Skip to content

Instantly share code, notes, and snippets.

@iahmad-khan
Created October 18, 2018 13:03
Show Gist options
  • Star 1 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save iahmad-khan/5d32b4070b6faf3836b932a7177095ff to your computer and use it in GitHub Desktop.
Save iahmad-khan/5d32b4070b6faf3836b932a7177095ff to your computer and use it in GitHub Desktop.
C02W84XMHTD5:ucp iahmad$ kubectl get pods --namespace=kube-system
NAME READY STATUS RESTARTS AGE
coredns-c4cffd6dc-nsd2k 1/1 Running 0 1d
etcd-minikube 1/1 Running 0 1d
kube-addon-manager-minikube 1/1 Running 0 1d
kube-apiserver-minikube 1/1 Running 0 1d
kube-controller-manager-minikube 1/1 Running 0 1d
kube-dns-86f4d74b45-d5njm 3/3 Running 0 1d
kube-proxy-rt45q 1/1 Running 0 1d
kube-scheduler-minikube 1/1 Running 0 1d
kubernetes-dashboard-6f4cfc5d87-b7n7v 1/1 Running 0 1d
storage-provisioner 1/1 Running 0 1d
C02W84XMHTD5:ucp iahmad$ kubectl cp --namespace kube-system kube-apiserver-minikube:/var/lib/minikube/certs/apiserver-etcd-client.crt apiserver-etcd-client.crt
tar: removing leading '/' from member names
C02W84XMHTD5:ucp iahmad$ kubectl cp --namespace kube-system kube-apiserver-minikube:/var/lib/minikube/certs/apiserver-etcd-client.key apiserver-etcd-client.key
C02W84XMHTD5:ucp iahmad$ kubectl cp --namespace kube-system apiserver-etcd-client.crt etcd-minikube:/var/lib/minikube/certs/
C02W84XMHTD5:ucp iahmad$
C02W84XMHTD5:ucp iahmad$
C02W84XMHTD5:ucp iahmad$ kubectl cp --namespace kube-system apiserver-etcd-client.key etcd-minikube:/var/lib/minikube/certs/
C02W84XMHTD5:ucp iahmad$
C02W84XMHTD5:ucp iahmad$ kubectl exec -it --namespace kube-system etcd-minikube sh
/ #
/ #
/ # export ETCDCTL_API=3
/ # cd /var/lib/minikube/certs/
/var/lib/minikube/certs # ls
apiserver-etcd-client.crt apiserver-etcd-client.key etcd
/var/lib/minikube/certs # etcdctl --cacert="etcd/ca.crt" --key=apiserver-etcd-client.key --cert=apiserver-et
cd-client.crt endpoint status
2018-10-18 12:55:04.740853 I | warning: ignoring ServerName for user-provided CA for backwards compatibility is deprecated
127.0.0.1:2379, 8e9e05c52164694d, 3.1.12, 1.7 MB, true, 2, 44595
/var/lib/minikube/certs #
/var/lib/minikube/certs #
/var/lib/minikube/certs # etcdctl --cacert="etcd/ca.crt" --key=apiserver-etcd-client.key --cert=apiserver-et
cd-client.crt get / --prefix --keys-only
2018-10-18 12:56:14.319450 I | warning: ignoring ServerName for user-provided CA for backwards compatibility is deprecated
/registry/apiregistration.k8s.io/apiservices/v1.
/registry/apiregistration.k8s.io/apiservices/v1.apps
/registry/apiregistration.k8s.io/apiservices/v1.authentication.k8s.io
/registry/apiregistration.k8s.io/apiservices/v1.authorization.k8s.io
/registry/apiregistration.k8s.io/apiservices/v1.autoscaling
/registry/apiregistration.k8s.io/apiservices/v1.batch
/registry/apiregistration.k8s.io/apiservices/v1.networking.k8s.io
/registry/apiregistration.k8s.io/apiservices/v1.rbac.authorization.k8s.io
/registry/apiregistration.k8s.io/apiservices/v1.storage.k8s.io
/registry/apiregistration.k8s.io/apiservices/v1beta1.admissionregistration.k8s.io
/registry/apiregistration.k8s.io/apiservices/v1beta1.apiextensions.k8s.io
/registry/apiregistration.k8s.io/apiservices/v1beta1.apps
/registry/apiregistration.k8s.io/apiservices/v1beta1.authentication.k8s.io
/registry/apiregistration.k8s.io/apiservices/v1beta1.authorization.k8s.io
/registry/apiregistration.k8s.io/apiservices/v1beta1.batch
/registry/apiregistration.k8s.io/apiservices/v1beta1.certificates.k8s.io
/registry/apiregistration.k8s.io/apiservices/v1beta1.events.k8s.io
/registry/apiregistration.k8s.io/apiservices/v1beta1.extensions
/registry/apiregistration.k8s.io/apiservices/v1beta1.policy
/registry/apiregistration.k8s.io/apiservices/v1beta1.rbac.authorization.k8s.io
/registry/apiregistration.k8s.io/apiservices/v1beta1.storage.k8s.io
/registry/apiregistration.k8s.io/apiservices/v1beta2.apps
/registry/apiregistration.k8s.io/apiservices/v2beta1.autoscaling
/registry/clusterrolebindings/cluster-admin
/registry/clusterrolebindings/kubeadm:kubelet-bootstrap
/registry/clusterrolebindings/kubeadm:node-autoapprove-bootstrap
/registry/clusterrolebindings/kubeadm:node-autoapprove-certificate-rotation
/registry/clusterrolebindings/kubeadm:node-proxier
/registry/clusterrolebindings/minikube-rbac
/registry/clusterrolebindings/storage-provisioner
/registry/clusterrolebindings/system:aws-cloud-provider
/registry/clusterrolebindings/system:basic-user
/registry/clusterrolebindings/system:controller:attachdetach-controller
/registry/clusterrolebindings/system:controller:certificate-controller
/registry/clusterrolebindings/system:controller:clusterrole-aggregation-controller
/registry/clusterrolebindings/system:controller:cronjob-controller
/registry/clusterrolebindings/system:controller:daemon-set-controller
/registry/clusterrolebindings/system:controller:deployment-controller
/registry/clusterrolebindings/system:controller:disruption-controller
/registry/clusterrolebindings/system:controller:endpoint-controller
/registry/clusterrolebindings/system:controller:generic-garbage-collector
/registry/clusterrolebindings/system:controller:horizontal-pod-autoscaler
/registry/clusterrolebindings/system:controller:job-controller
/registry/clusterrolebindings/system:controller:namespace-controller
/registry/clusterrolebindings/system:controller:node-controller
/registry/clusterrolebindings/system:controller:persistent-volume-binder
/registry/clusterrolebindings/system:controller:pod-garbage-collector
/registry/clusterrolebindings/system:controller:pv-protection-controller
/registry/clusterrolebindings/system:controller:pvc-protection-controller
/registry/clusterrolebindings/system:controller:replicaset-controller
/registry/clusterrolebindings/system:controller:replication-controller
/registry/clusterrolebindings/system:controller:resourcequota-controller
/registry/clusterrolebindings/system:controller:route-controller
/registry/clusterrolebindings/system:controller:service-account-controller
/registry/clusterrolebindings/system:controller:service-controller
/registry/clusterrolebindings/system:controller:statefulset-controller
/registry/clusterrolebindings/system:controller:ttl-controller
/registry/clusterrolebindings/system:coredns
/registry/clusterrolebindings/system:discovery
/registry/clusterrolebindings/system:kube-controller-manager
/registry/clusterrolebindings/system:kube-dns
/registry/clusterrolebindings/system:kube-scheduler
/registry/clusterrolebindings/system:node
/registry/clusterrolebindings/system:node-proxier
/registry/clusterrolebindings/system:volume-scheduler
/registry/clusterroles/admin
/registry/clusterroles/cluster-admin
/registry/clusterroles/edit
/registry/clusterroles/system:aggregate-to-admin
/registry/clusterroles/system:aggregate-to-edit
/registry/clusterroles/system:aggregate-to-view
/registry/clusterroles/system:auth-delegator
/registry/clusterroles/system:aws-cloud-provider
/registry/clusterroles/system:basic-user
/registry/clusterroles/system:certificates.k8s.io:certificatesigningrequests:nodeclient
/registry/clusterroles/system:certificates.k8s.io:certificatesigningrequests:selfnodeclient
/registry/clusterroles/system:controller:attachdetach-controller
/registry/clusterroles/system:controller:certificate-controller
/registry/clusterroles/system:controller:clusterrole-aggregation-controller
/registry/clusterroles/system:controller:cronjob-controller
/registry/clusterroles/system:controller:daemon-set-controller
/registry/clusterroles/system:controller:deployment-controller
/registry/clusterroles/system:controller:disruption-controller
/registry/clusterroles/system:controller:endpoint-controller
/registry/clusterroles/system:controller:generic-garbage-collector
/registry/clusterroles/system:controller:horizontal-pod-autoscaler
/registry/clusterroles/system:controller:job-controller
/registry/clusterroles/system:controller:namespace-controller
/registry/clusterroles/system:controller:node-controller
/registry/clusterroles/system:controller:persistent-volume-binder
/registry/clusterroles/system:controller:pod-garbage-collector
/registry/clusterroles/system:controller:pv-protection-controller
/registry/clusterroles/system:controller:pvc-protection-controller
/registry/clusterroles/system:controller:replicaset-controller
/registry/clusterroles/system:controller:replication-controller
/registry/clusterroles/system:controller:resourcequota-controller
/registry/clusterroles/system:controller:route-controller
/registry/clusterroles/system:controller:service-account-controller
/registry/clusterroles/system:controller:service-controller
/registry/clusterroles/system:controller:statefulset-controller
/registry/clusterroles/system:controller:ttl-controller
/registry/clusterroles/system:coredns
/registry/clusterroles/system:discovery
/registry/clusterroles/system:heapster
/registry/clusterroles/system:kube-aggregator
/registry/clusterroles/system:kube-controller-manager
/registry/clusterroles/system:kube-dns
/registry/clusterroles/system:kube-scheduler
/registry/clusterroles/system:kubelet-api-admin
/registry/clusterroles/system:node
/registry/clusterroles/system:node-bootstrapper
/registry/clusterroles/system:node-problem-detector
/registry/clusterroles/system:node-proxier
/registry/clusterroles/system:persistent-volume-provisioner
/registry/clusterroles/system:volume-scheduler
/registry/clusterroles/view
/registry/configmaps/kube-public/cluster-info
/registry/configmaps/kube-system/coredns
/registry/configmaps/kube-system/extension-apiserver-authentication
/registry/configmaps/kube-system/kube-proxy
/registry/configmaps/kube-system/kubeadm-config
/registry/configmaps/kube-system/kubernetes-dashboard-settings
/registry/controllerrevisions/kube-system/kube-proxy-55f785bb78
/registry/daemonsets/kube-system/kube-proxy
/registry/deployments/kube-system/coredns
/registry/deployments/kube-system/kube-dns
/registry/deployments/kube-system/kubernetes-dashboard
/registry/minions/minikube
/registry/namespaces/default
/registry/namespaces/kube-public
/registry/namespaces/kube-system
/registry/pods/kube-system/coredns-c4cffd6dc-nsd2k
/registry/pods/kube-system/etcd-minikube
/registry/pods/kube-system/kube-addon-manager-minikube
/registry/pods/kube-system/kube-apiserver-minikube
/registry/pods/kube-system/kube-controller-manager-minikube
/registry/pods/kube-system/kube-dns-86f4d74b45-d5njm
/registry/pods/kube-system/kube-proxy-rt45q
/registry/pods/kube-system/kube-scheduler-minikube
/registry/pods/kube-system/kubernetes-dashboard-6f4cfc5d87-b7n7v
/registry/pods/kube-system/storage-provisioner
/registry/ranges/serviceips
/registry/ranges/servicenodeports
/registry/replicasets/kube-system/coredns-c4cffd6dc
/registry/replicasets/kube-system/kube-dns-86f4d74b45
/registry/replicasets/kube-system/kubernetes-dashboard-6f4cfc5d87
/registry/rolebindings/kube-public/kubeadm:bootstrap-signer-clusterinfo
/registry/rolebindings/kube-public/system:controller:bootstrap-signer
/registry/rolebindings/kube-system/system::leader-locking-kube-controller-manager
/registry/rolebindings/kube-system/system::leader-locking-kube-scheduler
/registry/rolebindings/kube-system/system:controller:bootstrap-signer
/registry/rolebindings/kube-system/system:controller:cloud-provider
/registry/rolebindings/kube-system/system:controller:token-cleaner
/registry/roles/kube-public/kubeadm:bootstrap-signer-clusterinfo
/registry/roles/kube-public/system:controller:bootstrap-signer
/registry/roles/kube-system/extension-apiserver-authentication-reader
/registry/roles/kube-system/system::leader-locking-kube-controller-manager
/registry/roles/kube-system/system::leader-locking-kube-scheduler
/registry/roles/kube-system/system:controller:bootstrap-signer
/registry/roles/kube-system/system:controller:cloud-provider
/registry/roles/kube-system/system:controller:token-cleaner
/registry/secrets/default/default-token-wmrlr
/registry/secrets/kube-public/default-token-lg285
/registry/secrets/kube-system/attachdetach-controller-token-r5tpv
/registry/secrets/kube-system/bootstrap-signer-token-kfs4x
/registry/secrets/kube-system/bootstrap-token-whfcyv
/registry/secrets/kube-system/certificate-controller-token-6qqzt
/registry/secrets/kube-system/clusterrole-aggregation-controller-token-pmn99
/registry/secrets/kube-system/coredns-token-kzjgd
/registry/secrets/kube-system/cronjob-controller-token-kq5jb
/registry/secrets/kube-system/daemon-set-controller-token-4t7nc
/registry/secrets/kube-system/default-token-vr2t7
/registry/secrets/kube-system/deployment-controller-token-jr5pz
/registry/secrets/kube-system/disruption-controller-token-d5p45
/registry/secrets/kube-system/endpoint-controller-token-fj525
/registry/secrets/kube-system/generic-garbage-collector-token-797ms
/registry/secrets/kube-system/horizontal-pod-autoscaler-token-k5t98
/registry/secrets/kube-system/job-controller-token-tcz6s
/registry/secrets/kube-system/kube-dns-token-ndcgf
/registry/secrets/kube-system/kube-proxy-token-2v8kg
/registry/secrets/kube-system/kubernetes-dashboard-key-holder
/registry/secrets/kube-system/namespace-controller-token-fqb28
/registry/secrets/kube-system/node-controller-token-cmnjl
/registry/secrets/kube-system/persistent-volume-binder-token-grqnj
/registry/secrets/kube-system/pod-garbage-collector-token-mfxmc
/registry/secrets/kube-system/pv-protection-controller-token-dsv79
/registry/secrets/kube-system/pvc-protection-controller-token-x9ztc
/registry/secrets/kube-system/replicaset-controller-token-5smqg
/registry/secrets/kube-system/replication-controller-token-w5vtg
/registry/secrets/kube-system/resourcequota-controller-token-wd5dp
/registry/secrets/kube-system/service-account-controller-token-jdkfn
/registry/secrets/kube-system/service-controller-token-znbn7
/registry/secrets/kube-system/statefulset-controller-token-bnbp9
/registry/secrets/kube-system/storage-provisioner-token-vp94x
/registry/secrets/kube-system/token-cleaner-token-kpw9q
/registry/secrets/kube-system/ttl-controller-token-kb4cx
/registry/serviceaccounts/default/default
/registry/serviceaccounts/kube-public/default
/registry/serviceaccounts/kube-system/attachdetach-controller
/registry/serviceaccounts/kube-system/bootstrap-signer
/registry/serviceaccounts/kube-system/certificate-controller
/registry/serviceaccounts/kube-system/clusterrole-aggregation-controller
/registry/serviceaccounts/kube-system/coredns
/registry/serviceaccounts/kube-system/cronjob-controller
/registry/serviceaccounts/kube-system/daemon-set-controller
/registry/serviceaccounts/kube-system/default
/registry/serviceaccounts/kube-system/deployment-controller
/registry/serviceaccounts/kube-system/disruption-controller
/registry/serviceaccounts/kube-system/endpoint-controller
/registry/serviceaccounts/kube-system/generic-garbage-collector
/registry/serviceaccounts/kube-system/horizontal-pod-autoscaler
/registry/serviceaccounts/kube-system/job-controller
/registry/serviceaccounts/kube-system/kube-dns
/registry/serviceaccounts/kube-system/kube-proxy
/registry/serviceaccounts/kube-system/namespace-controller
/registry/serviceaccounts/kube-system/node-controller
/registry/serviceaccounts/kube-system/persistent-volume-binder
/registry/serviceaccounts/kube-system/pod-garbage-collector
/registry/serviceaccounts/kube-system/pv-protection-controller
/registry/serviceaccounts/kube-system/pvc-protection-controller
/registry/serviceaccounts/kube-system/replicaset-controller
/registry/serviceaccounts/kube-system/replication-controller
/registry/serviceaccounts/kube-system/resourcequota-controller
/registry/serviceaccounts/kube-system/service-account-controller
/registry/serviceaccounts/kube-system/service-controller
/registry/serviceaccounts/kube-system/statefulset-controller
/registry/serviceaccounts/kube-system/storage-provisioner
/registry/serviceaccounts/kube-system/token-cleaner
/registry/serviceaccounts/kube-system/ttl-controller
/registry/services/endpoints/default/kubernetes
/registry/services/endpoints/kube-system/kube-controller-manager
/registry/services/endpoints/kube-system/kube-dns
/registry/services/endpoints/kube-system/kube-scheduler
/registry/services/endpoints/kube-system/kubernetes-dashboard
/registry/services/specs/default/kubernetes
/registry/services/specs/kube-system/kube-dns
/registry/services/specs/kube-system/kubernetes-dashboard
/registry/storageclasses/standard
/var/lib/minikube/certs #
/var/lib/minikube/certs #
/var/lib/minikube/certs # etcdctl --cacert="etcd/ca.crt" --key=apiserver-etcd-client.key --cert=apiserver-et
cd-client.crt get / --prefix --keys-only | grep nginx
2018-10-18 12:57:07.675373 I | warning: ignoring ServerName for user-provided CA for backwards compatibility is deprecated
after running nginx deployment in another tab:
/var/lib/minikube/certs #
/var/lib/minikube/certs # etcdctl --cacert="etcd/ca.crt" --key=apiserver-etcd-client.key --cert=apiserver-et
cd-client.crt get / --prefix --keys-only | grep nginx
2018-10-18 12:58:43.603073 I | warning: ignoring ServerName for user-provided CA for backwards compatibility is deprecated
/registry/deployments/default/nginx
/registry/events/default/nginx-65899c769f-572jc.155eb558355b71eb
/registry/events/default/nginx-65899c769f-572jc.155eb55847e20b33
/registry/events/default/nginx-65899c769f-572jc.155eb5588879c932
/registry/events/default/nginx-65899c769f.155eb55831e1e50b
/registry/events/default/nginx.155eb5582c33a80f
/registry/pods/default/nginx-65899c769f-572jc
/registry/replicasets/default/nginx-65899c769f
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment