# Using kubectl inside a build

**URL:** <https://drone.discourse.group/t/using-kubectl-inside-a-build/8384>\
**Category:** Drone Support\
**Created:** [April 3, 2019, 5:00pm UTC](https://drone.discourse.group/t/using-kubectl-inside-a-build/8384 "2019-04-03T17:00:57Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![malcolmholmes](https://avatars.discourse-cdn.com/v4/letter/m/e9a140/32.png) [@malcolmholmes](https://drone.discourse.group/u/malcolmholmes)\
**Post date:** [April 3, 2019, 5:00pm UTC](https://drone.discourse.group/t/using-kubectl-inside-a-build/8384/1 "2019-04-03T17:00:57Z")

</div>

I’m attempting to build out a simple CI/CD setup, within Drone 1.0 inside Kubernetes. Generally this is a lovely setup, but I have for the last while been battling with getting a call to `kubectl` to work, to actually deploy the build to our dev environment.

Can anyone recommend an approach to using kubectl inside a Drone build, running in k8s/GKE?

Thanks!

(my current issue is that if I run my kubectl container with `kubectl run`, it works as expected, but when run inside Drone it says `The connection to the server localhost:8080 was refused - did you specify the right host or port?` Do I really have to pass every connection envvar into kubectl? Why isn’t it picking them up when running in Drone?)

---

<div class="post-metadata">

**Author:** ![bradrydzewski](https://yyz1.discourse-cdn.com/flex003/user_avatar/drone.discourse.group/bradrydzewski/32/3513_2.png) [@bradrydzewski](https://drone.discourse.group/u/bradrydzewski)\
**Post date:** [April 3, 2019, 5:39pm UTC](https://drone.discourse.group/t/using-kubectl-inside-a-build/8384/2 "2019-04-03T17:39:21Z")

</div>

Please provide more information about how you installed Drone. Specifically are you using agents ([https://docs.drone.io/installation/github/multi-machine/](https://docs.drone.io/installation/github/multi-machine/)) or the native Kubernetes runtime ([https://docs.drone.io/installation/github/kubernetes/](https://docs.drone.io/installation/github/kubernetes/))?

---

<div class="post-metadata">

**Author:** ![malcolmholmes](https://avatars.discourse-cdn.com/v4/letter/m/e9a140/32.png) [@malcolmholmes](https://drone.discourse.group/u/malcolmholmes)\
**Post date:** [April 3, 2019, 5:55pm UTC](https://drone.discourse.group/t/using-kubectl-inside-a-build/8384/3 "2019-04-03T17:55:43Z")

</div>

I am using Kubernetes native runtime (it is an excellent approach).

I’m wondering if there is a simple image/config pair that I can use to just run `kubectl` in a build step, rather than the approach I’ve been taking.

Assuming not, let me describe what I’ve been doing.

Firstly, here’s my envvars:

```auto
      DRONE_SERVER_HOST: build.example.com
      DRONE_SERVER_PROTO: http
      DRONE_RPC_HOST: drone.build.svc.cluster.local
      DRONE_RPC_PROTO: http
      DRONE_KUBERNETES_ENABLED: true
      DRONE_KUBERNETES_NAMESPACE: build-jobs
      DRONE_KUBERNETES_SERVICE_ACCOUNT: build-pipeline
      DRONE_LOGS_DEBUG: true
      DRONE_USER_CREATE: username:<my-username>,admin:true
      DRONE_GITLAB_CLIENT_ID: XXXX
      DRONE_GITLAB_CLIENT_SECRET: XXXX
      DRONE_RPC_SECRET: XXXX

```

The image I am using is really nothing more than a wrapper around `kubectl` to allow me to run it inside a build.

When I run a pod manually (through kubectl run), I see a `/run/secrets/kubernetes.io/serviceaccount/token` file. However, when a job runs in Drone, that file is not present. I presume that will be needed for a job to be able to connect to the Kuberenetes API.

Also, having set the `DRONE_KUBERNETES_SERVICE_ACCOUNT`, that has been applied to the ‘job controller’ pods. However, the builds themselves, which fire up in randomised namespaces such as `e5vmbwh2nezkfk6dt2vsclbagupaf0wy` have a service account set to default.

I’m not sure if either of these are a problem.

Let me know if there are any other details I can provide.

---

<div class="post-metadata">

**Author:** ![ynilu](https://avatars.discourse-cdn.com/v4/letter/y/4da419/32.png) [@ynilu](https://drone.discourse.group/u/ynilu)\
**Post date:** [April 4, 2019, 4:00am UTC](https://drone.discourse.group/t/using-kubectl-inside-a-build/8384/4 "2019-04-04T04:00:12Z")

</div>

We had the same problem and decided to write a plugin for that.  
Try out our drone plugin [https://hub.docker.com/r/sinlead/drone-kubectl](https://hub.docker.com/r/sinlead/drone-kubectl)

---

<div class="post-metadata">

**Author:** ![malcolmholmes](https://avatars.discourse-cdn.com/v4/letter/m/e9a140/32.png) [@malcolmholmes](https://drone.discourse.group/u/malcolmholmes)\
**Post date:** [April 5, 2019, 7:17pm UTC](https://drone.discourse.group/t/using-kubectl-inside-a-build/8384/5 "2019-04-05T19:17:31Z")

</div>

Thanks, that is very helpful. Something weird going on with Drone truncating the command (by one character). Had to fork your plugin to be able to track it down ☹ Will post on a separate thread about that.

---

<div class="post-metadata">

**Author:** ![malikbenkirane](https://avatars.discourse-cdn.com/v4/letter/m/59ef9b/32.png) [@malikbenkirane](https://drone.discourse.group/u/malikbenkirane)\
**Post date:** [June 21, 2020, 6:25am UTC](https://drone.discourse.group/t/using-kubectl-inside-a-build/8384/6 "2020-06-21T06:25:15Z")

</div>

@malcolmholmes Thank you for this post, I didn’t found any doc about those KUBERNETES env vars and I’m stuck on `secrets is forbidden: User "system:serviceaccount:palight-dev:default" cannot create resource "secrets" in API group "" in the namespace "default"` although the pods are not in `default` namespace as well as the service account and it role bindings.

There is no reference in the docs but at least there is

> <https://github.com/drone/drone/blob/fcaea8f4eac4061d1def910440cac484e2f9d4b4/cmd/drone-server/config/config.go#L141-L150>

I’m wondering why for instance the namespace value is not set from `/var/run/secrets/kubernetes.io/serviceaccount/namespace`

_ **Also setting those envvars did not solved my issue.** _ Could this be rather related to drone-runners/drone-runner-kube ?

---

<div class="post-metadata">

**Author:** ![malikbenkirane](https://avatars.discourse-cdn.com/v4/letter/m/59ef9b/32.png) [@malikbenkirane](https://drone.discourse.group/u/malikbenkirane)\
**Post date:** [June 21, 2020, 2:36pm UTC](https://drone.discourse.group/t/using-kubectl-inside-a-build/8384/7 "2020-06-21T14:36:49Z")

</div>

As far I have gone with my investigation I cannot see how I could use the kubernetes runner outside namespace “default” as I didn’t figured out yet how I could have a role in “my-namespace”, a role binding to the default service account - for instance - and I need to create/delete secrets etc outside of “my-namespace”.

Again, setting DRONE\_KUBERNETES\_… environment variables does not change the behavior of the runner.

---

<div class="post-metadata">

**Author:** ![bradrydzewski](https://yyz1.discourse-cdn.com/flex003/user_avatar/drone.discourse.group/bradrydzewski/32/3513_2.png) [@bradrydzewski](https://drone.discourse.group/u/bradrydzewski)\
**Post date:** [June 21, 2020, 3:56pm UTC](https://drone.discourse.group/t/using-kubectl-inside-a-build/8384/8 "2020-06-21T15:56:38Z")

</div>

you can set the namespace in the yaml  
[https://docs.drone.io/pipeline/kubernetes/syntax/metadata/](https://docs.drone.io/pipeline/kubernetes/syntax/metadata/)

or you can set the default namespace globally:  
[https://docs.drone.io/runner/kubernetes/configuration/reference/drone-namespace-default/](https://docs.drone.io/runner/kubernetes/configuration/reference/drone-namespace-default/)

---

<div class="post-metadata">

**Author:** ![malikbenkirane](https://avatars.discourse-cdn.com/v4/letter/m/59ef9b/32.png) [@malikbenkirane](https://drone.discourse.group/u/malikbenkirane)\
**Post date:** [June 21, 2020, 6:29pm UTC](https://drone.discourse.group/t/using-kubectl-inside-a-build/8384/9 "2020-06-21T18:29:51Z")

</div>

Well, thank you for those references @bradrydzewski ! I feel I’ve got to dig the docs harder

_The second solution fits my needs._ So thank you again! This is a releaf.
