#kubectl
Learn Kubernetes is now in beta 🚀

Free, hands-on prep for #CKAD, #CKA and #CKS:
• 140 YAML walkthroughs
• 280 kubectl + manifest questions
• A review queue for what you get wrong
• No sign-up, installs as an app

learn-kubernetes.adegoodyer.com

#Kubernetes #K8s #DevOps #CloudNative #CNCF
September 29, 2026 at 11:50 AM
CRI has no file op at all, so kubectl cp is tar-over-exec by design. Two escape hatches: on the node, crictl inspect <id> gives runtimeSpec.root.path, the live rootfs you can cp from directly; in-cluster, kubectl debug --target=<ctr> shares the PID ns, so the target's fs sits at /proc/<pid>/root.
September 29, 2026 at 9:35 AM
2/ The real error is inside the record. The release field is base64 twice, then gzip. info.description is where Helm writes what actually failed:

kubectl get secret <release-secret> -o jsonpath='{.data.release}' | base64 -d | base64 -d | gunzip | jq .info.description
September 29, 2026 at 1:14 AM
1/ Find stuck releases fast. Helm 3 keeps each revision as a Secret labelled owner=helm, with the status on the label:

kubectl get secrets -A -l owner=helm -o custom-columns=NS:.metadata.namespace,REL:.metadata.labels.name,ST:.metadata.labels.status | grep -E 'pend|fail'
September 29, 2026 at 1:14 AM
Running AI agents at scale means juggling sandboxing, scheduling, secrets, and crash recovery. AX by handles all of it with declarative YAML, sub-second suspend/resume, and a kubectl-style CLI. Full specs in the next post. #DevTools
September 28, 2026 at 11:00 PM
kai, by basebandit, exposes Kubernetes operations as MCP tools for LLM clients. It uses the current kubectl context by default, so cluster access must already be configured.
September 28, 2026 at 10:59 PM
CVE-2026-19444: kubectl cp path traversal on Windows allows arbitrary file writes -
CVE-2026-19444: kubectl cp path traversal on Windows allows arbitrary file writes · Issue #141294 · kubernetes/kubernetes
CVSS Rating: CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:C/C:L/I:H/A:N - Medium (6.5) Description of vulnerability A path traversal vulnerability exists in the kubectl cp command when it is run on Windows. kube...
github.com
September 28, 2026 at 10:07 PM
krew (⭐️ 7041)

📦 Find and install kubectl plugins

#go
September 28, 2026 at 9:17 PM
kubectl-x is a kubectl plugin that runs the same read-only command against every context in your kubeconfig in parallel, and can merge the results into valid JSON or YAML

➤ https://ku.bz/DKVVbR-vB
September 28, 2026 at 6:26 PM
Please god I need a CRI API to do file transfers from please relying on tar and kubectl exec is terrible.
September 28, 2026 at 4:54 PM
CVE-2026-19444: kubectl cp path traversal on Windows allows arbitrary file writes -
CVE-2026-19444: kubectl cp path traversal on Windows allows arbitrary file writes · Issue #141294 · kubernetes/kubernetes
CVSS Rating: CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:C/C:L/I:H/A:N - Medium (6.5) Description of vulnerability A path traversal vulnerability exists in the kubectl cp command when it is run on Windows. kube...
github.com
September 28, 2026 at 3:06 PM
🚨 EUVD-2026-88223
📊 6.5/10
🏢 Kubernetes

📝 A path traversal vulnerability was discovered in the Kubernetes kubectl client's kubectl cp command on Windows. When copying files from a container, ku...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88223

#cybersecurity #infosec #cve #euvd
September 28, 2026 at 1:01 PM
CVE-2026-19444: Kubernetes disclosed a path traversal flaw in the kubectl cp command on Windows. A malicious tar binary in a container can write files to arbitrary local paths. Fixed in kubectl v1.34.12, v1.35.9, and v1.36.5. No exploitation confirmed.
CVE-2026-19444: Kubernetes disclosed a path traversal flaw in the kubectl cp command on Windows. A malicious tar binary in a container can write files to arbitrary local paths. Fixed in kubectl v1.34.
CVE-2026-19444: Kubernetes disclosed a path traversal flaw in the kubectl cp command on Windows. A malicious tar binary in a container can write files to arbitrary local paths. Fixed in kubectl v1.34.12, v1.35.9, and v1.36.5. No exploitation confirmed.
seclists.org
September 28, 2026 at 11:46 AM
kubectl get service cumulocity-ontoplb --namespace=c8yedge
September 28, 2026 at 10:33 AM
The legacy-token part is the most fixable bit. Since 1.27 the controller labels auto-generated SA token Secrets with kubernetes.io/legacy-token-last-used, and 1.29+ invalidates ones unused for a year. kubectl get secrets -A --field-selector type=kubernetes.io/service-account-token lists them.
September 28, 2026 at 9:36 AM
2/ Scope it first:
kubectl get pods -A --field-selector status.phase=Pending -o wide | grep ContainerCreating
One node = that node's CNI pod or containerd. One AZ = that subnet is out of IPs. Every node = cluster-wide CNI config, expired credential, or unreachable registry.
September 28, 2026 at 6:07 AM
1/ Read the error, not the status:
kubectl describe pod api-x2kq -n prod | grep -A3 FailedCreatePodSandBox
One rule: "failed to setup network for sandbox" = CNI ADD failure, the plugin type in the message names the culprit. Anything else = runtime failed before CNI was called.
September 28, 2026 at 6:07 AM
can work better. This is where K9s can help.

Using kubectl tends to become repetitive including getting pods, copying the pod name, describe the pod, pulling the logs and rinse and repeat. K9s helps to put all that in a live terminal view, where :po lists pods, l shows logs, s puts you in a shell,
September 28, 2026 at 5:30 AM
https://lckhd.eu/UYBeFf

#Kubernetes #K9s #kubectl

I have spent years looking at Kubernetes clusters with kubectl, and I know the common resource types and flags by heart. This works really good for me, but it can take a long time to get there, and for many a higher level view of what is running
September 28, 2026 at 5:30 AM
1/ ACME challenge failing. Certificate Ready=False, Challenge stuck pending. The reason is at the bottom of the chain:
kubectl get certificate,order,challenge -n shop -o wide
"wrong status code '404'" = an Ingress rule shadows the acme-challenge path. Fix in Git, not a retry.
September 28, 2026 at 1:17 AM
darkubectl-bin
kubectl-like access to the Hamravesh Darkube platform
aur.archlinux.org
September 27, 2026 at 8:43 PM
diffyml compares YAML files by structure instead of line by line, and knows enough about Kubernetes resources to match them up even when the order changes

➤ https://ku.bz/69kPj1b9R
September 27, 2026 at 3:16 PM
Two VPA gotchas that bit us: run it with updateMode: Off first and read the recommendation from kubectl describe vpa, since it needs ~8 days of history (24h histogram half-life) before the target settles. And never pair VPA with an HPA on the same CPU metric, they fight each other.
September 27, 2026 at 9:34 AM
Layer 1: kill switch = one ConfigMap field, 3 modes: active / readonly / paused.

kubectl -n agents patch configmap agent-controls --type merge -p '{"data":{"mode":"readonly"}}'

On-call memorises ONE command. Prefer readonly over paused: keep reading logs, stop writes.
September 27, 2026 at 1:15 AM
#k3s #kubernetes

% type k
k is an alias for #kubectl

% k create namespace burak

% k get all -n burak
No resources found in burak namespace.

% k config set-context --current --namespace=burak

% k run test --restart=Never --image=hello-world -it

% k get all
NAME READY STATUS RESTARTS AGE […]
Original post on gursoy.social
gursoy.social
September 26, 2026 at 10:33 PM