{"id":13481566,"url":"https://github.com/k0sproject/k0sctl","last_synced_at":"2026-04-13T13:04:03.738Z","repository":{"id":39708476,"uuid":"327003095","full_name":"k0sproject/k0sctl","owner":"k0sproject","description":"A bootstrapping and management tool for k0s clusters.","archived":false,"fork":false,"pushed_at":"2026-03-26T08:30:29.000Z","size":1570,"stargazers_count":549,"open_issues_count":82,"forks_count":107,"subscribers_count":8,"default_branch":"main","last_synced_at":"2026-03-27T02:58:12.540Z","etag":null,"topics":["devops-tools","k0s","kubernetes"],"latest_commit_sha":null,"homepage":"","language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"other","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/k0sproject.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":"AGENTS.md","dco":null,"cla":null}},"created_at":"2021-01-05T13:12:44.000Z","updated_at":"2026-03-24T20:59:56.000Z","dependencies_parsed_at":"2024-05-20T08:45:56.665Z","dependency_job_id":"03e3b07e-27d8-409d-893b-6f3ccefe6a63","html_url":"https://github.com/k0sproject/k0sctl","commit_stats":{"total_commits":452,"total_committers":34,"mean_commits":"13.294117647058824","dds":0.6172566371681416,"last_synced_commit":"6e58f89fe66aa65754582ed6a1cd200911885372"},"previous_names":[],"tags_count":105,"template":false,"template_full_name":null,"purl":"pkg:github/k0sproject/k0sctl","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/k0sproject%2Fk0sctl","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/k0sproject%2Fk0sctl/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/k0sproject%2Fk0sctl/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/k0sproject%2Fk0sctl/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/k0sproject","download_url":"https://codeload.github.com/k0sproject/k0sctl/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/k0sproject%2Fk0sctl/sbom","scorecard":{"id":546260,"data":{"date":"2025-08-11","repo":{"name":"github.com/k0sproject/k0sctl","commit":"bedaa91bb273fc43ffd5b3045282b0e87d8a8c8e"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":5.5,"checks":[{"name":"Code-Review","score":3,"reason":"Found 6/17 approved changesets -- score normalized to 3","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Maintained","score":10,"reason":"24 commit(s) and 5 issue activity found in the last 90 days -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Info: jobLevel 'actions' permission set to 'read': .github/workflows/codeql-analysis.yml:28","Info: jobLevel 'contents' permission set to 'read': .github/workflows/codeql-analysis.yml:29","Warn: jobLevel 'contents' permission set to 'write': .github/workflows/release.yml:13","Warn: no topLevel permission defined: .github/workflows/actionlint.yml:1","Warn: no topLevel permission defined: .github/workflows/codeql-analysis.yml:1","Info: topLevel 'contents' permission set to 'read': .github/workflows/dco.yaml:10","Warn: no topLevel permission defined: .github/workflows/go.yml:1","Warn: no topLevel permission defined: .github/workflows/golangci-lint.yml:1","Warn: no topLevel permission defined: .github/workflows/gomod-lint.yml:1","Warn: no topLevel permission defined: .github/workflows/release.yml:1","Warn: no topLevel permission defined: .github/workflows/smoke.yml:1","Warn: topLevel 'contents' permission set to 'write': .github/workflows/update-latest-release.yml:15"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"License","score":9,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Warn: project license file does not contain an FSF or OSI license."],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Pinned-Dependencies","score":0,"reason":"dependency not pinned by hash detected -- score normalized to 0","details":["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/actionlint.yml:11: update your workflow using https://app.stepsecurity.io/secureworkflow/k0sproject/k0sctl/actionlint.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/actionlint.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/k0sproject/k0sctl/actionlint.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/k0sproject/k0sctl/codeql-analysis.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/k0sproject/k0sctl/codeql-analysis.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:53: update your workflow using https://app.stepsecurity.io/secureworkflow/k0sproject/k0sctl/codeql-analysis.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:67: update your workflow using https://app.stepsecurity.io/secureworkflow/k0sproject/k0sctl/codeql-analysis.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:80: update your workflow using https://app.stepsecurity.io/secureworkflow/k0sproject/k0sctl/codeql-analysis.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/dco.yaml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/k0sproject/k0sctl/dco.yaml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/dco.yaml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/k0sproject/k0sctl/dco.yaml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/dependabot-auto-approve.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/k0sproject/k0sctl/dependabot-auto-approve.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go.yml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/k0sproject/k0sctl/go.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go.yml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/k0sproject/k0sctl/go.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/k0sproject/k0sctl/go.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/k0sproject/k0sctl/go.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/golangci-lint.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/k0sproject/k0sctl/golangci-lint.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/golangci-lint.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/k0sproject/k0sctl/golangci-lint.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/golangci-lint.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/k0sproject/k0sctl/golangci-lint.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/gomod-lint.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/k0sproject/k0sctl/gomod-lint.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/gomod-lint.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/k0sproject/k0sctl/gomod-lint.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/k0sproject/k0sctl/release.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/k0sproject/k0sctl/release.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/k0sproject/k0sctl/release.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/k0sproject/k0sctl/release.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:56: update your workflow using https://app.stepsecurity.io/secureworkflow/k0sproject/k0sctl/release.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/smoke.yml:218: update your workflow using https://app.stepsecurity.io/secureworkflow/k0sproject/k0sctl/smoke.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/smoke.yml:238: update your workflow using https://app.stepsecurity.io/secureworkflow/k0sproject/k0sctl/smoke.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/smoke.yml:271: update your workflow using https://app.stepsecurity.io/secureworkflow/k0sproject/k0sctl/smoke.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/smoke.yml:321: update your workflow using https://app.stepsecurity.io/secureworkflow/k0sproject/k0sctl/smoke.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/smoke.yml:166: update your workflow using https://app.stepsecurity.io/secureworkflow/k0sproject/k0sctl/smoke.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/smoke.yml:177: update your workflow using https://app.stepsecurity.io/secureworkflow/k0sproject/k0sctl/smoke.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/smoke.yml:197: update your workflow using https://app.stepsecurity.io/secureworkflow/k0sproject/k0sctl/smoke.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/smoke.yml:289: update your workflow using https://app.stepsecurity.io/secureworkflow/k0sproject/k0sctl/smoke.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/smoke.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/k0sproject/k0sctl/smoke.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/smoke.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/k0sproject/k0sctl/smoke.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/smoke.yml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/k0sproject/k0sctl/smoke.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/smoke.yml:105: update your workflow using https://app.stepsecurity.io/secureworkflow/k0sproject/k0sctl/smoke.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/smoke.yml:258: update your workflow using https://app.stepsecurity.io/secureworkflow/k0sproject/k0sctl/smoke.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/smoke.yml:52: update your workflow using https://app.stepsecurity.io/secureworkflow/k0sproject/k0sctl/smoke.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/smoke.yml:71: update your workflow using https://app.stepsecurity.io/secureworkflow/k0sproject/k0sctl/smoke.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/smoke.yml:122: update your workflow using https://app.stepsecurity.io/secureworkflow/k0sproject/k0sctl/smoke.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/smoke.yml:308: update your workflow using https://app.stepsecurity.io/secureworkflow/k0sproject/k0sctl/smoke.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/smoke.yml:84: update your workflow using https://app.stepsecurity.io/secureworkflow/k0sproject/k0sctl/smoke.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/smoke.yml:140: update your workflow using https://app.stepsecurity.io/secureworkflow/k0sproject/k0sctl/smoke.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/smoke.yml:155: update your workflow using https://app.stepsecurity.io/secureworkflow/k0sproject/k0sctl/smoke.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/update-latest-release.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/k0sproject/k0sctl/update-latest-release.yml/main?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/update-latest-release.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/k0sproject/k0sctl/update-latest-release.yml/main?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/update-latest-release.yml:89: update your workflow using https://app.stepsecurity.io/secureworkflow/k0sproject/k0sctl/update-latest-release.yml/main?enable=pin","Warn: containerImage not pinned by hash: Dockerfile:1","Warn: containerImage not pinned by hash: Dockerfile:27: pin your Docker image by updating docker.io/library/alpine:latest to docker.io/library/alpine:latest@sha256:4bcff63911fcb4448bd4fdacec207030997caf25e9bea4045fa6c8c44de311d1","Warn: containerImage not pinned by hash: smoke-test/Dockerfile.kalilinux:1: pin your Docker image by updating kalilinux/kali-rolling:latest to kalilinux/kali-rolling:latest@sha256:05802cc65d198460a8926e2eae95f39874e72be19b9b8752ac118a22bd8deb4b","Warn: downloadThenRun not pinned by hash: smoke-test/smoke.common.sh:34","Info:   0 out of  40 GitHub-owned GitHubAction dependencies pinned","Info:   0 out of   7 third-party GitHubAction dependencies pinned","Info:   0 out of   3 containerImage dependencies pinned","Info:   0 out of   1 downloadThenRun dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"Signed-Releases","score":0,"reason":"Project has not signed or included provenance with any releases.","details":["Warn: release artifact dev not signed: https://api.github.com/repos/k0sproject/k0sctl/releases/240175046","Warn: release artifact v0.25.1 not signed: https://api.github.com/repos/k0sproject/k0sctl/releases/223573222","Warn: release artifact v0.25.0 not signed: https://api.github.com/repos/k0sproject/k0sctl/releases/223050926","Warn: release artifact v0.24.0 not signed: https://api.github.com/repos/k0sproject/k0sctl/releases/219707859","Warn: release artifact v0.24.0-beta.1 not signed: https://api.github.com/repos/k0sproject/k0sctl/releases/218269075","Warn: release artifact dev does not have provenance: https://api.github.com/repos/k0sproject/k0sctl/releases/240175046","Warn: release artifact v0.25.1 does not have provenance: https://api.github.com/repos/k0sproject/k0sctl/releases/223573222","Warn: release artifact v0.25.0 does not have provenance: https://api.github.com/repos/k0sproject/k0sctl/releases/223050926","Warn: release artifact v0.24.0 does not have provenance: https://api.github.com/repos/k0sproject/k0sctl/releases/219707859","Warn: release artifact v0.24.0-beta.1 does not have provenance: https://api.github.com/repos/k0sproject/k0sctl/releases/218269075"],"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Branch-Protection","score":-1,"reason":"internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration","details":null,"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"Packaging","score":10,"reason":"packaging workflow detected","details":["Info: Project packages its releases by way of GitHub Actions.: .github/workflows/release.yml:9"],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Vulnerabilities","score":10,"reason":"0 existing vulnerabilities detected","details":null,"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}},{"name":"SAST","score":9,"reason":"SAST tool detected but not run on all commits","details":["Info: SAST configuration detected: CodeQL","Warn: 28 commits out of 30 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}}]},"last_synced_at":"2025-08-20T09:36:03.766Z","repository_id":39708476,"created_at":"2025-08-20T09:36:03.766Z","updated_at":"2025-08-20T09:36:03.766Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":31307462,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-04-02T12:59:32.332Z","status":"ssl_error","status_checked_at":"2026-04-02T12:54:48.875Z","response_time":89,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.5:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["devops-tools","k0s","kubernetes"],"created_at":"2024-07-31T17:00:52.864Z","updated_at":"2026-04-02T14:02:03.278Z","avatar_url":"https://github.com/k0sproject.png","language":"Go","funding_links":[],"categories":["Go","kubernetes"],"sub_categories":[],"readme":"# k0sctl\n[![FOSSA Status](https://app.fossa.com/api/projects/git%2Bgithub.com%2Fk0sproject%2Fk0sctl.svg?type=shield)](https://app.fossa.com/projects/git%2Bgithub.com%2Fk0sproject%2Fk0sctl?ref=badge_shield)\n\n\n*A command-line bootstrapping and management tool for [k0s zero friction kubernetes](https://k0sproject.io/) clusters.*\n\n- [Installation](#installation)\n- [Development status](#development-status)\n- [Usage](#usage)\n- [Configuration](#configuration-file)\n\nExample output of k0sctl deploying a k0s cluster:\n\n```text\nINFO ==\u003e Running phase: Connect to hosts\nINFO ==\u003e Running phase: Detect host operating systems\nINFO [ssh] 10.0.0.1:22: is running Ubuntu 20.10\nINFO [ssh] 10.0.0.2:22: is running Ubuntu 20.10\nINFO ==\u003e Running phase: Prepare hosts\nINFO ==\u003e Running phase: Gather host facts\nINFO [ssh] 10.0.0.1:22: discovered 10.12.18.133 as private address\nINFO ==\u003e Running phase: Validate hosts\nINFO ==\u003e Running phase: Gather k0s facts\nINFO ==\u003e Running phase: Download k0s binaries on hosts\nINFO ==\u003e Running phase: Configure k0s\nINFO ==\u003e Running phase: Initialize the k0s cluster\nINFO [ssh] 10.0.0.1:22: installing k0s controller\nINFO ==\u003e Running phase: Install workers\nINFO [ssh] 10.0.0.1:22: generating token\nINFO [ssh] 10.0.0.2:22: installing k0s worker\nINFO [ssh] 10.0.0.2:22: waiting for node to become ready\nINFO ==\u003e Running phase: Disconnect from hosts\nINFO ==\u003e Finished in 2m2s\nINFO k0s cluster version 1.22.3+k0s.0 is now installed\nINFO Tip: To access the cluster you can now fetch the admin kubeconfig using:\nINFO      k0sctl kubeconfig\n```\n\nYou can find example Terraform and [bootloose](https://github.com/k0sproject/bootloose) configurations in the [examples/](examples/) directory.\n\n## Installation\n\n### Install from the released binaries\n\nDownload the desired version for your operating system and processor architecture from the [k0sctl releases page](https://github.com/k0sproject/k0sctl/releases). Make the file executable and place it in a directory available in your `$PATH`.\n\nAs the released binaries aren't signed yet, on macOS and Windows, you must first run the executable via \"Open\" in the context menu and allow running it.\n\n### Install from the sources\n\nIf you have a working Go toolchain, you can use `go install` to install k0sctl to your `$GOPATH/bin`.\n\n```sh\ngo install github.com/k0sproject/k0sctl@latest\n```\n\n### Package managers\n\n#### [Homebrew](https://brew.sh/) (macOS, Linux)\n\n```sh\nbrew install k0sproject/tap/k0sctl\n```\n\n#### [Chocolatey](https://chocolatey.org/) (Windows)\n\nNote: The [chocolatey package](https://community.chocolatey.org/packages/k0sctl) is community maintained, any issues should be reported to the maintainer of the package.\n\n```sh\nchoco install k0sctl\n```\n\n### Container usage\n\nIt is possible to use `k0sctl` as a docker/OCI container:\n\n```sh\n# pull the image\ndocker pull ghcr.io/k0sproject/k0sctl:latest\n\n# create a backup\ndocker run -it --workdir /backup \\\n  -v ./backup:/backup \\\n  -v ./k0sctl.yaml:/etc/k0s/k0sctl.yaml \\\n  ghcr.io/k0sproject/k0sctl:latest k0sctl backup --config /etc/k0s/k0sctl.yaml\n```\n\n#### Shell auto-completions\n\n##### Bash\n\n```sh\nk0sctl completion \u003e /etc/bash_completion.d/k0sctl\n```\n\n##### Zsh\n\n```sh\nk0sctl completion \u003e /usr/local/share/zsh/site-functions/_k0sctl\n\n# For oh my zsh\nk0sctl completion \u003e $ZSH_CACHE_DIR/completions/_k0sctl\n```\n\n##### Fish\n\n```sh\nk0sctl completion \u003e ~/.config/fish/completions/k0sctl.fish\n```\n\n## Development status\n\nK0sctl is ready for use and in continuous development.\n\n### Contributing \u0026 Agent Guidelines\n\nFor repository layout, development, and testing guidelines (including notes for AI assistants), see [AGENTS.md](AGENTS.md).\n\n## Usage\n\n### `k0sctl apply`\n\nThe main function of k0sctl is the `k0sctl apply` subcommand. Provided a configuration file describing the desired cluster state, k0sctl will connect to the listed hosts, determines the current state of the hosts and configures them as needed to form a k0s cluster.\n\nThe default location for the configuration file is `k0sctl.yaml` in the current working directory. To load a configuration from a different location, use:\n\n```sh\nk0sctl apply --config path/to/k0sctl.yaml\n```\n\nIf the configuration cluster version `spec.k0s.version` is greater than the version detected on the cluster, a cluster upgrade will be performed. If the configuration lists hosts that are not part of the cluster, they will be configured to run k0s and will be joined to the cluster.\n\n### `k0sctl init`\n\nGenerate a configuration template. Use `--k0s` to include an example `spec.k0s.config` k0s configuration block. You can also supply a list of host addresses via arguments or stdin.\n\nOutput a minimal configuration template:\n\n```sh\nk0sctl init \u003e k0sctl.yaml\n```\n\nOutput an example configuration with a default k0s config:\n\n```sh\nk0sctl init --k0s \u003e k0sctl.yaml\n```\n\nCreate a configuration from a list of host addresses and pipe it to k0sctl apply:\n\n```sh\nk0sctl init 10.0.0.1 10.0.0.2 ubuntu@10.0.0.3:8022 | k0sctl apply --config -\n```\n\n### `k0sctl backup \u0026 restore`\n\nTakes a [backup](https://docs.k0sproject.io/stable/backup/) of the cluster control plane state into the current working directory.\n\nThe files are currently named with a running (unix epoch) timestamp, e.g. `k0s_backup_1623220591.tar.gz`.\n\nRestoring a backup can be done as part of the [k0sctl apply](#k0sctl-apply) command using `--restore-from k0s_backup_1623220591.tar.gz` flag.\n\nRestoring the cluster state is a full restoration of the cluster control plane state, including:\n- Etcd datastore content\n- Certificates\n- Keys\n\nIn general restore is intended to be used as a disaster recovery mechanism and thus it expects that no k0s components actually exist on the controllers.\n\nKnown limitations in the current restore process:\n- The control plane address (`externalAddress`) needs to remain the same between backup and restore. This is caused by the fact that all worker node components connect to this address and cannot currently be re-configured.\n\n### `k0sctl reset`\n\nUninstall k0s from the hosts listed in the configuration.\n\n### `k0sctl kubeconfig`\n\nConnects to the cluster and outputs a kubeconfig file that can be used with `kubectl` or `kubeadm` to manage the kubernetes cluster.\n\nExample:\n\n```sh\n$ k0sctl kubeconfig --config path/to/k0sctl.yaml \u003e k0s.config\n$ kubectl get node --kubeconfig k0s.config\nNAME      STATUS     ROLES    AGE   VERSION\nworker0   NotReady   \u003cnone\u003e   10s   v1.20.2-k0s1\n```\n\n## Configuration file\n\nThe configuration file is in YAML format and loosely resembles the syntax used in Kubernetes. YAML anchors and aliases can be used.\n\nTo generate a simple skeleton configuration file, you can use the `k0sctl init` subcommand.\n\nConfiguration example:\n\n```yaml\napiVersion: k0sctl.k0sproject.io/v1beta1\nkind: Cluster\nmetadata:\n  name: my-k0s-cluster\n  user: admin\nspec:\n  hosts:\n  - role: controller\n    installFlags:\n    - --debug\n    ssh:\n      address: 10.0.0.1\n      user: root\n      port: 22\n      keyPath: ~/.ssh/id_rsa\n  - role: worker\n    installFlags:\n    - --debug\n    ssh:\n      address: 10.0.0.2\n  k0s:\n    version: 0.10.0\n    config:\n      apiVersion: k0s.k0sproject.io/v1beta1\n      kind: ClusterConfig\n      metadata:\n        name: my-k0s-cluster\n      spec:\n        images:\n          calico:\n            cni:\n              image: calico/cni\n              version: v3.16.2\n  options:\n    wait:\n      enabled: true\n    drain:\n      enabled: true\n    evictTaint:\n      enabled: false\n      taint: k0sctl.k0sproject.io/evict=true\n      effect: NoExecute\n    concurrency:\n      limit: 30\n      uploads: 5\n```\n\n### Environment variable substitution\n\nSimple bash-like expressions are supported in the configuration for environment variable substition.\n\n- `$VAR` or `${VAR}` value of `VAR` environment variable\n- `${var:-DEFAULT_VALUE}` will use `VAR` if non-empty, otherwise `DEFAULT_VALUE`\n- `$$var` - escape, result will be `$var`.\n- And [several other expressions](https://github.com/a8m/envsubst#docs)\n\n### Configuration Header Fields\n\n###### `apiVersion` \u0026lt;string\u0026gt; (required)\n\nThe configuration file syntax version. Currently the only supported version is `k0sctl.k0sproject.io/v1beta1`.\n\n###### `kind` \u0026lt;string\u0026gt; (required)\n\nIn the future, some of the configuration APIs can support multiple types of objects. For now, the only supported kind is `Cluster`.\n\n###### `spec` \u0026lt;mapping\u0026gt; (required)\n\nThe main object definition, see [below](#spec-fields)\n\n###### `metadata` \u0026lt;mapping\u0026gt; (optional)\n\nInformation that can be used to uniquely identify the object.\n\nExample:\n\n```yaml\nmetadata:\n  name: k0s-cluster-name\n  user: kubernetes-admin\n```\n\n### Spec Fields\n\n##### `spec.hosts` \u0026lt;sequence\u0026gt; (required)\n\nA list of cluster hosts. Host requirements:\n\n* Linux nodes are supported for all roles.\n* Windows nodes can join as `worker` hosts when reachable over SSH or WinRM. This support is experimental and requires k0s version \u0026gt;= 1.34.\n* On Linux, the SSH user must either be root or have passwordless `sudo` (or `doas`) access. Windows workers must allow WinRM access for the configured user (defaults to `Administrator`).\n* The host must fulfill the k0s system requirements\n\nSee [host object documentation](#host-fields) below.\n\n##### `spec.k0s` \u0026lt;mapping\u0026gt; (optional)\n\nSettings related to the k0s cluster.\n\nSee [k0s object documentation](#k0s-fields) below.\n\n### Host Fields\n\n###### `spec.hosts[*].role` \u0026lt;string\u0026gt; (required)\n\nOne of:\n- `controller` - a controller host\n- `controller+worker` - a controller host that will also run workloads\n- `single` - a [single-node cluster](https://docs.k0sproject.io/stable/k0s-single-node/) host, the configuration can only contain one host\n- `worker` - a worker host\n\n###### `spec.hosts[*].noTaints` \u0026lt;boolean\u0026gt; (optional) (default: `false`)\n\nWhen `true` and used in conjuction with the `controller+worker` role, the default taints are disabled making regular workloads schedulable on the node. By default, k0s sets a node-role.kubernetes.io/master:NoSchedule taint on controller+worker nodes and only workloads with toleration for it will be scheduled.\n\n###### `spec.hosts[*].uploadBinary` \u0026lt;boolean\u0026gt; (optional) (default: `false`)\n\nWhen `true`, the k0s binaries for target host will be downloaded and cached on the local host and uploaded to the target.\nWhen `false`, the k0s binary downloading is performed on the target host itself\n\n###### `spec.hosts[*].useExistingK0s` \u0026lt;boolean\u0026gt; (optional) (default: `false`)\n\nWhen `true`, k0sctl reuses the k0s binary that already exists on the host. No binary downloads or uploads are performed, and upgrades for the host are skipped. This option cannot be combined with `uploadBinary`, `k0sBinaryPath`, or `k0sDownloadURL`.\n\n###### `spec.hosts[*].k0sBinaryPath` \u0026lt;string\u0026gt; (optional)\n\nA path to a file on the local host that contains a k0s binary to be uploaded to the host. Can be used to test drive a custom development build of k0s.\n\n###### `spec.hosts[*].k0sInstallPath` \u0026lt;string\u0026gt; (optional) (default: depends on OS)\n\nA path on the node where to install the k0s binary.\n\n###### `spec.hosts[*].k0sDownloadURL` \u0026lt;string\u0026gt; (optional)\n\nA URL to download the k0s binary from. The default is to download from the [k0s repository](https://github.com/k0sproject/k0s). The URL can contain '%'-prefixed tokens that will be replaced with the host's information, see [tokens](#tokens).\n\n###### `spec.hosts[*].hostname` \u0026lt;string\u0026gt; (optional)\n\nOverride host's hostname. When not set, the hostname reported by the operating system is used.\n\n###### `spec.hosts[*].dataDir` \u0026lt;string\u0026gt; (optional) (default: `/var/lib/k0s`)\n\nSet host's k0s data-dir.\n\n###### `spec.hosts[*].kubeletRootDir` \u0026lt;string\u0026gt; (optional) (default: `\"\"`)\n\nSet host's k0s kubelet-root-dir.\n\n###### `spec.hosts[*].installFlags` \u0026lt;sequence\u0026gt; (optional)\n\nExtra flags passed to the `k0s install` command on the target host. See `k0s install --help` for a list of options.\n\n###### `spec.hosts[*].environment` \u0026lt;mapping\u0026gt; (optional)\n\nList of key-value pairs to set to the target host's environment variables.\n\nExample:\n\n```yaml\nenvironment:\n  HTTP_PROXY: 10.0.0.1:443\n```\n\n###### `spec.hosts[*].files` \u0026lt;sequence\u0026gt; (optional)\n\nList of files to be uploaded to the host.\n\nExample:\n\n```yaml\n- name: image-bundle\n  src: airgap-images.tgz\n  dstDir: /var/lib/k0s/images/\n  perm: 0600\n```\n\nInline data example:\n\n```yaml\n- name: motd\n  data: |\n    Powered by k0s\n  dst: /etc/motd\n  perm: 0644\n```\n\n* `name`: name of the file \"bundle\", used only for logging purposes (optional)\n* `src`: File path, an URL or [Glob pattern](https://golang.org/pkg/path/filepath/#Match) to match files to be uploaded. URL sources will be directly downloaded using the target host. If the value is a URL, '%'-prefixed tokens can be used, see [tokens](#tokens). (required when `data` is not set)\n* `data`: Inline file data to write to the destination. Use together with `dst` or `dst` + `dstDir`. (required when `src` is not set)\n* `dstDir`: Destination directory for the file(s). `k0sctl` will create full directory structure if it does not already exist on the host (default: user home)\n* `dst`: Destination filename for the file. Only usable for single file uploads (default: basename of file)\n* `perm`: File permission mode for uploaded file(s) (default: same as local)\n* `dirPerm`: Directory permission mode for created directories (default: 0755)\n* `user`: User name of file/directory owner, must exist on the host (optional)\n* `group`: Group name of file/directory owner, must exist on the host (optional)\n\n###### `spec.hosts[*].hooks` \u0026lt;mapping\u0026gt; (optional)\n\nRun a set of commands on the remote host during k0sctl operations.\n\nExample:\n\n```yaml\nhooks:\n  connect:\n    after:\n      - echo \"connected and detected\" \u003e\u003e k0sctl-connect.log\n  upgrade:\n    before:\n      - echo \"about to upgrade\" \u003e\u003e k0sctl-upgrade.log\n    after:\n      - echo \"upgraded\" \u003e\u003e k0sctl-upgrade.log\n  apply:\n    before:\n      - date \u003e\u003e k0sctl-apply.log\n    after:\n      - echo \"apply success\" \u003e\u003e k0sctl-apply.log\n```\n\nThe currently available \"hook points\" are:\n\n* `connect`: \n    - `after`: Runs immediately after OS detection completes\n* `apply`: Runs during `k0sctl apply`\n    - `before`: Runs after configuration and host validation, right before configuring k0s on the host\n    - `after`: Runs before disconnecting from the host after a successful apply operation\n* `upgrade`: Runs during `k0sctl apply`\n    - `before`: Runs for each host that is going to be upgraded, before the upgrade begins\n    - `after`: Runs for each host that was upgraded, after the upgrade completes\n* `install`: Runs during `k0sctl apply`\n    - `before`: Runs on each host just before installing its k0s components. This includes the first controller (Initialize the k0s cluster), additional controllers, and workers.\n    - `after`: Runs on each host immediately after installing its k0s components (service started and ready checks done).\n* `backup`: Runs during `k0s backup`\n    - `before`: Runs before k0sctl runs the `k0s backup` command\n    - `after`: Runs before disconnecting from the host after successfully taking a backup\n* `reset`: Runs during `k0sctl reset` or when `k0sctl apply` resets a host.\n    - `before`: Runs after gathering information about the cluster, right before starting to remove the k0s installation.\n    - `after`: Runs before disconnecting from the host after a successful reset operation\n\nNotes:\n\n- Hooks run on each host that defines them, using the same remote user as the connection. If elevated privileges are required, prefix commands with `sudo`.\n- In dry-run mode, hooks are not executed; k0sctl prints what would run on each host.\n- Hooks execute only on hosts targeted by the related phase. For example, `upgrade` hooks run only for hosts that need upgrade.\n\n##### `spec.hosts[*].os` \u0026lt;string\u0026gt; (optional) (default: ``)\n\nOverride OS distribution auto-detection. By default `k0sctl` detects the OS by reading `/etc/os-release` or `/usr/lib/os-release` files. In case your system is based on e.g. Debian but the OS release info has something else configured you can override `k0sctl` to use Debian based functionality for the node with:\n\n```yaml\n  - role: worker\n    os: debian\n    ssh:\n      address: 10.0.0.2\n```\n\n##### `spec.hosts[*].privateInterface` \u0026lt;string\u0026gt; (optional) (default: ``)\n\nOverride private network interface selected by host fact gathering.\nUseful in case fact gathering picks the wrong private network interface.\n\n```yaml\n  - role: worker\n    os: debian\n    privateInterface: eth1\n```\n\n##### `spec.hosts[*].privateAddress` \u0026lt;string\u0026gt; (optional) (default: ``)\n\nOverride private IP address selected by host fact gathering.\nUseful in case fact gathering picks the wrong IPAddress.\n\n##### `spec.hosts[*].reset` \u0026lt;boolean\u0026gt; (optional) (default: `false`)\n\nIf set to `true` k0sctl will remove the node from kubernetes and reset k0s on the host.\n\n```yaml\n  - role: worker\n    os: debian\n    privateAddress: 10.0.0.2\n```\n\n##### `spec.hosts[*].ssh` \u0026lt;mapping\u0026gt; (optional)\n\nSSH connection options.\n\nExample:\n\n```yaml\nspec:\n  hosts:\n    - role: controller\n      ssh:\n        address: 10.0.0.2\n        user: ubuntu\n        keyPath: ~/.ssh/id_rsa\n```\n\nWindows worker nodes can also use the SSH transport when an SSH server is available on the host.\n\nIt's also possible to tunnel connections over SSH through a bastion host. The bastion configuration has all the same fields as any SSH connection:\n\n```yaml\nspec:\n  hosts:\n    - role: controller\n      ssh:\n        address: 10.0.0.2\n        user: ubuntu\n        keyPath: ~/.ssh/id_rsa\n        bastion:\n          address: 10.0.0.1\n          user: root\n          keyPath: ~/.ssh/id_rsa2\n```\n\nSSH agent and auth forwarding are also supported, a host without a keyfile:\n\n```yaml\nspec:\n  hosts:\n    - role: controller\n      ssh:\n        address: 10.0.0.2\n        user: ubuntu\n```\n\n```shell\n$ ssh-add ~/.ssh/aws.pem\n$ ssh -A user@jumphost\nuser@jumphost ~ $ k0sctl apply\n```\n\nPageant or openssh-agent can be used on Windows.\n\n###### `spec.hosts[*].ssh.address` \u0026lt;string\u0026gt; (required)\n\nIP address of the host\n\n###### `spec.hosts[*].ssh.user` \u0026lt;string\u0026gt; (optional) (default: `root`)\n\nUsername to log in as.\n\n###### `spec.hosts[*].ssh.port` \u0026lt;number\u0026gt; (required)\n\nTCP port of the SSH service on the host.\n\n###### `spec.hosts[*].ssh.keyPath` \u0026lt;string\u0026gt; (optional) (default: `~/.ssh/identity ~/.ssh/id_rsa ~/.ssh/id_dsa`)\n\nPath to an SSH key file. If a public key is used, ssh-agent is required. When left empty, the default value will first be looked for from the ssh configuration (default `~/.ssh/config`) `IdentityFile` parameter.\n\n##### `spec.hosts[*].localhost` \u0026lt;mapping\u0026gt; (optional)\n\nLocalhost connection options. Can be used to use the local host running k0sctl as a node in the cluster.\n\n###### `spec.hosts[*].localhost.enabled` \u0026lt;boolean\u0026gt; (optional) (default: `false`)\n\nThis must be set `true` to enable the localhost connection.\n\n##### `spec.hosts[*].openSSH` \u0026lt;mapping\u0026gt; (optional)\n\nAn alternative SSH client protocol that uses the system's openssh client for connections.\n\nExample:\n\n```yaml\nspec:\n  hosts:\n    - role: controller\n      openSSH:\n        address: 10.0.0.2\n```\n\nThe only required field is the `address` and it can also be a hostname that is found in the ssh config. All other options such as user, port and keypath will use the same defaults as if running `ssh` from the command-line or will use values found from the ssh config.\n\nAn example SSH config:\n\n```\nHost controller1\n  Hostname 10.0.0.1\n  Port 2222\n  IdentityFile ~/.ssh/id_cluster_esa\n```\n\nIf this is in your `~/.ssh/config`, you can simply use the host alias as the address in your k0sctl config:\n\n```yaml\nspec:\n  hosts:\n    - role: controller\n      openSSH:\n        address: controller1\n        # if the ssh configuration is in a different file, you can use:\n        # configPath: /path/to/config\n```\n\n###### `spec.hosts[*].openSSH.address` \u0026lt;string\u0026gt; (required)\n\nIP address, hostname or ssh config host alias of the host\n\n###### `spec.hosts[*].openSSH.user` \u0026lt;string\u0026gt; (optional)\n\nUsername to connect as.\n\n###### `spec.hosts[*].openSSH.port` \u0026lt;number\u0026gt; (optional)\n\nRemote port.\n\n###### `spec.hosts[*].openSSH.keyPath` \u0026lt;string\u0026gt; (optional)\n\nPath to private key.\n\n###### `spec.hosts[*].openSSH.configPath` \u0026lt;string\u0026gt; (optional)\n\nPath to ssh config, defaults to ~/.ssh/config with fallback to /etc/ssh/ssh_config.\n\n###### `spec.hosts[*].openSSH.disableMultiplexing` \u0026lt;boolean\u0026gt; (optional)\n\nThe default mode of operation is to use connection multiplexing where a ControlMaster connection is opened and the subsequent connections to the same host use the master connection over a socket to communicate to the host. \n\nIf this is disabled by setting `disableMultiplexing: true`, running every remote command will require reconnecting and reauthenticating to the host.\n\n###### `spec.hosts[*].openSSH.options` \u0026lt;mapping\u0026gt; (optional)\n\nAdditional options as key/value pairs to use when running the ssh client.\n\nExample:\n\n```yaml\nopenSSH:\n  address: host\n  options:\n      ForwardAgent: true  # -o ForwardAgent=yes\n      StrictHostkeyChecking: false # -o StrictHostkeyChecking: no\n```\n\n##### `spec.hosts[*].winrm` \u0026lt;mapping\u0026gt; (optional)\n\nWinRM connection options for Windows worker nodes. Use this transport when targeting Windows hosts that prefer WinRM instead of SSH. Windows support is limited to the `worker` role and requires k0s version \u0026gt;= 1.34.\n\nExample:\n\n```yaml\nspec:\n  hosts:\n    - role: worker\n      winrm:\n        address: win-worker-1.internal\n        user: Administrator\n        password: ${WINRM_PASSWORD}\n        useHTTPS: true\n        insecure: false\n```\n\n###### `spec.hosts[*].winrm.address` \u0026lt;string\u0026gt; (required)\n\nIP address or hostname of the host.\n\n###### `spec.hosts[*].winrm.user` \u0026lt;string\u0026gt; (optional) (default: `Administrator`)\n\nWinRM user name. The user must have administrative privileges. Windows does not provide a built-in way to elevate privileges over WinRM, so the user must already have them.\n\n###### `spec.hosts[*].winrm.port` \u0026lt;number\u0026gt; (optional) (default: `5985`)\n\nTCP port for the WinRM endpoint. When `useHTTPS` is `true`, the default port automatically switches to `5986`.\n\n###### `spec.hosts[*].winrm.password` \u0026lt;string\u0026gt; (optional)\n\nPassword for the WinRM user. Required unless certificate-based authentication is configured. Consider using environment variable substitution to avoid storing plaintext passwords in the configuration file.\n\n###### `spec.hosts[*].winrm.useHTTPS` \u0026lt;boolean\u0026gt; (optional) (default: `false`)\n\nEnable HTTPS for WinRM. When enabled, set `caCertPath` (and optionally `certPath`/`keyPath`) to verify the remote endpoint.\n\n###### `spec.hosts[*].winrm.insecure` \u0026lt;boolean\u0026gt; (optional) (default: `false`)\n\nSkip TLS certificate verification when connecting over HTTPS. Use only in trusted environments.\n\n###### `spec.hosts[*].winrm.useNTLM` \u0026lt;boolean\u0026gt; (optional) (default: `false`)\n\nUse NTLM authentication instead of basic authentication.\n\n###### `spec.hosts[*].winrm.caCertPath` \u0026lt;string\u0026gt; (optional)\n\nPath to a CA bundle used to validate the WinRM server certificate.\n\n###### `spec.hosts[*].winrm.certPath` \u0026lt;string\u0026gt; (optional)\n\nClient certificate for mutual TLS authentication.\n\n###### `spec.hosts[*].winrm.keyPath` \u0026lt;string\u0026gt; (optional)\n\nPrivate key that matches `certPath`.\n\n###### `spec.hosts[*].winrm.tlsServerName` \u0026lt;string\u0026gt; (optional)\n\nOverride the TLS server name used during certificate verification.\n\n###### `spec.hosts[*].winrm.bastion` \u0026lt;mapping\u0026gt; (optional)\n\nSSH connection details for a bastion host to reach the host. The fields match those documented under `spec.hosts[*].ssh`.\n\n### K0s Fields\n\n##### `spec.k0s.version` \u0026lt;string\u0026gt; (optional) (default: auto-discovery)\n\nThe version of k0s to deploy. When left out, k0sctl will default to using the latest released version of k0s or the version already running on the cluster.\n\n##### `spec.k0s.versionChannel` \u0026lt;string\u0026gt; (optional) (default: `stable`)\n\nPossible values are `stable` and `latest`.\n\nWhen `spec.k0s.version` is left undefined, this setting can be set to `latest` to allow k0sctl to include k0s pre-releases when looking for the latest version. The default is to only look for stable releases.\n\n##### `spec.k0s.dynamicConfig` \u0026lt;boolean\u0026gt; (optional) (default: false)\n\nEnable k0s dynamic config. The setting will be automatically set to true if:\n\n* Any controller node has `--enable-dynamic-config` in `installFlags`\n* Any existing controller node has `--enable-dynamic-config` in run arguments (`k0s status -o json`)\n\n**Note:** When running k0s in dynamic config mode, k0sctl will ONLY configure the cluster-wide configuration during the first time initialization, after that the configuration has to be managed via `k0s config edit` or `k0sctl config edit`. The node specific configuration will be updated on each apply.\n\nSee also:\n\n* [k0s Dynamic Configuration](https://docs.k0sproject.io/stable/dynamic-configuration/)\n\n##### `spec.k0s.config` \u0026lt;mapping\u0026gt; (optional) (default: auto-generated)\n\nEmbedded k0s cluster configuration. See [k0s configuration documentation](https://docs.k0sproject.io/stable/configuration/) for details.\n\nWhen left out, the output of `k0s config create` will be used.\n\nYou can also host the configuration in a separate file or as a separate YAML document in the same file in the standard k0s configuration format.\n\n```yaml\napiVersion: k0sctl.k0sproject.io/v1beta1\nkind: Cluster\nspec:\n  hosts:\n    - role: single\n      ssh:\n        address: 10.0.0.1\n---\napiVersion: k0s.k0sproject.io/v1beta1\nkind: ClusterConfig\nmetadata:\n  name: my-k0s-cluster\nspec:\n  api:\n    externalAddress: 10.0.0.2\n```\n\n### Options Fields\n\nThe `spec.options` field contains options that can be used to modify the behavior of k0sctl.\n\nExample:\n\n```yaml\nspec:\n  options:\n    wait:\n      enabled: true\n    drain:\n      enabled: true\n    evictTaint:\n      enabled: false\n      taint: k0sctl.k0sproject.io/evict=true\n      effect: NoExecute\n    concurrency:\n      limit: 30\n      workerDisruptionPercent: 10\n      uploads: 5\n```\n\n##### `spec.options.wait.enabled` \u0026lt;boolean\u0026gt; (optional) (default: true)\n\nIf set to `false`, k0sctl will not wait for k0s to become ready after restarting the service. By default, k0sctl waits for nodes to become ready before continuing to the next operation. This is functionally the same as using `--no-wait` on the command line.\n\n##### `spec.options.drain.enabled` \u0026lt;boolean\u0026gt; (optional) (default: true)\n\nIf set to `false`, k0sctl will skip draining nodes before performing disruptive operations like upgrade or reset. By default, nodes are drained to allow for graceful pod eviction. This is functionally the same as using `--no-drain` on the command line.\n\n##### `spec.options.drain.gracePeriod` \u0026lt;duration\u0026gt; (optional) (default: 2m)\n\nThe duration to wait for pods to be evicted from the node before proceeding with the operation. \n\n##### `spec.options.drain.timeout` \u0026lt;duration\u0026gt; (optional) (default: 5m)\n\nThe duration to wait for the drain operation to complete before timing out. \n\n##### `spec.options.drain.force` \u0026lt;boolean\u0026gt; (optional) (default: true)\n\nUse `--force` in kubectl when draining the node.\n\n##### `spec.options.drain.ignoreDaemonSets` \u0026lt;boolean\u0026gt; (optional) (default: true)\n\nIgnore DaemonSets when draining the node.\n\n##### `spec.options.drain.deleteEmptyDirData` \u0026lt;boolean\u0026gt; (optional) (default: true)\n\nContinue even if there are pods using emptyDir (local data that will be deleted when the node is drained).\n\n##### `spec.options.drain.skipWaitForDeleteTimeout` \u0026lt;duration\u0026gt; (optional) (default: 0s)\n\nIf pod DeletionTimestamp older than N seconds, skip waiting for the pod. Seconds must be greater than 0 to skip.\n\n##### `spec.options.drain.podSelector` \u0026lt;string\u0026gt; (optional) (default: ``)\n\nLabel selector to filter pods on the node\n\n##### `spec.options.evictTaint.enabled` \u0026lt;boolean\u0026gt; (optional) (default: false)\n\nWhen enabled, k0sctl will apply a taint to nodes before service-affecting operations such as upgrade or reset. This is used to signal workloads to be evicted in advance of node disruption. You can also use the `--evict-taint=k0sctl.k0sproject.io/evic=true:NoExecute` command line option to enable this feature.\n\n##### `spec.options.evictTaint.taint` \u0026lt;string\u0026gt; (optional) (default: `k0sctl.k0sproject.io/evict=true`)\n\nThe taint to apply when `evictTaint.enabled` is `true`. Must be in the format `key=value`.\n\n##### `spec.options.evictTaint.effect` \u0026lt;string\u0026gt; (optional) (default: `NoExecute`)\n\nThe taint effect to apply. Must be one of:\n\n* `NoExecute`\n* `NoSchedule`\n* `PreferNoSchedule`\n\n##### `spec.options.evictTaint.controllerWorkers` \u0026lt;boolean\u0026gt; (optional) (default: false)\n\nWhether to also apply the taint to nodes with the controller+worker dual role. By default, taints are only applied to worker-only nodes.\n\n##### `spec.options.concurrency.limit` \u0026lt;integer\u0026gt; (optional) (default: 30)\n\nThe maximum number of hosts to operate on concurrently during cluster operations. Same as the `--concurrency` command line option.\n\n##### `spec.options.concurrency.workerDisruptionPercent` \u0026lt;integer\u0026gt; (optional) (default: 10)\n\nThe maximum percentage of worker nodes that can be disrupted at the same time during operations such as upgrade. This is used to ensure that a minimum number of worker nodes remain available during the operation. The value must be between 0 and 100.\n\n##### `spec.options.concurrency.uploads` \u0026lt;integer\u0026gt; (optional) (default: 5)\n\nThe maximum number of concurrent file uploads to perform. Same as the `--concurrent-uploads` command line option.\n\n### Tokens\n\nThe following tokens can be used in the `k0sDownloadURL` and `files.[*].src` fields:\n\n- `%%` - literal `%`\n- `%p` - host architecture (arm, arm64, amd64)\n- `%v` - k0s version (v1.21.0+k0s.0)\n- `%x` - k0s binary extension (.exe on Windows, empty elsewhere)\n\nAny other tokens will be output as-is including the `%` character.\n\nExample:\n\n```yaml\n  - role: controller\n    k0sDownloadURL: https://files.example.com/k0s%20files/k0s-%v-%p%x\n    # Expands to https://files.example.com/k0s%20files/k0s-v1.21.0+k0s.0-amd64\n```\n## License\n[![FOSSA Status](https://app.fossa.com/api/projects/git%2Bgithub.com%2Fk0sproject%2Fk0sctl.svg?type=large)](https://app.fossa.com/projects/git%2Bgithub.com%2Fk0sproject%2Fk0sctl?ref=badge_large)\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fk0sproject%2Fk0sctl","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fk0sproject%2Fk0sctl","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fk0sproject%2Fk0sctl/lists"}