kubectl port-forward, to open an admin page, query a database or call an API that isn’t exposed. Forwards keep running while you work, listed in the header until you stop them.


Forwarding a local port to a service.
Start a forward
1
Open a pod or a service
A running pod, or a service that selects pods.
2
Choose Forward a port…
From the object’s actions, its right-click menu, or the command palette (⌘K, or CtrlK on Windows and Linux).
3
Pick the port
Pick one of the ports it declares, or type another:
- For a pod: each container’s ports, as container · name · port.
- For a service: its ports, as name · port → target port.
4
Start forwarding
Tick Open http://localhost:N in the browser to open it right away, then choose Start forwarding.
Your forwards
While any forward runs, a Port forwards button in the header shows how many. It lists the forwards of every cluster, each with:- Its address,
localhost:8080. Choose it to open it in your browser, or Copy address. - Where it goes: the service, the pod and the pod’s port, with the namespace and cluster.
- How many connections it has, and any error.
- Stop forwarding.
How it works
- Only on your computer. Forwards listen on
127.0.0.1, so nothing else on your network can reach them. - To a service’s pod. A forward to a service goes to the first of its pods that’s ready. A named target port is looked up in the pod’s containers. The pod is picked when the forward starts: if it’s replaced, start the forward again.
- Port in use. If the local port is taken, the dialog says so (“Port 8080 on this computer can’t be used”) and you pick another.
- Read-only clusters. Port forwards don’t change the cluster, so they work in read-only clusters too.
In your cluster: port forwarding isn’t offered when KubeStacks runs in your cluster, because there’s no computer of yours to forward to. Use the desktop app, or
kubectl port-forward.create on pods/portforward in the namespace. See Permissions.
Shells and debug containers
A terminal inside the container, or a debug container with tools.
Networking
Services, ingresses and network policies.