DigitalOcean GetKubeconfig

DigitalOcean GetKubeconfig

Certified

Download a DigitalOcean Kubernetes cluster's kubeconfig

Fetches the kubeconfig for a Kubernetes (DOKS) cluster and stores it in Kestra internal storage. The kubeconfig contains a client certificate and key, so it is never returned inline as a string output; only a storage URI is returned. Use it with a downstream task that accepts a kubeconfig file, such as io.kestra.plugin.kubernetes tasks.

yaml
type: io.kestra.plugin.digitalocean.kubernetes.GetKubeconfig

Download a cluster's kubeconfig for use in a later task

yaml
id: digitalocean_get_kubeconfig
namespace: company.team

tasks:
  - id: get_kubeconfig
    type: io.kestra.plugin.digitalocean.kubernetes.GetKubeconfig
    apiToken: "{{ secret('DIGITALOCEAN_TOKEN') }}"
    clusterId: "3fa85f64-5717-4562-b3fc-2c963f66afa6"
Properties

DigitalOcean API token

Personal access token used to authenticate against the DigitalOcean API v2, sent as Authorization: Bearer <token>. Create one (prefixed dop_v1_) in the DigitalOcean control panel under API > Tokens, and store it as a Kestra secret.

Cluster ID

UUID of the Kubernetes cluster whose kubeconfig to download.

Assets this task consumes as inputs or produces as outputs, for lineage tracking and the asset graph (Enterprise Edition). A flow declaring this property on a task is rejected in the open-source edition.

Definitions
assetFailureBehaviorstring
Possible Values
IGNOREFAILWARN

Asset failure behavior

Behavior applied to the task state when a declared asset fails to render, emit, or be persisted (e.g. a lock conflict): FAIL escalates it to FAILED, WARN (default) warns it if it would otherwise succeed, IGNORE leaves the state untouched.

enableAutobooleanstring

Whether to auto-register assets referenced dynamically at runtime that are not statically declared in inputs or outputs.

inputsarray

The assets consumed as inputs.

id*string
Min length1
typestring
outputs

The assets produced as outputs.

id*string
Min length1
Max length150
type*object
descriptionstring
displayNamestring
metadataobject
Default{}
namespacestring
Min length1
Max length150
id*string
Min length1
Max length150
type*object
descriptionstring
displayNamestring
metadataobject
Default{}
namespacestring
Min length1
Max length150
id*string
Min length1
Max length150
type*object
descriptionstring
displayNamestring
metadataobject
Default{}
namespacestring
Min length1
Max length150
id*string
Min length1
Max length150
type*object
descriptionstring
displayNamestring
metadataobject
Default{}
namespacestring
Min length1
Max length150
id*string
Min length1
Max length150
type*object
descriptionstring
displayNamestring
metadataobject
Default{}
namespacestring
Min length1
Max length150
id*string
Min length1
Max length150
type*string
Min length1

Custom asset type

descriptionstring
displayNamestring
metadataobject
Default{}
namespacestring
Min length1
Max length150
Defaulthttps://api.digitalocean.com

DigitalOcean API base URL

Base endpoint for all DigitalOcean API calls. Defaults to https://api.digitalocean.com.

HTTP client options

Optional HTTP configuration (timeouts, proxy, SSL) applied to every DigitalOcean API call.

Definitions
allowFailedbooleanstring
Defaultfalse

If true, allow a failed response code (response code >= 400)

allowedResponseCodesarray
SubTypeinteger

List of response code allowed for this request

auth

The authentication to use.

type*object
passwordstring

The password for HTTP basic authentication.

usernamestring

The username for HTTP basic authentication.

type*object
tokenstring

The token for bearer token authentication.

type*object
passwordstring

The password for HTTP Digest authentication.

usernamestring

The username for HTTP Digest authentication.

defaultCharsetstring
DefaultUTF-8

The default charset for the request.

enabledTcpExtendedKeepAlivebooleanstring
Defaulttrue

Whether to enable TCP Keep-Alive extended socket options (TCP_KEEPIDLE, TCP_KEEPINTERVAL, TCP_KEEPCOUNT).

Set to false when running on Windows workers, as these extended socket options are not supported by the Windows JDK and will cause connection failures.

followRedirectsbooleanstring
Defaulttrue

Whether redirects should be followed automatically.

logsarray
SubTypestring
Possible Values
REQUEST_HEADERSREQUEST_BODYRESPONSE_HEADERSRESPONSE_BODY

The enabled log.

proxy

The proxy configuration.

addressstring

The address of the proxy server.

passwordstring

The password for proxy authentication.

portintegerstring

The port of the proxy server.

typestring
DefaultDIRECT
Possible Values
DIRECTHTTPSOCKS

The type of proxy to use.

usernamestring

The username for proxy authentication.

ssl

The SSL request options

insecureTrustAllCertificatesbooleanstring

Whether to disable checking of the remote SSL certificate.

Only applies if no trust store is configured. Note: This makes the SSL connection insecure and should only be used for testing. If you are using a self-signed certificate, set up a trust store instead.

timeout

The timeout configuration.

connectTimeoutstring

The time allowed to establish a connection to the server before failing.

readIdleTimeoutstring
DefaultPT5M

The time allowed for a read connection to remain idle before closing it.

Formaturi

Kubeconfig URI

URI of the kubeconfig YAML file in Kestra internal storage.