kubectl Basics
kubectl basics kubectl basics is a practical kubernetes capability, not just a definition to memorize. this lesson explains the problem it solves,
Introduction
kubectl Basics is a practical Kubernetes capability, not just a definition to memorize. This lesson explains the problem it solves, why teams use it in production, how it behaves under failure, and how to practice it hands-on.
Purpose of this lesson
By the end, you should be able to decide when kubectl Basics belongs in a design, implement it with a clear manifest or command flow, and troubleshoot the most common failure modes using Kubernetes status, events, logs, metrics, and ownership relationships.
Understanding the topic
kubectl is your API client. Learn get, describe, logs, exec, apply, diff, rollout, events, and explain before adding higher-level tools.
kubectl is the fastest way to interrogate the API during development and incidents. Even in GitOps organizations, operators use kubectl to read live state, prove hypotheses, and perform controlled emergency mitigation.
- Read every object through metadata, spec, and status: who owns it, what should happen, and what the cluster reports actually happened.
- Connect YAML to the responsible component: scheduler, kubelet, controller manager, cloud controller, CSI driver, CNI, CoreDNS, admission webhook, or application runtime.
- Use it only when it improves a real operating concern such as availability, rollout safety, service discovery, isolation, security, cost, or developer workflow.
Visual explanation
Use this mental model when explaining the lesson during design reviews or incidents:
kubectl command-> kubeconfig context-> API server-> resource, subresource, or logs endpoint-> human reads status and events
Step-by-step explanation
- Identify the workload or platform problem first: availability, traffic routing, storage, configuration, identity, policy, scaling, observability, or troubleshooting.
- Write the smallest useful desired state for kubectl Basics; include labels, namespace, ownership, resource settings, and health checks where relevant.
- Apply or render the change in a safe environment, then read status and events before assuming the manifest worked.
- Break one realistic dependency such as a selector, image tag, probe, permission, quota, or endpoint and practice the recovery path.
- Promote through Git or your release process with a rollback plan, alert coverage, and a short runbook.
Informative example
Hands-on commands you should be comfortable running: After applying it, verify both desired and observed state. A production-ready workflow should include kubectl diff, apply, describe, get events, and a rollout or health check when the object supports it.
kubectl get pods -Akubectl describe pod web-abc123kubectl logs deploy/web --tail=100kubectl exec -it deploy/web -- shkubectl diff -f k8s/kubectl apply -f k8s/kubectl rollout status deploy/web
Real-world use
A rollout is failing in production. The on-call engineer uses kubectl rollout status, describe, logs --previous, and get endpointslices to discover that readiness never passes because a ConfigMap key was renamed.
Best practices
- Use explicit namespaces and contexts; production mistakes often start with the wrong kubeconfig context.
- Prefer
kubectl diffbeforeapplywhen changing shared resources. - Use
kubectl explainto confirm schema instead of guessing YAML fields.
Common mistakes
- Confusing resource exists with resource is healthy. Always inspect status, events, and downstream dependencies.
- Changing selectors, labels, or names casually; these are contracts between controllers, Services, policies, dashboards, and GitOps tools.
- Debugging from memory instead of reading the object:
kubectl describe, events, endpoints, and controller logs usually tell the story.
Debugging tips
- Start with
kubectl describeand recent events sorted by time; they often identify scheduling, image, probe, volume, or policy failures. - Compare desired state with live state using
kubectl get -o yaml,kubectl diff, and the owning controller's status. - Follow the traffic or lifecycle path one hop at a time rather than jumping straight to the node or the application code.
Optimization strategies
- Tune requests, limits, probes, and rollout settings from observed production behavior instead of copying defaults.
- Reduce blast radius with namespaces, quotas, PodDisruptionBudgets, topology spread, and progressive delivery.
- Automate validation with CI, policy checks, and GitOps drift detection so correctness is enforced before outages.
Advanced interview questions
Interview Prep
Practice concise answers, then expand each card for the explanation.
1QuestionHow should you explain <strong>kubectl Basics</strong> in a senior Kubernetes discussion?+
Answer
2QuestionWhat separates a lab answer from a production-ready answer?+
Answer
Hands-on exercise
Build a personal runbook using only read commands: get, describe, logs, events, top, explain, auth can-i, and rollout history. Know exactly which command answers which question.
# Suggested lab loop for kubectl Basicskubectl create namespace kubectl-basics-labkubectl -n kubectl-basics-lab apply -f lesson.yamlkubectl -n kubectl-basics-lab get allkubectl -n kubectl-basics-lab describe allkubectl -n kubectl-basics-lab get events --sort-by=.lastTimestamp
Summary
kubectl Basics becomes valuable when you connect the API object or command to real operational behavior. Practice the happy path, then deliberately break it so troubleshooting becomes evidence-driven rather than guesswork.