CloudOpsGuide
kubernetes

The Complete kubectl Cheat Sheet: Every Command That Matters

Intermediate
14 minutes
October 2026
CloudOpsGuide Team

The Complete kubectl Cheat Sheet: Every Command That Matters

This is the kubectl reference that actually gets used — every command group from the official CLI taxonomy, organized the way work happens: getting things running, managing them, debugging them, and operating the cluster itself. Bookmark it.

Table of Contents

Getting started: create, run, expose, delete

The basic lifecycle of anything on Kubernetes:

kubectl create -f deployment.yaml          # create from manifest
cat pod.json | kubectl create -f -         # create from stdin
kubectl create deployment web --image=nginx:1.27
kubectl create namespace staging
kubectl create configmap app-config --from-file=config/
kubectl create secret generic db-creds \
  --from-literal=user=app --from-literal=pass=s3cret
kubectl get pods                           # list
kubectl get pods -o wide                   # with node/IP columns
kubectl get pods -n kube-system            # namespace-scoped
kubectl get all -A                         # everything, all namespaces
kubectl delete pod web-abc                 # delete a resource
kubectl delete -f deployment.yaml          # delete by manifest
kubectl delete pods --all -n test          # nuke a namespace's pods

kubectl run starts a quick throwaway pod (kubectl run tmp --image=busybox -it --rm -- sh is the classic debug shell), and kubectl expose wraps a workload in a Service.

App management: apply, patch, rollout

kubectl apply -f manifests/                # declarative apply (dir or file)
kubectl apply -k overlays/prod             # apply a kustomization
kubectl diff -f manifests/                 # preview server-side diff
kubectl edit deployment web                # live-edit in $EDITOR
kubectl patch deployment web -p \
  '{"spec":{"replicas":5}}'                # surgical in-place change
kubectl label pod web-abc tier=frontend    # add/update a label
kubectl annotate pod web-abc note="canary" # add annotation

Rollouts: ship and un-ship

kubectl rollout status deploy/web          # watch a rollout finish
kubectl rollout history deploy/web         # revision list
kubectl rollout undo deploy/web            # back to previous revision
kubectl rollout undo deploy/web --to-revision=3
kubectl rollout restart deploy/web         # bounce pods (config reload)
kubectl rollout pause deploy/web           # freeze mid-deploy

Scale and set

kubectl scale deploy/web --replicas=5
kubectl autoscale deploy/web --min=2 --max=10 --cpu-percent=80
kubectl set image deploy/web web=nginx:1.28
kubectl set resources deploy/web \
  --requests=cpu=250m,memory=256Mi
kubectl set env deploy/web LOG_LEVEL=debug
kubectl wait --for=condition=ready pod -l app=web --timeout=60s

wait is the underrated one — block until a condition is true, perfect for scripts and CI.

Working with apps: exec, logs, port-forward

kubectl exec -it web-abc -- sh             # shell into a container
kubectl exec web-abc -c sidecar -- ls /    # target a specific container
kubectl logs web-abc                       # current logs
kubectl logs web-abc -f                    # follow
kubectl logs web-abc --previous            # crashed container's last words
kubectl logs -l app=web --tail=50          # all pods matching a label
kubectl describe pod web-abc               # events, probes, why it's pending
kubectl get events --sort-by=.lastTimestamp -n prod
kubectl top pods -n prod                   # live cpu/memory (needs metrics-server)
kubectl top nodes
kubectl port-forward svc/web 8080:80       # local port to service
kubectl port-forward web-abc 5432:5432     # direct to a pod
kubectl cp web-abc:/var/log/app.log ./app.log   # copy files in/out
kubectl attach -it web-abc                 # attach to a running process
kubectl auth can-i create deployments      # "do I have permission?"
kubectl debug -it web-abc --image=busybox --target=web  # ephemeral debug container

debug is the modern answer to "this container has no shell" — it injects a tooling container into the running pod.

Cluster management: nodes and capacity

kubectl get nodes
kubectl describe node node-1               # capacity, conditions, pressure
kubectl cordon node-1                      # stop scheduling new pods
kubectl drain node-1 --ignore-daemonsets \
  --delete-emptydir-data                   # evict pods safely (for maintenance)
kubectl uncordon node-1                    # schedulable again
kubectl taint nodes node-1 gpu=true:NoSchedule   # repel non-tolerating pods
kubectl taint nodes node-1 gpu=true:NoSchedule-  # remove taint

drain is the maintenance command — it evicts pods respecting PodDisruptionBudgets, so workloads migrate instead of dying. Always cordon first during triage; drain when you're ready to move things.

Discovery: explain, api-resources

kubectl explain deployment.spec            # what does this field do?
kubectl explain pod.spec.containers.resources
kubectl api-resources                      # every type the cluster serves
kubectl api-versions
kubectl cluster-info
kubectl api-resources --namespaced=false   # cluster-scoped types only

explain means you rarely need to leave the terminal for the API docs.

Context and kubeconfig

kubectl config get-contexts                # your clusters
kubectl config current-context
kubectl config use-context prod-cluster    # switch
kubectl config set-context --current --namespace=web   # default ns for context
kubectl config view --minify               # just the active context

Output formatting: the force multiplier

kubectl get pods -o json                   # full objects
kubectl get pods -o yaml
kubectl get pods -o jsonpath='{.items[*].spec.nodeName}'
kubectl get pods --sort-by=.metadata.creationTimestamp
kubectl get pods --field-selector=status.phase=Failed
kubectl get deploy web -o json | jq .spec.replicas

Combine jsonpath/jq with --selector and --field-selector and kubectl becomes a query engine, not just a client.

Aliases worth setting

alias k=kubectl
alias kgp='kubectl get pods'
alias kdp='kubectl describe pod'
alias kl='kubectl logs -f'
complete -F __start_kubectl k

Learn get, describe, logs, exec, and apply deeply — they cover 90% of daily work. Reach for drain, debug, and rollout undo when things get serious.

Related Articles


Last Updated: October 2026 Author: CloudOpsGuide Team Difficulty: Intermediate Estimated Reading Time: 14 minutes