
Security News
OWASP 2025 Top 10 Adds Software Supply Chain Failures, Ranked Top Community Concern
OWASP’s 2025 Top 10 introduces Software Supply Chain Failures as a new category, reflecting rising concern over dependency and build system risks.
@kubernetes/client-node
Advanced tools
The Javascript clients for Kubernetes is implemented in typescript, but can be called from either Javascript or Typescript. The client is implemented for server-side use with Node.
npm install @kubernetes/client-node
const k8s = require('@kubernetes/client-node');
const kc = new k8s.KubeConfig();
kc.loadFromDefault();
const k8sApi = kc.makeApiClient(k8s.CoreV1Api);
k8sApi.listNamespacedPod({ namespace: 'default' }).then((res) => {
console.log(res);
});
const k8s = require('@kubernetes/client-node');
const kc = new k8s.KubeConfig();
kc.loadFromDefault();
const k8sApi = kc.makeApiClient(k8s.CoreV1Api);
var namespace = {
metadata: {
name: 'test',
},
};
k8sApi.createNamespace({ body: namespace }).then(
(response) => {
console.log('Created namespace');
console.log(response);
k8sApi.readNamespace(namespace.metadata.name).then((response) => {
console.log(response);
k8sApi.deleteNamespace(namespace.metadata.name, {} /* delete options */);
});
},
(err) => {
console.log('Error!: ' + err);
},
);
const k8s = require('@kubernetes/client-node');
const cluster = {
name: 'my-server',
server: 'http://server.com',
};
const user = {
name: 'my-user',
password: 'some-password',
};
const context = {
name: 'my-context',
user: user.name,
cluster: cluster.name,
};
const kc = new k8s.KubeConfig();
kc.loadFromOptions({
clusters: [cluster],
users: [user],
contexts: [context],
currentContext: context.name,
});
const k8sApi = kc.makeApiClient(k8s.CoreV1Api);
...
There are several more JS and TS examples in the examples directory.
Documentation for the library is split into two resources:
Prior to the 0.13.0 release, release versions did not track Kubernetes versions. Starting with the 0.13.0
release, we will increment the minor version whenever we update the minor Kubernetes API version
(e.g. 1.19.x) that this library is generated from.
We switched from request to fetch as the HTTP(S) backend for the 1.0.0 release.
Generally speaking newer clients will work with older Kubernetes, but compatibility isn't 100% guaranteed.
| client version | older versions | 1.28 | 1.29 | 1.30 | 1.31 | 1.32 | 1.33 |
|---|---|---|---|---|---|---|---|
| 0.19.x | - | ✓ | x | x | x | x | x |
| 0.20.x | - | + | ✓ | x | x | x | x |
| 0.21.x | - | + | + | ✓ | x | x | x |
| 0.22.x | - | + | + | + | ✓ | x | x |
| 1.0.x | - | + | + | + | + | ✓ | x |
| 1.1.x | - | + | + | + | + | ✓ | x |
| 1.2.x | - | + | + | + | + | + | ✓ |
Key:
✓ Exactly the same features / API objects in both javascript-client and the Kubernetes
version.+ javascript-client has features or api objects that may not be present in the
Kubernetes cluster, but everything they have in common will work.- The Kubernetes cluster has features the javascript-client library can't use
(additional API objects, etc).x The Kubernetes cluster has no guarantees to support the API client of
this version, as it only promises n-2 version support. It is not tested,
and operations using API versions that have been deprecated and removed in
later server versions won't function correctly.Multiple kubeconfigs are not completely supported. Credentials are cached based on the kubeconfig username and these can collide across configs. Here is the related issue.
In scenarios where multiple headers with the same key are required in a request, such as Impersonate-Group, avoid using fetch. Fetch will merge the values into a single header key, with the values as a single string vs a list of strings, Impersonate-Group: "group1,group2". The workaround is to use a low-level library such as https to make the request. Refer to issue #2474 for more details.
All dependencies of this project are expressed in its
package.json file. Before you start developing, ensure
that you have NPM installed, then run:
npm install
npm run generate
Documentation is generated via typedoc:
npm run docs
To view the generated documentation, open docs/index.html
Run npm run format or install an editor plugin like https://github.com/prettier/prettier-vscode and https://marketplace.visualstudio.com/items?itemName=EditorConfig.EditorConfig
Run npm run lint or install an editor plugin.
Tests are written using the node:test test runner and
node:assert assertion library. See
config_test.ts for an example.
To run tests, execute the following:
npm test
Please see CONTRIBUTING.md for instructions on how to contribute.
The 'kubernetes-client' package, also known as 'node-kubernetes-client', is another Node.js client for Kubernetes. It provides similar functionalities to @kubernetes/client-node, such as managing Kubernetes resources and performing CRUD operations. However, it is not an official client library and may have different API conventions and support.
The 'k8s' package is a lightweight Kubernetes client for Node.js. It offers basic functionalities for interacting with Kubernetes clusters, such as listing, creating, and deleting resources. Compared to @kubernetes/client-node, it is simpler and may lack some advanced features but can be easier to use for basic tasks.
FAQs
NodeJS client for kubernetes
The npm package @kubernetes/client-node receives a total of 848,356 weekly downloads. As such, @kubernetes/client-node popularity was classified as popular.
We found that @kubernetes/client-node demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
OWASP’s 2025 Top 10 introduces Software Supply Chain Failures as a new category, reflecting rising concern over dependency and build system risks.

Research
/Security News
Socket researchers discovered nine malicious NuGet packages that use time-delayed payloads to crash applications and corrupt industrial control systems.

Security News
Socket CTO Ahmad Nassri discusses why supply chain attacks now target developer machines and what AI means for the future of enterprise security.