Skip to content
Kubernetes: Official Documentation

The Trove library · other

Kubernetes: Official Documentation

By Kubernetes Project

Official Kubernetes documentation covering cluster architecture, components, concepts, workloads, services, storage, configuration, security, administration, and API fundamentals.

  • 3145 pages
  • 646 chapters
  • Updated March 16, 2026

Free to add

Read a preview
Use with your AI agent

Add the book to your library, then connect Trove to the AI tool you use.

See installation options

A look inside · First page

Kubernetes Documentation

Source: https://github.com/kubernetes/website/tree/main/content/en/docs


Concepts

Concepts

<!-- overview -->

The Concepts section helps you learn about the parts of the Kubernetes system and the abstractions Kubernetes uses to represent your {{< glossary_tooltip text="cluster" term_id="cluster" length="all" >}}, and helps you obtain a deeper understanding of how Kubernetes works.

<!-- body -->

Cluster Architecture

A Kubernetes cluster consists of a control plane plus a set of worker machines, called nodes, that run containerized applications. Every cluster needs at least one worker node in order to run Pods.

The worker node(s) host the Pods that are the components of the application workload. The control plane manages the worker nodes and the Pods in the cluster. In production environments, the control plane usually runs across multiple computers and a cluster usually runs multiple nodes, providing fault-tolerance and high availability.

This document outlines the various components you need to have for a complete and working Kubernetes cluster.

{{< figure src="/images/docs/kubernetes-cluster-architecture.svg" alt="The control plane (kube-apiserver, etcd, kube-controller-manager, kube-scheduler) and several nodes. Each node is running a kubelet and kube-proxy." caption="Figure 1. Kubernetes cluster components." class="diagram-large" >}}

{{< details summary="About this architecture" >}} The diagram in Figure 1 presents an example reference architecture for a Kubernetes cluster. The actual distribution of components can vary based on specific cluster setups and requirements.

In the diagram, each node runs the kube-proxy component. You need a network proxy component on each node to ensure that the {{< glossary_tooltip text="Service" term_id="service">}} API and associated behaviors are available on your cluster network. However, some network plugins provide their own, third party implementation of proxying. When you use that kind of network plugin, the node does not need to run kube-proxy. {{< /details >}}

Control plane components

The control plane's components make global decisions about the cluster (for example, scheduling), as well as detecting and responding to cluster events (for example, starting up a new {{< glossary_tooltip text="pod" term_id="pod">}} when a Deployment's {{< glossary_tooltip text="replicas" term_id="replica" >}} field is unsatisfied).

Control plane components can be run on any machine in the cluster. However, for simplicity, setup scripts typically start all control plane components on the same machine, and do not run user containers on this machine. See Creating Highly Available clusters with kubeadm for an example control plane setup that runs across multiple machines.

kube-apiserver

{{< glossary_definition term_id="kube-apiserver" length="all" >}}

etcd

{{< glossary_definition term_id="etcd" length="all" >}}

kube-scheduler

{{< glossary_definition term_id="kube-scheduler" length="all" >}}

kube-controller-manager

{{< glossary_definition term_id="kube-controller-manager" length="all" >}}

There are many different types of controllers. Some examples of them are:

  • Node controller: Responsible for noticing and responding when nodes go down.
  • Job controller: Watches for Job objects that represent one-off tasks, then creates Pods to run those tasks to completion.
  • EndpointSlice controller: Populates EndpointSlice objects (to provide a link between Services and Pods).
  • ServiceAccount controller: Create default ServiceAccounts for new namespaces.

The above is not an exhaustive list.

Add this book to your library to keep reading.

What’s inside

01Kubernetes Documentationp. 1

03required command line arguments for this featurep. 16
04requestheader-allowed-names can be set to blank to allow any Common Namep. 16
05optional flags for this featurep. 16

07Fetch kubelet logs from a node named node-1.examplep. 84

10RuntimeClass is defined in the node.k8s.io API groupp. 132

12# This Pod needs 2 of the hardware-vendor.example/foo devicesp. 150
13and can only schedule onto a Node that's able to satisfyp. 150
14that need.p. 150
15# If the Node has more than 2 of those devices available, thep. 150

19In a namespacep. 186

21You need to change this example to match the actual runtime name, and per-Podp. 249

23Run this on the node where the Pod is scheduledp. 251
24Run this on the node where the Pod is scheduledp. 251
25Run this on the node where the Pod is scheduled.p. 251

27The per-mode level label indicates which policy level to apply for the mode.p. 307
28# MODE must be one of `enforce`, `audit`, or `warn`.p. 307
29LEVEL must be one of `privileged`, `baseline`, or `restricted`.p. 307
30Optional: per-mode version label that can be used to pin the policy to thep. 307
31version that shipped with a given Kubernetes minor version (for example v{{< skew currentVersion >}}).p. 307
32# MODE must be one of `enforce`, `audit`, or `warn`.p. 307

34This manifest mounts /data/foo on the host as /foo inside thep. 446
35single container that runs within the hostpath-example-linux Pod.p. 446
36# The mount into the container is read-only.p. 446
37This manifest mounts C:\Data\foo on the host as C:\foo, inside thep. 446
38single container that runs within the hostpath-example-windows Pod.p. 446

41wait for rollout to finishp. 477

45┌───────────── minute (0 - 59)p. 495
46│ ┌───────────── hour (0 - 23)p. 495
47│ │ ┌───────────── day of the month (1 - 31)p. 495
48│ │ │ ┌───────────── month (1 - 12)p. 495
49│ │ │ │ ┌───────────── day of the week (0 - 6) (Sunday to Saturday)p. 495
50│ │ │ │ │ OR sun, mon, tue, wed, thu, fri, satp. 495
51│ │ │ │ │p. 495
52│ │ │ │ │p. 495

56View revision historyp. 556

58List all revisions for the StatefulSetp. 556

60container restart delays will start at 10s, increasingp. 592
612x each time they are restarted, to a maximum of 100sp. 592

63The format isp. 610
64name:firstID:count of IDsp. 610
65wherep. 610
66- firstID is 65536 (the minimum value possible)p. 610
67- count of IDs is 110 * 65536p. 610

70sysctl params required by setup, params persist across rebootsp. 632

72sysctl params required by setup, params persist across rebootsp. 648

75This is a file that "kubeadm init" and "kubeadm join" generate at runtime, populatingp. 665
76the KUBELET_KUBEADM_ARGS variable dynamicallyp. 665
77This is a file that the user can use for overrides of the kubelet args as a last resort. Preferably,p. 665
78the user should use the .NodeRegistration.KubeletExtraArgs object in the configuration files instead.p. 665

82Add kubernetes-dashboard repositoryp. 694

84Check all possible clusters, as your .KUBECONFIG may have multiple contexts:p. 697
85Select name of cluster you want to interact with from above output:p. 698
86Point to the API server referring the cluster namep. 698
87Create a secret to hold a token for the default service accountp. 698
88Wait for the token controller to populate the secret with a token:p. 698
89Get the token valuep. 698

91Clone java libraryp. 699

93cat-pictures-pvc.yamlp. 705
94cat-pictures-writer-deployment.yamlp. 706
95IMPORTANT: Make sure to edit your PVC in cat-pictures-pvc.yaml before applying. You need to:p. 706
96- Set ReadWriteOncePod as the only access modep. 706

101# CAUTION: this is an example configuration.p. 735
102Do not use this for your own cluster!p. 735

104Do not run this in a session where you have set a random numberp. 740

107providers is a list of credential provider helper plugins that will be enabled by the kubelet.p. 759
108Multiple providers may match against a single image, in which case credentialsp. 759
109from all providers will be returned to the kubelet. If multiple providers are calledp. 759
110for a single image, the results are combined. If providers return overlappingp. 759

112Disable AppArmorp. 764
113Ignore an error during setting oom_score_adjp. 764
114Disable hugetlb cgroup v2 controller (because systemd does not support delegating hugetlb controller)p. 764
115Using non-fuse overlayfs is also possible for kernel >= 5.11, but requires SELinux to be disabledp. 765
116We use cgroupfs that is delegated by systemd, so we do not use SystemdCgroup driverp. 765
117(unless you run another systemd in the namespace)p. 765
118Using non-fuse overlayfs is also possible for kernel >= 5.11, but requires SELinux to be disabledp. 765
119We use cgroupfs that is delegated by systemd, so we do not use "systemd" driverp. 765

121We use cgroupfs that is delegated by systemd, so we do not use "systemd" driverp. 765

123Skip setting sysctl value "net.netfilter.nf_conntrack_max"p. 765
124Skip setting "net.netfilter.nf_conntrack_tcp_timeout_established"p. 765

127DCCP is unlikely to be needed, has had multiple seriousp. 790
128vulnerabilities, and is not well-maintained.p. 790
129SCTP is not used in most Kubernetes clusters, and has also hadp. 790

131Retrieve the latest available Kubernetes release versionp. 804
132Verify the SHA512 sump. 804
133Verify the SHA256 sump. 805
134Retrieve sigstore signature and certificatep. 805

136Run this on a control plane nodep. 805
137Run this on a control plane nodep. 805

139Run this on a control plane nodep. 807

141On your system, this configuration file could have a different namep. 808
142On your system, this configuration file could have a different namep. 808

145If you are running cluster with a replicated control plane, this commandp. 814

147example.yamlp. 817
148Will be used as the target "cluster" in the kubeconfigp. 817
149Will be used as the "server" (IP or DNS name) of this cluster in the kubeconfigp. 817

151Set certificate expiration time in daysp. 819
152Process all CSR files except those for front-proxy and etcdp. 820
153Process all etcd CSRsp. 820

155Cleanup CSR filesp. 820

157For Kubernetes control plane componentsp. 821

159Find the latest {{< skew currentVersion >}} version in the list.p. 825
160It should look like {{< skew currentVersion >}}.x-*, where x is the latest patch.p. 825
161Find the latest {{< skew currentVersion >}} version in the list.p. 825
162It should look like {{< skew currentVersion >}}.x-*, where x is the latest patch.p. 825
163Find the latest {{< skew currentVersion >}} version in the list.p. 825

167replace x in {{< skew currentVersion >}}.x-* with the latest patch versionp. 830
168replace x in {{< skew currentVersion >}}.x-* with the latest patch versionp. 830

170execute this command on a control plane nodep. 830

172execute this command on a control plane nodep. 830

175Please edit the object below. Lines beginning with a '#' will be ignored,p. 859
176and an empty file will abort the edit. If an error occurs while saving this file, it will bep. 859
177reopened with the relevant failures.p. 859

180This assumes that your Node uses "sudo" to run commandsp. 887
181as the superuserp. 887
182This again assumes that your Node uses "sudo" to run commandsp. 887

184Be sure to run these 3 commands inside the root shell that comes fromp. 888

186This assumes that your Node uses "sudo" to run commandsp. 889
187as the superuserp. 889

189Be sure to run these 3 commands inside the root shell that comes fromp. 889
190running "kubectl exec" in the previous stepp. 889
191Be sure to run these commands inside the root shell that comes fromp. 889

193This assumes that your Node uses "sudo" to run commandsp. 889

195Download the sample files into `configure-pod-container/configmap/` directoryp. 891

197Env-files contain a list of environment variables.p. 892
198These syntax rules apply:p. 892
199Each line in an env file has to be in VAR=VAL format.p. 892
200Lines beginning with # (i.e. comments) are ignored.p. 892
201Blank lines are ignored.p. 892
202There is no special handling of quotation marks (i.e. they will be part of the ConfigMap value)).p. 892
203Download the sample files into `configure-pod-container/configmap/` directoryp. 892
204The env-file `game-env-file.properties` looks like belowp. 893

211The following cluster-scoped commands are only needed once.p. 923
212Per-namespace disablep. 923

214Wait a moment for the pod to be runningp. 931
215Alternative methods:p. 931
216kubectl -n qos-example edit pod resize-demo --subresource resizep. 931

219Wait a moment for the pod to be runningp. 934
220Alternative methods:p. 934
221kubectl -n qos-example edit pod resize-demo --subresource resizep. 934

223run this inside the "shell" containerp. 947
224run this inside the "shell" containerp. 947

226Run this command on the node where the kubelet is runningp. 950
227Run these commands on the node where the kubelet is runningp. 950

229This assumes you are using filesystem-hosted static Pod configurationp. 951
230Run these commands on the node where the container is runningp. 951
231mv /etc/kubernetes/manifests/static-web.yaml /tmpp. 951

233Linuxp. 951
234macOSp. 951

236Run this inside the containerp. 986

238Run this inside the containerp. 987

242optional argument handlingp. 1012

244create a pluginp. 1013
245"install" your plugin by moving it to a directory in your $PATHp. 1013
246check that kubectl recognizes your pluginp. 1013
247test that calling your plugin via a "kubectl" command worksp. 1013
248even when additional arguments and flags are passed to yourp. 1013

250create a plugin containing an underscore in its filenamep. 1013
251move the plugin into your $PATHp. 1013
252You can now invoke your plugin via kubectl:p. 1013
253You can invoke your custom command with a dashp. 1013

266If the new Pod isn't yet healthy, rerun this command a few times.p. 1072

271Create a temporary interactive containerp. 1075
272Run these commands inside the Podp. 1075
273Note the rabbitmq-service has a DNS name, provided by Kubernetes:p. 1075
274run this check inside the Podp. 1075
275Run these commands inside the Podp. 1075
276In the next line, rabbitmq-service is the hostname where the rabbitmq-servicep. 1075
277can be reached. 5672 is the standard port for rabbitmq.p. 1075
278If you could not resolve "rabbitmq-service" in the previous step,p. 1075
279then use this command instead:p. 1075
280Now create a queue:p. 1075

283this assumes you downloaded and then edited the manifest alreadyp. 1076

285this assumes you downloaded and then edited the manifest alreadyp. 1080

287This uses the first approach (relying on $JOB_COMPLETION_INDEX)p. 1081

291Remove the Jobs you createdp. 1084

294Remove the Jobs you createdp. 1085

298last-applied-configuration valuep. 1104
299configuration file valuep. 1104
300live configurationp. 1104

302last-applied-configuration valuep. 1104
303configuration file valuep. 1104
304live configurationp. 1104

306...p. 1105
307...p. 1106
308last-applied-configurationp. 1106
309configuration filep. 1106
310live configurationp. 1106

312Create a application.properties filep. 1111
313Create a .env filep. 1112

315Create a password.txt filep. 1113

318Create a deployment.yaml filep. 1114
319Create a service.yaml filep. 1114

321Create a deployment.yaml filep. 1114
322Create a patch increase_replicas.yamlp. 1114
323Create another patch set_memory.yamlp. 1115
324Create a deployment.yaml filep. 1115
325Create a json patchp. 1115
326Create a kustomization.yamlp. 1116
327Create a deployment.yaml file (quoting the here doc delimiter)p. 1116

329Create a directory to hold the basep. 1117
330Create a base/deployment.yamlp. 1117
331Create a base/service.yaml filep. 1117

333Create a deployment.yaml filep. 1117

336Kubernetes-managed hosts file.p. 1127

339Point to the internal API server hostnamep. 1136
340Path to ServiceAccount tokenp. 1136
341Read this Pod's namespacep. 1136
342Read the ServiceAccount bearer tokenp. 1136
343Reference the internal certificate authority (CA)p. 1136

346Run this in a separate terminalp. 1144
347so that the load generation continues and you can carry on with the rest of the stepsp. 1144

354Start a new terminal, and leave this running.p. 1184

357Allocate storage and restrict accessp. 1199
358Create an encrypted device backed by the allocated storagep. 1199
359Format the swap spacep. 1199
360Activate the swap space for pagingp. 1199
361Allocate storage and restrict accessp. 1199
362Format the swap spacep. 1199

364Pick one Pod that belongs to the Deployment, and view its logsp. 1206
365You can leave the existing metadata as they are.p. 1206

367You can leave the existing metadata as they are.p. 1207
368The values you'll see won't exactly match these.p. 1208
369As the text explains, the output does NOT changep. 1208
370Trigger the rolloutp. 1208
371Wait for the rollout to completep. 1208

373this stays running in the backgroundp. 1209
374You can leave the existing metadata as they are.p. 1209
375The values you'll see won't exactly match these.p. 1209

377this stays running in the backgroundp. 1210
378You can leave the existing metadata as they are.p. 1210
379The values you'll see won't exactly match these.p. 1210

381Pick one Pod that belongs to the Deployment, and view its logsp. 1212

384Change 32373 to the port number you saw from "kubectl get service audit-pod"p. 1239

386The log path on your computer might be different from "/var/log/syslog"p. 1241

388Create a public private key pairp. 1246

390Run this in a shell on the node you want to query.p. 1251
391Run this inside the terminal from "kubectl run"p. 1251

393Run this locally on a node you choosep. 1253

395use this terminal to run commands that specify --watchp. 1255

397Do not start a new watch;p. 1255

399Run this in the dns-test container shellp. 1256
400Start a new watchp. 1256
401End this watch when you've seen that the delete is finishedp. 1256
402This should already be runningp. 1256

404End this watch when you've reached the end of the section.p. 1257
405At the start of "Scaling a StatefulSet" you'll start a new watch.p. 1258

407If you already have a watch running, you can continue using that.p. 1258
408Otherwise, start one.p. 1258
409End this watch when there are 5 healthy Pods for the StatefulSetp. 1258

411End this watch when there are only 3 Pods for the StatefulSetp. 1259

413End this watch when the rollout is completep. 1259

415The value of "partition" determines which ordinals a change applies top. 1260
416Make sure to use a number bigger than the last ordinal for thep. 1260
417StatefulSetp. 1261

419The value of "partition" should match the highest existing ordinal forp. 1261
420the StatefulSetp. 1261
421This should already be runningp. 1261

424End this watch when there are no Pods for the StatefulSetp. 1263
425Leave this watch running until the next time you start a watchp. 1263

427Leave this running until the next page sectionp. 1264

430sts is an abbreviation for statefulsetp. 1266

432Use this if you are able to apply cassandra-statefulset.yaml unmodifiedp. 1269

435clusters refers to the remote service.p. 1304

437# CAUTION: this is an example configuration.p. 1312
438Do not use this as-is for your own cluster!p. 1312

441# CAUTION: this is an example configuration.p. 1320
442Do not use this for your own cluster!p. 1320
443apiVersion: apiserver.config.k8s.io/v1p. 1320
444list of authenticators to authenticate Kubernetes users using JWT compliant tokens.p. 1320

446Kubernetes API versionp. 1326
447kind of the API objectp. 1326
448clusters refers to the remote service.p. 1326
449users refers to the API server's webhook configuration.p. 1326

451# CAUTION: this is an example configuration.p. 1332
452Check and amend this before you use it in your own cluster!p. 1332

454# DO NOT USE THE CONFIG AS IS. THIS IS AN EXAMPLE.p. 1343

457Deprecated in v1.17 in favor of apiserver.config.k8s.io/v1p. 1361
458name should be set to the DNS name of the service or the host (including port) of the URL the webhook is configured to speak to.p. 1361
459If a non-443 port is used for services, it must be included in the name when configuring 1.16+ API servers.p. 1361
460# For a webhook configured to speak to a service on the default port (443), specify the DNS name of the service:p. 1361
461- name: webhook1.ns1.svcp. 1361
462user: ...p. 1361
463# For a webhook configured to speak to a service on non-default port (e.g. 8443), specify the DNS name and port of the service in 1.16+:p. 1361
464- name: webhook1.ns1.svc:8443p. 1361
465user: ...p. 1361
466and optionally create a second stanza using only the DNS name of the service for compatibility with 1.15 API servers:p. 1361
467- name: webhook1.ns1.svcp. 1361
468user: ...p. 1361
469# For webhooks configured to speak to a URL, match the host (and port) specified in the webhook's URL. Examples:p. 1361
470A webhook with `url: https://www.example.com`:p. 1361
471- name: www.example.comp. 1361
472user: ...p. 1361
473# A webhook with `url: https://www.example.com:443`:p. 1361
474- name: www.example.com:443p. 1361
475user: ...p. 1361
476# A webhook with `url: https://www.example.com:8443`:p. 1361
477- name: www.example.com:8443p. 1361
478user: ...p. 1361
479- name: 'webhook1.ns1.svc'p. 1361
480The `name` supports using * to wildcard-match prefixing segments.p. 1361

482HELP apiserver_admission_webhook_rejection_count [ALPHA] Admission webhook rejection count, identified by name and broken out for each admission type (validating or admit) and operation. Additional labels specify an error type (calling_webhook_error or apiserver_internal_error if an error occurred; no_error otherwise) and optionally a non-zero rejection code if the webhook rejects the request with an HTTP status code (honored by the apiserver when the code is greater or equal to 400). Codes greater than 600 are truncated to 600, to keep the metrics cardinality bounded.p. 1373

485Approve all CSRs for the group "system:bootstrappers"p. 1380

487When you create the "monitoring-endpointslices" ClusterRole,p. 1394

490Can set "Impersonate-Extra-scopes" header and the "Impersonate-Uid" header.p. 1418
491Can impersonate the user "[email protected]"p. 1418
492Can impersonate the groups "developers" and "admins"p. 1418
493Can impersonate the extras field "scopes" with the values "view" and "development"p. 1418

496Kubernetes API versionp. 1432
497kind of the API objectp. 1432
498clusters refers to the remote service.p. 1433
499users refers to the API Server's webhook configuration.p. 1433

501You need to run "kubectl proxy" firstp. 1722

503HELP kubernetes_healthcheck [ALPHA] This metric records the result of a single healthcheck.p. 1722
504TYPE kubernetes_healthcheck gaugep. 1723
505HELP kubernetes_healthchecks_total [ALPHA] This metric records the results of all healthcheck.p. 1723

507Replace <node-name> with the name of a node in your clusterp. 1724

509Replace <node-name> with the name of a node in your clusterp. 1725

511Replace <node-name> with the name of a node in your clusterp. 1725

513Create a service using the definition in example-service.yaml.p. 1735
514Create a replication controller using the definition in example-controller.yaml.p. 1735
515Create the objects that are defined in any .yaml, .yml, or .json file within the <directory> directory.p. 1735
516List all pods in plain-text output format.p. 1735
517List all pods in plain-text output format and include additional information (such as node name).p. 1735
518List the replication controller with the specified name in plain-text output format. Tip: You can shorten and replace the 'replicationcontroller' resource type with the alias 'rc'.p. 1735
519List all replication controllers and services together in plain-text output format.p. 1735
520List all daemon sets in plain-text output format.p. 1735
521List all pods running on node server01p. 1735
522Display the details of the node with name <node-name>.p. 1735
523Display the details of the pod with name <pod-name>.p. 1735
524Display the details of all the pods that are managed by the replication controller named <rc-name>.p. 1735
525Remember: Any pods that are created by the replication controller get prefixed with the name of the replication controller.p. 1735
526Describe all podsp. 1735
527Delete a pod using the type and name specified in the pod.yaml file.p. 1735
528Delete all the pods and services that have the label '<label-key>=<label-value>'.p. 1735
529Delete all pods, including uninitialized ones.p. 1735
530Get output from running 'date' from pod <pod-name>. By default, output is from the first container.p. 1735
531Get output from running 'date' in container <container-name> of pod <pod-name>.p. 1735
532Get an interactive TTY and run /bin/bash from pod <pod-name>. By default, output is from the first container.p. 1735
533Return a snapshot of the logs from pod <pod-name>.p. 1735
534Start streaming the logs from pod <pod-name>. This is similar to the 'tail -f' Linux command.p. 1736
535Diff resources included in "pod.json".p. 1736

537create a simple plugin in any language and name the resulting executable filep. 1736
538so that it begins with the prefix "kubectl-"p. 1736
539this plugin prints the words "hello world"p. 1736
540and move it to a location in our PATHp. 1736
541You have now created and "installed" a kubectl plugin.p. 1736
542You can begin using this plugin by invoking it from kubectl as if it were a regular commandp. 1736
543You can "uninstall" a plugin, by removing it from the folder in yourp. 1736
544$PATH where you placed itp. 1736
545this plugin makes use of the `kubectl config` command in order to outputp. 1736
546information about the current user, based on the currently selected contextp. 1736
547make the file executablep. 1736

549start the pod running nginxp. 1737
550add env to nginx-appp. 1737

552exitp. 1738

555kubectl does not support regular expressions for JSONpath outputp. 1743
556The following command does not workp. 1743

559use multiple kubeconfig files at the same time and view merged configp. 1751
560Show merged kubeconfig settings and raw certificate data and exposed secretsp. 1751
561get the password for the e2e userp. 1751
562get the certificate for the e2e userp. 1752
563configure the URL to a proxy server to use for requests made by this client in the kubeconfigp. 1752
564add a new user to your kubeconf that supports basic authp. 1752
565permanently save the namespace for all subsequent kubectl commands in that context.p. 1752
566set a context utilizing a specific username and namespace.p. 1752

568create a Job which prints "Hello World"p. 1752
569create a CronJob that prints "Hello World" every minutep. 1752
570Create multiple YAML objects from stdinp. 1752

572Get commands with basic outputp. 1753
573Describe commands with verbose outputp. 1753
574List Services Sorted by Namep. 1753
575List pods Sorted by Restart Countp. 1753
576List PersistentVolumes sorted by capacityp. 1753
577Get the version label of all pods with label app=cassandrap. 1753
578Retrieve the value of a key with dots, e.g. 'ca.crt'p. 1753
579Retrieve a base64 encoded value with dashes instead of underscores.p. 1753
580Get all worker nodes (use a selector to exclude results that have a labelp. 1753
581named 'node-role.kubernetes.io/control-plane')p. 1753
582Get all running pods in the namespacep. 1753
583Get ExternalIPs of all nodesp. 1753
584List Names of Pods that belong to Particular RCp. 1753
585"jq" command useful for transformations that are too complex for jsonpath, it can be found at https://jqlang.github.io/jq/p. 1753
586Show labels for all pods (or any other Kubernetes object that supports labelling)p. 1753
587Check which nodes are readyp. 1753
588Check which nodes are ready with custom-columnsp. 1753
589Output decoded secrets without external toolsp. 1753
590List all Secrets currently in use by a podp. 1753
591List all containerIDs of initContainer of all podsp. 1753
592Helpful when cleaning up stopped containers, while avoiding removal of initContainers.p. 1753
593List Events sorted by timestampp. 1753
594List all warning eventsp. 1753
595Compares the current state of the cluster against the state that the cluster would be in if the manifest was applied.p. 1753
596Produce a period-delimited tree of all keys returned for nodesp. 1753
597Helpful when locating a key within a complex nested JSON structurep. 1753
598Produce a period-delimited tree of all keys returned for pods, etcp. 1753
599Produce ENV for all pods, assuming you have a default container for the pods, default namespace and the `env` command is supported.p. 1753
600Helpful when running any supported command across all pods, not just `env`p. 1754

602Force replace, delete and then re-create the resource. Will cause a service outage.p. 1754
603Create a service for a replicated nginx, which serves on port 80 and connects to the containers on port 8000p. 1754

605Partially update a nodep. 1754
606Update a container's image; spec.containers[*].name is required because it's a merge keyp. 1754
607Update a container's image using a json patch with positional arraysp. 1754
608Disable a deployment livenessProbe using a json patch with positional arraysp. 1754
609Add a new element to a positional arrayp. 1754

612View existing taints on which exist on current nodes.p. 1756

614All images running in a clusterp. 1757
615All images running in namespace: default, grouped by Podp. 1757

619Install bash completion on a Mac using homebrewp. 2874
620Load the kubeadm completion code for bash into the current shellp. 2874
621Write bash completion code to a file and source it from .bash_profilep. 2874

625See the OWNERS docs at https://go.k8s.io/ownersp. 3055
626This is the localization project for Spanish.p. 3055

630These are the original gist links, linking to my gists now.p. 3093
631curl -O https://gist.githubusercontent.com/a2ikm/761c2ab02b7b3935679e55af5d81786a/raw/ab644cb92f216c019a2f032bbf25e258b01d87f9/limit.maxfiles.plistp. 3093

633reopen an issuep. 3096
634transfer issues that don't fit in k/website to another repositoryp. 3096
635change the state of rotten issuesp. 3096
636change the state of stale issuesp. 3096
637assign sig to an issuep. 3096
638add specific areap. 3096
639for beginner friendly issuesp. 3096
640issues that needs helpp. 3096
641tagging issue as support specificp. 3096
642to accept triaging for an issuep. 3096

644add English labelp. 3098
645add squash label to PR if more than one commitp. 3098

About this book

Official Kubernetes documentation covering cluster architecture, components, concepts, workloads, services, storage, configuration, security, administration, and API fundamentals.