Skip to content

CLI Reference

Generated from this checkout's CLI commands. Examples use the kubectl bind plugin. See plugin installation.

Bundle output contains provider credentials: encrypt it or use a secret manager, never commit plaintext to git. Override --konnector-image with an explicit v2 image, the compiled latest default is not a v2 guarantee.

kubectl bind

bind is a thin client over a kbind gateway. Everything it does is reproducible by hand: binding returns a one-apply YAML bundle that a plain "kubectl apply -f" (or GitOps) consumes just as well.

kubectl bind login https://provider.example.com
kubectl bind connect                 # install the konnector
kubectl bind catalog
kubectl bind export mangodb          # bind a service
kubectl bind export mangodb -o yaml  # GitOps mode: print, don't apply
Usage:
  bind [command]

Available Commands:
  catalog     List the provider's offerings (Exports and Collections)
  clusters    List the consumer clusters connected to this provider
  connect     Connect a cluster: install/upgrade the konnector
  export      Bind a catalog Export: fetch the one-apply bundle and apply it
  instances   List the objects consumers synced under a catalog item (all items when omitted)
  login       Authenticate against a kbind gateway and cache the session

Flags:
  -h, --help            help for bind
      --server string   gateway base URL (default: the last login)
  -v, --version         version for bind

Use "bind [command] --help" for more information about a command.

kubectl bind catalog

List the provider's offerings (Exports and Collections)

Usage:
  bind catalog [flags]

Flags:
  -h, --help   help for catalog

Global Flags:
      --server string   gateway base URL (default: the last login)

kubectl bind clusters

Clusters shows which consumer clusters are heartbeating against the provider (from the konnector's Leases), what each has bound, and how many objects it is syncing.

Usage:
  bind clusters [flags]

Flags:
  -h, --help   help for clusters

Global Flags:
      --server string   gateway base URL (default: the last login)

kubectl bind connect

Connect installs the konnector (CRDs, RBAC, Deployment) into your current cluster — the only kbind component that ever runs on the consumer side. Bind services afterwards with "kubectl bind export <name>".

Reproducible by hand: curl -fsS <gateway>/api/konnector | kubectl apply -f -

Usage:
  bind connect [flags]

Flags:
  -h, --help                     help for connect
      --konnector-image string   konnector image to install (default "ghcr.io/kbind-dev/konnector:latest")
      --kubeconfig string        consumer cluster kubeconfig (default: usual kubectl resolution)

Global Flags:
      --server string   gateway base URL (default: the last login)

kubectl bind export

Bind requests credentials for an Export, picks up the one-apply bundle (Secret + Connection + ClusterBinding) and applies it to your current cluster.

With -o yaml the bundle is printed instead of applied — commit it to git and your GitOps pipeline is the client (the credentials inside stay valid until the provider revokes the grant).

Usage:
  bind export <name> [flags]

Flags:
  -h, --help                     help for export
      --install-konnector        install/upgrade the konnector before applying the bundle (default true)
      --konnector-image string   konnector image to install (default "ghcr.io/kbind-dev/konnector:latest")
      --kubeconfig string        consumer cluster kubeconfig (default: usual kubectl resolution)
  -o, --output string            print the bundle instead of applying (yaml)

Global Flags:
      --server string   gateway base URL (default: the last login)

kubectl bind instances

List the objects consumers synced under a catalog item (all items when omitted)

Usage:
  bind instances [export] [flags]

Flags:
  -h, --help   help for instances

Global Flags:
      --server string   gateway base URL (default: the last login)

kubectl bind login

Authenticate against a kbind gateway and cache the session

Usage:
  bind login <server-url> [flags]

Flags:
  -h, --help         help for login
      --no-browser   print the login URL instead of opening a browser

Global Flags:
      --server string   gateway base URL (default: the last login)