Kubernetes Specialist
When to Use This Skill
- Deploying workloads (Deployments, StatefulSets, DaemonSets, Jobs)
- Configuring networking (Services, Ingress, NetworkPolicies)
- Managing configuration (ConfigMaps, Secrets, environment variables)
- Setting up persistent storage (PV, PVC, StorageClasses)
- Creating Helm charts for application packaging
- Troubleshooting cluster and workload issues
- Implementing security best practices
Core Workflow
- Analyze requirements — Understand workload characteristics, scaling needs, security requirements
- Design architecture — Choose workload types, networking patterns, storage solutions
- Implement manifests — Create declarative YAML with proper resource limits, health checks
- Secure — Apply RBAC, NetworkPolicies, Pod Security Standards, least privilege
- Validate — Run
kubectl rollout status, kubectl get pods -w, and kubectl describe pod <name> to confirm health; roll back with kubectl rollout undo if needed
Reference Guide
Load detailed guidance based on context:
| Topic |
Reference |
Load When |
| Workloads |
references/workloads.md |
Deployments, StatefulSets, DaemonSets, Jobs, CronJobs |
| Networking |
references/networking.md |
Services, Ingress, NetworkPolicies, DNS |
| Configuration |
references/configuration.md |
ConfigMaps, Secrets, environment variables |
| Storage |
references/storage.md |
PV, PVC, StorageClasses, CSI drivers |
| Helm Charts |
references/helm-charts.md |
Chart structure, values, templates, hooks, testing, repositories |
| Troubleshooting |
references/troubleshooting.md |
kubectl debug, logs, events, common issues |
| Custom Operators |
references/custom-operators.md |
CRD, Operator SDK, controller-runtime, reconciliation |
| Service Mesh |
references/service-mesh.md |
Istio, Linkerd, traffic management, mTLS, canary |
| GitOps |
references/gitops.md |
ArgoCD, Flux, progressive delivery, sealed secrets |
| Cost Optimization |
references/cost-optimization.md |
VPA, HPA tuning, spot instances, quotas, right-sizing |
| Multi-Cluster |
references/multi-cluster.md |
Cluster API, federation, cross-cluster networking, DR |
Constraints
MUST DO
- Use declarative YAML manifests (avoid imperative kubectl commands)
- Set resource requests and limits on all containers
- Include liveness and readiness probes
- Use secrets for sensitive data (never hardcode credentials)
- Apply least privilege RBAC permissions
- Implement NetworkPolicies for network segmentation
- Use namespaces for logical isolation
- Label resources consistently for organization
- Document configuration decisions in annotations
MUST NOT DO
- Deploy to production without resource limits
- Store secrets in ConfigMaps or as plain environment variables
- Use default ServiceAccount for application pods
- Allow unrestricted network access (default allow-all)
- Run containers as root without justification
- Skip health checks (liveness/readiness probes)
- Use latest tag for production images
- Expose unnecessary ports or services
Common YAML Patterns
Deployment with resource limits, probes, and security context
apiVersion: apps/v1
kind: Deployment
metadata:
name: my-app
namespace: my-namespace
labels:
app: my-app
version: "1.2.3"
spec:
replicas: 3
selector:
matchLabels:
app: my-app
template:
metadata:
labels:
app: my-app
version: "1.2.3"
spec:
serviceAccountName: my-app-sa # never use default SA
securityContext:
runAsNonRoot: true
runAsUser: 1000
fsGroup: 2000
containers:
- name: my-app
image: my-registry/my-app:1.2.3 # never use latest
ports:
- containerPort: 8080
resources:
requests:
cpu: "100m"
memory: "128Mi"
limits:
cpu: "500m"
memory: "512Mi"
livenessProbe:
httpGet:
path: /healthz
port: 8080
initialDelaySeconds: 15
periodSeconds: 20
readinessProbe:
httpGet:
path: /ready
port: 8080
initialDelaySeconds: 5
periodSeconds: 10
securityContext:
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
capabilities:
drop: ["ALL"]
envFrom:
- secretRef:
name: my-app-secret # pull credentials from Secret, not ConfigMap
Minimal RBAC (least privilege)
apiVersion: v1
kind: ServiceAccount
metadata:
name: my-app-sa
namespace: my-namespace
---
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
name: my-app-role
namespace: my-namespace
rules:
- apiGroups: [""]
resources: ["configmaps"]
verbs: ["get", "list"] # grant only what is needed
---
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: my-app-rolebinding
namespace: my-namespace
subjects:
- kind: ServiceAccount
name: my-app-sa
namespace: my-namespace
roleRef:
kind: Role
name: my-app-role
apiGroup: rbac.authorization.k8s.io
NetworkPolicy (default-deny + explicit allow)
# Deny all ingress and egress by default
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: default-deny-all
namespace: my-namespace
spec:
podSelector: {}
policyTypes: ["Ingress", "Egress"]
---
# Allow only specific traffic
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: allow-my-app
namespace: my-namespace
spec:
podSelector:
matchLabels:
app: my-app
policyTypes: ["Ingress"]
ingress:
- from:
- podSelector:
matchLabels:
app: frontend
ports:
- protocol: TCP
port: 8080
Validation Commands
After deploying, verify health and security posture:
# Watch rollout complete
kubectl rollout status deployment/my-app -n my-namespace
# Stream pod events to catch crash loops or image pull errors
kubectl get pods -n my-namespace -w
# Inspect a specific pod for failures
kubectl describe pod <pod-name> -n my-namespace
# Check container logs
kubectl logs <pod-name> -n my-namespace --previous # use --previous for crashed containers
# Verify resource usage vs. limits
kubectl top pods -n my-namespace
# Audit RBAC permissions for a service account
kubectl auth can-i --list --as=system:serviceaccount:my-namespace:my-app-sa
# Roll back a failed deployment
kubectl rollout undo deployment/my-app -n my-namespace
Output Templates
When implementing Kubernetes resources, provide:
- Complete YAML manifests with proper structure
- RBAC configuration if needed (ServiceAccount, Role, RoleBinding)
- NetworkPolicy for network isolation
- Brief explanation of design decisions and security considerations
1---2name: kubernetes-specialist3description: Use when deploying or managing Kubernetes workloads. Invoke to create deployment manifests, configure pod security policies, set up service accounts, define network isolation rules, debug pod crashes, analyze resource limits, inspect container logs, or right-size workloads. Use for Helm charts, RBAC policies, NetworkPolicies, storage configuration, performance optimization, GitOps pipelines, and multi-cluster management.4license: MIT5---6
7# Kubernetes Specialist
8
9## When to Use This Skill
10
11- Deploying workloads (Deployments, StatefulSets, DaemonSets, Jobs)
12- Configuring networking (Services, Ingress, NetworkPolicies)
13- Managing configuration (ConfigMaps, Secrets, environment variables)
14- Setting up persistent storage (PV, PVC, StorageClasses)
15- Creating Helm charts for application packaging
16- Troubleshooting cluster and workload issues
17- Implementing security best practices
18
19## Core Workflow
20
211. **Analyze requirements** — Understand workload characteristics, scaling needs, security requirements
222. **Design architecture** — Choose workload types, networking patterns, storage solutions
233. **Implement manifests** — Create declarative YAML with proper resource limits, health checks
244. **Secure** — Apply RBAC, NetworkPolicies, Pod Security Standards, least privilege
255. **Validate** — Run `kubectl rollout status`, `kubectl get pods -w`, and `kubectl describe pod <name>` to confirm health; roll back with `kubectl rollout undo` if needed
26
27## Reference Guide
28
29Load detailed guidance based on context:
30
31| Topic | Reference | Load When |
32|-------|-----------|-----------|
33| Workloads | `references/workloads.md` | Deployments, StatefulSets, DaemonSets, Jobs, CronJobs |
34| Networking | `references/networking.md` | Services, Ingress, NetworkPolicies, DNS |
35| Configuration | `references/configuration.md` | ConfigMaps, Secrets, environment variables |
36| Storage | `references/storage.md` | PV, PVC, StorageClasses, CSI drivers |
37| Helm Charts | `references/helm-charts.md` | Chart structure, values, templates, hooks, testing, repositories |
38| Troubleshooting | `references/troubleshooting.md` | kubectl debug, logs, events, common issues |
39| Custom Operators | `references/custom-operators.md` | CRD, Operator SDK, controller-runtime, reconciliation |
40| Service Mesh | `references/service-mesh.md` | Istio, Linkerd, traffic management, mTLS, canary |
41| GitOps | `references/gitops.md` | ArgoCD, Flux, progressive delivery, sealed secrets |
42| Cost Optimization | `references/cost-optimization.md` | VPA, HPA tuning, spot instances, quotas, right-sizing |
43| Multi-Cluster | `references/multi-cluster.md` | Cluster API, federation, cross-cluster networking, DR |
44
45## Constraints
46
47### MUST DO
48- Use declarative YAML manifests (avoid imperative kubectl commands)
49- Set resource requests and limits on all containers
50- Include liveness and readiness probes
51- Use secrets for sensitive data (never hardcode credentials)
52- Apply least privilege RBAC permissions
53- Implement NetworkPolicies for network segmentation
54- Use namespaces for logical isolation
55- Label resources consistently for organization
56- Document configuration decisions in annotations
57
58### MUST NOT DO
59- Deploy to production without resource limits
60- Store secrets in ConfigMaps or as plain environment variables
61- Use default ServiceAccount for application pods
62- Allow unrestricted network access (default allow-all)
63- Run containers as root without justification
64- Skip health checks (liveness/readiness probes)
65- Use latest tag for production images
66- Expose unnecessary ports or services
67
68## Common YAML Patterns
69
70### Deployment with resource limits, probes, and security context
71
72```yaml
73apiVersion: apps/v1
74kind: Deployment
75metadata:
76 name: my-app
77 namespace: my-namespace
78 labels:
79 app: my-app
80 version: "1.2.3"
81spec:
82 replicas: 3
83 selector:
84 matchLabels:
85 app: my-app
86 template:
87 metadata:
88 labels:
89 app: my-app
90 version: "1.2.3"
91 spec:
92 serviceAccountName: my-app-sa # never use default SA
93 securityContext:
94 runAsNonRoot: true
95 runAsUser: 1000
96 fsGroup: 2000
97 containers:
98 - name: my-app
99 image: my-registry/my-app:1.2.3 # never use latest
100 ports:
101 - containerPort: 8080
102 resources:
103 requests:
104 cpu: "100m"
105 memory: "128Mi"
106 limits:
107 cpu: "500m"
108 memory: "512Mi"
109 livenessProbe:
110 httpGet:
111 path: /healthz
112 port: 8080
113 initialDelaySeconds: 15
114 periodSeconds: 20
115 readinessProbe:
116 httpGet:
117 path: /ready
118 port: 8080
119 initialDelaySeconds: 5
120 periodSeconds: 10
121 securityContext:
122 allowPrivilegeEscalation: false
123 readOnlyRootFilesystem: true
124 capabilities:
125 drop: ["ALL"]
126 envFrom:
127 - secretRef:
128 name: my-app-secret # pull credentials from Secret, not ConfigMap
129```
130
131### Minimal RBAC (least privilege)
132
133```yaml
134apiVersion: v1
135kind: ServiceAccount
136metadata:
137 name: my-app-sa
138 namespace: my-namespace
139---
140apiVersion: rbac.authorization.k8s.io/v1
141kind: Role
142metadata:
143 name: my-app-role
144 namespace: my-namespace
145rules:
146 - apiGroups: [""]
147 resources: ["configmaps"]
148 verbs: ["get", "list"] # grant only what is needed
149---
150apiVersion: rbac.authorization.k8s.io/v1
151kind: RoleBinding
152metadata:
153 name: my-app-rolebinding
154 namespace: my-namespace
155subjects:
156 - kind: ServiceAccount
157 name: my-app-sa
158 namespace: my-namespace
159roleRef:
160 kind: Role
161 name: my-app-role
162 apiGroup: rbac.authorization.k8s.io
163```
164
165### NetworkPolicy (default-deny + explicit allow)
166
167```yaml
168# Deny all ingress and egress by default
169apiVersion: networking.k8s.io/v1
170kind: NetworkPolicy
171metadata:
172 name: default-deny-all
173 namespace: my-namespace
174spec:
175 podSelector: {}
176 policyTypes: ["Ingress", "Egress"]
177---
178# Allow only specific traffic
179apiVersion: networking.k8s.io/v1
180kind: NetworkPolicy
181metadata:
182 name: allow-my-app
183 namespace: my-namespace
184spec:
185 podSelector:
186 matchLabels:
187 app: my-app
188 policyTypes: ["Ingress"]
189 ingress:
190 - from:
191 - podSelector:
192 matchLabels:
193 app: frontend
194 ports:
195 - protocol: TCP
196 port: 8080
197```
198
199## Validation Commands
200
201After deploying, verify health and security posture:
202
203```bash
204# Watch rollout complete
205kubectl rollout status deployment/my-app -n my-namespace
206
207# Stream pod events to catch crash loops or image pull errors
208kubectl get pods -n my-namespace -w
209
210# Inspect a specific pod for failures
211kubectl describe pod <pod-name> -n my-namespace
212
213# Check container logs
214kubectl logs <pod-name> -n my-namespace --previous # use --previous for crashed containers
215
216# Verify resource usage vs. limits
217kubectl top pods -n my-namespace
218
219# Audit RBAC permissions for a service account
220kubectl auth can-i --list --as=system:serviceaccount:my-namespace:my-app-sa
221
222# Roll back a failed deployment
223kubectl rollout undo deployment/my-app -n my-namespace
224```
225
226## Output Templates
227
228When implementing Kubernetes resources, provide:
2291. Complete YAML manifests with proper structure
2302. RBAC configuration if needed (ServiceAccount, Role, RoleBinding)
2313. NetworkPolicy for network isolation
2324. Brief explanation of design decisions and security considerations