如何使用Kubernetes Python CLI列出并描述指定命名空间的Certificate资源
操作步骤
先确保本地kubeconfig已配置完成,Python环境安装好kubernetes依赖:
pip install kubernetes
1. 列出指定命名空间下的所有Certificate资源
对应kubectl get certificates -n my-namespace的效果,Python代码示例如下:
from kubernetes import client, config from kubernetes.client.api import custom_objects_api # 本地调试加载kubeconfig,集群内运行可替换为config.load_incluster_config() config.load_kube_config() custom_api = custom_objects_api.CustomObjectsApi() # 替换为你的目标命名空间 namespace = "my-namespace" # 查询指定命名空间下的全部Certificate资源 cert_list = custom_api.list_namespaced_custom_object( group="cert-manager.io", version="v1", namespace=namespace, plural="certificates" ) # 输出基础信息,和kubectl get的输出对应 for cert in cert_list["items"]: status = cert['status']['conditions'][0]['type'] if 'status' in cert else '未就绪' print(f"证书名称:{cert['metadata']['name']},当前状态:{status}")
2. 单个Certificate详情查询(对应describe操作)
对应kubectl describe certificate my-certificate -n my-namespace的效果,Python代码示例如下:
from kubernetes import client, config from kubernetes.client.api import custom_objects_api import json config.load_kube_config() custom_api = custom_objects_api.CustomObjectsApi() # 替换为你的目标命名空间和证书名称 namespace = "my-namespace" cert_name = "my-certificate" # 查询指定证书的全量详情 cert_detail = custom_api.get_namespaced_custom_object( group="cert-manager.io", version="v1", namespace=namespace, plural="certificates", name=cert_name ) # 输出格式化后的详情,也可以按需提取对应的字段 print(json.dumps(cert_detail, indent=2, ensure_ascii=False))
注意:如果集群中安装的cert-manager版本较低,对应的API版本可能不是v1,可执行
kubectl api-resources | grep certificates查询当前集群Certificate资源对应的GROUP和VERSION值,替换代码中对应的参数即可。
内容的提问来源于stack exchange,提问作者marcin_
相关产品推荐
相关产品推荐

