PageSourceSearch

https://archive-os-3-28.netlify.app/assets/js/94720613.eb884a5b.js

js archive-os-3-28.netlify.app collected 2026-10-03 11:35:10 UTC 11,606 bytes, 1 lines download raw bytes

1"use strict";(self.webpackChunktigera_docs=self.webpackChunktigera_docs||[]).push([["3718"],{18489:function(e,n,i){i.r(n),i.d(n,{frontMatter:()=>r,toc:()=>a,default:()=>h,metadata:()=>c,assets:()=>s,contentTitle:()=>l});var c=JSON.parse('{"id":"operations/calicoctl/configure/kdd","title":"Configure calicoctl to connect to the Kubernetes API datastore","description":"Sample configuration files for kdd.","source":"@site/calico_versioned_docs/version-3.28/operations/calicoctl/configure/kdd.mdx","sourceDirName":"operations/calicoctl/configure","slug":"/operations/calicoctl/configure/kdd","permalink":"/calico/3.28/operations/calicoctl/configure/kdd","draft":false,"unlisted":false,"editUrl":"https://github.com/tigera/docs/edit/main/calico_versioned_docs/version-3.28/operations/calicoctl/configure/kdd.mdx","tags":[],"version":"3.28","frontMatter":{"description":"Sample configuration files for kdd."},"sidebar":"calicoSidebar","previous":{"title":"Configure calicoctl to connect to an etcd datastore","permalink":"/calico/3.28/operations/calicoctl/configure/etcd"},"next":{"title":"Install using an alternate registry","permalink":"/calico/3.28/operations/image-options/"}}'),t=i(37937),o=i(17869);let r={description:"Sample configuration files for kdd."},l="Configure calicoctl to connect to the Kubernetes API datastore",s={},a=[{value:"Big picture",id:"big-picture",level:2},{value:"Value",id:"value",level:2},{value:"Concepts",id:"concepts",level:2},{value:"calicoctl vs kubectl",id:"calicoctl-vs-kubectl",level:3},{value:"Default configuration",id:"default-configuration",level:3},{value:"How to",id:"how-to",level:2},{value:"Complete list of Kubernetes API connection configuration",id:"complete-list-of-kubernetes-api-connection-configuration",level:3},{value:"Kubernetes command line",id:"kubernetes-command-line",level:3},{value:"Example configuration file",id:"example-configuration-file",level:3},{value:"Example using environment variables",id:"example-using-environment-variables",level:3},{value:"Checking the configuration",id:"checking-the-configuration",level:3},{value:"Next steps",id:"next-steps",level:2}];function d(e){let n={a:"a",admonition:"admonition",code:"code",h1:"h1",h2:"h2",h3:"h3",header:"header",li:"li",p:"p",pre:"pre",table:"table",tbody:"tbody",td:"td",th:"th",thead:"thead",tr:"tr",ul:"ul",...(0,o.R)(),...e.components};return(0,t.jsxs)(t.Fragment,{children:[(0,t.jsx)(n.header,{children:(0,t.jsx)(n.h1,{id:"configure-calicoctl-to-connect-to-the-kubernetes-api-datastore",children:"Configure calicoctl to connect to the Kubernetes API datastore"})}),"\n",(0,t.jsx)(n.h2,{id:"big-picture",children:"Big picture"}),"\n",(0,t.jsx)(n.p,{children:"Learn how to configure the calicoctl CLI tool for your Kubernetes cluster."}),"\n",(0,t.jsx)(n.h2,{id:"value",children:"Value"}),"\n",(0,t.jsxs)(n.p,{children:["The ",(0,t.jsx)(n.code,{children:"calicoctl"})," CLI tool provides helpful administrative commands for interacting with a Calico cluster."]}),"\n",(0,t.jsx)(n.h2,{id:"concepts",children:"Concepts"}),"\n",(0,t.jsx)(n.h3,{id:"calicoctl-vs-kubectl",children:"calicoctl vs kubectl"}),"\n",(0,t.jsxs)(n.p,{children:["In previous releases, calicoctl has been required to manage Calico API resources in the ",(0,t.jsx)(n.code,{children:"projectcalico.org/v3"})," API group. The calicoctl CLI tool provides important validation and defaulting on these APIs."]}),"\n",(0,t.jsxs)(n.p,{children:["In newer releases, the Calico API server performs that defaulting and validation server-side, exposing the same API semantics without a dependency on calicoctl. For this reason, we recommend\n",(0,t.jsx)(n.a,{href:"/calico/3.28/operations/install-apiserver",children:"installing the Calico API server"})," and using ",(0,t.jsx)(n.code,{children:"kubectl"})," instead of ",(0,t.jsx)(n.code,{children:"calicoctl"})," for most operations."]}),"\n",(0,t.jsx)(n.p,{children:"calicoctl is still required for the following subcommands:"}),"\n",(0,t.jsxs)(n.ul,{children:["\n",(0,t.jsx)(n.li,{children:(0,t.jsx)(n.a,{href:"/calico/3.28/reference/calicoctl/node/",children:"calicoctl node"})}),"\n",(0,t.jsx)(n.li,{children:(0,t.jsx)(n.a,{href:"/calico/3.28/reference/calicoctl/ipam/",children:"calicoctl ipam"})}),"\n",(0,t.jsx)(n.li,{children:(0,t.jsx)(n.a,{href:"/calico/3.28/reference/calicoctl/convert",children:"calicoctl convert"})}),"\n",(0,t.jsx)(n.li,{children:(0,t.jsx)(n.a,{href:"/calico/3.28/reference/calicoctl/version",children:"calicoctl version"})}),"\n"]}),"\n",(0,t.jsx)(n.h3,{id:"default-configuration",children:"Default configuration"}),"\n",(0,t.jsxs)(n.p,{children:["By default, calicoctl will attempt to read from the Kubernetes API using the default kubeconfig located at ",(0,t.jsx)(n.code,{children:"$(HOME)/.kube/config"}),"."]}),"\n",(0,t.jsx)(n.p,{children:"If the default kubeconfig does not exist, or you would like to specify alternative API access information, you can do so using the following configuration options."}),"\n",(0,t.jsx)(n.h2,{id:"how-to",children:"How to"}),"\n",(0,t.jsx)(n.h3,{id:"complete-list-of-kubernetes-api-connection-configuration",children:"Complete list of Kubernetes API connection configuration"}),"\n",(0,t.jsxs)(n.table,{children:[(0,t.jsx)(n.thead,{children:(0,t.jsxs)(n.tr,{children:[(0,t.jsx)(n.th,{children:"Configuration file option"}),(0,t.jsx)(n.th,{children:"Environment variable"}),(0,t.jsx)(n.th,{children:"Description"}),(0,t.jsx)(n.th,{children:"Schema"})]})}),(0,t.jsxs)(n.tbody,{children:[(0,t.jsxs)(n.tr,{children:[(0,t.jsx)(n.td,{children:(0,t.jsx)(n.code,{children:"datastoreType"})}),(0,t.jsx)(n.td,{children:(0,t.jsx)(n.code,{children:"DATASTORE_TYPE"})}),(0,t.jsxs)(n.td,{children:["Indicates the datastore to use. [Default: ",(0,t.jsx)(n.code,{children:"kubernetes"}),"]"]}),(0,t.jsxs)(n.td,{children:[(0,t.jsx)(n.code,{children:"kubernetes"}),", ",(0,t.jsx)(n.code,{children:"etcdv3"})]})]}),(0,t.jsxs)(n.tr,{children:[(0,t.jsx)(n.td,{children:(0,t.jsx)(n.code,{children:"kubeconfig"})}),(0,t.jsx)(n.td,{children:(0,t.jsx)(n.code,{children:"KUBECONFIG"})}),(0,t.jsx)(n.td,{children:"When using the Kubernetes datastore, the location of a kubeconfig file to use, e.g. /path/to/kube/config."}),(0,t.jsx)(n.td,{children:"string"})]}),(0,t.jsxs)(n.tr,{children:[(0,t.jsx)(n.td,{children:(0,t.jsx)(n.code,{children:"k8sAPIEndpoint"})}),(0,t.jsx)(n.td,{children:(0,t.jsx)(n.code,{children:"K8S_API_ENDPOINT"})}),(0,t.jsxs)(n.td,{children:["Location of the Kubernetes API. Not required if using kubeconfig. [Default: ",(0,t.jsx)(n.code,{children:"https://kubernetes-api:443"}),"]"]}),(0,t.jsx)(n.td,{children:"string"})]}),(0,t.jsxs)(n.tr,{children:[(0,t.jsx)(n.td,{children:(0,t.jsx)(n.code,{children:"k8sCertFile"})}),(0,t.jsx)(n.td,{children:(0,t.jsx)(n.code,{children:"K8S_CERT_FILE"})}),(0,t.jsxs)(n.td,{children:["Location of a client certificate for accessing the Kubernetes API, e.g., ",(0,t.jsx)(n.code,{children:"/path/to/cert"}),"."]}),(0,t.jsx)(n.td,{children:"string"})]}),(0,t.jsxs)(n.tr,{children:[(0,t.jsx)(n.td,{children:(0,t.jsx)(n.code,{children:"k8sKeyFile"})}),(0,t.jsx)(n.td,{children:(0,t.jsx)(n.code,{children:"K8S_KEY_FILE"})}),(0,t.jsxs)(n.td,{children:["Location of a client key for accessing the Kubernetes API, e.g., ",(0,t.jsx)(n.code,{children:"/path/to/key"}),"."]}),(0,t.jsx)(n.td,{children:"string"})]}),(0,t.jsxs)(n.tr,{children:[(0,t.jsx)(n.td,{children:(0,t.jsx)(n.code,{children:"k8sCAFile"})}),(0,t.jsx)(n.td,{children:(0,t.jsx)(n.code,{children:"K8S_CA_FILE"})}),(0,t.jsxs)(n.td,{children:["Location of a CA for accessing the Kubernetes API, e.g., ",(0,t.jsx)(n.code,{children:"/path/to/ca"}),"."]}),(0,t.jsx)(n.td,{children:"string"})]}),(0,t.jsxs)(n.tr,{children:[(0,t.jsx)(n.td,{children:(0,t.jsx)(n.code,{children:"k8sToken"})}),(0,t.jsx)(n.td,{}),(0,t.jsx)(n.td,{children:"Token to be used for accessing the Kubernetes API."}),(0,t.jsx)(n.td,{children:"string"})]})]})]}),"\n",(0,t.jsx)(n.admonition,{type:"note",children:(0,t.jsxs)(n.p,{children:["All environment variables may also be prefixed with ",(0,t.jsx)(n.code,{children:'"CALICO_"'}),", for\nexample ",(0,t.jsx)(n.code,{children:'"CALICO_DATASTORE_TYPE"'})," and ",(0,t.jsx)(n.code,{children:'"CALICO_KUBECONFIG"'})," etc. may be used.\nThis is useful if the non-prefixed names clash with existing environment\nvariables defined on your system."]})}),"\n",(0,t.jsx)(n.h3,{id:"kubernetes-command-line",children:"Kubernetes command line"}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-bash",children:"DATASTORE_TYPE=kubernetes KUBECONFIG=~/.kube/config calicoctl get nodes\n"})}),"\n",(0,t.jsx)(n.h3,{id:"example-configuration-file",children:"Example configuration file"}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-yaml",children:"apiVersion: projectcalico.org/v3\nkind: CalicoAPIConfig\nmetadata:\nspec:\n  datastoreType: 'kubernetes'\n  kubeconfig: '/path/to/.kube/config'\n"})}),"\n",(0,t.jsx)(n.h3,{id:"example-using-environment-variables",children:"Example using environment variables"}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-bash",children:"export DATASTORE_TYPE=kubernetes\nexport KUBECONFIG=~/.kube/config\ncalicoctl get workloadendpoints\n"})}),"\n",(0,t.jsxs)(n.p,{children:["And using ",(0,t.jsx)(n.code,{children:"CALICO_"})," prefixed names:"]}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-bash",children:"export CALICO_DATASTORE_TYPE=kubernetes\nexport CALICO_KUBECONFIG=~/.kube/config\ncalicoctl get workloadendpoints\n"})}),"\n",(0,t.jsxs)(n.p,{children:["With multiple ",(0,t.jsx)(n.code,{children:"kubeconfig"})," files:"]}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-bash",children:"export DATASTORE_TYPE=kubernetes\nexport KUBECONFIG=~/.kube/main:~/.kube/auxy\ncalicoctl get --context main workloadendpoints\ncalicoctl get --context auxy workloadendpoints\n"})}),"\n",(0,t.jsx)(n.h3,{id:"checking-the-configuration",children:"Checking the configuration"}
1),"\n",(0,t.jsx)(n.p,{children:"Here is a simple command to check that the installation and configuration is\ncorrect."}),"\n",(0,t.jsx)(n.pre,{children:(0,t.jsx)(n.code,{className:"language-bash",children:"calicoctl get nodes\n"})}),"\n",(0,t.jsx)(n.p,{children:"A correct setup will yield a list of the nodes that have registered. If an\nempty list is returned you are either pointed at the wrong datastore or no\nnodes have registered. If an error is returned then attempt to correct the\nissue then try again."}),"\n",(0,t.jsx)(n.h2,{id:"next-steps",children:"Next steps"}),"\n",(0,t.jsxs)(n.p,{children:["Now you are ready to read and configure most aspects of Calico. You can\nfind the full list of commands in the\n",(0,t.jsx)(n.a,{href:"/calico/3.28/reference/calicoctl/overview",children:"Command Reference"}),"."]}),"\n",(0,t.jsxs)(n.p,{children:["The full list of resources that can be managed, including a description of each,\ncan be found in the\n",(0,t.jsx)(n.a,{href:"/calico/3.28/reference/resources/overview",children:"Resource Definitions"}),"."]})]})}function h(e={}){let{wrapper:n}={...(0,o.R)(),...e.components};return n?(0,t.jsx)(n,{...e,children:(0,t.jsx)(d,{...e})}):d(e)}},17869:function(e,n,i){i.d(n,{R:()=>r,x:()=>l});var c=i(82645);let t={},o=c.createContext(t);function r(e){let n=c.useContext(o);return c.useMemo(function(){return"function"==typeof e?e(n):{...n,...e}},[n,e])}function l(e){let n;return n=e.disableParentContext?"function"==typeof e.components?e.components(t):e.components||t:r(e.components),c.createElement(o.Provider,{value:n},e.children)}}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.