8 ms·
Everything useful I know about kubectl
- iechoz6H 5y agoBreak in case of Fire (i.e. rollback to the previous deployment version): kubectl rollout undo deployment <deployment-name>
- throwaaskjdfh 5y agoAlong those lines, this was an interesting statement: "You should learn how to use these commands, but they shouldn't be a regular part of your prod workflows. That will lead to a flaky system." It seems like there's some theory vs. practice tension here. In theory, you shouldn't need to use these commands often, but in practice, you should be able to do them quickly. How often is it the case in reality that a team of Kubernetes superheroes, well versed in these commands, is necessary to make Continuous Integration and/or Continuous Deployment work?
- lazyant 5y agoFor the read-only commands, you can obv use them as much as you can, the issue is with the write commands. I see them as a tool for troubleshooting (eg, you are adding a debugging pod, not changing the running system) and emergency work that would be faster on command line than running the CI/CD pipeline but the final state needs to be in sync with the code (tools like ArgoCD help with this), otherwise it's a mess.
- alek_m 5y agoEvery time I'm starting a new service to run internally or reviewing something we have going, I find myself struggling to find the right instance type for the needs. For instance, there are three families (r, x, z) that optimize RAM in various ways in various combinations and I always forget about the x and z variants. So I put together this "cheat sheet" for us internally and thought I'd share it for anyone interested. Pull requests welcome for updates: https://github.com/wrble/public/blob/main/aws-instance-types.md https://github.com/wrble/public/blob/main/aws-instance-types... Did I miss anything?
- secondcoming 5y agoBoth AWS and GCP allow you to customise a machine's spec. You're not limited to the ones they offer.
- loriverkutya 5y agoMaybe I’m not 100% up-to-date with AWS Ec2 offerings, but as far as I’m aware, you can only choose from predefined instance types.
- seneca 5y agoIt seems this may have been posted on the wrong article, as it's completely unrelated to the topic.
- tut-urut-utut 5y agoI would add one more important point about kubectl? If you don't work at Google, you don't need a complexity of kubernetes at all, so better forget everything you already know about it. The company would be grateful. Joke aside, trying to sell something to the masses that could potentially benefit only 0.001% of the projects is just insincere. Pure CV pump and dump scheme.
- imglorp 5y agoThis is getting downvoted for cynicism maybe, but I feel it's the most important advice here. Know /when/ to use Kubernetes. It's very often the wrong tool to deploy our tiny app but many of us go along with it because it ticks some management boxes for various buzzwords, compliance, hipness, or whatever. Once you get out this hammer factory, it's a big and complicated one, so you will probably need a full time team to understand it and manage it. It's also a metric hammer factory, so you'll need to adapt all your other tooling to interoperate. Most of us can get by with lesser hammer factories, even k3s is less management. If you just need to deploy some containers, think hard if you want to buy the whole tool factory or just a hammer.
- nvarsj 5y agoThis kind of comment is on every single HN post about Kubernetes and is tiresome. I also think it's off topic (TFA is about kubectl tricks, not about the merits of K8s).
- busterarm 5y agoI think it's important to have comments like those as Google, who does not use Kubernetes, is exerting a lot of pressure on the industry to adopt it. It is an extremely complicated tool to learn to use well and companies act like there aren't reasonable alternatives. Those of us who have gone through it are often coming back with war stories saying to use something else. Some of us have invested thousands of man hours into this already and have strong opinions. At the very least, give Nomad a look. It is maybe a tenth of the effort to run for exactly the features most people want and then some. People need to be made aware that there are options. I have friends at companies that have large teams just dedicated to managing Kubernetes and they still deal with failure frequently or they spend their entire day-to-day tuning etcd.
- dmitriid 5y agoAll that is good and dandy until you run a command and it spews a serialised Go struct instead of a proper error. And, of course, that struct has zero relationship to what the actual error is. Example: The Job "export-by-user" is invalid: spec.template: Invalid value: core.PodTemplateSpec{ObjectMeta:v1.ObjectMeta{Name:"", GenerateName:"", Namespace:"", SelfLink:"", UID:"", ResourceVersion:"", Generation:0, CreationTimestamp:v1.Time{Time:time.Time{wall:0x0, ext:0, loc:(*time.Location)(nil)}}, DeletionTimestamp:(*v1.Time)(nil), DeletionGracePeriodSeconds:(*int64)(nil), Labels:map[string]string{"controller-uid":"416d5527-9d9b-4d3c-95d2-5d17c969be19", "job-name": "export-by-user", Annotations:map[string]string(nil), OwnerReferences:[]v1.OwnerReference(nil), Finalizers:[]string(nil), ClusterName:"", ManagedFields:[]v1.ManagedFieldsEntry(nil)}, Spec:core.PodSpec{Volumes:[]core.Volume(nil), InitContainers:[]core.Container(nil), Containers:[]core.Container{core.Container{Name:".... And it just goes on. The actual error? The job is already running and cannot be modified
- nvarsj 5y agoThat one has annoyed people for a long time. See https://github.com/kubernetes/kubernetes/issues/48388 https://github.com/kubernetes/kubernetes/issues/48388. I'm pretty sure if you have the time to make a PR to fix it, it would be welcome. But I'm guessing it's non trivial or it would have been fixed by now - probably a quirk of the code generation logic.
- smarterclayton 5y agoWow, I’d forgotten about this. The reason no one has fixed it is partially because I didn’t do a great job of describing what the fix was I expected to see (clarified now). Reopened and will poke folks to look.
- dmitriid 5y ago> I'm pretty sure if you have the time to make a PR to fix it, it would be welcome. Google had a net income of $17.9 billion in just Q1 of 2021. I believe they have the resources to fix that, and I will not be shamed into "if you have time, please open a PR towards this opensource project". > But I'm guessing it's non trivial or it would have been fixed by now - probably a quirk of the code generation logic. I remember the "quirks of generation logic" being used as an excuse for Google's horrendous Java APIs towards their cloud services. "It's just how we generate it from specs and don't have the time to make it pretty". For the life of me can't find that GitHub issue that called this out. Somehow their other APIs (for example, .net) are much better. Edit: found it https://github.com/googleapis/google-cloud-java/issues/2331#issuecomment-321847796 https://github.com/googleapis/google-cloud-java/issues/2331#... and https://github.com/googleapis/google-cloud-java/issues/2331#issuecomment-321883945 https://github.com/googleapis/google-cloud-java/issues/2331#...
- nsxwolf 5y agoI’d love to know the easiest way to answer this question: “what IP address and port is the microservice pod the CI server just deployed listening on?”
- whalesalad 5y agoWhy wouldn't that be determinstic? You should be using a service for that. kubectl get svc -l app=<your-app-name>
- lazyant 5y agoFor the port is trivial: `kubectl get pod <yourpod> --output jsonpath={.spec.ports[*].port}` or if you don't remember the json path just `k get pod <yourpod> |grep Port`. For the IP address, why do you need that? with k8s dns you can easily find anything by name.
- theden 5y agoOne useful debugging trick I use often is to edit a deployment or pod via `kubectl edit` and update the command to be `tail -f /dev/null` e.g., spec: containers: - command: - bash - -c - tail -f /dev/null (and comment out any liveness or readiness probes) Very useful to then `exec` with a shell in the pod debug things or test out different configs quickly, check the environment etc.
- mdavid626 5y agoNice trick, I usually use sleep 10000000 as the command.
- deleted 5y ago[deleted]
- icythere 5y agoOne of the issues I've often seen that my team mates send "right command" to wrong cluster and context. We have a bunch of clusters and it's always surprising to see some laptop deployments on ... production cluster. So I wrote this https://github.com/icy/gk8s#seriously-why-dont-just-use-kubectl-config https://github.com/icy/gk8s#seriously-why-dont-just-use-kube... It doesn't come with any autocompletion by default, but it's a robust way to deal with multiple clusters. Hope this helps. Edit: Fix typo err0rs
- iechoz6H 5y agoWe partially resolve this by having different namespaces in each of our environments. Nothing is ever run in the 'default' namespace. So if we think we're targeting the dev cluster and run 'kubectl -n dev-namespace delete deployment service-deployment' but our current context is actually pointing to prod then we trigger an error as there is no 'dev-namespace' in prod. Obviously we can associate specific namespaces to contexts to traverse this safety net but it can help in some situations.
- lazyant 5y agoI like the spirit of this but for dealing with multiple clusters, kubectx is pretty standard, always returns highlighting where you are and we don't have to type in the cluster name in every command. Also avoiding "kubectl delete" seems such a narrow case, I can still delete with "k scale --replicas=0" and possibly many other ways; at this point you are better of with a real RBAC implementation.
- jeffbee 5y agoisn't kubectx the problem, not the solution? You think you are in one context but you are actually in another. You wanted to tear down the dev deployments but you nuked the production ones instead.
- Osiris 5y agok9s is a fantastic tool. It's a CLI GUI written in go.
- throwaway984393 5y ago> kubectl is self-documenting, which is another reason why it's 100x better than a UI A console tool has a UI, it's the shell. And GUIs can be self-documenting too: tool tips, help bars, interactive prompts, manuals.
- vasergen 5y agoIn case you work a lot with k8s, you can take a look as well at k9s, hightly reccomend it. It can save a lot of time with typings, especially to quickly check what pods/deployments are running, execute command in pod, describe to understand why did it fail, change cluster / namespace and so on
- namelosw 5y agoI have been using kubectl + zsh for quite a while. But now my choice is Intellij (or other IDEs from JetBrains) + Lens, which I find more productive and straightforward (more GUI, fewer commands to memorize). Here's my setup and workflow: 1. For each repository, I put the Kubernetes deployment, service configurations, etc. in the same directory. I open and edit them with Intellij. 2. There's also a centralized repository for Ingress, Certificate, Helm charts, etc. I also open with Intellij. Spend some time to organize Kubernetes configs really worth it. I'm working with multiple projects and the configs gets overwhelming very quickly. 3. Set shortcuts for applying and deleting Kubernetes resources for current configs for Intellij. So I can create, edit, and delete resources in a blink. 4. There's a Kubernetes panel in Intellij for basic monitoring and operations. 5. For more information and operations, I would use Lens instead of Intellij. The operations are very straightforward, I can navigate back and forth, tweak configurations much faster than I could with the shell command only.
- vvladymyrov 5y agoOne the most useful things (for me) about kubectl - is moving to k9s cli UI for k8s. Makes daily debugging so much easier.
- bobbyi_settv 5y agoHow is this command from the page: # Lint a Helm chart # Good to put in pre-merge checks $ helm template . | kubeval - different/ better than "helm lint" (https://helm.sh/docs/helm/helm_lint/ https://helm.sh/docs/helm/helm_lint/)?
- alexhwoods 5y agoI could be wrong here, but I think `helm lint` just checks that the chart is formed correctly — Go templating and all. I don't think it validates the Kubernetes resources. Here's an example: $ helm create foo $ cd foo Then change "apiVersion" in deployment.yaml to "apiVersion: nonsense" In the linting, I got $ helm lint ==> Linting . [INFO] Chart.yaml: icon is recommended 1 chart(s) linted, 0 chart(s) failed $ helm template . | kubeval - ERR - foo/templates/deployment.yaml: Failed initializing schema https://kubernetesjsonschema.dev/master-standalone/deployment-nonsense.json https://kubernetesjsonschema.dev/master-standalone/deploymen...: Could not read schema from HTTP, response status is 404 Not Found
- nielsole 5y agoWant a crude way to see pods run on a node with the READY, STATUS and RESTARTS fields instead of the `kubectl describe node` output? kubectl get po --all-namespaces -o wide | grep $NODE_NAME Of course becomes unbearably slow, the more pods you have
- arianvanp 5y agoYou can use fieldSelector https://stackoverflow.com/questions/39231880/kubernetes-api-gets-pods-on-specific-nodes https://stackoverflow.com/questions/39231880/kubernetes-api-...
- dmitryminkovsky 5y agoNice list. Learned a couple neat things. Thank you! Would like to add that my favorite under-appreciated can't-live-without kubectl tool is `kubectl port-forward`. So nice being able to easily open a port on localhost to any port in any container without manipulating ingress and potentially compromising security.
- ithkuil 5y agoNot only containers, it can also forward services!
- deleted 5y ago[deleted]
- adolph 5y agoSomething this guide misses that is helpful about explain is that it can explain down to primaries types. “K explain po” is great, but “k explain po.spec” will give more details about the spec and its fields. This dot field pattern can go as deep as needed, like pod.spec.volumes.secret.items
- hongsy 5y agoomg TIL `k explain foo` and `k explain foo.spec` is a thing. thank you for this!!!
- adolph 5y agoI'm new to k8s and have found it useful. Hope it helps you too.
- KabirKwatra 5y agoWait What
- adolph 5y ago$ k explain -h List the fields for supported resources This command describes the fields associated with each supported API resource. Fields are identified via a simple JSONPath identifier: <type>.<fieldName>[.<fieldName>] Add the --recursive flag to display all of the fields at once without descriptions. Information about each field is retrieved from the server in OpenAPI format. Use "kubectl api-resources" for a complete list of supported resources. Examples: # Get the documentation of the resource and its fields kubectl explain pods # Get the documentation of a specific field of a resource kubectl explain pods.spec.containers Options: --api-version='': Get different explanations for particular API version (API group/version) --recursive=false: Print the fields of fields (Currently only 1 level deep) Usage: kubectl explain RESOURCE [options] Use "kubectl options" for a list of global command-line options (applies to all commands). $
- _el 5y agoThis is a really great article, thanks for sharing!
- toniaanderson 5y agoI'm Tonia Anderson by name, I am from the States, Suffolk county to be precise. I am here today to testify of the good works LORD ZAKUZA has done in my life, I never knew great men still exist until I found him. I have been suffering from heart break for the past 3 years, my partner who I invested on cheated on me with my best friend on my matrimonial bed, I was yet to recover from this terrible shock and needed help to make him stop cheating. A friend of mine directed me to this spell caster called Lord Zakuza. I doubted him at first but as things went further, I had to give him my trust and I did exactly what he told me to do. Ever since then, I have been happy all my life and my love life with my partner has been so wonderful and all this happened within 48 hours of contacting Lord Zakuza.. You can also need his help for anything and here's his contact information's. Email: lordzakuza7 @ gmail. com and Website: lordzakuzaspells.com or Call/text/WhatsApp +1 (740) 573-9483.