Ecosyste.ms: Awesome
An open API service indexing awesome lists of open source software.
https://github.com/kvaps/kubectl-node-shell
Exec into node via kubectl
https://github.com/kvaps/kubectl-node-shell
kubectl kubectl-enter kubectl-node-shell kubectl-plugin kubectl-plugins kubernetes nsenter
Last synced: about 1 month ago
JSON representation
Exec into node via kubectl
- Host: GitHub
- URL: https://github.com/kvaps/kubectl-node-shell
- Owner: kvaps
- License: apache-2.0
- Created: 2019-03-14T20:03:40.000Z (over 5 years ago)
- Default Branch: master
- Last Pushed: 2024-04-24T19:25:51.000Z (7 months ago)
- Last Synced: 2024-05-21T12:42:04.805Z (6 months ago)
- Topics: kubectl, kubectl-enter, kubectl-node-shell, kubectl-plugin, kubectl-plugins, kubernetes, nsenter
- Language: Shell
- Homepage:
- Size: 43.9 KB
- Stars: 1,336
- Watchers: 13
- Forks: 167
- Open Issues: 16
-
Metadata Files:
- Readme: README.md
- License: LICENSE
Awesome Lists containing this project
- awesome-starred - kvaps/kubectl-node-shell - Exec into node via kubectl (kubernetes)
README
# kubectl node-shell
*(formerly known as **kubectl-enter**)*Start a root shell in the node's host OS running. Uses an alpine pod with nsenter for Linux nodes and a [HostProcess pod](https://kubernetes.io/docs/tasks/configure-pod-container/create-hostprocess-pod/) with PowerShell for Windows nodes.
![demo](https://gist.githubusercontent.com/kvaps/2e3d77975a844654ec297893e21a0829/raw/c778a8405ff8c686e4e807a97e9721b423e7208f/kubectl-node-shell.gif)
## Installation
using [krew](https://krew.sigs.k8s.io/):
Plugin can be installed from the official krew repository:
kubectl krew install node-shellOr from our own krew repository:
kubectl krew index add kvaps https://github.com/kvaps/krew-index
kubectl krew install kvaps/node-shellor using curl:
```bash
curl -LO https://github.com/kvaps/kubectl-node-shell/raw/master/kubectl-node_shell
chmod +x ./kubectl-node_shell
sudo mv ./kubectl-node_shell /usr/local/bin/kubectl-node_shell
```## Usage
```bash
# Get standard bash shell
kubectl node-shell# Use X-mode (mount /host, and do not enter host namespace)
kubectl node-shell -x# Execute custom command
kubectl node-shell -- echo 123# Use stdin
cat /etc/passwd | kubectl node-shell -- sh -c 'cat > /tmp/passwd'# Run oneliner script
kubectl node-shell -- sh -c 'cat /tmp/passwd; rm -f /tmp/passwd'
```## X-mode
X-mode can be useful for debugging minimal systems that do not have a built-in shell (eg. Talos).
Here's an example of how you can debug the network for a rootless kube-apiserver container without a filesystem:```bash
kubectl node-shell -x# Download crictl
wget https://github.com/kubernetes-sigs/cri-tools/releases/download/v1.28.0/crictl-v1.28.0-linux-amd64.tar.gz -O- | \
tar -xzf- -C /usr/local/bin/# Setup CRI endpoint
export CONTAINER_RUNTIME_ENDPOINT=unix:///host/run/containerd/containerd.sock# Find your container
crictl ps | grep kube-apiserver
#3ff4626a9f10e e7972205b6614 6 hours ago Running kube-apiserver 0 215107b47bd7e kube-apiserver-talos-rzq-nkg# Find pid of the container
crictl inspect 3ff4626a9f10e | grep pid
# "pid": 2152,
# "pid": 1
# "type": "pid"
# "getpid",
# "getppid",
# "pidfd_open",
# "pidfd_send_signal",
# "waitpid",# Go to network namespace of the pid, but keep mount namespace of the debug container
nsenter -t 2152 -n
```*You need to be able to start privileged containers for that.*