The Complete kubectl Cheat Sheet: Every Command That Matters
The Complete kubectl Cheat Sheet: Every Command That Matters
This is the kubectl reference that actually gets used — every command group from the official CLI taxonomy, organized the way work happens: getting things running, managing them, debugging them, and operating the cluster itself. Bookmark it.
Table of Contents
- Getting started: create, run, expose, delete
- App management: apply, patch, rollout
- Working with apps: exec, logs, port-forward
- Cluster management: nodes and capacity
- Discovery: explain, api-resources
- Context and kubeconfig
- Output formatting: the force multiplier
- Aliases worth setting
Getting started: create, run, expose, delete
The basic lifecycle of anything on Kubernetes:
kubectl create -f deployment.yaml # create from manifest
cat pod.json | kubectl create -f - # create from stdin
kubectl create deployment web --image=nginx:1.27
kubectl create namespace staging
kubectl create configmap app-config --from-file=config/
kubectl create secret generic db-creds \
--from-literal=user=app --from-literal=pass=s3cret
kubectl get pods # list
kubectl get pods -o wide # with node/IP columns
kubectl get pods -n kube-system # namespace-scoped
kubectl get all -A # everything, all namespaces
kubectl delete pod web-abc # delete a resource
kubectl delete -f deployment.yaml # delete by manifest
kubectl delete pods --all -n test # nuke a namespace's pods
kubectl run starts a quick throwaway pod (kubectl run tmp --image=busybox -it --rm -- sh is the classic debug shell), and kubectl expose wraps a workload in a Service.
App management: apply, patch, rollout
kubectl apply -f manifests/ # declarative apply (dir or file)
kubectl apply -k overlays/prod # apply a kustomization
kubectl diff -f manifests/ # preview server-side diff
kubectl edit deployment web # live-edit in $EDITOR
kubectl patch deployment web -p \
'{"spec":{"replicas":5}}' # surgical in-place change
kubectl label pod web-abc tier=frontend # add/update a label
kubectl annotate pod web-abc note="canary" # add annotation
Rollouts: ship and un-ship
kubectl rollout status deploy/web # watch a rollout finish
kubectl rollout history deploy/web # revision list
kubectl rollout undo deploy/web # back to previous revision
kubectl rollout undo deploy/web --to-revision=3
kubectl rollout restart deploy/web # bounce pods (config reload)
kubectl rollout pause deploy/web # freeze mid-deploy
Scale and set
kubectl scale deploy/web --replicas=5
kubectl autoscale deploy/web --min=2 --max=10 --cpu-percent=80
kubectl set image deploy/web web=nginx:1.28
kubectl set resources deploy/web \
--requests=cpu=250m,memory=256Mi
kubectl set env deploy/web LOG_LEVEL=debug
kubectl wait --for=condition=ready pod -l app=web --timeout=60s
wait is the underrated one — block until a condition is true, perfect for scripts and CI.
Working with apps: exec, logs, port-forward
kubectl exec -it web-abc -- sh # shell into a container
kubectl exec web-abc -c sidecar -- ls / # target a specific container
kubectl logs web-abc # current logs
kubectl logs web-abc -f # follow
kubectl logs web-abc --previous # crashed container's last words
kubectl logs -l app=web --tail=50 # all pods matching a label
kubectl describe pod web-abc # events, probes, why it's pending
kubectl get events --sort-by=.lastTimestamp -n prod
kubectl top pods -n prod # live cpu/memory (needs metrics-server)
kubectl top nodes
kubectl port-forward svc/web 8080:80 # local port to service
kubectl port-forward web-abc 5432:5432 # direct to a pod
kubectl cp web-abc:/var/log/app.log ./app.log # copy files in/out
kubectl attach -it web-abc # attach to a running process
kubectl auth can-i create deployments # "do I have permission?"
kubectl debug -it web-abc --image=busybox --target=web # ephemeral debug container
debug is the modern answer to "this container has no shell" — it injects a tooling container into the running pod.
Cluster management: nodes and capacity
kubectl get nodes
kubectl describe node node-1 # capacity, conditions, pressure
kubectl cordon node-1 # stop scheduling new pods
kubectl drain node-1 --ignore-daemonsets \
--delete-emptydir-data # evict pods safely (for maintenance)
kubectl uncordon node-1 # schedulable again
kubectl taint nodes node-1 gpu=true:NoSchedule # repel non-tolerating pods
kubectl taint nodes node-1 gpu=true:NoSchedule- # remove taint
drain is the maintenance command — it evicts pods respecting PodDisruptionBudgets, so workloads migrate instead of dying. Always cordon first during triage; drain when you're ready to move things.
Discovery: explain, api-resources
kubectl explain deployment.spec # what does this field do?
kubectl explain pod.spec.containers.resources
kubectl api-resources # every type the cluster serves
kubectl api-versions
kubectl cluster-info
kubectl api-resources --namespaced=false # cluster-scoped types only
explain means you rarely need to leave the terminal for the API docs.
Context and kubeconfig
kubectl config get-contexts # your clusters
kubectl config current-context
kubectl config use-context prod-cluster # switch
kubectl config set-context --current --namespace=web # default ns for context
kubectl config view --minify # just the active context
Output formatting: the force multiplier
kubectl get pods -o json # full objects
kubectl get pods -o yaml
kubectl get pods -o jsonpath='{.items[*].spec.nodeName}'
kubectl get pods --sort-by=.metadata.creationTimestamp
kubectl get pods --field-selector=status.phase=Failed
kubectl get deploy web -o json | jq .spec.replicas
Combine jsonpath/jq with --selector and --field-selector and kubectl becomes a query engine, not just a client.
Aliases worth setting
alias k=kubectl
alias kgp='kubectl get pods'
alias kdp='kubectl describe pod'
alias kl='kubectl logs -f'
complete -F __start_kubectl k
Learn get, describe, logs, exec, and apply deeply — they cover 90% of daily work. Reach for drain, debug, and rollout undo when things get serious.
Related Articles
- Kubernetes for Beginners: Pods, Deployments, and Services
- Kubernetes Ingress and TLS: Exposing Services Properly
Last Updated: October 2026 Author: CloudOpsGuide Team Difficulty: Intermediate Estimated Reading Time: 14 minutes