Reference
kubectl Cheat Sheet
Every command taught across the course. In the real app this grows as you complete lessons — here, the full sheet is shown.
Cluster & control plane
kubectl cluster-infoShow the API server and core service endpoints for the current context.
kubectl get nodes -o wideList nodes with their roles, versions, and internal IPs.
kubectl describe node <name>Full detail on a node: capacity, conditions, and the pods scheduled to it.
kubectl get pods -n kube-systemSee the control plane's own pods (API server, scheduler, controller-manager, CoreDNS) if they run as pods.
kubectl config current-contextShow which cluster/context kubectl is currently pointed at.
kubectl versionShow both client (kubectl) and server (API server) versions — check for skew.
Watching reconciliation happen
kubectl get pods -wWatch pods in real time as controllers create, reschedule, or delete them.
kubectl get events --sort-by=.lastTimestampSee the cluster's own narration of what just happened, oldest first.
kubectl explain deployment.specLook up what a field in a resource's spec means, straight from the API's built-in docs.
kubectl delete pod <name>Delete a single pod — if it's controller-managed, watch the reconciliation loop recreate it.
Pods & namespaces
kubectl run <name> --image=<image>Quickly create a single standalone pod (no controller) for a one-off test.
kubectl get pods -AList pods across every namespace (short for --all-namespaces).
kubectl create namespace <name>Create a new namespace to organize and isolate a set of objects.
kubectl config set-context --current --namespace=<ns>Stop typing -n <ns> on every command by setting a default namespace for your context.
kubectl get pod <name> -o yamlDump a pod's full spec and live status as YAML.
Labels & selectors
kubectl label pod <name> <key>=<value>Attach (or overwrite, with --overwrite) a label on an existing object.
kubectl get pods -l <key>=<value>Filter objects by a label selector — the same mechanism Services and Deployments use internally.
kubectl get pods --show-labelsList pods with all of their current labels visible.
kubectl logs <pod>Print a pod's stdout/stderr — your first stop when a pod is crashing.
kubectl describe pod <pod>Show events, container statuses, and restart counts — the second stop when diagnosing CrashLoopBackOff.
Deployments & ReplicaSets
kubectl create deployment <name> --image=<image>Create a Deployment (and its ReplicaSet and pods) in one shot.
kubectl scale deployment <name> --replicas=<n>Change the desired replica count; the ReplicaSet controller reconciles the rest.
kubectl get rsList ReplicaSets — notice one per revision of a Deployment, old ones scaled to 0.
kubectl get deploy -o wideSee a Deployment's desired/current/up-to-date/available replica counts at a glance.
Rolling updates & rollbacks
kubectl set image deployment/<name> <container>=<image>Trigger a rolling update by changing a container's image.
kubectl rollout status deployment/<name>Block and report on the progress of an in-flight rollout.
kubectl rollout history deployment/<name>List revisions kept for this Deployment.
kubectl rollout undo deployment/<name>Roll back to the previous revision (add --to-revision=<n> for a specific one).
kubectl rollout pause|resume deployment/<name>Pause a rollout mid-flight (e.g. to inspect canary pods) and resume it later.
Services
kubectl get svc -AList all Services across every namespace, with their type and ClusterIP.
kubectl get endpointslice -l kubernetes.io/service-name=<svc>See which pod IPs a Service is actually routing to right now — empty means a selector mismatch.
kubectl describe svc <svc>Show a Service's selector, ports, and endpoints together in one view.
Cluster DNS
kubectl exec <pod> -- nslookup <name>Resolve a Service name from inside a pod, exactly as the app would see it.
kubectl exec <pod> -- cat /etc/resolv.confSee the DNS server and search domains Kubernetes wrote into this pod.
kubectl get svc <name> -n <namespace>Confirm which namespace a Service actually lives in before assuming a DNS bug.
ConfigMaps
kubectl create configmap <name> --from-literal=key=valueCreate a ConfigMap from literal key-value pairs without writing a YAML file.
kubectl get configmap <name> -n <ns> -o yamlSee a ConfigMap's actual keys — the fastest way to catch a key-name mismatch.
kubectl exec <pod> -n <ns> -- printenv <VAR>Check what an env var actually resolved to inside a running container.
Secrets
kubectl create secret generic <name> --from-literal=key=valueCreate an Opaque Secret from literal key-value pairs.
kubectl get secret <name> -n <ns> -o jsonpath='{.data.<key>}' | base64 -dDecode a Secret value — proof it's encoding, not encryption.
kubectl get pod <pod> -n <ns> -o jsonpath='{.status.containerStatuses[0].state}'See the exact reason a container won't start, e.g. CreateContainerConfigError.
Probes
kubectl describe pod <name> -n <ns>Check the Events section for 'Unhealthy'/probe-failed messages — the fastest way to see which probe is failing and why.
kubectl get endpointslice -n <ns> -l kubernetes.io/service-name=<service>Empty address list + pod Running/0 restarts is the signature of a readiness-probe failure, not a crash.
kubectl exec -n <ns> <pod> -- curl -s -o /dev/null -w "%{http_code}\n" http://localhost:<port><path>Manually hit the exact path/port a probe uses from inside the container to confirm what it actually returns.
Resources & QoS
kubectl get pod <name> -n <ns> -o jsonpath='{.status.qosClass}'Print a pod's derived QoS class directly.
kubectl describe pod <name> -n <ns>Check 'Last State'/'Reason: OOMKilled' to confirm a restart was the kernel OOM killer, not a crash.
kubectl top pods -n <ns>Live CPU/memory usage per pod (needs metrics-server).
Volumes & PVCs
kubectl get pvc -n <ns>List PersistentVolumeClaims and their Bound/Pending status.
kubectl describe pvc <name> -n <ns>See why a claim is stuck Pending — the Events always name the exact cause.
kubectl get pvList PersistentVolumes cluster-wide (not namespaced).
StorageClasses
kubectl get storageclassList StorageClasses; the one marked (default) is used when a PVC omits storageClassName.
kubectl get storageclass <name> -o yamlInspect a class's provisioner, reclaimPolicy, and volumeBindingMode.
StatefulSets
kubectl get statefulset -n <ns>Check ready vs. desired replicas for a StatefulSet.
kubectl get pods -n <ns> -l <selector>StatefulSet pods list in strict ordinal order: name-0, name-1, ...
kubectl delete pod <name>-0 -n <ns>Force a StatefulSet pod's recreation — it comes back with the same name and the same per-pod PVC.
Ingress
kubectl get ingress -AList all Ingress objects and which controller class each uses.
kubectl describe ingress <name>See resolved rules, backend status, and events for one Ingress.
kubectl get ingressclassList available Ingress controllers registered in the cluster, and which is default.
kubectl exec <pod> -- wget -q -O- --header="Host: <host>" http://<svc>Test host/path routing from inside the cluster when there's no real external load balancer.
Gateway API
kubectl get gatewayclassList registered Gateway API controllers (the GatewayClass layer).
kubectl get gateway -AList Gateways and whether each is PROGRAMMED (accepted by its controller).
kubectl describe gateway <name>Check a Gateway's per-listener Accepted/Programmed conditions and attached-route counts.
kubectl get httproute -AList HTTPRoutes and the hostnames/parentRefs each attaches to.
kubectl describe httproute <name>See per-parentRef Accepted status and resolved backendRefs for one HTTPRoute.
Jobs & CronJobs
kubectl get jobs -n <ns>List Jobs and their completion status.
kubectl describe job <name> -n <ns>See a Job's Events — why it retried or gave up (BackoffLimitExceeded).
kubectl logs -n <ns> -l job-name=<name> --tail=20Read a Job's pod output directly by its job-name label.
kubectl get cronjob <name> -n <ns>Check SCHEDULE and LAST SCHEDULE for a CronJob.
kubectl get cronjob <name> -n <ns> -o jsonpath='{.status.lastSuccessfulTime}'Confirm a CronJob has actually fired successfully, not just that it exists.
DaemonSets
kubectl get daemonset -n <ns>Compare DESIRED/CURRENT/READY — DESIRED already accounts for nodeSelector/tolerations.
kubectl get nodes --selector='!node-role.kubernetes.io/control-plane'List only worker nodes — the usual baseline to compare DaemonSet coverage against.
kubectl get pods -n <ns> -o wideConfirm a DaemonSet's pods landed one-per-node, on the nodes you expect.
Taints & Tolerations
kubectl taint nodes <node> key=value:EffectAdd a taint (NoSchedule, PreferNoSchedule, or NoExecute) to a node.
kubectl taint nodes <node> key:Effect-Remove a taint — trailing dash after the effect.
kubectl describe node <node>Show a node's current taints under the Taints: field.
kubectl describe pod <pod>Check Events for 'untolerated taint(s)' when a pod won't schedule.
kubectl get pod <pod> -o jsonpath='{.spec.nodeName}'See which node a pod actually landed on.
Affinity & Topology Spread
kubectl get nodes --show-labelsSee what topology/label keys your nodes actually carry before writing affinity rules.
kubectl label nodes <node> key=valueAdd a label to a node (for nodeAffinity/nodeSelector targeting).
kubectl label nodes <node> key-Remove a node label — trailing dash.
kubectl get pods -n <ns> -o wideCheck which node each pod landed on — essential for verifying spread.
kubectl explain pod.spec.topologySpreadConstraintsLook up topologySpreadConstraints fields (maxSkew, topologyKey, whenUnsatisfiable, nodeTaintsPolicy) directly from the API.
RBAC & ServiceAccounts
kubectl create role <name> --verb=get,list,watch --resource=pods -n <ns>Imperatively create a Role (useful for drafting before writing YAML).
kubectl create rolebinding <name> --role=<role> --serviceaccount=<ns>:<sa> -n <ns>Bind a Role to a ServiceAccount.
kubectl auth can-i <verb> <resource> --as=system:serviceaccount:<ns>:<sa> -n <ns>Check an RBAC decision directly against the API server, without a running pod.
kubectl get rolebinding,role -n <ns>List the RBAC objects in a namespace.
Pod Security & NetworkPolicies
kubectl label namespace <ns> pod-security.kubernetes.io/enforce=restrictedEnforce a Pod Security Standard on a namespace at admission time.
kubectl get networkpolicy -n <ns>List NetworkPolicies in a namespace.
kubectl describe pod <name> -n <ns>See exactly which Pod Security constraint a rejected pod violated.
Helm
helm template <release> <chart>Render a chart to plain YAML locally — no cluster contact. Always check this before install/upgrade when something looks wrong.
helm install <release> <chart> -n <ns>Install a chart for the first time under a given release name.
helm upgrade <release> <chart> -n <ns>Re-render against new values and apply the diff to an existing release.
helm rollback <release> <revision>Revert a release to an older revision — the chart-level equivalent of kubectl rollout undo.
helm uninstall <release> -n <ns>Remove every object a release created.
Kustomize
kubectl kustomize <dir>Render a kustomization to plain YAML locally — no cluster contact. The Kustomize equivalent of helm template.
kubectl apply -k <dir>Render and apply a kustomization in one step.
kubectl diff -k <dir>Show what apply -k would change against the live cluster, without changing anything.
Logs, events, describe, metrics
kubectl logs <pod> --previousRead the crashed container's logs after it's been replaced, not the new one's.
kubectl logs <pod> -c <container>Logs from one specific container in a multi-container pod.
kubectl describe pod <pod>Full status plus chronological Events — check Last State/Reason/Exit Code for crashes.
kubectl get events --sort-by=.lastTimestampNamespace- or cluster-wide event timeline, oldest first — use when you don't yet know which object to describe.
kubectl top nodes / kubectl top podsLive CPU/memory from metrics-server (a separate add-on from the API server).
Structured debugging method
kubectl get endpointslice -l kubernetes.io/service-name=<svc>Check whether a Service actually has any backing pods before assuming the Service itself is broken.
kubectl get <kind> <name> -o jsonpath='{.status}'Pull just the live status block to compare against spec — fast way to spot a mismatch.
Autoscaling: HPA
kubectl autoscale deployment <name> --cpu-percent=50 --min=1 --max=5Imperatively create an HPA (equivalent to applying a HorizontalPodAutoscaler YAML).
kubectl get hpa -wWatch an HPA's current vs. target metric and replica count live.
kubectl describe hpa <name>See why an HPA isn't scaling — Events name the exact blocker (e.g. missing resource requests).
kubectl top podsPoint-in-time CPU/memory usage per pod, from metrics-server.
VPA & Cluster Autoscaling
kubectl get vpaList VerticalPodAutoscaler objects and their current recommendations (requires the VPA controller installed).
kubectl get nodepoolList Karpenter NodePools (requires Karpenter installed — this is an EKS-world command).
VPC CNI & networking
kubectl get pod <name> -o jsonpath='{.status.podIP}'See a pod's real IP — on EKS this is a routable VPC address, not an overlay address.
kubectl get networkpolicy <name> -o yamlInspect a NetworkPolicy's ipBlock CIDRs — on EKS these must match your real VPC/subnet ranges.
IRSA & Pod Identity
kubectl get serviceaccount <name> -o yamlCheck a ServiceAccount's eks.amazonaws.com/role-arn annotation for IRSA.
kubectl get deployment <name> -o jsonpath='{.spec.template.spec.serviceAccountName}'Confirm a Deployment's pods actually reference the IAM-mapped ServiceAccount.
Load balancers, storage & cost
kubectl get storageclass <name> -o jsonpath='{.provisioner}'Check which provisioner (e.g. ebs.csi.aws.com) a StorageClass actually points at.
kubectl get service <name> -o yamlInspect AWS Load Balancer Controller annotations (aws-load-balancer-type, -nlb-target-type) on a Service.
Capstone grading & diagnosis
kubectl get all,ingress,hpa,networkpolicy -n <ns>One-shot overview of every resource kind in a multi-tier namespace.
kubectl describe hpa <name> -n <ns>Shows HPA Conditions — the fastest way to see why it can't find its scale target or can't read metrics.
kubectl exec -n <ns> <pod> -- nc -z -w2 <host> <port>Quick TCP reachability test from inside the cluster — how you verify a NetworkPolicy is actually blocking (not just that the object exists).