kubectl cheat sheet with Helm commands

The kubectl and Helm commands most people look up, grouped by task. Search or filter, then copy the command and replace the placeholders. Nothing on this page connects to a cluster.

By , Founder at SeaGit

101 of 101 commands shown.

Context and config

  • kubectl config get-contexts

    List the contexts in your kubeconfig.

  • kubectl config current-context

    Show the context kubectl is using now.

  • kubectl config use-context <context>

    Switch to another cluster or user.

  • kubectl config set-context --current --namespace=<namespace>

    Set the default namespace for the current context.

  • kubectl config view --minify

    Show only the settings for the current context.

  • kubectl cluster-info

    Show the control plane and core service endpoints.

  • kubectl version

    Show the client and server versions. Use --client to skip the server.

  • kubectl api-resources

    List resource kinds, short names and API groups the cluster serves.

  • kubectl explain deployment.spec.strategy

    Show the documentation for a field, straight from the API schema.

  • kubectl auth can-i create deployments -n <namespace>

    Check whether you have a permission. Add --list to show all of them.

  • source <(kubectl completion zsh)

    Turn on shell completion for zsh. Use bash or fish for other shells.

Get and describe

  • kubectl get pods -n <namespace>

    List pods in a namespace.

  • kubectl get pods -A

    List pods in every namespace. -A is short for --all-namespaces.

  • kubectl get pods -o wide

    Add node name, pod IP and other columns.

  • kubectl get pod <pod> -o yaml

    Print the full object, including status.

  • kubectl get pods -l app=<label>

    Filter by label selector.

  • kubectl get pods --field-selector status.phase=Running

    Filter by a field instead of a label.

  • kubectl get pods -w

    Watch for changes and print each one.

  • kubectl get deploy,svc,ingress -n <namespace>

    List several resource kinds at once.

  • kubectl get all -n <namespace>

    List pods, Services, Deployments and ReplicaSets. Ingress and ConfigMaps are not included.

  • kubectl get pods --sort-by='.status.containerStatuses[0].restartCount'

    Sort pods by restart count to find the one crashing.

  • kubectl get pods -o jsonpath='{.items[*].metadata.name}'

    Print one field for each item, for use in scripts.

  • kubectl get events -n <namespace> --sort-by=.lastTimestamp

    Show recent events, oldest first, so the latest is at the bottom.

  • kubectl describe pod <pod>

    Show conditions, mounted volumes and the events for one object.

  • kubectl get endpointslices -l kubernetes.io/service-name=<service>

    Check which pod IPs a Service sends traffic to.

  • kubectl diff -f manifest.yaml

    Show what an apply would change, without changing anything.

Logs, exec and port-forward

  • kubectl logs <pod>

    Print the logs of a pod.

  • kubectl logs <pod> -c <container>

    Choose a container in a multi-container pod.

  • kubectl logs <pod> --previous

    Print logs from the last container that crashed.

  • kubectl logs -f deploy/<deployment>

    Follow the logs of one pod from a Deployment.

  • kubectl logs -l app=<label> --all-containers --prefix

    Logs from all matching pods, with the pod name on each line.

  • kubectl logs <pod> --since=1h

    Only logs from the last hour.

  • kubectl exec -it <pod> -- sh

    Open a shell in a running container. Use bash if the image has it.

  • kubectl exec <pod> -- env

    Run one command and print its output.

  • kubectl port-forward svc/<service> 8080:80

    Reach a Service from your laptop on localhost:8080.

  • kubectl port-forward pod/<pod> 8080:8080

    Forward one pod port to your machine.

  • kubectl cp <namespace>/<pod>:/path/file ./file

    Copy a file out of a container.

Apply and rollout

  • kubectl apply -f manifest.yaml

    Create or update objects from a file. Re-running it is safe.

  • kubectl apply -f ./manifests/

    Apply every YAML file in a directory.

  • kubectl apply -k ./overlays/prod

    Apply a kustomization directory.

  • kubectl apply --server-side -f manifest.yaml

    Apply with server-side apply, which tracks field ownership.

  • kubectl delete -f manifest.yaml

    Delete the objects defined in a file.

  • kubectl set image deployment/<deployment> <container>=<image>:<tag>

    Change the image of one container and start a rolling update.

  • kubectl rollout status deployment/<deployment>

    Wait for a rollout to finish and report its progress.

  • kubectl rollout history deployment/<deployment>

    List the revisions a Deployment kept.

  • kubectl rollout undo deployment/<deployment> --to-revision=<n>

    Roll back to a revision. Leave out --to-revision for the previous one.

  • kubectl rollout restart deployment/<deployment>

    Recreate the pods with a rolling restart, for example to reload a Secret.

  • kubectl rollout pause deployment/<deployment>

    Stop a rollout partway, then resume it with rollout resume.

  • kubectl create deployment web --image=nginx:1.27 --dry-run=client -o yaml

    Print the manifest a command would create, without creating it.

  • kubectl wait --for=condition=Available deployment/<deployment> --timeout=120s

    Block until a condition is true or the timeout passes. Useful in CI.

  • kubectl label pod <pod> env=staging

    Add or change a label. Use env- at the end to remove it.

  • kubectl annotate deployment/<deployment> kubernetes.io/change-cause="bump image"

    Add an annotation, such as the reason shown in rollout history.

Debugging

  • kubectl get pod <pod> -o jsonpath='{.status.containerStatuses[*].lastState.terminated.reason}'

    Print why the last container instance stopped, such as OOMKilled.

  • kubectl run debug --rm -it --image=busybox:1.36 --restart=Never -- sh

    Start a throwaway pod in the namespace and delete it when you exit.

  • kubectl debug -it <pod> --image=busybox:1.36 --target=<container>

    Add a debug container to a running pod, sharing its process namespace.

  • kubectl debug node/<node> -it --image=busybox:1.36

    Open a debug pod on a node.

  • kubectl get pods -v=6

    Show the HTTP requests kubectl makes. Use -v=8 for request bodies.

  • kubectl describe node <node>

    Show node conditions such as MemoryPressure and DiskPressure.

  • kubectl get pods -A -o wide --field-selector spec.nodeName=<node>

    List what runs on one node.

Scaling

  • kubectl scale deployment/<deployment> --replicas=3

    Set the number of replicas. Setting 0 stops every pod but keeps the Deployment.

  • kubectl autoscale deployment <deployment> --min=2 --max=10 --cpu-percent=70

    Create a HorizontalPodAutoscaler based on CPU. Needs metrics-server.

  • kubectl get hpa -n <namespace>

    Show targets, current replicas and the bounds of each autoscaler.

Resources and top

  • kubectl top nodes

    Show CPU and memory use per node. Needs metrics-server.

  • kubectl top pods -n <namespace> --sort-by=memory

    Show pod CPU and memory, largest first.

  • kubectl top pods --containers -n <namespace>

    Show usage for each container in each pod.

  • kubectl describe node <node> | grep -A8 "Allocated resources"

    Check Allocatable and the Allocated resources table to see requests against capacity.

Secrets and ConfigMaps

  • kubectl create configmap app-config --from-file=config.yaml

    Create a ConfigMap from a file.

  • kubectl create configmap app-config --from-literal=LOG_LEVEL=info

    Create a ConfigMap from key and value pairs.

  • kubectl create secret generic db-creds --from-literal=password='<value>'

    Create a Secret. The value lands in shell history, so prefer --from-file or --from-env-file.

  • kubectl create secret generic db-creds --from-env-file=.env

    Create a Secret with one key for each line of an env file.

  • kubectl get secret <secret> -o jsonpath='{.data.<key>}' | base64 -d

    Decode one value from a Secret. Secrets are base64, not encrypted.

  • kubectl create secret docker-registry regcred --docker-server=<server> --docker-username=<user> --docker-password=<token>

    Create a pull secret for a private registry. Reference it with imagePullSecrets.

  • kubectl get configmap <name> -n <namespace> -o yaml

    Print a ConfigMap to check its keys.

Namespaces

  • kubectl create namespace <namespace>

    Create a namespace.

  • kubectl get namespaces

    List namespaces. ns works as a short name.

  • kubectl delete namespace <namespace>

    Delete a namespace and everything in it. Check the name twice first.

Nodes, cordon and drain

  • kubectl get nodes -o wide

    List nodes with their OS, kernel and container runtime.

  • kubectl get nodes -L topology.kubernetes.io/zone

    Show one label as a column, here the availability zone.

  • kubectl cordon <node>

    Mark a node unschedulable. Existing pods keep running.

  • kubectl drain <node> --ignore-daemonsets --delete-emptydir-data

    Cordon the node and evict its pods, so you can maintain it. Pods with emptyDir data need the flag.

  • kubectl uncordon <node>

    Make the node schedulable again after maintenance.

  • kubectl taint nodes <node> dedicated=batch:NoSchedule

    Keep ordinary pods off a node. Add a trailing - to remove the taint.

Helm

  • helm repo add <name> <url>

    Add a chart repository.

  • helm repo update

    Refresh the index of every repository you added.

  • helm search repo <keyword>

    Search the charts in the repositories you added.

  • helm show values <repo>/<chart>

    Print a chart default values.yaml, so you know what you can override.

  • helm install <release> <repo>/<chart> -n <namespace> --create-namespace -f values.yaml

    Install a chart as a named release. Fails if the release already exists.

  • helm upgrade --install <release> <chart> -n <namespace> -f values.yaml

    Install the release, or upgrade it if it exists. Use this in CI.

  • helm upgrade <release> <chart> --set image.tag=<tag> --reuse-values

    Change one value and keep the rest of the release values.

  • helm list -A

    List releases in every namespace.

  • helm status <release> -n <namespace>

    Show the state of a release and its notes.

  • helm history <release> -n <namespace>

    List the revisions of a release and why each changed.

  • helm get values <release> -n <namespace>

    Print the values the release was installed with. Add --all for computed values.

  • helm get manifest <release> -n <namespace>

    Print the Kubernetes objects Helm rendered for the release.

  • helm rollback <release> <revision> -n <namespace>

    Return the release to an earlier revision. Omit the revision for the previous one.

  • helm uninstall <release> -n <namespace>

    Remove a release and the objects it created.

  • helm template <release> <chart> -f values.yaml

    Render the chart to YAML on your machine, without a cluster.

  • helm install <release> <chart> --dry-run=server -n <namespace>

    Ask the cluster to validate the release without installing it.

  • helm lint ./chart

    Check a chart for errors and common mistakes.

  • helm dependency update ./chart

    Download the subcharts listed in Chart.yaml into charts/.

  • helm pull <repo>/<chart> --untar

    Download a chart and unpack it to read or edit it.

How to read these commands

Almost every kubectl command has the same shape: a verb, a resource type, a name, and flags. kubectl get pods -n shop reads as get the pods in the shop namespace. A placeholder in angle brackets, such as <deployment>, is a value you supply. Resource types accept short names, so deploy, svc and ns work anywhere the full name does.

Use -n <namespace> to choose a namespace for one command, or set a default for your context. Use -A to look across every namespace. Add -o wide for more columns, or -o yaml to see the full object.

kubectl config set-context --current --namespace=shop
kubectl get deployments
kubectl rollout status deployment/web

Commands that change things

Read commands are safe to repeat. Some commands change or remove running workloads, so check the target before you press Enter:

  • kubectl delete namespace removes everything in the namespace, including its Secrets and volume claims.
  • kubectl scale --replicas=0 stops every pod of a Deployment. The Deployment and its Service stay.
  • kubectl drain evicts the pods on a node. Confirm the replicas and disruption budgets first.
  • kubectl rollout undo returns to an earlier ReplicaSet. Check the revision with rollout history before you use it.

For a change you want to review, print it first with kubectl diff -f or create the object with --dry-run=client -o yaml, then apply the reviewed file.

Helm alongside kubectl

Helm adds a release layer on top of the objects kubectl manages. A release has a name, a chart version and a revision history, which is why helm rollback works on a whole application at once. Use helm upgrade --install in CI so the same command installs the first time and upgrades afterwards. Use helm template to see the rendered YAML before it reaches a cluster.

Helm 3 and Helm 4 share these commands. The Helm reference lists the flags for each version. Check the Helm upgrade guide for how a failed upgrade is handled.

Frequently asked questions

Which kubectl version do these commands target?

The commands use flags that appear in the kubectl quick reference for Kubernetes v1.37, and they work on current clusters back to the older releases that still receive support. A flag can be added or removed between releases, so run kubectl explain or kubectl <command> --help on your version when a command fails.

What is the difference between kubectl apply and kubectl create?

kubectl create makes an object and fails if it already exists. kubectl apply compares the file with the last applied state and changes only what differs, so you can run it again safely. Use apply for manifests kept in Git, and use create for one-off objects.

Why do secret commands use --from-file instead of --from-literal?

A value passed on the command line is saved in your shell history and can show up in process listings. --from-file and --from-env-file read the value from a file you control. Secrets are base64 encoded, not encrypted, so restrict who can read them with RBAC.

Is it safe to run kubectl drain on a production node?

It is safe when the workloads on the node have enough replicas and PodDisruptionBudgets, because the drain waits for pods to move. Check kubectl get pods -o wide --field-selector spec.nodeName=<node> first. A single-replica Deployment will be interrupted while its pod moves.

How do I reuse a command from this page?

Click Copy and replace each placeholder in angle brackets, such as <namespace> or <deployment>. The page does not run anything. It has no connection to your cluster, so a command that works here still needs the right context and permissions on your side.

Sources

Checked 10 October 2026.

  1. kubectl Quick Reference (Kubernetes documentation) — the flags and commands for the context, logs, rollout, drain and secret entries
  2. kubectl Overview (Kubernetes documentation) — how kubectl selects contexts, namespaces and output formats
  3. Helm command reference (helm.sh) — the install, upgrade, rollback, template and get commands in the Helm section