kubectl 命令速查表 - Kubernetes 常用命令大全
面向应用开发与集群运维的 kubectl 命令手册,覆盖资源查询、Pod 诊断、副本伸缩与集群上下文切换。与直接读 YAML 相比,kubectl 是观察集群状态、控制变更的一致入口,CrashLoopBackOff、Pod 卡在 Pending、滚动更新失败这类高频事故都能在命令层面快速定位。读完可独立完成"看状态 → 查事件 → 看日志 → 恢复或回滚"的完整排障闭环。
典型使用场景
面向 Kubernetes 集群的运维与交付:查看资源状态、扩缩容、滚动更新、排查 Pod 处于 Pending/CrashLoopBackOff/ImagePullBackOff 等异常,以及查看日志与事件定位根因。
查询资源 Get 5
kubectl get pods -n prodkubectl get pods -o widekubectl get pods -Akubectl get svc,ingress -n prodkubectl get events --sort-by=.lastTimestamp描述与诊断 Describe 5
kubectl describe pod <pod> -n prodkubectl logs <pod> -n prodkubectl logs <pod> --previouskubectl logs <pod> -c <container>kubectl exec -it <pod> -- sh伸缩与更新 Scale & Rollout 5
kubectl scale deploy/app --replicas=3kubectl rollout status deploy/appkubectl rollout undo deploy/appkubectl set image deploy/app c=app:1.1kubectl delete pod <pod>上下文与配置 Context 4
kubectl config get-contextskubectl config use-context <ctx>kubectl config set-context --current --namespace=prodkubectl top pod -n prod常见问题 FAQ 5
Q: 如何查看所有命名空间的 Pod?Q: kubectl apply 和 kubectl create 有什么区别?Q: 如何查看 Pod 的日志?Q: 如何进入 Pod 的容器?Q: 如何查看集群节点状态?高频补充命令(容量增强 · REQ-02) 35
kubectl cluster-infokubectl config get-contextskubectl config use-context <ctx>kubectl api-resourceskubectl explain pod.spec.containerskubectl get all -n <ns>kubectl get pods -l app=webkubectl get pods -o widekubectl get events --sort-by=.lastTimestampkubectl describe pod <pod>kubectl logs <pod> -c <container>kubectl exec -it <pod> -- bashkubectl port-forward <pod> 8080:80kubectl cp <pod>:/path ./localkubectl apply -f - <<EOFkubectl create deployment web --image=nginxkubectl scale deployment web --replicas=3kubectl rollout status deployment/webkubectl rollout undo deployment/webkubectl rollout history deployment/webkubectl set image deployment/web web=nginx:1.25kubectl delete pod <pod> --grace-period=0kubectl cordon <node>kubectl drain <node> --ignore-daemonsetskubectl uncordon <node>kubectl taint nodes <node> key=value:NoSchedulekubectl label nodes <node> disktype=ssdkubectl top nodekubectl top podkubectl get hpakubectl apply -k <dir>kubectl get secret <name> -o jsonpath={.data.token}kubectl create configmap <name> --from-file=./cfgkubectl proxykubectl auth can-i create pods调试与输出格式化(REQ-02 补充) 22
kubectl get pods --field-selector=status.phase=Runningkubectl get nodes --selector='!node-role.kubernetes.io/control-plane'kubectl get pods --show-labelskubectl get services --sort-by=.metadata.namekubectl get pods --sort-by='.status.containerStatuses[0].restartCount'kubectl get pv --sort-by=.spec.capacity.storagekubectl get nodes -o jsonpath={.items[*].status.addresses[?(@.type=="ExternalIP")].address}kubectl get secret my-secret -o go-template={{range $k,$v := .data}}{{$k}}:{{$v|base64decode}}{{end}}kubectl get pods -A -o=custom-columns='DATA:spec.containers[*].image'kubectl get node -o custom-columns='NODE_NAME:.metadata.name,STATUS:.status.conditions[?(@.type=="Ready")].status'kubectl diff -f ./my-manifest.yamlkubectl patch node k8s-node-1 -p {"spec":{"unschedulable":true}}kubectl patch deployment web --subresource=scale --type=merge -p {"spec":{"replicas":2}}kubectl replace --force -f ./pod.jsonkubectl expose deployment web --port=80 --target-port=8000kubectl logs -f -l name=myLabel --all-containerskubectl logs my-pod --previouskubectl debug my-pod -it --image=busybox:1.28kubectl debug node/my-node -it --image=busybox:1.28kubectl cluster-info dump --output-directory=/path/to/cluster-statekubectl api-resources --verbs=list,getkubectl run nginx --image=nginx --dry-run=client -o yaml > pod.yaml参数矩阵
| 参数 | 作用 | 示例 |
|---|---|---|
-n | 指定命名空间,避免操作默认空间 | kubectl -n prod get pods |
-o | 输出格式(yaml/json/wide/name) | kubectl get pod web -o yaml |
--kubeconfig | 指定集群凭证文件 | kubectl --kubeconfig ~/.kube/prod get nodes |
-f | 按 YAML 文件创建/应用/删除资源 | kubectl apply -f deploy.yaml |
--dry-run=client | 仅校验不创建,可生成清单 | kubectl run nginx --image=nginx --dry-run=client -o yaml |
-l | 按标签筛选资源 | kubectl get pods -l app=web |
--previous | 查看上一次崩溃容器的日志 | kubectl logs web --previous |
-c | 指定多容器 Pod 中的某个容器 | kubectl logs web -c app |
--watch | 持续观察资源变化 | kubectl get pods --watch |
--record | 记录变更原因到修订历史 | kubectl set image deploy/web app=new:1.1 --record |
易错点与避坑指南
现象Pod 长时间处于 Pending。
原因节点资源不足、没有匹配的节点(taint/亲和),或 PVC 无法绑定。
处置kubectl describe pod 看 Events;检查节点资源(kubectl top nodes)与 PVC 状态;放宽资源请求或污点容忍。
现象Pod 反复重启,状态 CrashLoopBackOff。
原因应用启动即崩溃(配置错误、依赖未就绪、端口被占),或探针失败。
处置kubectl logs web --previous 看上一次崩溃日志;kubectl describe pod 看 Last State 与 Events;修正启动命令或探针阈值。
现象镜像拉取失败,状态 ImagePullBackOff / ErrImagePull。
原因镜像名/标签写错、私有仓库未配置 imagePullSecret、或节点无法访问仓库。
处置核对镜像地址与 tag;为私有仓库配置 imagePullSecrets;在节点上手动 crictl pull 验证网络。
现象kubectl top 报错 metrics not available。
原因集群未安装 metrics-server,不是命令写错。
处置确认 metrics-server 已部署(kubectl get apiservice v1beta1.metrics.k8s.io);安装后再用 top。
现象误在本地把资源改到了生产集群。
原因当前 context 指向生产,操作时未确认集群。
处置任何写操作前执行 kubectl config get-contexts 与 kubectl config current-context 确认;用别名或工具防止误操作。
现象apply 之后改动未生效。
原因字段被其他控制器(如 HPA、Operator)覆盖,或字段不可变。
处置kubectl get 看实际值;对不可变字段(如 selector)需删除重建;排查是否有 controller 在管理该资源。
排障路径
1先看 Pod 状态与事件
kubectl describe pod webEvents 段通常有最直接的失败原因(FailedScheduling、BackOff、FailedMount 等)。
2读应用日志(含上一次崩溃)
kubectl logs web --previous -c appCrashLoop 时当前容器已退出,必须加 --previous 才能看到崩溃前的输出。
3确认节点资源与调度
kubectl top nodesPending 多半是 CPU/内存不足或没有可调度节点。
4查看完整修订历史以便回滚
kubectl rollout history deploy/web确认有可回滚版本后再 kubectl rollout undo deploy/web 回退。
提示
- 排障顺序:get 看状态 → describe 看事件 → logs 看应用错误,CrashLoop 加 --previous。
- 操作前先 kubectl config get-contexts 确认当前集群,避免在生产集群误操作。
- kubectl top 报错通常是没装 metrics-server,不是命令写错。
由 巧匠 维护
公开更新于 2026年9月10日,内容持续校对官方文档。