如何将指定kubectl镜像更新命令转换为curl REST API调用?
kubectl set image to Kubernetes REST API curl call Got it, let's break down how to turn that kubectl set image deployment/mydep mypot=img --insecure-skip-tls-verify command into a direct curl request to the Kubernetes API. No kubectl middleman required — here's what you need to do:
1. Grab your Kubernetes API server address
First, you'll need the URL of your cluster's API server. If you don't have it handy, pull it with this quick command:
kubectl cluster-info | grep 'Kubernetes control plane' | awk '{print $NF}'
2. Prepare the patch payload
We'll use a strategic merge patch to update only the container image (instead of overwriting the entire Deployment spec). Create a file named patch.json with this content:
{ "spec": { "template": { "spec": { "containers": [ { "name": "mypot", "image": "img" } ] } } } }
This targets exactly the mypot container in your Deployment's pod template and updates its image to img.
3. Full curl command
This command includes authentication (using the default service account token) and skips TLS verification to match the original --insecure-skip-tls-verify flag:
curl -k -X PATCH \ -H "Authorization: Bearer $(kubectl get secret $(kubectl get serviceaccount default -o jsonpath='{.secrets[0].name}') -o jsonpath='{.data.token}' | base64 -d)" \ -H "Content-Type: application/strategic-merge-patch+json" \ -d @patch.json \ https://<YOUR_KUBE_APISERVER>/apis/apps/v1/namespaces/default/deployments/mydep
Quick notes:
- If your Deployment lives in a non-default namespace, replace
defaultin the API endpoint URL with your target namespace. - The
application/strategic-merge-patch+jsoncontent type is critical here — it tells the Kubernetes API how to safely merge your changes with the existing Deployment spec. - If you don't want to use the default service account, swap the token with one from a service account that has
updatepermissions for Deployments.
内容的提问来源于stack exchange,提问作者Jonas

