
Kubernetes Patch
CertifiedPatch Kubernetes resources with merge or JSON patch
Kubernetes Patch
Patch Kubernetes resources with merge or JSON patch
Applies targeted updates to a namespaced resource using Strategic Merge (default), JSON Merge, or JSON Patch. Supports waiting for readiness after the patch (waitUntilReady, default PT0S).
type: io.kestra.plugin.kubernetes.kubectl.PatchExamples
Patch pod resource limits and wait for it to become ready.
id: patch_pod_with_wait
namespace: company.team
tasks:
- id: patch
type: io.kestra.plugin.kubernetes.kubectl.Patch
connection:
masterUrl: "{{ secret('K8S_MASTER_URL') }}"
oauthToken: "{{ secret('K8S_TOKEN') }}"
namespace: production
resourceType: pod
resourceName: my-pod
waitUntilReady: PT5M
patch: |
{
"spec": {
"containers": [
{
"name": "app",
"resources": {
"limits": {"memory": "512Mi", "cpu": "500m"},
"requests": {"memory": "256Mi", "cpu": "250m"}
}
}
]
}
}
Patch a deployment to update container resources using strategic merge (default).
id: patch_deployment_resources
namespace: company.team
tasks:
- id: patch
type: io.kestra.plugin.kubernetes.kubectl.Patch
connection:
masterUrl: "{{ secret('K8S_MASTER_URL') }}"
oauthToken: "{{ secret('K8S_TOKEN') }}"
namespace: production
resourceType: deployment
resourceName: my-api
apiGroup: apps
patch: |
{
"spec": {
"template": {
"spec": {
"containers": [
{
"name": "api",
"resources": {
"limits": {"memory": "2Gi", "cpu": "1000m"},
"requests": {"memory": "1Gi", "cpu": "500m"}
}
}
]
}
}
}
}
Scale a deployment using JSON Patch operations.
id: scale_deployment
namespace: company.team
tasks:
- id: scale
type: io.kestra.plugin.kubernetes.kubectl.Patch
connection:
masterUrl: "{{ secret('K8S_MASTER_URL') }}"
oauthToken: "{{ secret('K8S_TOKEN') }}"
namespace: production
resourceType: deployment
resourceName: my-api
apiGroup: apps
patchStrategy: JSON_PATCH
patch: |
[
{"op": "replace", "path": "/spec/replicas", "value": 5}
]
Remove an annotation using JSON Merge Patch.
id: remove_annotation
namespace: company.team
tasks:
- id: patch
type: io.kestra.plugin.kubernetes.kubectl.Patch
connection:
masterUrl: "{{ secret('K8S_MASTER_URL') }}"
oauthToken: "{{ secret('K8S_TOKEN') }}"
namespace: production
resourceType: deployment
resourceName: my-api
apiGroup: apps
patchStrategy: JSON_MERGE
patch: |
{
"metadata": {
"annotations": {
"deprecated-annotation": null
}
}
}
Patch a custom resource.
id: patch_custom_resource
namespace: company.team
tasks:
- id: patch
type: io.kestra.plugin.kubernetes.kubectl.Patch
connection:
masterUrl: "{{ secret('K8S_MASTER_URL') }}"
oauthToken: "{{ secret('K8S_TOKEN') }}"
namespace: production
resourceType: shirts
resourceName: my-shirt
apiGroup: stable.example.com
apiVersion: v1
patch: |
{
"spec": {
"color": "blue",
"size": "L"
}
}
Conditionally update replicas using JSON Patch test operation.
id: conditional_scale
namespace: company.team
tasks:
- id: scale
type: io.kestra.plugin.kubernetes.kubectl.Patch
connection:
masterUrl: "{{ secret('K8S_MASTER_URL') }}"
oauthToken: "{{ secret('K8S_TOKEN') }}"
namespace: production
resourceType: deployment
resourceName: my-api
apiGroup: apps
patchStrategy: JSON_PATCH
patch: |
[
{"op": "test", "path": "/spec/replicas", "value": 3},
{"op": "replace", "path": "/spec/replicas", "value": 10}
]
Properties
patch *Requiredstring
Patch content
The format depends on the patchStrategy. For STRATEGIC_MERGE and JSON_MERGE, provide a JSON object with the fields to update. For JSON_PATCH, provide a JSON array of operations with 'op', 'path', and 'value' fields.
resourceName *Requiredstring
Resource name
resourceType *Requiredstring
Resource kind
Namespaced Kubernetes kind (e.g., Deployment, StatefulSet, Pod). Cluster-scoped kinds are not supported.
apiGroup string
API group
Group for the resource kind. Leave empty for core resources.
apiVersion string
API version
Version for the resource kind (e.g., v1). Defaults to v1 when omitted.
connection Non-dynamic
Kubernetes connection
Connection settings for the cluster. If omitted, the client resolves credentials in order: system properties, environment variables, kubeconfig, then in-cluster service account.
io.kestra.plugin.kubernetes.models.Connection
v1API version
API group version used by the client. Default v1.
CA certificate data
Base64-encoded PEM CA bundle. Whitespace is stripped automatically.
CA certificate file
Path to a PEM CA bundle.
Client certificate data
Base64-encoded client cert. Whitespace is stripped automatically.
Client certificate file
RSAClient key algorithm
Algorithm for the client key. Default RSA.
Client key data
Base64-encoded client key. Whitespace is stripped automatically.
Client key file
Client key passphrase
Disable hostname verification
Disables TLS hostname checks. Avoid in production clusters.
Keystore file
Keystore passphrase
https://kubernetes.default.svcKubernetes API URL
API server endpoint. Default https://kubernetes.default.svc.
Default namespace
Namespace used when resources omit a namespace.
OAuth token
OAuth token provider
io.kestra.plugin.kubernetes.models.OAuthTokenProvider
PT5MdurationToken cache duration
How long a fetched token is cached before the underlying task is called again. Defaults to 5 minutes. Set to PT0S or a negative duration to disable caching and re-fetch a token on every request.
Password
Trust all certificates
When true, skips TLS cert validation. Use only for testing.
Truststore file
Truststore passphrase
Username
containerDefaultSpec object
Default container spec applied to all containers in the pod
When set, these container spec fields are merged into all containers including:
- User-defined containers in the spec
- Init and sidecar containers for file transfer (unless fileSidecar.defaultSpec is set)
This provides a convenient way to apply uniform container settings across all containers, which is especially useful in restrictive environments like GovCloud.
Supports any valid Kubernetes container spec fields such as:
- securityContext: Security settings for all containers
- volumeMounts: Volume mounts to add to all containers
- resources: Resource limits/requests for all containers
- env: Environment variables for all containers
Merge behavior:
- For nested objects (like securityContext): deep merge, container-specific values take precedence
- For volumeMounts: concatenated, with defaults added first
- For env: deduplicated by name — container-specific values always win over defaults on collision
- Container-specific values always override defaults
Example configuration:
containerDefaultSpec:
securityContext:
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
readOnlyRootFilesystem: true
seccompProfile:
type: RuntimeDefault
volumeMounts:
- name: tmp
mountPath: /tmp
resources:
limits:
memory: "256Mi"
fileSidecar Non-dynamic
{
"image": "busybox"
}The configuration of the file sidecar container that handles the download and upload of files
io.kestra.plugin.kubernetes.models.SideCar
Default spec for file transfer containers
Overrides containerDefaultSpec for the init and sidecar containers that move files. Accepts Pod container fields such as securityContext, volumeMounts, resources, and env; useful for hardening or adding mounts used only by file transfer helpers.
Example: fileSidecar: defaultSpec: securityContext: allowPrivilegeEscalation: false readOnlyRootFilesystem: true volumeMounts: - name: tmp mountPath: /tmp
busyboxImage for file sidecar
Container image used by the init container (uploads input files) and the sidecar (downloads output files). Defaults to busybox.
The image must provide, on its PATH: a POSIX shell (sh), test/[, and sleep — required by the polling script that waits for the transfer to complete before the container exits. find and wc are also used, on a best-effort basis, to verify that uploaded files were fully transferred; if they're missing, verification is skipped rather than failing the task.
Configure sidecar resource requests/limits
Optional Kubernetes resources block applied to the file transfer sidecar.
inheritClusterConfig booleanstring
falseInherit cluster auto-config
When true and a connection is set, the client config is seeded from the ambient auto-config (system properties, env, kubeconfig, in-cluster service account) before applying connection, so a partial connection (e.g. only a namespace) keeps the resolved credentials instead of starting blank. Default false.
inputFiles object
The files to create on the local filesystem – it can be a map or a JSON object
The files will be available inside the kestra/working-dir directory of the container. You can use the special variable {{workingDir}} in your command to refer to it.
namespace string
defaultThe namespace where the operation will be done
The Kubernetes namespace in which to execute the operation. Defaults to 'default' if not specified.
outputFiles array
The files from the container filesystem to send to Kestra's internal storage
Only files created inside the kestra/working-dir directory of the container can be retrieved.
Must be a list of glob expressions relative to the current working directory, some examples: my-dir/**, my-dir/*/** or my-dir/my-file.txt..
patchStrategy string
STRATEGIC_MERGESTRATEGIC_MERGEJSON_MERGEJSON_PATCHPatch strategy
STRATEGIC_MERGE (default): Kubernetes strategic merge patch, most user-friendly. Understands K8s resource structure and intelligently merges lists by merge keys. JSON_MERGE: Simple merge with null-deletion semantics (RFC 7386). JSON_PATCH: Precision operations with add/remove/replace/test (RFC 6902).
pluginDefaultsRef Non-dynamicstring
Reference (ref) of the pluginDefaults to apply to this task.
waitRunning string
PT1HWait for pod completion
Maximum run time after reaching Running (defaults to PT1H). PodCreate fails and deletes the pod when exceeded.
waitUntilReady string
PT0SThe maximum duration to wait until the resource becomes ready
When set to a positive duration, waits for the resource to report Ready=True in its status conditions. Set to PT0S (zero, default) to skip waiting. Supports Pods, StatefulSets, and custom resources that use the Ready condition. Note: Deployments are not supported as they use the Available condition instead of Ready.
waitUntilRunning string
PT10MWait for pod to reach Running
Maximum time to reach Running (defaults to PT10M). Covers scheduling, image pulls, and startup. Used by PodCreate.
Outputs
metadata
Patched resource metadata
Metadata returned after patch application.
io.kestra.plugin.kubernetes.models.Metadata
Resource annotations
Cluster name
date-timeCreation timestamp
Deletion grace period in seconds
date-timeDeletion timestamp
Finalizers
Generated name prefix
Generation
Resource labels
Managed fields
io.fabric8.kubernetes.api.model.ManagedFieldsEntry
io.fabric8.kubernetes.api.model.FieldsV1
Resource name
Resource namespace
Owner references
io.fabric8.kubernetes.api.model.OwnerReference
Resource version
Self link
Generated UUID of this resource
status
Patched resource status
Current status snapshot (conditions, replicas, phase) after the patch.
io.kestra.plugin.kubernetes.models.ResourceStatus
The status of the Kubernetes resource
Contains the current state of the resource as a generic map structure