Kubernetes Apply

Kubernetes Apply

Certified

Apply Kubernetes resources with server-side apply

Applies one or more YAML/JSON manifests using server-side apply, then optionally waits until each resource is Ready (waitUntilReady, default PT0S). Namespaces must be provided for namespaced kinds.

yaml
type: io.kestra.plugin.kubernetes.kubectl.Apply

Apply a Kubernetes resource.

yaml
id: create_or_replace_deployment
namespace: company.team

tasks:
  - id: apply
    type: io.kestra.plugin.kubernetes.kubectl.Apply
    connection:
      masterUrl: "{{ secret('K8S_MASTER_URL') }}"
      oauthToken: "{{ secret('K8S_TOKEN') }}"
    namespace: default
    spec: |-
      apiVersion: apps/v1
      kind: Deployment
      metadata:
        name: mypod
        labels:
          app: mypod
      spec:
        replicas: 1
        selector:
          matchLabels:
            app: mypod
        template:
          metadata:
            labels:
              app: mypod
          spec:
            containers:
              - name: app
                image: nginx:stable-alpine
                ports:
                  - containerPort: 80

Apply a core-group v1 Service.

yaml
id: create_or_replace_service
namespace: company.team

tasks:
  - id: apply
    type: io.kestra.plugin.kubernetes.kubectl.Apply
    connection:
      masterUrl: "{{ secret('K8S_MASTER_URL') }}"
      oauthToken: "{{ secret('K8S_TOKEN') }}"
    namespace: default
    spec: |-
      apiVersion: v1
      kind: Service
      metadata:
        name: my-service
      spec:
        selector:
          app: myapp
        ports:
          - protocol: TCP
            port: 80
            targetPort: 8080

Apply a Kubernetes resource, using a namespace file.

yaml
id: create_or_replace_deployment
namespace: company.team

tasks:
  - id: apply
    type: io.kestra.plugin.kubernetes.kubectl.Apply
    connection:
      masterUrl: "{{ secret('K8S_MASTER_URL') }}"
      oauthToken: "{{ secret('K8S_TOKEN') }}"
    namespaceFiles:
      enabled: true
    namespace: default
    spec: "{{ read('deployment.yaml') }}"

Apply a Kubernetes custom resource definition.

yaml
id: k8s
namespace: company.name

tasks:
  - id: apply
    type: io.kestra.plugin.kubernetes.kubectl.Apply
    connection:
      masterUrl: "{{ secret('K8S_MASTER_URL') }}"
      oauthToken: "{{ secret('K8S_TOKEN') }}"
    namespace: default
    spec: |-
      apiVersion: apiextensions.k8s.io/v1
      kind: CustomResourceDefinition
      metadata:
        name: shirts.stable.example.com
      spec:
        group: stable.example.com
        scope: Namespaced
        names:
          plural: shirts
          singular: shirt
          kind: Shirt
        versions:
        - name: v1
          served: true
          storage: true
          schema:
            openAPIV3Schema:
              type: object
              properties:
                apiVersion:
                  type: string
                kind:
                  type: string
                metadata:
                  type: object
                spec:
                  type: object
                  x-kubernetes-preserve-unknown-fields: true # Allows any fields in spec
                  properties:
                    # You should define your actual Shirt properties here later
                    # For example:
                    # color:
                    #   type: string
                    # size:
                    #   type: string
                    #   enum: ["S", "M", "L", "XL"]
                status:
                  type: object
                  x-kubernetes-preserve-unknown-fields: true # Allows any fields in status
                  properties:
                    # Define your status properties here
                    # message:
                    #   type: string

Apply a custom resource and wait for it to become ready.

yaml
id: apply_and_wait_for_custom_resource
namespace: company.team

tasks:
  - id: apply
    type: io.kestra.plugin.kubernetes.kubectl.Apply
    connection:
      masterUrl: "{{ secret('K8S_MASTER_URL') }}"
      oauthToken: "{{ secret('K8S_TOKEN') }}"
    namespace: default
    waitUntilReady: PT10M
    spec: |-
      apiVersion: example.com/v1
      kind: MyResource
      metadata:
        name: my-resource
      spec:
        foo: bar
Properties

Resource manifest

YAML or JSON manifest to apply. Can include multiple documents separated by '---'. Supports template expressions before apply.

Kubernetes connection

Connection settings for the cluster. If omitted, the client resolves credentials in order: system properties, environment variables, kubeconfig, then in-cluster service account.

Definitions
apiVersionstring
Defaultv1

API version

API group version used by the client. Default v1.

caCertDatastring

CA certificate data

Base64-encoded PEM CA bundle. Whitespace is stripped automatically.

caCertFilestring

CA certificate file

Path to a PEM CA bundle.

clientCertDatastring

Client certificate data

Base64-encoded client cert. Whitespace is stripped automatically.

clientCertFilestring

Client certificate file

clientKeyAlgostring
DefaultRSA

Client key algorithm

Algorithm for the client key. Default RSA.

clientKeyDatastring

Client key data

Base64-encoded client key. Whitespace is stripped automatically.

clientKeyFilestring

Client key file

clientKeyPassphrasestring

Client key passphrase

disableHostnameVerificationbooleanstring

Disable hostname verification

Disables TLS hostname checks. Avoid in production clusters.

keyStoreFilestring

Keystore file

keyStorePassphrasestring

Keystore passphrase

masterUrlstring
Defaulthttps://kubernetes.default.svc

Kubernetes API URL

API server endpoint. Default https://kubernetes.default.svc.

namespacestring

Default namespace

Namespace used when resources omit a namespace.

oauthTokenstring

OAuth token

oauthTokenProvider

OAuth token provider

cachestring
DefaultPT5M
Formatduration

Token cache duration

How long a fetched token is cached before the underlying task is called again. Defaults to 5 minutes. Set to PT0S or a negative duration to disable caching and re-fetch a token on every request.

outputstring
task
passwordstring

Password

trustCertsbooleanstring

Trust all certificates

When true, skips TLS cert validation. Use only for testing.

trustStoreFilestring

Truststore file

trustStorePassphrasestring

Truststore passphrase

usernamestring

Username

Default container spec applied to all containers in the pod

When set, these container spec fields are merged into all containers including:

  • User-defined containers in the spec
  • Init and sidecar containers for file transfer (unless fileSidecar.defaultSpec is set)

This provides a convenient way to apply uniform container settings across all containers, which is especially useful in restrictive environments like GovCloud.

Supports any valid Kubernetes container spec fields such as:

  • securityContext: Security settings for all containers
  • volumeMounts: Volume mounts to add to all containers
  • resources: Resource limits/requests for all containers
  • env: Environment variables for all containers

Merge behavior:

  • For nested objects (like securityContext): deep merge, container-specific values take precedence
  • For volumeMounts: concatenated, with defaults added first
  • For env: deduplicated by name — container-specific values always win over defaults on collision
  • Container-specific values always override defaults

Example configuration:

containerDefaultSpec: 
  securityContext: 
    allowPrivilegeEscalation: false
    capabilities: 
      drop: 
      - ALL
    readOnlyRootFilesystem: true
    seccompProfile: 
      type: RuntimeDefault
  volumeMounts: 
    - name: tmp
      mountPath: /tmp
  resources: 
    limits: 
      memory: "256Mi"
Default{ "image": "busybox" }

The configuration of the file sidecar container that handles the download and upload of files

Definitions
defaultSpecobject

Default spec for file transfer containers

Overrides containerDefaultSpec for the init and sidecar containers that move files. Accepts Pod container fields such as securityContext, volumeMounts, resources, and env; useful for hardening or adding mounts used only by file transfer helpers.

Example: fileSidecar: defaultSpec: securityContext: allowPrivilegeEscalation: false readOnlyRootFilesystem: true volumeMounts: - name: tmp mountPath: /tmp

imagestring
Defaultbusybox

Image for file sidecar

Container image used by the init container (uploads input files) and the sidecar (downloads output files). Defaults to busybox.

The image must provide, on its PATH: a POSIX shell (sh), test/[, and sleep — required by the polling script that waits for the transfer to complete before the container exits. find and wc are also used, on a best-effort basis, to verify that uploaded files were fully transferred; if they're missing, verification is skipped rather than failing the task.

resourcesobject

Configure sidecar resource requests/limits

Optional Kubernetes resources block applied to the file transfer sidecar.

Defaultfalse

Inherit cluster auto-config

When true and a connection is set, the client config is seeded from the ambient auto-config (system properties, env, kubeconfig, in-cluster service account) before applying connection, so a partial connection (e.g. only a namespace) keeps the resolved credentials instead of starting blank. Default false.

SubTypestring

The files to create on the local filesystem – it can be a map or a JSON object

The files will be available inside the kestra/working-dir directory of the container. You can use the special variable {{workingDir}} in your command to refer to it.

Defaultdefault

The namespace where the operation will be done

The Kubernetes namespace in which to execute the operation. Defaults to 'default' if not specified.

SubTypestring

The files from the container filesystem to send to Kestra's internal storage

Only files created inside the kestra/working-dir directory of the container can be retrieved. Must be a list of glob expressions relative to the current working directory, some examples: my-dir/**, my-dir/*/** or my-dir/my-file.txt..

Reference (ref) of the pluginDefaults to apply to this task.

DefaultPT1H

Wait for pod completion

Maximum run time after reaching Running (defaults to PT1H). PodCreate fails and deletes the pod when exceeded.

DefaultPT0S

The maximum duration to wait until the resource becomes ready

When set to a positive duration, waits for the resource to report Ready=True in its status conditions. Set to PT0S (zero, default) to skip waiting. Supports Pods, StatefulSets, and custom resources that use the Ready condition. Note: Deployments are not supported as they use the Available condition instead of Ready.

DefaultPT10M

Wait for pod to reach Running

Maximum time to reach Running (defaults to PT10M). Covers scheduling, image pulls, and startup. Used by PodCreate.

Applied resource metadata

Metadata returned by the API after server-side apply.

Definitions
annotationsobject

Resource annotations

clusterNamestring

Cluster name

creationTimestampstring
Formatdate-time

Creation timestamp

deletionGracePeriodSecondsinteger

Deletion grace period in seconds

deletionTimestampstring
Formatdate-time

Deletion timestamp

finalizersarray
SubTypestring

Finalizers

generateNamestring

Generated name prefix

generationinteger

Generation

labelsobject

Resource labels

managedFieldsarray

Managed fields

apiVersionstring
fieldsTypestring
fieldsV1
managerstring
operationstring
subresourcestring
timestring
namestring

Resource name

namespacestring

Resource namespace

ownerReferencesarray

Owner references

apiVersionstring
blockOwnerDeletionboolean
controllerboolean
kindstring
namestring
uidstring
resourceVersionstring

Resource version

selfLinkstring

Self link

uidstring

Generated UUID of this resource