On-call needs a chronological view of what happened in the permits namespace during an incident. Which approach helps reconstruct the timeline?
Select an answer to reveal the explanation.
Short Explanation
Incidents leave footprints in namespace Events—scheduled, pulled, killed, warned. Sorting with kubectl get events --sort-by=.lastTimestamp lays those footprints out in order. Don’t wipe Events before you’ve read the timeline.
Full Explanation
Kubernetes Events record notable state changes and warnings in a namespace. Listing them sorted by lastTimestamp helps operators reconstruct application incident sequences. Draining nodes, ignoring Events for registry digests alone, or deleting Events before analysis removes or skips valuable diagnostic context.