Kubernetes Patterns
Production-grade Kubernetes patterns for deploying, managing, and debugging workloads reliably.
When to Activate
- Writing Kubernetes manifests (Deployments, Services, Ingress, Jobs)
- Configuring resource requests/limits, liveness/readiness probes
- Setting up RBAC, namespaces, or ServiceAccounts
- Managing configuration and secrets in K8s
- Debugging CrashLoopBackOff, OOMKilled, pending pods, or image pull errors
- Configuring HPA (Horizontal Pod Autoscaler) or PodDisruptionBudgets
- Reviewing K8s YAML for security or correctness
When to Use
Same as When to Activate above. This alias satisfies repo skill-format conventions. Use this skill any time you are writing, reviewing, or debugging Kubernetes YAML and workloads.
How It Works
This skill provides copy-pasteable, production-grade YAML patterns and kubectl debugging commands organized by task:
- Deployment template — A fully configured production
Deploymentwith security context, rolling update strategy, all three probe types, resource limits, and environment injection from ConfigMap/Secret. - Probes — Decision table for startup vs liveness vs readiness, with correct
failureThreshold × periodSecondsmath. - Services & Ingress — ClusterIP, LoadBalancer, and TLS Ingress patterns with cert-manager annotations.
- ConfigMaps & Secrets —
envFrom, file-mount, and external secrets guidance. - Resource management — Requests vs limits rules of thumb by workload type (web API, JVM, worker, sidecar).
- RBAC — Least-privilege ServiceAccount → Role → RoleBinding chain.
- HPA & PDB — Autoscaling and node-drain safety configurations.
- Jobs & CronJobs — One-off and scheduled workload patterns with correct
restartPolicy. - kubectl cheatsheet — Logs, exec, rollback, port-forward, dry-run, and common error diagnosis commands.
- Anti-patterns & checklist — What NOT to do, and a security/reliability/observability checklist.
Examples
See the sections below for complete, runnable examples. Quick references:
Core Workload Patterns
Deployment — Production Template
Probes — Liveness, Readiness, Startup
Understanding when to use each probe is critical:
Services and Ingress
Service Types
Ingress with TLS
ConfigMaps and Secrets
ConfigMap — Non-sensitive configuration
Secrets — Sensitive data
Important: Raw Kubernetes Secrets are only base64-encoded, not encrypted at rest unless your cluster has encryption configured. Use Sealed Secrets or External Secrets Operator for production.
Resource Requests and Limits
Rules of thumb:
RBAC — Roles and ServiceAccounts
Principle of Least Privilege
Two patterns depending on whether the app calls the Kubernetes API:
Pattern A — App does NOT need the Kubernetes API (most apps)
Disable token automounting on the ServiceAccount. The Role/RoleBinding are not needed.
Pattern B — App DOES need the Kubernetes API (operators, controllers, config watchers)
Enable the token and grant only the permissions actually required.
Horizontal Pod Autoscaler (HPA)
HPA requires
resources.requeststo be set on all containers — it calculates utilization ascurrent / request.
PodDisruptionBudget (PDB)
Prevent too many pods going down during node drains or rolling updates:
Namespaces and Multi-Tenancy
Jobs and CronJobs
kubectl Debugging Cheatsheet
Diagnosing Common Errors
Anti-Patterns
Best Practices Checklist
Security
- Container runs as non-root (
runAsNonRoot: true,runAsUserset) -
readOnlyRootFilesystem: truewithemptyDirfor writable paths -
allowPrivilegeEscalation: false - All capabilities dropped (
capabilities.drop: [ALL]) - Dedicated ServiceAccount per app, not
default -
automountServiceAccountToken: falseunless needed - RBAC follows least privilege (use
Role, notClusterRoleunless needed) - Secrets managed via Sealed Secrets or External Secrets Operator
Reliability
- All 3 probe types configured (startup + liveness + readiness)
- Resource requests AND limits set on every container
-
minReplicas: 2+for any production workload - PodDisruptionBudget defined for stateful or critical services
-
RollingUpdatestrategy withmaxUnavailable: 0 - HPA configured for variable-load services
Observability
- App exposes
/health(liveness) and/ready(readiness) endpoints - Structured JSON logging (no PII in logs)
- Resource labels:
app,version,environment
Related Skills
docker-patterns— Multi-stage Dockerfiles and image securitydeployment-patterns— CI/CD pipelines, rollback strategy, health check endpointssecurity-review— Broader security hardening contextgit-workflow— GitOps integration with K8s (ArgoCD / Flux patterns)


