IBM Cloud Kubernetes Service CLI Map
This page lists all ibmcloud ks commands as they are structured in the CLI. For more details on a specific command, click the command or see the IBM Cloud Kubernetes Service CLI reference.
api commands
View the current API endpoint.
* [`ibmcloud ks api`](/docs/containers?topic=containers-kubernetes-service-cli#api-cli)
api-key commands
View information about the API key for a cluster or reset it to a new key.
* [`ibmcloud ks api-key info`](/docs/containers?topic=containers-kubernetes-service-cli#api-key-info-cli)
* [`ibmcloud ks api-key reset`](/docs/containers?topic=containers-kubernetes-service-cli#api-key-reset-cli)
cluster commands
View and modify cluster and cluster service settings.
cluster addon: View, enable, update, and disable cluster add-ons.cluster ca: Manage the Certificate Authority (CA) certificates of a cluster.cluster create: Create a classic or VPC cluster.cluster image-security: Manage image security enforcement in your cluster.cluster master: View and modify the master for a cluster.cluster pull-secret: Manage image pull secrets for the cluster to access images in IBM Cloud Container Registry.cluster service: View, bind, and unbind IBM Cloud services on a cluster.cluster subnet: Add and create portable subnets for a classic cluster.ibmcloud ks cluster addon disable acmibmcloud ks cluster addon disable alb-oauth-proxyibmcloud ks cluster addon disable cluster-autoscaleribmcloud ks cluster addon disable debug-tool- Beta
ibmcloud ks cluster addon disable headlamp ibmcloud ks cluster addon disable hpcs-router- Beta
ibmcloud ks cluster addon disable ibm-storage-operator ibmcloud ks cluster addon disable image-key-synchronizeribmcloud ks cluster addon disable istio- Deprecated
ibmcloud ks cluster addon disable istio-extras - Deprecated
ibmcloud ks cluster addon disable istio-sample-bookinfo ibmcloud ks cluster addon disable knativeibmcloud ks cluster addon disable kube-terminalibmcloud ks cluster addon disable openshift-data-foundationibmcloud ks cluster addon disable static-routeibmcloud ks cluster addon disable vpc-block-csi-driveribmcloud ks cluster addon enable acmibmcloud ks cluster addon enable alb-oauth-proxyibmcloud ks cluster addon enable cluster-autoscaleribmcloud ks cluster addon enable debug-tool- Beta
ibmcloud ks cluster addon enable headlamp ibmcloud ks cluster addon enable hpcs-router- Beta
ibmcloud ks cluster addon enable ibm-storage-operator ibmcloud ks cluster addon enable image-key-synchronizeribmcloud ks cluster addon enable istio- Deprecated
ibmcloud ks cluster addon enable istio-extras - Deprecated
ibmcloud ks cluster addon enable istio-sample-bookinfo ibmcloud ks cluster addon enable openshift-data-foundationibmcloud ks cluster addon enable static-routeibmcloud ks cluster addon enable vpc-block-csi-driveribmcloud ks cluster addon getibmcloud ks cluster addon lsibmcloud ks cluster addon optionsibmcloud ks cluster addon update acmibmcloud ks cluster addon update alb-oauth-proxyibmcloud ks cluster addon update cluster-autoscaleribmcloud ks cluster addon update debug-tool- Beta
ibmcloud ks cluster addon update headlamp ibmcloud ks cluster addon update hpcs-router- Beta
ibmcloud ks cluster addon update ibm-storage-operator ibmcloud ks cluster addon update image-key-synchronizeribmcloud ks cluster addon update istio- Deprecated
ibmcloud ks cluster addon update istio-extras - Deprecated
ibmcloud ks cluster addon update istio-sample-bookinfo ibmcloud ks cluster addon update knativeibmcloud ks cluster addon update kube-terminalibmcloud ks cluster addon update openshift-data-foundationibmcloud ks cluster addon update static-routeibmcloud ks cluster addon update vpc-block-csi-driveribmcloud ks cluster addon versionsibmcloud ks cluster ca createibmcloud ks cluster ca getibmcloud ks cluster ca rotateibmcloud ks cluster ca statusibmcloud ks cluster configibmcloud ks cluster create classicibmcloud ks cluster create satelliteibmcloud ks cluster create vpc-classicibmcloud ks cluster create vpc-gen2ibmcloud ks cluster getibmcloud ks cluster image-security disableibmcloud ks cluster image-security enableibmcloud ks cluster lsibmcloud ks cluster master audit-webhook getibmcloud ks cluster master audit-webhook setibmcloud ks cluster master audit-webhook unsetibmcloud ks cluster master console-oauth-access getibmcloud ks cluster master console-oauth-access setibmcloud ks cluster master pod-security getibmcloud ks cluster master pod-security policy disableibmcloud ks cluster master pod-security policy enableibmcloud ks cluster master pod-security policy getibmcloud ks cluster master pod-security setibmcloud ks cluster master pod-security unset- Deprecated
ibmcloud ks cluster master private-service-endpoint allowlist add - Deprecated
ibmcloud ks cluster master private-service-endpoint allowlist disable - Deprecated
ibmcloud ks cluster master private-service-endpoint allowlist enable - Deprecated
ibmcloud ks cluster master private-service-endpoint allowlist get - Deprecated
ibmcloud ks cluster master private-service-endpoint allowlist rm ibmcloud ks cluster master private-service-endpoint enableibmcloud ks cluster master public-service-endpoint disableibmcloud ks cluster master public-service-endpoint enableibmcloud ks cluster master refreshibmcloud ks cluster master satellite-service-endpoint allowlist addibmcloud ks cluster master satellite-service-endpoint allowlist disableibmcloud ks cluster master satellite-service-endpoint allowlist enableibmcloud ks cluster master satellite-service-endpoint allowlist getibmcloud ks cluster master satellite-service-endpoint allowlist rmibmcloud ks cluster master updateibmcloud ks cluster pull-secret applyibmcloud ks cluster rmibmcloud ks cluster service bindibmcloud ks cluster service lsibmcloud ks cluster service unbindibmcloud ks cluster subnet addibmcloud ks cluster subnet createibmcloud ks cluster subnet detach
credential commands
Set and unset credentials that allow you to access the IBM Cloud classic infrastructure portfolio through your IBM Cloud account.
credential set: Set credentials that allow you to access the IBM Cloud classic infrastructure portfolio through your IBM Cloud account. This command applies to the targeted resource group, or to the default resource group if no resource group is targeted.
experimental commands
[Expires on 2026-10-21] Experiment with new commands. IMPORTANT: Commands here will retire after the [date] in their description.
experimental trusted-profile: [Expires on 2026-10-21] View and set the trusted profile on a cluster or the default trusted profile for clusters created in a resource-group.experimental vni: [Deactivated on 2026-05-20! Useibmcloud ks vniinstead] Attach, detach, and list Virtual Network Interfaces on worker nodes.ibmcloud ks experimental trusted-profile default getibmcloud ks experimental trusted-profile default setibmcloud ks experimental trusted-profile getibmcloud ks experimental trusted-profile setibmcloud ks experimental vni attach baremetalibmcloud ks experimental vni attach virtualibmcloud ks experimental vni detachibmcloud ks experimental vni ls
flavor commands
Getting flavor related information. Flavors determine how much virtual CPU, memory, and disk space is available to each worker node.
* [`ibmcloud ks flavor get`](/docs/containers?topic=containers-kubernetes-service-cli#flavor-get-cli)
* [`ibmcloud ks flavor ls`](/docs/containers?topic=containers-kubernetes-service-cli#flavor-ls-cli)
infra-permissions commands
View information about infrastructure permissions that allow you to access the IBM Cloud classic infrastructure portfolio through your IBM Cloud account.
* [`ibmcloud ks infra-permissions get`](/docs/containers?topic=containers-kubernetes-service-cli#infra-permissions-get-cli)
ingress commands
View and modify Ingress services and settings
ingress alb: View and configure an Ingress application load balancer (ALB).ingress domain: Manage a cluster's Ingress domains.ingress instance: Manage registered instances of the IBM Cloud Secrets Manager.ingress load-balancer: Modify load balancers that expose Ingress ALBs in your cluster.ingress secret: Manage Ingress secrets in a cluster.ingress security: Modify the ingress security configuration for your cluster.ingress status-report: View and configure Ingress status reports.ibmcloud ks ingress alb autoscale getibmcloud ks ingress alb autoscale setibmcloud ks ingress alb autoscale unsetibmcloud ks ingress alb autoupdate disableibmcloud ks ingress alb autoupdate enableibmcloud ks ingress alb autoupdate getibmcloud ks ingress alb create classicibmcloud ks ingress alb create vpc-gen2ibmcloud ks ingress alb disableibmcloud ks ingress alb enable classicibmcloud ks ingress alb enable vpc-gen2ibmcloud ks ingress alb getibmcloud ks ingress alb health-checker disableibmcloud ks ingress alb health-checker enableibmcloud ks ingress alb health-checker getibmcloud ks ingress alb lsibmcloud ks ingress alb updateibmcloud ks ingress alb versionsibmcloud ks ingress domain createibmcloud ks ingress domain default replaceibmcloud ks ingress domain getibmcloud ks ingress domain lsibmcloud ks ingress domain rmibmcloud ks ingress domain secret regenerateibmcloud ks ingress domain secret rmibmcloud ks ingress domain updateibmcloud ks ingress instance default setibmcloud ks ingress instance default unsetibmcloud ks ingress instance getibmcloud ks ingress instance lsibmcloud ks ingress instance registeribmcloud ks ingress instance unregisteribmcloud ks ingress load-balancer backend setibmcloud ks ingress load-balancer getibmcloud ks ingress load-balancer proxy-protocol disableibmcloud ks ingress load-balancer proxy-protocol enableibmcloud ks ingress secret createibmcloud ks ingress secret field addibmcloud ks ingress secret field lsibmcloud ks ingress secret field rmibmcloud ks ingress secret getibmcloud ks ingress secret lsibmcloud ks ingress secret rmibmcloud ks ingress secret updateibmcloud ks ingress security port80 disableibmcloud ks ingress security port80 enableibmcloud ks ingress security port80 getibmcloud ks ingress status-report disableibmcloud ks ingress status-report enableibmcloud ks ingress status-report getibmcloud ks ingress status-report ignored-errors addibmcloud ks ingress status-report ignored-errors lsibmcloud ks ingress status-report ignored-errors rm
kms commands
View and configure Key Management Service integrations.
kms crk: List and configure the root keys for a Key Management Service instance.kms instance: View and configure available Key Management Service instances.
locations commands
List supported IBM Cloud Kubernetes Service locations.
* [`ibmcloud ks locations`](/docs/containers?topic=containers-kubernetes-service-cli#locations-cli)
logging commands
Forward logs from your cluster.
logging autoupdate: Manage automatic updates of the Fluentd add-on in a cluster.logging config: View or modify log forwarding configurations for a cluster.logging filter: View or modify log filters for a cluster.ibmcloud ks logging autoupdate disableibmcloud ks logging autoupdate enableibmcloud ks logging autoupdate getibmcloud ks logging config createibmcloud ks logging config getibmcloud ks logging config rmibmcloud ks logging config updateibmcloud ks logging filter createibmcloud ks logging filter getibmcloud ks logging filter rmibmcloud ks logging filter updateibmcloud ks logging refresh
messages commands
View the current user messages.
* [`ibmcloud ks messages`](/docs/containers?topic=containers-kubernetes-service-cli#messages-cli)
nlb-dns commands
Create and manage host names for network load balancer (NLB) IP addresses in a cluster and health check monitors for host names.
nlb-dns create: Create a DNS host name.nlb-dns monitor: Create and manage health check monitors for network load balancer (NLB) IP addresses and host names in a clusternlb-dns rm: Remove an NLB IP or load balancer host name from an NLB host name.nlb-dns secret: Manage the secret for an NLB subdomain.ibmcloud ks nlb-dns addibmcloud ks nlb-dns create classicibmcloud ks nlb-dns create vpc-gen2ibmcloud ks nlb-dns getibmcloud ks nlb-dns lsibmcloud ks nlb-dns monitor configureibmcloud ks nlb-dns monitor disableibmcloud ks nlb-dns monitor enableibmcloud ks nlb-dns monitor getibmcloud ks nlb-dns monitor lsibmcloud ks nlb-dns replaceibmcloud ks nlb-dns rm classicibmcloud ks nlb-dns rm vpc-gen2ibmcloud ks nlb-dns secret regenerateibmcloud ks nlb-dns secret rm
quota commands
View the quota and limits for cluster-related resources in your IBM Cloud account.
* [`ibmcloud ks quota ls`](/docs/containers?topic=containers-kubernetes-service-cli#quota-ls-cli)
script commands
Rewrite scripts that call IBM Cloud Kubernetes Service plug-in commands. Legacy-structured commands are replaced with beta-structured commands.
* [`ibmcloud ks script update`](/docs/containers?topic=containers-kubernetes-service-cli#script-update-cli)
security-group commands
Run operations against a security group.
* [`ibmcloud ks security-group ls`](/docs/containers?topic=containers-kubernetes-service-cli#security-group-ls-cli)
* [`ibmcloud ks security-group reset`](/docs/containers?topic=containers-kubernetes-service-cli#security-group-reset-cli)
* [`ibmcloud ks security-group sync`](/docs/containers?topic=containers-kubernetes-service-cli#security-group-sync-cli)
storage commands
View and modify storage resources.
storage attachment: View and modify storage volume attachments of worker nodes in your cluster.storage volume: View a list of storage volumes.
subnets commands
List available portable subnets in your IBM Cloud infrastructure account.
* [`ibmcloud ks subnets`](/docs/containers?topic=containers-kubernetes-service-cli#subnets-cli)
versions commands
List all the container platform versions that are available for IBM Cloud Kubernetes Service clusters.
* [`ibmcloud ks versions`](/docs/containers?topic=containers-kubernetes-service-cli#versions-cli)
vlan commands
List public and private VLANs for a zone and view the VLAN spanning status.
vlan spanning: View the VLAN spanning status for your IBM Cloud classic infrastructure account.
vni commands
Attach, detach, and list Virtual Network Interfaces on worker nodes.
vni attach: Attach a Virtual Network Interface to a worker node.
vpc commands
Get information about VPCs and manage VPC clusters.
vpc outbound-traffic-protection: Change the outbound traffic protection for a Secure By Default VPC cluster.vpc secure-by-default: Modify Secure By Default Network settings for a VPC cluster.
webhook-create commands
Register a webhook in a cluster.
* [`ibmcloud ks webhook-create`](/docs/containers?topic=containers-kubernetes-service-cli#webhook-create-cli)
worker commands
View and modify worker nodes for a cluster.
* [`ibmcloud ks worker get`](/docs/containers?topic=containers-kubernetes-service-cli#worker-get-cli)
* [`ibmcloud ks worker ls`](/docs/containers?topic=containers-kubernetes-service-cli#worker-ls-cli)
* [`ibmcloud ks worker reboot`](/docs/containers?topic=containers-kubernetes-service-cli#worker-reboot-cli)
* [`ibmcloud ks worker reload`](/docs/containers?topic=containers-kubernetes-service-cli#worker-reload-cli)
* [`ibmcloud ks worker replace`](/docs/containers?topic=containers-kubernetes-service-cli#worker-replace-cli)
* [`ibmcloud ks worker rm`](/docs/containers?topic=containers-kubernetes-service-cli#worker-rm-cli)
* [`ibmcloud ks worker update`](/docs/containers?topic=containers-kubernetes-service-cli#worker-update-cli)
worker-pool commands
View and modify worker pools for a cluster.
worker-pool create: Add a worker pool to a cluster. No worker nodes are created until zones are added to the worker pool.worker-pool label: Set and remove custom Kubernetes labels for all worker nodes in a worker pool.worker-pool operating-system: Manage the operating system of a worker pool.worker-pool taint: Set and remove Kubernetes taints for all worker nodes in a worker pool.ibmcloud ks worker-pool create classicibmcloud ks worker-pool create satelliteibmcloud ks worker-pool create vpc-classicibmcloud ks worker-pool create vpc-gen2ibmcloud ks worker-pool getibmcloud ks worker-pool label rmibmcloud ks worker-pool label setibmcloud ks worker-pool lsibmcloud ks worker-pool operating-system setibmcloud ks worker-pool rebalanceibmcloud ks worker-pool resizeibmcloud ks worker-pool rmibmcloud ks worker-pool taint rmibmcloud ks worker-pool taint setibmcloud ks worker-pool zones
zone commands
List availability zones and modify the zones attached to a worker pool.
zone add: Add a zone to one or more worker pools in a cluster.