etcdctl - etcd v3 client (etcd 3.6: talks to a live member)
etcdctl [--endpoints=URL] [--cacert=F --cert=F --key=F] command
Options you will use
snapshot save FILE- stream a consistent snapshot of the member's db to FILE
endpoint health- is the member answering (commits a proposal)
member list [-w table]- members, peer and client URLs
get KEY [--prefix] [--keys-only]- raw keys, e.g. /registry/pods/default/ (values are protobuf)
--endpoints https://127.0.0.1:2379- kubeadm etcd serves TLS on 127.0.0.1:2379 and the node IP
--cacert /etc/kubernetes/pki/etcd/ca.crt- the etcd CA (not the cluster CA)
--cert/--key /etc/kubernetes/pki/etcd/server.crt|.key- a client cert signed by the etcd CA (server, peer, healthcheck-client or apiserver-etcd-client)
--endpoints URLS- gRPC endpoints (default 127.0.0.1:2379).
--cacert FILE- Verify certificates of TLS-enabled secure servers using this CA bundle.
--cert FILE- Identify secure client using this TLS certificate file.
--key FILE- Identify secure client using this TLS key file.
-w, --write-out FORMAT- Set the output format (fields, json, protobuf, simple, table).
--dial-timeout DURATION- Dial timeout for client connections (default 2s).
--command-timeout DURATION- Timeout for short running command (excluding dial timeout) (default 5s).
Examples
$ sudo ETCDCTL_API=3 etcdctl --endpoints=https://127.0.0.1:2379 --cacert=/etc/kubernetes/pki/etcd/ca.crt --cert=/etc/kubernetes/pki/etcd/server.crt --key=/etc/kubernetes/pki/etcd/server.key snapshot save /backup/etcd.dbthe backup
Gotchas
- ETCDCTL_API=3 has been the default since etcd 3.4; setting it is harmless and still common in guides.
- etcd 3.6 removed
etcdctl snapshot statusandsnapshot restore: use etcdutl for both. - The keys are root-only (0600): run with sudo or you get "open ...server.key: permission denied".
Taught in
Try etcdctl in a real terminal Free, in your browser - a real Ubuntu terminal to try it in, with missions that check your work.