fastest way to see which probe is failing and why.

kubectl get endpointslice -n <ns> -l kubernetes.io/service-name=<service>

Empty address list + pod Running/0 restarts is the signature of a readiness-probe failure, not a crash.

kubectl exec -n <ns> <pod> -- curl -s -o /dev/null -w "%{http_code}\n" http://localhost:<port><path>

Manually hit the exact path/port a probe uses from inside the container to confirm what it actually returns.

Resources & QoS

kubectl get pod <name> -n <ns> -o jsonpath='{.status.qosClass}'

Print a pod's derived QoS class directly.

kubectl describe pod <name> -n <ns>

Check 'Last State'/'Reason: OOMKilled' to confirm a restart was the kernel OOM killer, not a crash.

kubectl top pods -n <ns>

Live CPU/memory usage per pod (needs metrics-server).

Volumes & PVCs

kubectl get pvc -n <ns>

List PersistentVolumeClaims and their Bound/Pending status.

kubectl describe pvc <name> -n <ns>

See why a claim is stuck Pending — the Events always name the exact cause.

kubectl get pv

List PersistentVolumes cluster-wide (not namespaced).

StorageClasses

kubectl get storageclass

List StorageClasses; the one marked (default) is used when a PVC omits storageClassName.

kubectl get storageclass <name> -o yaml

Inspect a class's provisioner, reclaimPolicy, and volumeBindingMode.

StatefulSets

kubectl get statefulset -n <ns>

Check ready vs. desired replicas for a StatefulSet.

kubectl get pods -n <ns> -l <selector>

StatefulSet pods list in strict ordinal order: name-0, name-1, ...

kubectl delete pod <name>-0 -n <ns>

Force a StatefulSet pod's recreation — it comes back with the same name and the same per-pod PVC.

Ingress

kubectl get ingress -A

List all Ingress objects and which controller class each uses.

kubectl describe ingress <name>

See resolved rules, backend status, and events for one Ingress.

kubectl get ingressclass

List available Ingress controllers registered in the cluster, and which is default.

kubectl exec <pod> -- wget -q -O- --header="Host: <host>" http://<svc>

Test host/path routing from inside the cluster when there's no real external load balancer.

Gateway API

kubectl get gatewayclass

List registered Gateway API controllers (the GatewayClass layer).

kubectl get gateway -A

List Gateways and whether each is PROGRAMMED (accepted by its controller).

kubectl describe gateway <name>

Check a Gateway's per-listener Accepted/Programmed conditions and attached-route counts.

kubectl get httproute -A

List HTTPRoutes and the hostnames/parentRefs each attaches to.

kubectl describe httproute <name>

See per-parentRef Accepted status and resolved backendRefs for one HTTPRoute.

Jobs & CronJobs

kubectl get jobs -n <ns>

List Jobs and their completion status.

kubectl describe job <name> -n <ns>

See a Job's Events — why it retried or gave up (BackoffLimitExceeded).

kubectl logs -n <ns> -l job-name=<name> --tail=20

Read a Job's pod output directly by its job-name label.

kubectl get cronjob <name> -n <ns>

Check SCHEDULE and LAST SCHEDULE for a CronJob.

kubectl get cronjob <name> -n <ns> -o jsonpath='{.status.lastSuccessfulTime}'

Confirm a CronJob has actually fired successfully, not just that it exists.

DaemonSets

kubectl get daemonset -n <ns>

Compare DESIRED/CURRENT/READY — DESIRED already accounts for nodeSelector/tolerations.

kubectl get nodes --selector='!node-role.kubernetes.io/control-plane'

List only worker nodes — the usual baseline to compare DaemonSet coverage against.

kubectl get pods -n <ns> -o wide

Confirm a DaemonSet's pods landed one-per-node, on the nodes you expect.

Taints & Tolerations

kubectl taint nodes <node> key=value:Effect

Add a taint (NoSchedule, PreferNoSchedule, or NoExecute) to a node.

kubectl taint nodes <node> key:Effect-

Remove a taint — trailing dash after the effect.

kubectl describe node <node>

Show a node's current taints under the Taints: field.

kubectl describe pod <pod>

Check Events for 'untolerated taint(s)' when a pod won't schedule.

kubectl get pod <pod> -o jsonpath='{.spec.nodeName}'

See which node a pod actually landed on.

Affinity & Topology Spread

kubectl get nodes --show-labels

See what topology/label keys your nodes actually carry before writing affinity rules.

kubectl label nodes <node> key=value

Add a label to a node (for nodeAffinity/nodeSelector targeting).

kubectl label nodes <node> key-

Remove a node label — trailing dash.

kubectl get pods -n <ns> -o wide

Check which node each pod landed on — essential for verifying spread.

kubectl explain pod.spec.topologySpreadConstraints

Look up topologySpreadConstraints fields (maxSkew, topologyKey, whenUnsatisfiable, nodeTaintsPolicy) directly from the API.

RBAC & ServiceAccounts

kubectl create role <name> --verb=get,list,watch --resource=pods -n <ns>

Imperatively create a Role (useful for drafting before writing YAML).

kubectl create rolebinding <name> --role=<role> --serviceaccount=<ns>:<sa> -n <ns>

Bind a Role to a ServiceAccount.

kubectl auth can-i <verb> <resource> --as=system:serviceaccount:<ns>:<sa> -n <ns>

Check an RBAC decision directly against the API server, without a running pod.

kubectl get rolebinding,role -n <ns>

List the RBAC objects in a namespace.

Pod Security & NetworkPolicies

kubectl label namespace <ns> pod-security.kubernetes.io/enforce=restricted

Enforce a Pod Security Standard on a namespace at admission time.

kubectl get networkpolicy -n <ns>

List NetworkPolicies in a namespace.

kubectl describe pod <name> -n <ns>

See exactly which Pod Security constraint a rejected pod violated.

Helm

helm template <release> <chart>

Render a chart to plain YAML locally — no cluster contact. Always check this before install/upgrade when something looks wrong.

helm install <release> <chart> -n <ns>

Install a chart for the first time under a given release name.

helm upgrade <release> <chart> -n <ns>

Re-render against new values and apply the diff to an existing release.

helm rollback <release> <revision>

Revert a release to an older revision — the chart-level equivalent of kubectl rollout undo.

helm uninstall <release> -n <ns>

Remove every object a release created.

Kustomize

kubectl kustomize <dir>

Render a kustomization to plain YAML locally — no cluster contact. The Kustomize equivalent of helm template.

kubectl apply -k <dir>

Render and apply a kustomization in one step.

kubectl diff -k <dir>

Show what apply -k would change against the live cluster, without changing anything.

Logs, events, describe, metrics

kubectl logs <pod> --previous

Read the crashed container's logs after it's been replaced, not the new one's.

kubectl logs <pod> -c <container>

Logs from one specific container in a multi-container pod.

kubectl describe pod <pod>

Full status plus chronological Events — check Last State/Reason/Exit Code for crashes.

kubectl get events --sort-by=.lastTimestamp

Namespace- or cluster-wide event timeline, oldest first — use when you don't yet know which object to describe.

kubectl top nodes / kubectl top pods

Live CPU/memory from metrics-server (a separate add-on from the API server).

Structured debugging method

kubectl get endpointslice -l kubernetes.io/service-name=<svc>

Check whether a Service actually has any backing pods before assuming the Service itself is broken.

kubectl get <kind> <name> -o jsonpath='{.status}'

Pull just the live status block to compare against spec — fast way to spot a mismatch.

Autoscaling: HPA

kubectl autoscale deployment <name> --cpu-percent=50 --min=1 --max=5

Imperatively create an HPA (equivalent to applying a HorizontalPodAutoscaler YAML).

kubectl get hpa -w

Watch an HPA's current vs. target metric and replica count live.

kubectl describe hpa <name>

See why an HPA isn't scaling — Events name the exact blocker (e.g. missing resource requests).

kubectl top pods

Point-in-time CPU/memory usage per pod, from metrics-server.

VPA & Cluster Autoscaling

kubectl get vpa

List VerticalPodAutoscaler objects and their current recommendations (requires the VPA controller installed).

kubectl get nodepool

List Karpenter NodePools (requires Karpenter installed — this is an EKS-world command).

VPC CNI & networking

kubectl get pod <name> -o jsonpath='{.status.podIP}'

See a pod's real IP — on EKS this is a routable VPC address, not an overlay address.

kubectl get networkpolicy <name> -o yaml

Inspect a NetworkPolicy's ipBlock CIDRs — on EKS these must match your real VPC/subnet ranges.

IRSA & Pod Identity

kubectl get serviceaccount <name> -o yaml

Check a ServiceAccount's eks.amazonaws.com/role-arn annotation for IRSA.

kubectl get deployment <name> -o jsonpath='{.spec.template.spec.serviceAccountName}'

Confirm a Deployment's pods actually reference the IAM-mapped ServiceAccount.

Load balancers, storage & cost

kubectl get storageclass <name> -o jsonpath='{.provisioner}'

Check which provisioner (e.g. ebs.csi.aws.com) a StorageClass actually points at.

kubectl get service <name> -o yaml

Inspect AWS Load Balancer Controller annotations (aws-load-balancer-type, -nlb-target-type) on a Service.

Capstone grading & diagnosis

kubectl get all,ingress,hpa,networkpolicy -n <ns>

One-shot overview of every resource kind in a multi-tier namespace.

kubectl describe hpa <name> -n <ns>

Shows HPA Conditions — the fastest way to see why it can't find its scale target or can't read metrics.

kubectl exec -n <ns> <pod> -- nc -z -w2 <host> <port>

Quick TCP reachability test from inside the cluster — how you verify a NetworkPolicy is actually blocking (not just that the object exists).