A battle-tested reference of high-frequency CLI commands for live incident triage, node resource debugging, JSONPath queries, and CKA time-saving shortcuts.
When a container enters CrashLoopBackOff or OOMKilled, inspect the previous execution before restarting:
# Stream previous container crash log
kubectl logs <pod-name> -c <container-name> --previous --tail=100
# View logs from all pods matching a label selector
kubectl logs -l app=payment-service --tail=50 --all-containers=true -f
# Real-time streaming with timestamps
kubectl logs <pod-name> --timestamps --tail=20 -f
Kubelet and Scheduler events provide the fastest clue for Pending pods and scheduling rejections:
# Show cluster events sorted chronologically (newest at bottom)
kubectl get events -A --sort-by=.metadata.creationTimestamp
# Filter warning events only across all namespaces
kubectl get events -A --field-selector type=Warning
# Check events for a specific target pod
kubectl get events --field-selector involvedObject.name=<pod-name>
Identify which pods are driving node memory pressure or CPU throttling:
# Node utilization sorted by CPU and Memory
kubectl top nodes
# Pod utilization sorted by Memory usage
kubectl top pods -A --sort-by='memory'
# Pod utilization sorted by CPU usage
kubectl top pods -A --sort-by='cpu'
# Inspect Node conditions (DiskPressure, MemoryPressure, PIDPressure)
kubectl describe node <node-name> | grep -A 10 "Conditions:"
When containers have no bash/sh installed, attach an ephemeral debugging container:
# Attach a busybox shell to target pod sharing network & process namespace
kubectl debug -it <target-pod> --image=busybox:1.36 --target=<container-name>
# Spin up a fast network troubleshooting utility pod
kubectl run net-tools --rm -it --image=nicolaka/netshoot -- /bin/bash
# In-pod network verification
nslookup kubernetes.default.svc.cluster.local
curl -v -m 3 http://payment-service.default:8080/healthz
Save critical exam minutes by generating valid manifests with --dry-run=client -o yaml:
# Generate Deployment manifest
kubectl create deployment web --image=nginx:1.25 --replicas=3 --dry-run=client -o yaml > deploy.yaml
# Generate ClusterIP Service exposing deployment
kubectl expose deployment web --port=80 --target-port=8080 --dry-run=client -o yaml > svc.yaml
# Generate ConfigMap from literal
kubectl create configmap app-config --from-literal=DB_HOST=postgres.db --dry-run=client -o yaml > cm.yaml
# Fast namespace deletion with zero grace period
kubectl delete pod <pod-name> --grace-period=0 --force
Explore production failure runbooks, deep-dive architectural blog posts, interactive troubleshooting games, and interview prep.