Free, hands-on prep for #CKAD, #CKA and #CKS:
• 140 YAML walkthroughs
• 280 kubectl + manifest questions
• A review queue for what you get wrong
• No sign-up, installs as an app
learn-kubernetes.adegoodyer.com
#Kubernetes #K8s #DevOps #CloudNative #CNCF
Free, hands-on prep for #CKAD, #CKA and #CKS:
• 140 YAML walkthroughs
• 280 kubectl + manifest questions
• A review queue for what you get wrong
• No sign-up, installs as an app
learn-kubernetes.adegoodyer.com
#Kubernetes #K8s #DevOps #CloudNative #CNCF
kubectl get secret <release-secret> -o jsonpath='{.data.release}' | base64 -d | base64 -d | gunzip | jq .info.description
kubectl get secret <release-secret> -o jsonpath='{.data.release}' | base64 -d | base64 -d | gunzip | jq .info.description
kubectl get secrets -A -l owner=helm -o custom-columns=NS:.metadata.namespace,REL:.metadata.labels.name,ST:.metadata.labels.status | grep -E 'pend|fail'
kubectl get secrets -A -l owner=helm -o custom-columns=NS:.metadata.namespace,REL:.metadata.labels.name,ST:.metadata.labels.status | grep -E 'pend|fail'
➤ https://ku.bz/DKVVbR-vB
➤ https://ku.bz/DKVVbR-vB
📊 6.5/10
🏢 Kubernetes
📝 A path traversal vulnerability was discovered in the Kubernetes kubectl client's kubectl cp command on Windows. When copying files from a container, ku...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88223
#cybersecurity #infosec #cve #euvd
📊 6.5/10
🏢 Kubernetes
📝 A path traversal vulnerability was discovered in the Kubernetes kubectl client's kubectl cp command on Windows. When copying files from a container, ku...
🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88223
#cybersecurity #infosec #cve #euvd
kubectl get pods -A --field-selector status.phase=Pending -o wide | grep ContainerCreating
One node = that node's CNI pod or containerd. One AZ = that subnet is out of IPs. Every node = cluster-wide CNI config, expired credential, or unreachable registry.
kubectl get pods -A --field-selector status.phase=Pending -o wide | grep ContainerCreating
One node = that node's CNI pod or containerd. One AZ = that subnet is out of IPs. Every node = cluster-wide CNI config, expired credential, or unreachable registry.
kubectl describe pod api-x2kq -n prod | grep -A3 FailedCreatePodSandBox
One rule: "failed to setup network for sandbox" = CNI ADD failure, the plugin type in the message names the culprit. Anything else = runtime failed before CNI was called.
kubectl describe pod api-x2kq -n prod | grep -A3 FailedCreatePodSandBox
One rule: "failed to setup network for sandbox" = CNI ADD failure, the plugin type in the message names the culprit. Anything else = runtime failed before CNI was called.
Using kubectl tends to become repetitive including getting pods, copying the pod name, describe the pod, pulling the logs and rinse and repeat. K9s helps to put all that in a live terminal view, where :po lists pods, l shows logs, s puts you in a shell,
Using kubectl tends to become repetitive including getting pods, copying the pod name, describe the pod, pulling the logs and rinse and repeat. K9s helps to put all that in a live terminal view, where :po lists pods, l shows logs, s puts you in a shell,
#Kubernetes #K9s #kubectl
I have spent years looking at Kubernetes clusters with kubectl, and I know the common resource types and flags by heart. This works really good for me, but it can take a long time to get there, and for many a higher level view of what is running
#Kubernetes #K9s #kubectl
I have spent years looking at Kubernetes clusters with kubectl, and I know the common resource types and flags by heart. This works really good for me, but it can take a long time to get there, and for many a higher level view of what is running
kubectl get certificate,order,challenge -n shop -o wide
"wrong status code '404'" = an Ingress rule shadows the acme-challenge path. Fix in Git, not a retry.
kubectl get certificate,order,challenge -n shop -o wide
"wrong status code '404'" = an Ingress rule shadows the acme-challenge path. Fix in Git, not a retry.
➤ https://ku.bz/69kPj1b9R
➤ https://ku.bz/69kPj1b9R
kubectl -n agents patch configmap agent-controls --type merge -p '{"data":{"mode":"readonly"}}'
On-call memorises ONE command. Prefer readonly over paused: keep reading logs, stop writes.
kubectl -n agents patch configmap agent-controls --type merge -p '{"data":{"mode":"readonly"}}'
On-call memorises ONE command. Prefer readonly over paused: keep reading logs, stop writes.
% type k
k is an alias for #kubectl
% k create namespace burak
% k get all -n burak
No resources found in burak namespace.
% k config set-context --current --namespace=burak
% k run test --restart=Never --image=hello-world -it
% k get all
NAME READY STATUS RESTARTS AGE […]
% type k
k is an alias for #kubectl
% k create namespace burak
% k get all -n burak
No resources found in burak namespace.
% k config set-context --current --namespace=burak
% k run test --restart=Never --image=hello-world -it
% k get all
NAME READY STATUS RESTARTS AGE […]