Skip to content

kubectl Basics

This guide assumes the Helm release and namespace are both named flow-like. Replace either name if your installation uses different values; chart resource names are derived from the Helm release.

Terminal window
kubectl config current-context
kubectl config get-contexts
kubectl cluster-info
kubectl get namespace flow-like

Set the namespace on the current context if you do not want to repeat -n flow-like:

Terminal window
kubectl config set-context --current --namespace=flow-like

This changes your local kubeconfig context, not the cluster resources.

Terminal window
kubectl get deployment,statefulset,job,cronjob,pod,service,pvc,hpa -n flow-like
kubectl get events -n flow-like --sort-by=.lastTimestamp

With default chart values, expect:

ResourceDefault form
APIDeployment and ClusterIP Service
Web appDeployment and ClusterIP Service
Execution managerRust Deployment and private ClusterIP Service
Queue bridgeTrusted background dispatch Deployment
Execution slotsDynamic single-use runner and gateway Pod pairs
RustFSStatefulSet, initializer Job and bucket-only gateway
RedisSingle-replica Deployment, Service named flow-like-redis-master, and optional PVC
Internal CockroachDBSingle-replica StatefulSet plus headless and public Services
Database migrationJob
CompilerDisabled unless configured
HPAsAbsent unless autoscaling is enabled

Use labels when Pod names include generated hashes:

Terminal window
kubectl get pods -n flow-like \
-l app.kubernetes.io/component=api \
-o wide

For details and recent events:

Terminal window
kubectl describe deployment flow-like-api -n flow-like
kubectl describe pod <pod-name> -n flow-like

kubectl top pods -n flow-like requires the cluster metrics API, commonly provided by Metrics Server.

Terminal window
kubectl port-forward service/flow-like-api 8083:8080 -n flow-like

In another terminal:

Terminal window
curl -fsS http://localhost:8083/health/ready
curl -fsS http://localhost:8083/api/v1/health

The command parts are:

PartMeaning
service/flow-like-apiKubernetes resource receiving the forwarded connection
first 8083Local port
second 8080Service port inside the cluster
-n flow-likeNamespace containing the Service

The port forward lasts only while the command is running.

Forward the internal CockroachDB Admin UI to localhost:

Terminal window
kubectl port-forward service/flow-like-cockroachdb-public 8084:8080 -n flow-like

Open http://localhost:8084. Keep database and metrics interfaces bound to localhost; do not publish them through an unauthenticated Ingress.

Terminal window
# Recent API logs
kubectl logs deployment/flow-like-api -n flow-like --tail=100
# Follow API logs
kubectl logs deployment/flow-like-api -n flow-like --follow
# Logs from a specific Pod and container
kubectl logs <pod-name> -c <container-name> -n flow-like
# Previous container instance after a restart
kubectl logs <pod-name> -c <container-name> -n flow-like --previous

List container names before selecting one:

Terminal window
kubectl get pod <pod-name> -n flow-like \
-o jsonpath='{.spec.containers[*].name}'
Terminal window
kubectl rollout restart deployment/flow-like-api -n flow-like
kubectl rollout status deployment/flow-like-api -n flow-like
kubectl rollout history deployment/flow-like-api -n flow-like

A rollout restart changes live cluster state and briefly replaces Pods. Check readiness and logs after it completes.

Terminal window
kubectl get pods -n flow-like
kubectl describe pod <pod-name> -n flow-like
kubectl logs <pod-name> -n flow-like --tail=200
kubectl logs <pod-name> -n flow-like --previous --tail=200
StatusFirst checks
PendingScheduling events, resource requests, PVC binding, node selectors
ImagePullBackOffImage name/tag or digest, pull policy, global.imagePullSecrets for forks and mirrors
CrashLoopBackOffCurrent and previous logs, environment references, probes
Running but not readyReadiness probe, dependencies, Service endpoints

Check which Pods back the API Service:

Terminal window
kubectl get endpointslice -n flow-like \
-l kubernetes.io/service-name=flow-like-api
Terminal window
kubectl get pods -n flow-like -l app.kubernetes.io/component=execution-sandbox -o wide
kubectl get pods -n flow-like -l app.kubernetes.io/component=execution-egress -o wide
kubectl logs deployment/flow-like-execution-manager -n flow-like --tail=100
kubectl logs deployment/flow-like-queue-bridge -n flow-like --tail=100
kubectl port-forward service/flow-like-execution-manager 9000:9000 -n flow-like

Check /ready for supervisor health and /metrics for available warm slots. The default manager can be reachable while its clean reserve is empty. Dynamic runner Pods use gVisor; the reusable executor-pool Deployment appears only in trusted_shared mode.

An arbitrary debug Pod does not acquire API or gateway access by sharing the namespace. Inspect the real caller’s labels and NetworkPolicies when testing Pod-to-Service connectivity. Do not remove restrictive runner policies to diagnose an execution that has not yet terminated.

List names and metadata:

Terminal window
kubectl get configmap,secret -n flow-like
kubectl describe secret flow-like-storage -n flow-like

kubectl describe secret shows key names and sizes without printing secret values. Avoid -o yaml, JSONPath decoding, shell tracing, or screenshots when handling production Secrets.

Check which environment sources the API Pod references without resolving their values:

Terminal window
kubectl get deployment flow-like-api -n flow-like \
-o jsonpath='{.spec.template.spec.containers[0].envFrom[*].secretRef.name}'

When api.autoscaling.enabled=false:

Terminal window
kubectl scale deployment/flow-like-api --replicas=3 -n flow-like
kubectl rollout status deployment/flow-like-api -n flow-like

Manual scale changes can be overwritten by a later Helm upgrade. Record the intended count in api.replicaCount.

When autoscaling is enabled:

Terminal window
kubectl get hpa flow-like-api -n flow-like
kubectl describe hpa flow-like-api -n flow-like

Let the HPA own the replica count and adjust the chart’s autoscaling values instead of repeatedly using kubectl scale.

Inspect the installed release:

Terminal window
helm status flow-like -n flow-like
helm get values flow-like -n flow-like
helm history flow-like -n flow-like

Apply updates through the checked-in helper, using the same ordered values files as installation:

Terminal window
cd apps/backend/kubernetes
./scripts/deploy.sh -f values-operator.yaml

The helper checks rendered values and Cilium prerequisites before updating the release. Reuse existing Secrets and preserve Redis replay claims. Drain or reconcile accepted jobs before queue protocol changes, and allow active managers to finish their shutdown period. Rebuild and push pinned manager and executor images together when their protocol changes.

A Helm rollback changes Kubernetes resources; it does not restore SQL schema, object data or lost Redis claims. Review compatibility and retained execution state before returning to an earlier revision.

TaskCommand
List workloadskubectl get deploy,sts,job,cronjob,pod -n flow-like
Recent eventskubectl get events -n flow-like --sort-by=.lastTimestamp
API logskubectl logs deploy/flow-like-api -n flow-like --tail=100
API port forwardkubectl port-forward svc/flow-like-api 8083:8080 -n flow-like
API rolloutkubectl rollout status deploy/flow-like-api -n flow-like
Describe a Podkubectl describe pod <pod-name> -n flow-like
List Service backendskubectl get endpointslice -n flow-like