<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Cli on Lead DevOps</title><link>https://lead-devops.blackdevhub.online/en/tags/cli/</link><description>Recent content in Cli on Lead DevOps</description><generator>Hugo</generator><language>en-US</language><lastBuildDate>Thu, 24 Sep 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://lead-devops.blackdevhub.online/en/tags/cli/index.xml" rel="self" type="application/rss+xml"/><item><title>kubectl cheatsheet: essential commands for Kubernetes</title><link>https://lead-devops.blackdevhub.online/en/posts/kubectl-cheatsheet/</link><pubDate>Thu, 24 Sep 2026 00:00:00 +0000</pubDate><guid>https://lead-devops.blackdevhub.online/en/posts/kubectl-cheatsheet/</guid><description>&lt;p&gt;kubectl is the primary interface to a Kubernetes cluster. This cheatheet covers routine operations — from context setup to pod debugging and namespace switching. All commands are verified against current kubectl versions (1.28+).&lt;/p&gt;&#10;&lt;h2 id="installation-and-context-setup"&gt;Installation and Context Setup&#10;&lt;/h2&gt;&#10;&lt;p&gt;Installation depends on your OS. On Linux, use the package manager or the binary directly:&lt;/p&gt;&#10;&lt;div class="td-code td-code--untitled" id="td-code-e824e41a-fence-0" data-td-code data-td-code-auto-id&#10; data-td-language="bash" data-td-line-count="3"&gt;&#10; &lt;div class="td-code__viewport" id="td-code-e824e41a-fence-0-viewport" data-td-code-viewport&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;curl -LO &lt;span class="s2"&gt;&amp;#34;https://dl.k8s.io/release/&lt;/span&gt;&lt;span class="k"&gt;$(&lt;/span&gt;curl -L -s https://dl.k8s.io/release/stable.txt&lt;span class="k"&gt;)&lt;/span&gt;&lt;span class="s2"&gt;/bin/linux/amd64/kubectl&amp;#34;&lt;/span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;chmod +x kubectl &lt;span class="o"&gt;&amp;amp;&amp;amp;&lt;/span&gt; sudo mv kubectl /usr/local/bin/&#10;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;kubectl version --client&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&#10;&lt;/div&gt;&#10;&lt;p&gt;Configuration lives in &lt;code&gt;~/.kube/config&lt;/code&gt;. A context defines the cluster, user, and default namespace.&lt;/p&gt;</description></item><item><title>Git Tag: Marking Releases and Bookmarks in History</title><link>https://lead-devops.blackdevhub.online/en/posts/git-tag/</link><pubDate>Wed, 23 Sep 2026 00:00:00 +0000</pubDate><guid>https://lead-devops.blackdevhub.online/en/posts/git-tag/</guid><description>&lt;h2 id="git-tag-marking-releases-and-bookmarks-in-history"&gt;Git Tag: Marking Releases and Bookmarks in History&#10;&lt;/h2&gt;&#10;&lt;p&gt;Tags are Git&amp;rsquo;s mechanism for assigning meaningful labels to specific commits. Unlike branches, tags don&amp;rsquo;t move — they&amp;rsquo;re pinned to a commit and serve as anchors for releases, versions, and critical checkpoints. Without tags, release history devolves into a hash search — and that&amp;rsquo;s a direct path to deployment errors.&lt;/p&gt;&#10;&lt;hr&gt;&#10;&lt;h2 id="types-of-tags-lightweight-vs-annotated"&gt;Types of Tags: Lightweight vs Annotated&#10;&lt;/h2&gt;&#10;&lt;p&gt;There are two types of tags. Lightweight is just a name attached to a commit, with no additional metadata. Annotated is a full Git object with author, date, message, and signing capability.&lt;/p&gt;</description></item><item><title>pipx: Isolated Python CLI Tools Without the Mess</title><link>https://lead-devops.blackdevhub.online/en/posts/pipx/</link><pubDate>Thu, 10 Sep 2026 00:00:00 +0000</pubDate><guid>https://lead-devops.blackdevhub.online/en/posts/pipx/</guid><description>&lt;p&gt;pipx solves a simple but chronic problem: you need to run a Python utility once or occasionally, and &lt;code&gt;pip install&lt;/code&gt; pollutes the global environment or leaves behind a virtual environment you forget to clean up. pipx creates an isolated venv for each utility, installs dependencies there, and makes the binary available in &lt;code&gt;$PATH&lt;/code&gt;. One command and the tool works without conflicting with anything.&lt;/p&gt;&#10;&lt;h2 id="what-is-pipx-and-why-you-need-it"&gt;What Is pipx and Why You Need It&#10;&lt;/h2&gt;&#10;&lt;p&gt;pipx installs and runs Python applications in isolated virtual environments. Each utility lives in its own venv under &lt;code&gt;~/.local/pipx/venvs/&lt;/code&gt;, and its console-scripts are symlinked into &lt;code&gt;~/.local/bin/&lt;/code&gt;.&lt;/p&gt;</description></item><item><title>ip: Network Setup and Diagnostics in CLI</title><link>https://lead-devops.blackdevhub.online/en/posts/ip-command-network-cli/</link><pubDate>Mon, 07 Sep 2026 00:00:00 +0000</pubDate><guid>https://lead-devops.blackdevhub.online/en/posts/ip-command-network-cli/</guid><description>&lt;p&gt;When ifconfig returns nothing and configuring a route requires a separate command, that&amp;rsquo;s not a system bug. It&amp;rsquo;s iproute2 — the package that replaced net-tools in modern Linux distributions. The &lt;code&gt;ip&lt;/code&gt; utility from iproute2 is the standard interface for managing the Linux network stack. It covers interfaces, addresses, routes, ARP cache, routing policies, and namespace isolation.&lt;/p&gt;&#10;&lt;h2 id="why-iproute2-replaced-net-tools"&gt;Why iproute2 replaced net-tools&#10;&lt;/h2&gt;&#10;&lt;p&gt;net-tools (ifconfig, route, arp, netstat, nameif) originated in BSD and migrated to Linux in the 1990s. By the 2000s it became clear: they cannot handle VLAN, IPsec, QoS, multicast routing, or Policy Routing. Each task required a separate command with unrelated syntax.&lt;/p&gt;</description></item><item><title>OpenSSL: TLS Certificate Verification and Parsing in CLI</title><link>https://lead-devops.blackdevhub.online/en/posts/openssl-check-tls-certificates/</link><pubDate>Sun, 06 Sep 2026 00:00:00 +0000</pubDate><guid>https://lead-devops.blackdevhub.online/en/posts/openssl-check-tls-certificates/</guid><description>&lt;p&gt;Certificates expiring on prod at the worst moment — a familiar story. OpenSSL answers TLS certificate questions faster than any marketplace checker. Here are the key scenarios without the fluff.&lt;/p&gt;&#10;&lt;h2 id="basic-certificate-parsing"&gt;Basic Certificate Parsing&#10;&lt;/h2&gt;&#10;&lt;p&gt;The first command for any diagnostics is the text dump:&lt;/p&gt;&#10;&lt;div class="td-code td-code--untitled" id="td-code-63c22da9-fence-0" data-td-code data-td-code-auto-id&#10; data-td-language="bash" data-td-line-count="1"&gt;&#10; &lt;div class="td-code__viewport" id="td-code-63c22da9-fence-0-viewport" data-td-code-viewport&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;openssl x509 -text -noout -in cert.pem&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&#10;&lt;/div&gt;&#10;&lt;p&gt;Output shows Subject, Issuer, validity dates, signature algorithm, and public key. For a quick summary without the wall of text:&lt;/p&gt;</description></item><item><title>curl: HTTP Debugging in CLI</title><link>https://lead-devops.blackdevhub.online/en/posts/curl-http-debugging-cli/</link><pubDate>Fri, 04 Sep 2026 00:00:00 +0000</pubDate><guid>https://lead-devops.blackdevhub.online/en/posts/curl-http-debugging-cli/</guid><description>&lt;p&gt;cURL is the standard tool for debugging HTTP in the terminal. It ships out of the box on Linux and macOS and is present in most Docker images. Need to quickly check an API, inspect response headers, or trace a redirect issue — one command line is enough.&lt;/p&gt;&#10;&lt;h2 id="basic-debug-flags"&gt;Basic Debug Flags&#10;&lt;/h2&gt;&#10;&lt;p&gt;The most common scenario: get a response and see what the server returned. The &lt;code&gt;-i&lt;/code&gt; flag prints headers before the body, &lt;code&gt;-v&lt;/code&gt; enables verbose mode with connection details.&lt;/p&gt;</description></item><item><title>ss: socket statistics instead of deprecated netstat</title><link>https://lead-devops.blackdevhub.online/en/posts/ss-replace-netstat/</link><pubDate>Thu, 03 Sep 2026 00:00:00 +0000</pubDate><guid>https://lead-devops.blackdevhub.online/en/posts/ss-replace-netstat/</guid><description>&lt;p&gt;When &lt;code&gt;netstat&lt;/code&gt; hangs on a server with tens of thousands of connections, it&amp;rsquo;s time to switch to &lt;code&gt;ss&lt;/code&gt;. Part of the &lt;code&gt;iproute2&lt;/code&gt; package, &lt;code&gt;ss&lt;/code&gt; queries the kernel directly via netlink instead of parsing &lt;code&gt;/proc/net/*&lt;/code&gt;. The result is instant output with minimal overhead.&lt;/p&gt;&#10;&lt;h2 id="why-switch-from-netstat"&gt;Why switch from netstat&#10;&lt;/h2&gt;&#10;&lt;p&gt;&lt;code&gt;netstat&lt;/code&gt; from &lt;code&gt;net-tools&lt;/code&gt; relies on a deprecated approach: it reads from &lt;code&gt;/proc/net/tcp&lt;/code&gt;, &lt;code&gt;/proc/net/unix&lt;/code&gt; and converts numeric IDs to symbolic names. On a server with active connections, this takes seconds and spikes CPU usage.&lt;/p&gt;</description></item></channel></rss>