A kubeconfig holds three lists. Clusters are API server addresses with the CA certificate that proves them; users are credentials (client certificates, tokens or an exec plugin that fetches them); contexts pair a cluster with a user and an optional default namespace. current-context picks the pair kubectl 5,150 uses. kubectl reads ~/.kube/config, or every file listed in KUBECONFIG (colon-separated) merged in order:
kubectl config view --minify
export KUBECONFIG=~/.kube/config:~/.kube/jenkins-l3-booknest.kubeconfig
kubectl config get-contexts && unset KUBECONFIGapiVersion: v1
clusters:
- cluster:
certificate-authority-data: DATA+OMITTED
server: https://127.0.0.1:33443
name: kind-l3-booknest
contexts:
- context:
cluster: kind-l3-booknest
user: kind-l3-booknest
name: kind-l3-booknest
current-context: kind-l3-booknest
kind: Config
users:
- name: kind-l3-booknest
user:
client-certificate-data: DATA+OMITTED
client-key-data: DATA+OMITTED
CURRENT NAME CLUSTER AUTHINFO NAMESPACE
jenkins l3-booknest jenkins jenkins
* kind-l3-booknest kind-l3-booknest kind-l3-booknest--minify shows only what the current context uses, and view hides key material as DATA+OMITTED (--raw reveals it). kind 14,561 's client certificate puts you in the group kubeadm 5,150 :cluster-admins, as kubectl auth whoami confirms: full administrator rights. Where merged files define the same name, the first file wins.
Switch with kubectl config use-context jenkins, or --context jenkins for one command; kubectl config set-context --current --namespace=booknest changes the default namespace. kubectx 20,017 and kubens (github.com/ahmetb/kubectx (https://github.com/ahmetb/kubectx 20,017 ), Apache-2.0) shorten both to a word. Treat every kubeconfig as a password file, and prefer exec plugins (such as aws eks get-token) that mint short-lived tokens.