Skip to content

kubectl 命令 详解

日常使用的 kubectl 命令,按任务分组:读取集群、检查工作负载、应用与回滚变更、暴露服务、管理节点、创建配置对象。每行将命令与一个贴近实际的调用示例配对。

kubectl 是你操控 Kubernetes 集群的把手。它是声明式模型:通常用 apply -f 应用清单,而不是命令式地创建对象,然后再读回结果(get、describe、logs)。下面的命令覆盖日常操作;不在默认 namespace 时,请搭配 namespace 标志(-n name)一起使用。

参考表格 · 59 条目
59 of 59 rows
集群与上下文
显示控制平面和核心服务运行在哪里。kubectl cluster-info
列出你可以在其间切换的集群和 namespace。kubectl config get-contexts
切换到另一个集群或 namespace 上下文。kubectl config use-context my-prod
设置当前上下文的默认 namespace。kubectl config set-context --current --namespace=staging
重命名 kubeconfig 中已保存的上下文。kubectl config rename-context old-name prod
列出集群支持的每一种资源类型。kubectl api-resources
打印客户端和服务端的 Kubernetes 版本。kubectl version
显示资源支持的字段,读取自 API schema。kubectl explain pod.spec.containers
检查当前用户是否可以执行某个操作。kubectl auth can-i delete pods
检查工作负载
列出 pod 及其状态;加 -o wide 可看到节点和 IP。kubectl get pods -A
一次调用列出某个 namespace 的常见资源。kubectl get all
为任意 get 命令添加节点和 IP 列。kubectl get pods -o wide
把资源打印成它背后的完整 YAML 清单。kubectl get deploy/web -o yaml
列出 deployment 以及多少副本已就绪。kubectl get deployments
列出 statefulset 及其就绪副本。kubectl get statefulsets
列出批处理 job 和定时 cronjob。kubectl get jobs,cronjobs
显示单个 pod 的事件、标签和状态。kubectl describe pod web-abc
显示节点的容量、状况和正在运行的 pod。kubectl describe node node-1
打印 pod 的 stdout;-f 跟随输出,--previous 查看上次崩溃。kubectl logs -f web-abc
在正在运行的 pod 内部执行命令。kubectl exec -it web-abc -- sh
查看 pod 或节点的实时 CPU 和内存(需要 metrics-server)。kubectl top pods
列出近期事件,例如镜像拉取失败和退避重试。kubectl get events -A --sort-by=.lastTimestamp
列出 ingress 规则及其负载均衡地址。kubectl get ingress
在本机和正在运行的 pod 之间复制文件。kubectl cp web-abc:/var/log/app.log ./app.log
阻塞等待,直到资源满足某个条件。kubectl wait --for=condition=ready pod -l app=web
从镜像启动一个一次性 pod,无需清单。kubectl run debug --rm -it --image=busybox -- sh
应用、扩缩与发布
显示 apply 将会改动什么,而不真正改动。kubectl diff -f deploy.yaml
从清单文件创建或更新资源。kubectl apply -f deploy.yaml
应用清单并删除已不在其中的对象。kubectl apply -f dir/ --prune -l app=web
在编辑器中打开线上资源,保存即应用。kubectl edit deploy/web
修改线上资源的少数字段。kubectl patch deploy/web --patch-file fix.json
把 deployment 的容器指向新镜像。kubectl set image deploy/web web=nginx:1.27
替换对象,必要时先删除再重建。kubectl replace --force -f deploy.yaml
删除清单文件中声明的资源。kubectl delete -f deploy.yaml
修改 deployment 的副本数量。kubectl scale deploy/web --replicas=4
观察 rollout 直到完成或失败。kubectl rollout status deploy/web
列出 rollout 经历过的修订版本。kubectl rollout history deploy/web
逐个重启 deployment 的所有 pod。kubectl rollout restart deploy/web
把 deployment 回滚到上一个修订版本。kubectl rollout undo deploy/web
服务与网络
列出 service 及其类型和集群 IP。kubectl get svc
显示当前支撑每个 service 的 pod IP。kubectl get endpoints web
创建一个 service 暴露一组 pod;--type=NodePort 或 LoadBalancer 可从集群外部访问。kubectl expose deploy/web --port=80
显示每个 ingress 背后的负载均衡地址(alpha)。kubectl ingress status -A
列出限制 pod 流量的网络策略。kubectl get networkpolicies
把本地端口隧道到 pod 或 service。kubectl port-forward svc/web 8080:80
节点与运维
列出集群节点及其状态。kubectl get nodes -o wide
将节点标记为不可调度(不再接收新 pod)。kubectl cordon node-1
将节点重新标记为可调度。kubectl uncordon node-1
驱逐节点上的 pod 并将其标记为不可调度。kubectl drain node-1 --ignore-daemonsets
添加或删除让 pod 远离节点的 taint。kubectl taint node node-1 key=value:NoSchedule
立即删除卡住的 pod,跳过优雅关机。kubectl delete pod web-abc --grace-period=0 --force
对象与配置
创建新的 namespace 来限定资源作用域。kubectl create namespace staging
列出 namespace 及其状态。kubectl get namespaces
把配置键或文件存储为集群对象。kubectl create configmap app --from-file=config.yaml
列出该 namespace 中的 configmap。kubectl get configmaps
把密码或证书存储为 secret。kubectl create secret generic db --from-literal=password=s3cret
列出该 namespace 中的 secret。kubectl get secrets
为资源附加或移除标签。kubectl label pod web-abc tier=backend
附加选择器无法匹配的元数据。kubectl annotate deploy/web release=july