kubectl create - Create a resource from a file or from stdin, or with a generator
kubectl create -f FILE | kubectl create TYPE NAME [flags]
Options you will use
role NAME --verb=V[,V] --resource=R[,R] [--resource-name=N]- a Role; resources are resolved to their API group (deployments -> apps), subresources as pods/log
clusterrole NAME --verb=... --resource=... | --non-resource-url=/x | --aggregation-rule=k=v- a ClusterRole
rolebinding NAME --role=R|--clusterrole=CR --user=U --group=G --serviceaccount=NS:NAME- bind in ONE namespace (even a ClusterRole)
clusterrolebinding NAME --clusterrole=CR --user|--group|--serviceaccount=...- bind everywhere
serviceaccount NAME- an identity for a workload
token SA [--duration=1h]- a short-lived, signed ServiceAccount token (TokenRequest API)
poddisruptionbudget NAME --selector=K=V --min-available=N|--max-unavailable=N- a PDB (N may be a percentage)
priorityclass NAME --value=N [--global-default] [--preemption-policy=Never]- a PriorityClass
quota NAME --hard=pods=10,requests.cpu=2- a ResourceQuota
deployment | configmap | secret | job | cronjob | service | namespace- the chapter 15 generators
Examples
$ kubectl create role pod-reader --verb=get,list,watch --resource=pods -n dev$ kubectl create rolebinding app-reads-pods --role=pod-reader --serviceaccount=dev:app -n dev$ kubectl create token app -n dev --duration=10mGotchas
- Add --dry-run=client -o yaml to any generator to get the manifest instead of creating it.
Taught in
Try kubectl create in a real terminal Free, in your browser - a real Ubuntu terminal to try it in, with missions that check your work.