How do you port-forward to a pod with kubectl?

Kubernetes (kubectl) · Manage Resources · updated 2026-08-23

kubectl port-forward [pod] 8080:80 — Port forward

kubectl port-forward [pod] 8080:80 maps local port 8080 to port 80 inside the pod, so http://localhost:8080 reaches the container while the command runs. The first number is the local port, the second is the pod port.

Port-forward opens a tunnel from your localhost to the pod through the API server, so it works even when the pod's service is ClusterIP-only and unreachable from outside. The first number is your local port, the second the pod's - 8080:80 means localhost:8080 reaches the container's 80.

Forwarding to a service (kubectl port-forward svc/name) is usually more convenient than a pod - it survives pod restarts by re-resolving to a healthy endpoint when you reconnect. The tunnel lives only as long as the command runs; it is a debugging tool, not an ingress.

Related Kubernetes (kubectl) shortcuts: Manage Resources

ShortcutActionNotes
kubectl apply -f [file]Apply resourceCreate/update resources from YAML.
kubectl delete pod [name]Delete podDelete a pod.
kubectl scale deploy [name] --replicas=3ScaleChange deployment replica count.
kubectl exec -it [pod] -- bashEnter podOpen bash shell inside a pod.
kubectl port-forward [pod] 8080:80Port forwardForward local port to pod port.
kubectl rollout restart deploy [name]Rolling restartRolling restart a deployment.

From the Kubernetes (kubectl) reference (17 entries) · all how-to answers

Ports, services and addresses

The first number is the local port and the second the port inside the pod; 8080:80 reaches container port 80 at localhost:8080, and a single number uses the same port on both sides. Forwarding to a Service — svc/my-service 8080:80 — is usually better than to a pod, because it keeps working when the pod is replaced. By default only localhost can connect; --address 0.0.0.0 exposes the forward on every interface, which is convenient on a jump host and dangerous on a laptop on public Wi-Fi.

It runs in the foreground

port-forward keeps running until Ctrl + C, and it dies with the terminal, so it belongs in a second terminal or a tmux window. It reconnects automatically if the pod restarts only in recent kubectl versions; on older ones the command exits with an error and must be rerun. Because the traffic goes through the API server, it is fine for debugging and wrong for anything with real throughput — that is what a Service or an Ingress is for.

Common failures

"Address already in use" means the local port is taken; pick another. "Connection refused" after the forward is established means the container is not listening on that port — check the container's port with kubectl describe pod or the Deployment spec. A pod that is not Running cannot be forwarded to at all.