How do you port-forward to a pod with kubectl?
kubectl port-forward [pod] 8080:80 — Port forward
kubectl port-forward [pod] 8080:80 maps local port 8080 to port 80 inside the pod, so http://localhost:8080 reaches the container while the command runs. The first number is the local port, the second is the pod port.
Port-forward opens a tunnel from your localhost to the pod through the API server, so it works even when the pod's service is ClusterIP-only and unreachable from outside. The first number is your local port, the second the pod's - 8080:80 means localhost:8080 reaches the container's 80.
Forwarding to a service (kubectl port-forward svc/name) is usually more convenient than a pod - it survives pod restarts by re-resolving to a healthy endpoint when you reconnect. The tunnel lives only as long as the command runs; it is a debugging tool, not an ingress.
Related Kubernetes (kubectl) shortcuts: Manage Resources
| Shortcut | Action | Notes |
|---|---|---|
| kubectl apply -f [file] | Apply resource | Create/update resources from YAML. |
| kubectl delete pod [name] | Delete pod | Delete a pod. |
| kubectl scale deploy [name] --replicas=3 | Scale | Change deployment replica count. |
| kubectl exec -it [pod] -- bash | Enter pod | Open bash shell inside a pod. |
| kubectl port-forward [pod] 8080:80 | Port forward | Forward local port to pod port. |
| kubectl rollout restart deploy [name] | Rolling restart | Rolling restart a deployment. |
From the Kubernetes (kubectl) reference (17 entries) · all how-to answers
Ports, services and addresses
The first number is the local port and the second the port inside the pod; 8080:80 reaches container port 80 at localhost:8080, and a single number uses the same port on both sides. Forwarding to a Service — svc/my-service 8080:80 — is usually better than to a pod, because it keeps working when the pod is replaced. By default only localhost can connect; --address 0.0.0.0 exposes the forward on every interface, which is convenient on a jump host and dangerous on a laptop on public Wi-Fi.
It runs in the foreground
port-forward keeps running until Ctrl + C, and it dies with the terminal, so it belongs in a second terminal or a tmux window. It reconnects automatically if the pod restarts only in recent kubectl versions; on older ones the command exits with an error and must be rerun. Because the traffic goes through the API server, it is fine for debugging and wrong for anything with real throughput — that is what a Service or an Ingress is for.
Common failures
"Address already in use" means the local port is taken; pick another. "Connection refused" after the forward is established means the container is not listening on that port — check the container's port with kubectl describe pod or the Deployment spec. A pod that is not Running cannot be forwarded to at all.