Part 3 — Go and Kubernetes · wrap-up
Cheat sheet & self-check
Every command from this section on one page.
Set-up
go get k8s.io/client-go@v0.34.0 k8s.io/apimachinery@v0.34.0 | client-go and apimachinery, versions matching your clusters' minor |
clientcmd.BuildConfigFromFlags("", kubeconfigPath) | Config from a kubeconfig file |
rest.InClusterConfig() | Config inside a pod (ServiceAccount token) |
kubernetes.NewForConfig(cfg) | The typed clientset |
Calls
cs.CoreV1().Nodes().List(ctx, metav1.ListOptions{}) | List nodes |
cs.CoreV1().Pods("").List(ctx, metav1.ListOptions{FieldSelector: "status.phase=Pending"}) | Pending pods in all namespaces |
cs.CoreV1().Nodes().Patch(ctx, name, types.MergePatchType, data, metav1.PatchOptions{}) | Patch a node (labels, annotations) |
apierrors.IsNotFound(err) | Was it a 404? |
Kubebuilder
kubebuilder init --domain platform.example.com --repo github.com/me/team-operator | Scaffold a project |
kubebuilder create api --group platform --version v1alpha1 --kind TeamNamespace | A CRD type and its controller |
make manifests generate | Regenerate CRD YAML, RBAC and deep-copy code after editing types |
make install run | Install the CRD into the current cluster and run the controller locally |
make test | Unit and envtest-based tests |
make docker-build deploy IMG=registry.example.com/team-operator:0.1.0 | Build and deploy into the cluster |
Quality
go test ./... -race -cover | All tests, race detector, coverage |
go test -run TestParse/empty -v ./internal/audit | One sub-test, verbose |
golangci-lint run | Many linters at once (errcheck, staticcheck, govet…) |
govulncheck ./... | Known vulnerabilities in code paths you actually call |
Ship
CGO_ENABLED=0 go build -trimpath -ldflags='-s -w' -o kaudit . | Small static binary |
docker build -t registry.example.com/kaudit:0.1.0 . | Multi-stage build into a distroless image |
goreleaser release --clean | Multi-platform binaries, checksums and release notes from a tag |