Logo Questions Linux Laravel Mysql Ubuntu Git Menu

How to access kubernetes keys in etcd


How to get the Kubernetes related keys from etcd? Tried to list keys in etcd but could not see related keys. Also where is etcdctl installed?

$ etcdctl
bash: etcdctl: command not found..

$ sudo netstat -tnlp
Active Internet connections (only servers)
Proto Recv-Q Send-Q Local Address           Foreign Address         State       PID/Program name    
tcp        0      0*               LISTEN      386/etcd            
tcp        0      0*               LISTEN      386/etcd            

$ curl -s http://localhost:2379/v2/keys | python -m json.tool
    "action": "get",
    "node": {
        "dir": true


Installed Kubernetes 1.8.5 by following Using kubeadm to Create a Cluster on CentOS 7. When I looked at Getting started with etcd, v2/keys looks to be the end point.

like image 682
mon Avatar asked Dec 14 '17 07:12


People also ask

How do you check etcd in Kubernetes?

If you have access to the master node, just do a curl from there with the client certificate paths; the certificate is in: /etc/kubernetes/pki/etcd-manager-main/etcd-clients-ca. crt and the key /etc/kubernetes/pki/etcd-manager-main/etcd-clients-ca.

How does Kubernetes work with etcd?

Kubernetes uses etcd to store all its data – its configuration data, its state, and its metadata. Kubernetes is a distributed system, so it needs a distributed data store like etcd. etcd lets any of the nodes in the Kubernetes cluster read and write data.

How are Kubernetes objects stored in etcd?

By default, Kubernetes objects are stored under the /registry key in etcd. This path can be prefixed by using the kube-apiserver flag --etcd-prefix="/foo" .

Where does etcd run in Kubernetes?

In the Kubernetes world, etcd is used as the backend for service discovery and stores the cluster's state and its configuration. Etcd is deployed as a cluster, several nodes whose communications are handled by the Raft algorithm.

2 Answers

Usually you need to get etcdctl by yourself. Just download the latest etcdctl archive from etcd releases page.

Also, starting from Kubernetes version 1.6 it uses etcd version 3, so to get a list of all keys is:

ETCDCTL_API=3 etcdctl --endpoints=<etcd_ip>:2379 get / --prefix --keys-only

You can find all etcdctl v3 actions using:

ETCDCTL_API=3 etcdctl --endpoints=<etcd_ip>:2379 --help

EDIT (thanks to @leodotcloud):

In case ETCD is configured with TLS certificates support:

ETCDCTL_API=3 etcdctl --endpoints <etcd_ip>:2379 --cacert <ca_cert_path> --cert <cert_path> --key <cert_key_path> get / --prefix --keys-only
like image 145
nickgryg Avatar answered Sep 24 '22 05:09


Access the docker container, and run the following commmand:

ETCDCTL_API=3 etcdctl --endpoints --cacert /etc/kubernetes/pki/etcd/ca.crt --cert /etc/kubernetes/pki/etcd/server.crt --key /etc/kubernetes/pki/etcd/server.key get / --prefix --keys-only

like image 35
vdboor Avatar answered Sep 24 '22 05:09
